{
  "artifact": "newsaarctech.com",
  "artifact_type": "domain",
  "session_id": "107aeeec-5730-437f-969a-3f434a0cae71",
  "suspicion_score": 83,
  "verdict": "highly suspicious",
  "summary": "newsaarctech.com was classified as domain. Investigation verdict is highly suspicious with score 83/100. Sources checked successfully: local-db, virustotal, otx, urlscan, censys. Found 15 ATT&CK technique lead(s) and 0 actor lead(s).",
  "actors": [],
  "techniques": [
    {
      "attack_id": "T1583",
      "name": "Acquire Infrastructure",
      "tactics": [
        "resource-development"
      ],
      "url": "https://attack.mitre.org/techniques/T1583",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1584",
      "name": "Compromise Infrastructure",
      "tactics": [
        "resource-development"
      ],
      "url": "https://attack.mitre.org/techniques/T1584",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1608",
      "name": "Stage Capabilities",
      "tactics": [
        "resource-development"
      ],
      "url": "https://attack.mitre.org/techniques/T1608",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1190",
      "name": "Exploit Public-Facing Application",
      "tactics": [
        "initial-access"
      ],
      "url": "https://attack.mitre.org/techniques/T1190",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1078",
      "name": "Valid Accounts",
      "tactics": [
        "stealth",
        "persistence",
        "privilege-escalation",
        "initial-access"
      ],
      "url": "https://attack.mitre.org/techniques/T1078",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1090",
      "name": "Proxy",
      "tactics": [
        "command-and-control"
      ],
      "url": "https://attack.mitre.org/techniques/T1090",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1505.003",
      "name": "Web Shell",
      "tactics": [
        "persistence"
      ],
      "url": "https://attack.mitre.org/techniques/T1505/003",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1573",
      "name": "Encrypted Channel",
      "tactics": [
        "command-and-control"
      ],
      "url": "https://attack.mitre.org/techniques/T1573",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1539",
      "name": "Steal Web Session Cookie",
      "tactics": [
        "credential-access"
      ],
      "url": "https://attack.mitre.org/techniques/T1539",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1071.001",
      "name": "Web Protocols",
      "tactics": [
        "command-and-control"
      ],
      "url": "https://attack.mitre.org/techniques/T1071/001",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1567",
      "name": "Exfiltration Over Web Service",
      "tactics": [
        "exfiltration"
      ],
      "url": "https://attack.mitre.org/techniques/T1567",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1059",
      "name": "Command and Scripting Interpreter",
      "tactics": [
        "execution"
      ],
      "url": "https://attack.mitre.org/techniques/T1059",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1137",
      "name": "Office Application Startup",
      "tactics": [
        "persistence"
      ],
      "url": "https://attack.mitre.org/techniques/T1137",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1218",
      "name": "System Binary Proxy Execution",
      "tactics": [
        "stealth"
      ],
      "url": "https://attack.mitre.org/techniques/T1218",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1027",
      "name": "Obfuscated Files or Information",
      "tactics": [
        "stealth"
      ],
      "url": "https://attack.mitre.org/techniques/T1027",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    }
  ],
  "sources": [
    {
      "source": "local-db",
      "status": "ok",
      "summary": "Found 0 local IOC record(s).",
      "technique_ids": [],
      "actors": []
    },
    {
      "source": "virustotal",
      "status": "ok",
      "summary": "2 engines marked malicious and 3 suspicious; 52 harmless, 32 undetected.",
      "technique_ids": [],
      "actors": []
    },
    {
      "source": "threatfox",
      "status": "not_found",
      "summary": "ThreatFox returned 0 record(s).",
      "technique_ids": [],
      "actors": []
    },
    {
      "source": "malwarebazaar",
      "status": "skipped",
      "summary": "MalwareBazaar is hash-focused; input is not a hash.",
      "technique_ids": [],
      "actors": []
    },
    {
      "source": "otx",
      "status": "ok",
      "summary": "OTX returned 3 pulse(s).",
      "technique_ids": [
        "T1583",
        "T1584",
        "T1608",
        "T1190",
        "T1078",
        "T1090",
        "T1505.003",
        "T1573",
        "T1539",
        "T1071.001",
        "T1567",
        "T1059",
        "T1137",
        "T1218",
        "T1027"
      ],
      "actors": []
    },
    {
      "source": "urlscan",
      "status": "ok",
      "summary": "urlscan returned 10 scan result(s). urlscan activity analysis found 2 suspicious pattern(s).",
      "technique_ids": [],
      "actors": []
    },
    {
      "source": "greynoise",
      "status": "skipped",
      "summary": "GreyNoise is IP-focused; input is not an IP.",
      "technique_ids": [],
      "actors": []
    },
    {
      "source": "abuseipdb",
      "status": "skipped",
      "summary": "AbuseIPDB is IP-focused; input is not an IP.",
      "technique_ids": [],
      "actors": []
    },
    {
      "source": "shodan",
      "status": "skipped",
      "summary": "Shodan host lookup is IP-focused; input is not an IP.",
      "technique_ids": [],
      "actors": []
    },
    {
      "source": "censys",
      "status": "ok",
      "summary": "Censys web property lookup returned 2 record(s) for newsaarctech.com. Broader Censys search requires an organization-enabled account and API role.",
      "technique_ids": [],
      "actors": []
    }
  ],
  "graph_counts": {
    "nodes": 23,
    "edges": 29
  },
  "public_note": "Derived platform summary, not the complete provider response. Bulk provider raw data, unrelated pivots and AI-input duplicates are not redistributed. Original response SHA-256 is recorded for provenance, not independently verifiable from this derivative.",
  "original_sha256": "ececeef71568d079048c3c469330432e1f38eedc65240ece99192021a5ddb6e8"
}
