1200KM · ANDREY PAUTOV
Home · Article · Ten reports · Screenshot gallery · Publication boundaries

Measured 19 September 2026 · Public derivative · Historical training evidence, not approved threat intelligence.

AdversaryGraph Deterministic PCAP Analysis

Source: 2022-02-23-traffic-analysis-exercise.pcap Capture SHA-256: eefc7e61b50e7846f5a3282d7645539d7b2b4b85aa08a09d0b823896c9449d1f Semantic result SHA-256: 8a329890ed01eedca67808c92bdfa492463b036b435540749e5ff2e599d7deee Analyzer manifest SHA-256: ee952aeb7cdc6958f4ae5178c54c274a1e4f0aec4d42f3bdb95baaff063b3dde

Executive summary

Decoded 30023 packets across 143 IP endpoints and 809 transport flows. Observed 499 DNS events, 43 HTTP requests, 111 TLS ClientHello events, and 500 exported HTTP object(s). Deterministic rules produced 57 finding(s): 0 high, 39 medium, and 18 low. Findings are evidence-bound candidates and require analyst review; encrypted payload contents remain unavailable.

Capture facts

Deterministic findings

MEDIUM — Script, archive, or executable transfer candidate

HTTP metadata names a script, archive, or executable. This is a transfer candidate, not proof of file type, execution, or malicious intent; legitimate updates use the same formats.

Rule: script-or-executable-transfer@pcap-rules-v3; confidence: 0.86; evidence: frame 3995 / TCP stream 186, frame 4675 / TCP stream 186.

Metrics: {"content_type":"application/x-msdownload","declared_body_bytes":593920,"destination":"172.16.0.149","response_count":1,"source":"64.34.171.228","uri":"/c7g8t/zbBYgukXYxzAF2hZc/"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 178 / TCP stream 8, frame 180 / TCP stream 8, frame 182 / TCP stream 8, frame 184 / TCP stream 8, frame 1710 / TCP stream 8.

Metrics: {"destination":"172.16.0.52","event_count":8,"operation_numbers":["0","1","12"],"protocol":"drsuapi","source":"172.16.0.131"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 100 / TCP stream 5, frame 117 / TCP stream 5, frame 120 / TCP stream 5, frame 212 / TCP stream 13, frame 229 / TCP stream 13.

Metrics: {"destination":"172.16.0.52","event_count":41,"operation_numbers":["","0","2","3"],"protocol":"ldap","source":"172.16.0.131"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 1785 / TCP stream 87, frame 1787 / TCP stream 87, frame 1790 / TCP stream 87, frame 1793 / TCP stream 87, frame 1795 / TCP stream 87.

Metrics: {"destination":"172.16.0.52","event_count":15,"operation_numbers":["1","16","17","3","34","36","39","5","6","64","7"],"protocol":"samr","source":"172.16.0.131"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 2143 / TCP stream 101, frame 2159 / TCP stream 101, frame 2162 / TCP stream 101, frame 2168 / TCP stream 101, frame 2214 / TCP stream 111.

Metrics: {"destination":"172.16.0.52","event_count":53,"operation_numbers":["0","1","12","13"],"protocol":"drsuapi","source":"172.16.0.149"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 1944 / TCP stream 94, frame 2015 / TCP stream 94, frame 2018 / TCP stream 94, frame 2055 / TCP stream 102, frame 2091 / TCP stream 102.

Metrics: {"destination":"172.16.0.52","event_count":103,"operation_numbers":["","0","2","3"],"protocol":"ldap","source":"172.16.0.149"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 2867 / TCP stream 95, frame 2869 / TCP stream 95, frame 2871 / TCP stream 95, frame 2873 / TCP stream 95, frame 2875 / TCP stream 95.

Metrics: {"destination":"172.16.0.52","event_count":15,"operation_numbers":["1","16","17","3","34","36","39","5","6","64","7"],"protocol":"samr","source":"172.16.0.149"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 746 / TCP stream 43, frame 748 / TCP stream 43, frame 750 / TCP stream 43, frame 752 / TCP stream 43, frame 784 / TCP stream 45.

Metrics: {"destination":"172.16.0.52","event_count":53,"operation_numbers":["0","1","12","13"],"protocol":"drsuapi","source":"172.16.0.170"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 577 / TCP stream 32, frame 618 / TCP stream 35, frame 673 / TCP stream 35, frame 682 / TCP stream 35, frame 684 / TCP stream 35.

Metrics: {"destination":"172.16.0.52","event_count":98,"operation_numbers":["","0","2","3"],"protocol":"ldap","source":"172.16.0.170"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 1424 / TCP stream 31, frame 1430 / TCP stream 31, frame 1435 / TCP stream 31, frame 1437 / TCP stream 31, frame 1439 / TCP stream 31.

Metrics: {"destination":"172.16.0.52","event_count":15,"operation_numbers":["1","16","17","3","34","36","39","5","6","64","7"],"protocol":"samr","source":"172.16.0.170"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 179 / TCP stream 8, frame 181 / TCP stream 8, frame 183 / TCP stream 8, frame 185 / TCP stream 8, frame 1711 / TCP stream 8.

Metrics: {"destination":"172.16.0.131","event_count":8,"operation_numbers":["0","1","12"],"protocol":"drsuapi","source":"172.16.0.52"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 102 / TCP stream 5, frame 119 / TCP stream 5, frame 214 / TCP stream 13, frame 231 / TCP stream 13, frame 233 / TCP stream 13.

Metrics: {"destination":"172.16.0.131","event_count":33,"operation_numbers":["","1","4,19,19,19,5","4,5","5"],"protocol":"ldap","source":"172.16.0.52"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 1786 / TCP stream 87, frame 1788 / TCP stream 87, frame 1792 / TCP stream 87, frame 1794 / TCP stream 87, frame 1796 / TCP stream 87.

Metrics: {"destination":"172.16.0.131","event_count":15,"operation_numbers":["1","16","17","3","34","36","39","5","6","64","7"],"protocol":"samr","source":"172.16.0.52"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 2147 / TCP stream 101, frame 2161 / TCP stream 101, frame 2164 / TCP stream 101, frame 2169 / TCP stream 101, frame 2215 / TCP stream 111.

Metrics: {"destination":"172.16.0.149","event_count":53,"operation_numbers":["0","1","12","13"],"protocol":"drsuapi","source":"172.16.0.52"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 1946 / TCP stream 94, frame 2017 / TCP stream 94, frame 2057 / TCP stream 102, frame 2093 / TCP stream 102, frame 2099 / TCP stream 102.

Metrics: {"destination":"172.16.0.149","event_count":83,"operation_numbers":["","1","4,19,19,19,5","4,5","5"],"protocol":"ldap","source":"172.16.0.52"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 2868 / TCP stream 95, frame 2870 / TCP stream 95, frame 2872 / TCP stream 95, frame 2874 / TCP stream 95, frame 2876 / TCP stream 95.

Metrics: {"destination":"172.16.0.149","event_count":15,"operation_numbers":["1","16","17","3","34","36","39","5","6","64","7"],"protocol":"samr","source":"172.16.0.52"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 747 / TCP stream 43, frame 749 / TCP stream 43, frame 751 / TCP stream 43, frame 753 / TCP stream 43, frame 785 / TCP stream 45.

Metrics: {"destination":"172.16.0.170","event_count":53,"operation_numbers":["0","1","12","13"],"protocol":"drsuapi","source":"172.16.0.52"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 579 / TCP stream 32, frame 620 / TCP stream 35, frame 681 / TCP stream 35, frame 683 / TCP stream 35, frame 686 / TCP stream 35.

Metrics: {"destination":"172.16.0.170","event_count":79,"operation_numbers":["","1","4,19,19,19,5","4,5","5"],"protocol":"ldap","source":"172.16.0.52"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 1427 / TCP stream 31, frame 1433 / TCP stream 31, frame 1436 / TCP stream 31, frame 1438 / TCP stream 31, frame 1440 / TCP stream 31.

Metrics: {"destination":"172.16.0.170","event_count":15,"operation_numbers":["1","16","17","3","34","36","39","5","6","64","7"],"protocol":"samr","source":"172.16.0.52"}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 4679 / TCP stream 187.

Metrics: {"destination":"135.148.121.246","destination_port":8080,"duration_seconds":52.845,"packets":127,"source":"172.16.0.149","wire_bytes":87055}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 4802 / TCP stream 188.

Metrics: {"destination":"135.148.121.246","destination_port":8080,"duration_seconds":96.025,"packets":19,"source":"172.16.0.149","wire_bytes":2721}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 5068 / TCP stream 198.

Metrics: {"destination":"135.148.121.246","destination_port":8080,"duration_seconds":47.78,"packets":19,"source":"172.16.0.149","wire_bytes":2517}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 6688 / TCP stream 203.

Metrics: {"destination":"27.254.174.84","destination_port":8080,"duration_seconds":60.005,"packets":117,"source":"172.16.0.170","wire_bytes":86156}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 6805 / TCP stream 204.

Metrics: {"destination":"27.254.174.84","destination_port":8080,"duration_seconds":104.051,"packets":20,"source":"172.16.0.170","wire_bytes":3034}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 7688 / TCP stream 213.

Metrics: {"destination":"27.254.174.84","destination_port":8080,"duration_seconds":49.984,"packets":18,"source":"172.16.0.170","wire_bytes":2793}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 7719 / TCP stream 214.

Metrics: {"destination":"135.148.121.246","destination_port":8080,"duration_seconds":46.582,"packets":19,"source":"172.16.0.149","wire_bytes":2755}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 7792 / TCP stream 216.

Metrics: {"destination":"27.254.174.84","destination_port":8080,"duration_seconds":41.718,"packets":76,"source":"172.16.0.170","wire_bytes":54377}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 8729 / TCP stream 221.

Metrics: {"destination":"135.148.121.246","destination_port":8080,"duration_seconds":51.375,"packets":412,"source":"172.16.0.149","wire_bytes":320581}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 9146 / TCP stream 222.

Metrics: {"destination":"135.148.121.246","destination_port":8080,"duration_seconds":76.16,"packets":19,"source":"172.16.0.149","wire_bytes":3342}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 9331 / TCP stream 227.

Metrics: {"destination":"168.197.250.14","destination_port":80,"duration_seconds":117.001,"packets":559,"source":"172.16.0.170","wire_bytes":492888}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 10803 / TCP stream 236.

Metrics: {"destination":"168.197.250.14","destination_port":80,"duration_seconds":66.043,"packets":21,"source":"172.16.0.170","wire_bytes":3237}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 10835 / TCP stream 237.

Metrics: {"destination":"135.148.121.246","destination_port":8080,"duration_seconds":61.284,"packets":117,"source":"172.16.0.149","wire_bytes":89737}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 10946 / TCP stream 238.

Metrics: {"destination":"135.148.121.246","destination_port":8080,"duration_seconds":61.474,"packets":21,"source":"172.16.0.149","wire_bytes":3151}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 11650 / TCP stream 247.

Metrics: {"destination":"135.148.121.246","destination_port":8080,"duration_seconds":46.562,"packets":412,"source":"172.16.0.149","wire_bytes":340415}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 11743 / TCP stream 249.

Metrics: {"destination":"168.197.250.14","destination_port":80,"duration_seconds":95.062,"packets":19,"source":"172.16.0.170","wire_bytes":2986}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 12139 / TCP stream 251.

Metrics: {"destination":"135.148.121.246","destination_port":8080,"duration_seconds":44.834,"packets":19,"source":"172.16.0.149","wire_bytes":3271}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 13103 / TCP stream 261.

Metrics: {"destination":"135.148.121.246","destination_port":8080,"duration_seconds":48.149,"packets":19,"source":"172.16.0.149","wire_bytes":2678}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 13119 / TCP stream 262.

Metrics: {"destination":"168.197.250.14","destination_port":80,"duration_seconds":79.426,"packets":19,"source":"172.16.0.170","wire_bytes":3058}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 13219 / TCP stream 268.

Metrics: {"destination":"168.197.250.14","destination_port":80,"duration_seconds":94.94,"packets":398,"source":"172.16.0.170","wire_bytes":319970}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 13452 / TCP stream 272.

Metrics: {"destination":"135.148.121.246","destination_port":8080,"duration_seconds":49.955,"packets":132,"source":"172.16.0.149","wire_bytes":101806}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 13684 / TCP stream 274.

Metrics: {"destination":"135.148.121.246","destination_port":8080,"duration_seconds":55.29,"packets":19,"source":"172.16.0.149","wire_bytes":2461}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 14063 / TCP stream 281.

Metrics: {"destination":"168.197.250.14","destination_port":80,"duration_seconds":90.205,"packets":19,"source":"172.16.0.170","wire_bytes":2359}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 14528 / TCP stream 293.

Metrics: {"destination":"168.197.250.14","destination_port":80,"duration_seconds":34.782,"packets":21,"source":"172.16.0.170","wire_bytes":4464}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 14623 / TCP stream 298.

Metrics: {"destination":"168.197.250.14","destination_port":80,"duration_seconds":40.858,"packets":201,"source":"172.16.0.170","wire_bytes":159636}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 16159 / TCP stream 306.

Metrics: {"destination":"162.144.76.184","destination_port":8080,"duration_seconds":32.803,"packets":767,"source":"172.16.0.170","wire_bytes":545561}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 17066 / TCP stream 311.

Metrics: {"destination":"128.199.93.156","destination_port":8080,"duration_seconds":36.477,"packets":767,"source":"172.16.0.170","wire_bytes":546358}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 18531 / TCP stream 324.

Metrics: {"destination":"135.148.121.246","destination_port":8080,"duration_seconds":51.515,"packets":422,"source":"172.16.0.149","wire_bytes":342682}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 18949 / TCP stream 325.

Metrics: {"destination":"135.148.121.246","destination_port":8080,"duration_seconds":83.461,"packets":19,"source":"172.16.0.149","wire_bytes":2922}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 19849 / TCP stream 329.

Metrics: {"destination":"135.148.121.246","destination_port":8080,"duration_seconds":35.196,"packets":19,"source":"172.16.0.149","wire_bytes":2531}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 20080 / TCP stream 333.

Metrics: {"destination":"135.148.121.246","destination_port":8080,"duration_seconds":85.095,"packets":19,"source":"172.16.0.149","wire_bytes":3198}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 20948 / TCP stream 367.

Metrics: {"destination":"139.196.72.155","destination_port":8080,"duration_seconds":51.093,"packets":124,"source":"172.16.0.170","wire_bytes":101936}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 21069 / TCP stream 368.

Metrics: {"destination":"139.196.72.155","destination_port":8080,"duration_seconds":38.15,"packets":19,"source":"172.16.0.170","wire_bytes":3125}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 21121 / TCP stream 369.

Metrics: {"destination":"139.196.72.155","destination_port":8080,"duration_seconds":58.283,"packets":413,"source":"172.16.0.170","wire_bytes":356002}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 21759 / TCP stream 390.

Metrics: {"destination":"185.184.25.78","destination_port":8080,"duration_seconds":123.7,"packets":1334,"source":"172.16.0.170","wire_bytes":1155759}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 23259 / TCP stream 411.

Metrics: {"destination":"54.37.106.167","destination_port":8080,"duration_seconds":122.065,"packets":23,"source":"172.16.0.170","wire_bytes":4023}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 23301 / TCP stream 417.

Metrics: {"destination":"198.199.98.78","destination_port":8080,"duration_seconds":95.397,"packets":890,"source":"172.16.0.170","wire_bytes":789030}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 24437 / TCP stream 469.

Metrics: {"destination":"128.199.192.135","destination_port":8080,"duration_seconds":49.124,"packets":302,"source":"172.16.0.170","wire_bytes":248547}

ATT&CK candidates

Identities

IOC and artifact candidates

Actor similarity leads

Local enrichment and correlations

No match means unknown in this corpus. Local CTI may postdate the capture. Matches and shared infrastructure require review; no automatic promotion or attribution. Snapshot: 27cd896e9110b1fda7f2da6c5f4df9153ce2ef635709a10b488145ec018823aa; recorded 2026-09-19T12:09:25.907745+00:00; mode: local-only. Coverage: {"matched_observables":0,"no_exact_match":2994,"observable_limit":5000,"observables_checked":2994,"observables_total":2994,"prior_case_limit_reached":false,"prior_cases_checked":11,"truncated":false}

Coverage and limitations