{
  "artifact": "b7aec5f73d2a6bbd8cd920edb4760e2edadc98c3a45bf4fa994d47ca9cbd02f6",
  "artifact_type": "hash",
  "session_id": "f5d34eb6-9ada-4b7b-8496-a5af3cd4e147",
  "suspicion_score": 100,
  "verdict": "highly suspicious",
  "summary": "b7aec5f73d2a6bbd8cd920edb4760e2edadc98c3a45bf4fa994d47ca9cbd02f6 was classified as hash. Investigation verdict is highly suspicious with score 100/100. Sources checked successfully: local-db, virustotal, malwarebazaar, otx, urlscan. Found 35 ATT&CK technique lead(s) and 0 actor lead(s).",
  "actors": [],
  "techniques": [
    {
      "attack_id": "T1010",
      "name": "Application Window Discovery",
      "tactics": [
        "discovery"
      ],
      "url": "https://attack.mitre.org/techniques/T1010",
      "evidence_sources": [
        "virustotal (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1012",
      "name": "Query Registry",
      "tactics": [
        "discovery"
      ],
      "url": "https://attack.mitre.org/techniques/T1012",
      "evidence_sources": [
        "virustotal (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1027",
      "name": "Obfuscated Files or Information",
      "tactics": [
        "stealth"
      ],
      "url": "https://attack.mitre.org/techniques/T1027",
      "evidence_sources": [
        "virustotal (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1033",
      "name": "System Owner/User Discovery",
      "tactics": [
        "discovery"
      ],
      "url": "https://attack.mitre.org/techniques/T1033",
      "evidence_sources": [
        "virustotal (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1036",
      "name": "Masquerading",
      "tactics": [
        "stealth"
      ],
      "url": "https://attack.mitre.org/techniques/T1036",
      "evidence_sources": [
        "virustotal (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1050",
      "name": "",
      "tactics": [],
      "url": "https://attack.mitre.org/techniques/T1050/",
      "evidence_sources": [
        "virustotal (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1053",
      "name": "Scheduled Task/Job",
      "tactics": [
        "execution",
        "persistence",
        "privilege-escalation"
      ],
      "url": "https://attack.mitre.org/techniques/T1053",
      "evidence_sources": [
        "virustotal (submitted indicator; provider-reported lead, not packet execution proof)",
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1057",
      "name": "Process Discovery",
      "tactics": [
        "discovery"
      ],
      "url": "https://attack.mitre.org/techniques/T1057",
      "evidence_sources": [
        "virustotal (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1060",
      "name": "",
      "tactics": [],
      "url": "https://attack.mitre.org/techniques/T1060/",
      "evidence_sources": [
        "virustotal (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1063",
      "name": "",
      "tactics": [],
      "url": "https://attack.mitre.org/techniques/T1063/",
      "evidence_sources": [
        "virustotal (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1070",
      "name": "Indicator Removal",
      "tactics": [
        "stealth"
      ],
      "url": "https://attack.mitre.org/techniques/T1070",
      "evidence_sources": [
        "virustotal (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1070.004",
      "name": "File Deletion",
      "tactics": [
        "stealth"
      ],
      "url": "https://attack.mitre.org/techniques/T1070/004",
      "evidence_sources": [
        "virustotal (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1071",
      "name": "Application Layer Protocol",
      "tactics": [
        "command-and-control"
      ],
      "url": "https://attack.mitre.org/techniques/T1071",
      "evidence_sources": [
        "virustotal (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1082",
      "name": "System Information Discovery",
      "tactics": [
        "discovery"
      ],
      "url": "https://attack.mitre.org/techniques/T1082",
      "evidence_sources": [
        "virustotal (submitted indicator; provider-reported lead, not packet execution proof)",
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1083",
      "name": "File and Directory Discovery",
      "tactics": [
        "discovery"
      ],
      "url": "https://attack.mitre.org/techniques/T1083",
      "evidence_sources": [
        "virustotal (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1087",
      "name": "Account Discovery",
      "tactics": [
        "discovery"
      ],
      "url": "https://attack.mitre.org/techniques/T1087",
      "evidence_sources": [
        "virustotal (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1095",
      "name": "Non-Application Layer Protocol",
      "tactics": [
        "command-and-control"
      ],
      "url": "https://attack.mitre.org/techniques/T1095",
      "evidence_sources": [
        "virustotal (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1105",
      "name": "Ingress Tool Transfer",
      "tactics": [
        "command-and-control"
      ],
      "url": "https://attack.mitre.org/techniques/T1105",
      "evidence_sources": [
        "virustotal (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1112",
      "name": "Modify Registry",
      "tactics": [
        "defense-impairment",
        "persistence"
      ],
      "url": "https://attack.mitre.org/techniques/T1112",
      "evidence_sources": [
        "virustotal (submitted indicator; provider-reported lead, not packet execution proof)",
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1129",
      "name": "Shared Modules",
      "tactics": [
        "execution"
      ],
      "url": "https://attack.mitre.org/techniques/T1129",
      "evidence_sources": [
        "virustotal (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1218",
      "name": "System Binary Proxy Execution",
      "tactics": [
        "stealth"
      ],
      "url": "https://attack.mitre.org/techniques/T1218",
      "evidence_sources": [
        "virustotal (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1218.010",
      "name": "Regsvr32",
      "tactics": [
        "stealth"
      ],
      "url": "https://attack.mitre.org/techniques/T1218/010",
      "evidence_sources": [
        "virustotal (submitted indicator; provider-reported lead, not packet execution proof)",
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1218.011",
      "name": "Rundll32",
      "tactics": [
        "stealth"
      ],
      "url": "https://attack.mitre.org/techniques/T1218/011",
      "evidence_sources": [
        "virustotal (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1497",
      "name": "Virtualization/Sandbox Evasion",
      "tactics": [
        "stealth",
        "discovery"
      ],
      "url": "https://attack.mitre.org/techniques/T1497",
      "evidence_sources": [
        "virustotal (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1518",
      "name": "Software Discovery",
      "tactics": [
        "discovery"
      ],
      "url": "https://attack.mitre.org/techniques/T1518",
      "evidence_sources": [
        "virustotal (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1518.001",
      "name": "Security Software Discovery",
      "tactics": [
        "discovery"
      ],
      "url": "https://attack.mitre.org/techniques/T1518/001",
      "evidence_sources": [
        "virustotal (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1574",
      "name": "Hijack Execution Flow",
      "tactics": [
        "stealth",
        "execution"
      ],
      "url": "https://attack.mitre.org/techniques/T1574",
      "evidence_sources": [
        "virustotal (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1574.002",
      "name": "",
      "tactics": [],
      "url": "https://attack.mitre.org/techniques/T1574/002/",
      "evidence_sources": [
        "virustotal (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1113",
      "name": "Screen Capture",
      "tactics": [
        "collection"
      ],
      "url": "https://attack.mitre.org/techniques/T1113",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1059.001",
      "name": "PowerShell",
      "tactics": [
        "execution"
      ],
      "url": "https://attack.mitre.org/techniques/T1059/001",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1566",
      "name": "Phishing",
      "tactics": [
        "initial-access"
      ],
      "url": "https://attack.mitre.org/techniques/T1566",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1059.003",
      "name": "Windows Command Shell",
      "tactics": [
        "execution"
      ],
      "url": "https://attack.mitre.org/techniques/T1059/003",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1204.001",
      "name": "Malicious Link",
      "tactics": [
        "execution"
      ],
      "url": "https://attack.mitre.org/techniques/T1204/001",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1059",
      "name": "Command and Scripting Interpreter",
      "tactics": [
        "execution"
      ],
      "url": "https://attack.mitre.org/techniques/T1059",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1553",
      "name": "Subvert Trust Controls",
      "tactics": [
        "defense-impairment"
      ],
      "url": "https://attack.mitre.org/techniques/T1553",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    }
  ],
  "sources": [
    {
      "source": "local-db",
      "status": "ok",
      "summary": "Found 0 local IOC record(s).",
      "technique_ids": [],
      "actors": []
    },
    {
      "source": "virustotal",
      "status": "ok",
      "summary": "58 engines marked malicious and 0 suspicious; 0 harmless, 12 undetected.",
      "technique_ids": [
        "T1010",
        "T1012",
        "T1027",
        "T1033",
        "T1036",
        "T1050",
        "T1053",
        "T1057",
        "T1060",
        "T1063",
        "T1070",
        "T1070.004",
        "T1071",
        "T1082",
        "T1083",
        "T1087",
        "T1095",
        "T1105",
        "T1112",
        "T1129",
        "T1218",
        "T1218.010",
        "T1218.011",
        "T1497",
        "T1518",
        "T1518.001",
        "T1574",
        "T1574.002"
      ],
      "actors": []
    },
    {
      "source": "threatfox",
      "status": "not_found",
      "summary": "ThreatFox returned 0 record(s).",
      "technique_ids": [],
      "actors": []
    },
    {
      "source": "malwarebazaar",
      "status": "ok",
      "summary": "MalwareBazaar returned 1 sample record(s).",
      "technique_ids": [],
      "actors": []
    },
    {
      "source": "otx",
      "status": "ok",
      "summary": "OTX returned 9 pulse(s).",
      "technique_ids": [
        "T1113",
        "T1082",
        "T1053",
        "T1112",
        "T1059.001",
        "T1566",
        "T1059.003",
        "T1204.001",
        "T1059",
        "T1553",
        "T1218.010"
      ],
      "actors": []
    },
    {
      "source": "urlscan",
      "status": "ok",
      "summary": "urlscan returned 0 scan result(s). urlscan activity analysis found no obvious suspicious pattern.",
      "technique_ids": [],
      "actors": []
    },
    {
      "source": "greynoise",
      "status": "skipped",
      "summary": "GreyNoise is IP-focused; input is not an IP.",
      "technique_ids": [],
      "actors": []
    },
    {
      "source": "abuseipdb",
      "status": "skipped",
      "summary": "AbuseIPDB is IP-focused; input is not an IP.",
      "technique_ids": [],
      "actors": []
    },
    {
      "source": "shodan",
      "status": "skipped",
      "summary": "Shodan host lookup is IP-focused; input is not an IP.",
      "technique_ids": [],
      "actors": []
    },
    {
      "source": "censys",
      "status": "skipped",
      "summary": "Censys host and search pivots support IP, domain, and URL inputs.",
      "technique_ids": [],
      "actors": []
    }
  ],
  "graph_counts": {
    "nodes": 12,
    "edges": 12
  },
  "public_note": "Derived platform summary, not the complete provider response. Bulk provider raw data, unrelated pivots and AI-input duplicates are not redistributed. Original response SHA-256 is recorded for provenance, not independently verifiable from this derivative.",
  "original_sha256": "e86846a92c38fb2c8dc76c88c8a450217c7584e06a22c63e045855329470e50f"
}
