{
  "artifact": "798563fcf7600f7ef1a35996291a9dfb5f9902733404dd499e2e736ea1dc6fc5",
  "artifact_type": "hash",
  "session_id": "69b5e3ba-8ca6-4c05-98e9-ec0567792f3c",
  "suspicion_score": 72,
  "verdict": "suspicious",
  "summary": "798563fcf7600f7ef1a35996291a9dfb5f9902733404dd499e2e736ea1dc6fc5 was classified as hash. Investigation verdict is suspicious with score 72/100. Sources checked successfully: local-db, virustotal, malwarebazaar, otx, urlscan. Found 15 ATT&CK technique lead(s) and 0 actor lead(s).",
  "actors": [],
  "techniques": [
    {
      "attack_id": "T1014",
      "name": "Rootkit",
      "tactics": [
        "stealth"
      ],
      "url": "https://attack.mitre.org/techniques/T1014",
      "evidence_sources": [
        "virustotal (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1027",
      "name": "Obfuscated Files or Information",
      "tactics": [
        "stealth"
      ],
      "url": "https://attack.mitre.org/techniques/T1027",
      "evidence_sources": [
        "virustotal (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1055",
      "name": "Process Injection",
      "tactics": [
        "stealth",
        "privilege-escalation"
      ],
      "url": "https://attack.mitre.org/techniques/T1055",
      "evidence_sources": [
        "virustotal (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1064",
      "name": "",
      "tactics": [],
      "url": "https://attack.mitre.org/techniques/T1064/",
      "evidence_sources": [
        "virustotal (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1071",
      "name": "Application Layer Protocol",
      "tactics": [
        "command-and-control"
      ],
      "url": "https://attack.mitre.org/techniques/T1071",
      "evidence_sources": [
        "virustotal (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1082",
      "name": "System Information Discovery",
      "tactics": [
        "discovery"
      ],
      "url": "https://attack.mitre.org/techniques/T1082",
      "evidence_sources": [
        "virustotal (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1496",
      "name": "Resource Hijacking",
      "tactics": [
        "impact"
      ],
      "url": "https://attack.mitre.org/techniques/T1496",
      "evidence_sources": [
        "virustotal (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1518",
      "name": "Software Discovery",
      "tactics": [
        "discovery"
      ],
      "url": "https://attack.mitre.org/techniques/T1518",
      "evidence_sources": [
        "virustotal (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1518.001",
      "name": "Security Software Discovery",
      "tactics": [
        "discovery"
      ],
      "url": "https://attack.mitre.org/techniques/T1518/001",
      "evidence_sources": [
        "virustotal (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1542",
      "name": "Pre-OS Boot",
      "tactics": [
        "stealth",
        "persistence"
      ],
      "url": "https://attack.mitre.org/techniques/T1542",
      "evidence_sources": [
        "virustotal (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1542.003",
      "name": "Bootkit",
      "tactics": [
        "stealth",
        "persistence"
      ],
      "url": "https://attack.mitre.org/techniques/T1542/003",
      "evidence_sources": [
        "virustotal (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1564",
      "name": "Hide Artifacts",
      "tactics": [
        "stealth"
      ],
      "url": "https://attack.mitre.org/techniques/T1564",
      "evidence_sources": [
        "virustotal (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1564.001",
      "name": "Hidden Files and Directories",
      "tactics": [
        "stealth"
      ],
      "url": "https://attack.mitre.org/techniques/T1564/001",
      "evidence_sources": [
        "virustotal (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1574",
      "name": "Hijack Execution Flow",
      "tactics": [
        "stealth",
        "execution"
      ],
      "url": "https://attack.mitre.org/techniques/T1574",
      "evidence_sources": [
        "virustotal (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1574.002",
      "name": "",
      "tactics": [],
      "url": "https://attack.mitre.org/techniques/T1574/002/",
      "evidence_sources": [
        "virustotal (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    }
  ],
  "sources": [
    {
      "source": "local-db",
      "status": "ok",
      "summary": "Found 0 local IOC record(s).",
      "technique_ids": [],
      "actors": []
    },
    {
      "source": "virustotal",
      "status": "ok",
      "summary": "27 engines marked malicious and 0 suspicious; 0 harmless, 37 undetected.",
      "technique_ids": [
        "T1014",
        "T1027",
        "T1055",
        "T1064",
        "T1071",
        "T1082",
        "T1496",
        "T1518",
        "T1518.001",
        "T1542",
        "T1542.003",
        "T1564",
        "T1564.001",
        "T1574",
        "T1574.002"
      ],
      "actors": []
    },
    {
      "source": "threatfox",
      "status": "not_found",
      "summary": "ThreatFox returned 0 record(s).",
      "technique_ids": [],
      "actors": []
    },
    {
      "source": "malwarebazaar",
      "status": "ok",
      "summary": "MalwareBazaar returned 1 sample record(s).",
      "technique_ids": [],
      "actors": []
    },
    {
      "source": "otx",
      "status": "ok",
      "summary": "OTX returned 0 pulse(s).",
      "technique_ids": [],
      "actors": []
    },
    {
      "source": "urlscan",
      "status": "ok",
      "summary": "urlscan returned 0 scan result(s). urlscan activity analysis found no obvious suspicious pattern.",
      "technique_ids": [],
      "actors": []
    },
    {
      "source": "greynoise",
      "status": "skipped",
      "summary": "GreyNoise is IP-focused; input is not an IP.",
      "technique_ids": [],
      "actors": []
    },
    {
      "source": "abuseipdb",
      "status": "skipped",
      "summary": "AbuseIPDB is IP-focused; input is not an IP.",
      "technique_ids": [],
      "actors": []
    },
    {
      "source": "shodan",
      "status": "skipped",
      "summary": "Shodan host lookup is IP-focused; input is not an IP.",
      "technique_ids": [],
      "actors": []
    },
    {
      "source": "censys",
      "status": "skipped",
      "summary": "Censys host and search pivots support IP, domain, and URL inputs.",
      "technique_ids": [],
      "actors": []
    }
  ],
  "graph_counts": {
    "nodes": 3,
    "edges": 3
  },
  "public_note": "Derived platform summary, not the complete provider response. Bulk provider raw data, unrelated pivots and AI-input duplicates are not redistributed. Original response SHA-256 is recorded for provenance, not independently verifiable from this derivative.",
  "original_sha256": "2916be97349be593c220b32ee3600d7b374b2b6e05f8187c08d4aed8f80bd9ee"
}
