{
  "artifact": "194.180.191.64",
  "artifact_type": "ip",
  "session_id": "94bf7f27-3bc4-4b5f-b440-8fda0059e9f4",
  "suspicion_score": 70,
  "verdict": "suspicious",
  "summary": "194.180.191.64 was classified as ip. Investigation verdict is suspicious with score 70/100. Sources checked successfully: local-db, virustotal, otx, urlscan, abuseipdb, shodan, censys. Found 8 ATT&CK technique lead(s) and 0 actor lead(s).",
  "actors": [],
  "techniques": [
    {
      "attack_id": "T1059.001",
      "name": "PowerShell",
      "tactics": [
        "execution"
      ],
      "url": "https://attack.mitre.org/techniques/T1059/001",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1055",
      "name": "Process Injection",
      "tactics": [
        "privilege-escalation",
        "stealth"
      ],
      "url": "https://attack.mitre.org/techniques/T1055",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1074.001",
      "name": "Local Data Staging",
      "tactics": [
        "collection"
      ],
      "url": "https://attack.mitre.org/techniques/T1074/001",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1057",
      "name": "Process Discovery",
      "tactics": [
        "discovery"
      ],
      "url": "https://attack.mitre.org/techniques/T1057",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1547.001",
      "name": "Registry Run Keys / Startup Folder",
      "tactics": [
        "persistence",
        "privilege-escalation"
      ],
      "url": "https://attack.mitre.org/techniques/T1547/001",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1204.002",
      "name": "Malicious File",
      "tactics": [
        "execution"
      ],
      "url": "https://attack.mitre.org/techniques/T1204/002",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1027",
      "name": "Obfuscated Files or Information",
      "tactics": [
        "stealth"
      ],
      "url": "https://attack.mitre.org/techniques/T1027",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1041",
      "name": "Exfiltration Over C2 Channel",
      "tactics": [
        "exfiltration"
      ],
      "url": "https://attack.mitre.org/techniques/T1041",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    }
  ],
  "sources": [
    {
      "source": "local-db",
      "status": "ok",
      "summary": "Found 0 local IOC record(s).",
      "technique_ids": [],
      "actors": []
    },
    {
      "source": "virustotal",
      "status": "ok",
      "summary": "3 engines marked malicious and 1 suspicious; 52 harmless, 33 undetected.",
      "technique_ids": [],
      "actors": []
    },
    {
      "source": "threatfox",
      "status": "not_found",
      "summary": "ThreatFox returned 0 record(s).",
      "technique_ids": [],
      "actors": []
    },
    {
      "source": "malwarebazaar",
      "status": "skipped",
      "summary": "MalwareBazaar is hash-focused; input is not a hash.",
      "technique_ids": [],
      "actors": []
    },
    {
      "source": "otx",
      "status": "ok",
      "summary": "OTX returned 7 pulse(s).",
      "technique_ids": [
        "T1059.001",
        "T1055",
        "T1074.001",
        "T1057",
        "T1547.001",
        "T1204.002",
        "T1027",
        "T1041"
      ],
      "actors": []
    },
    {
      "source": "urlscan",
      "status": "ok",
      "summary": "urlscan returned 2 scan result(s). urlscan activity analysis found 1 suspicious pattern(s).",
      "technique_ids": [],
      "actors": []
    },
    {
      "source": "greynoise",
      "status": "not_found",
      "summary": "GreyNoise classification: unknown.",
      "technique_ids": [],
      "actors": []
    },
    {
      "source": "abuseipdb",
      "status": "ok",
      "summary": "AbuseIPDB confidence score: 0/100.",
      "technique_ids": [],
      "actors": []
    },
    {
      "source": "shodan",
      "status": "ok",
      "summary": "Shodan returned 1 open port(s).",
      "technique_ids": [],
      "actors": []
    },
    {
      "source": "censys",
      "status": "ok",
      "summary": "Censys host lookup returned 5 service(s).",
      "technique_ids": [],
      "actors": []
    }
  ],
  "graph_counts": {
    "nodes": 14,
    "edges": 17
  },
  "public_note": "Derived platform summary, not the complete provider response. Bulk provider raw data, unrelated pivots and AI-input duplicates are not redistributed. Original response SHA-256 is recorded for provenance, not independently verifiable from this derivative.",
  "original_sha256": "73769a4eb8455bc910859f4a33962412b5d510341a39bb45d5b23e6f0b584cc6"
}
