{
  "artifact": "abca26cf70ef57ef879c81a3b45d9fc5ce4437f54bda65d0170f3f5bae8a54f5",
  "artifact_type": "hash",
  "session_id": "cd20c1f5-325a-4cf2-bc51-c0b907cba6d3",
  "suspicion_score": 0,
  "verdict": "low signal",
  "summary": "abca26cf70ef57ef879c81a3b45d9fc5ce4437f54bda65d0170f3f5bae8a54f5 was classified as hash. Investigation verdict is low signal with score 0/100. Sources checked successfully: local-db, otx, urlscan. Found 0 ATT&CK technique lead(s) and 0 actor lead(s).",
  "actors": [],
  "techniques": [],
  "sources": [
    {
      "source": "local-db",
      "status": "ok",
      "summary": "Found 0 local IOC record(s).",
      "technique_ids": [],
      "actors": []
    },
    {
      "source": "virustotal",
      "status": "not_found",
      "summary": "virustotal has no record for this lookup.",
      "technique_ids": [],
      "actors": []
    },
    {
      "source": "threatfox",
      "status": "not_found",
      "summary": "ThreatFox returned 0 record(s).",
      "technique_ids": [],
      "actors": []
    },
    {
      "source": "malwarebazaar",
      "status": "not_found",
      "summary": "MalwareBazaar returned 0 sample record(s).",
      "technique_ids": [],
      "actors": []
    },
    {
      "source": "otx",
      "status": "ok",
      "summary": "OTX returned 0 pulse(s).",
      "technique_ids": [],
      "actors": []
    },
    {
      "source": "urlscan",
      "status": "ok",
      "summary": "urlscan returned 0 scan result(s). urlscan activity analysis found no obvious suspicious pattern.",
      "technique_ids": [],
      "actors": []
    },
    {
      "source": "greynoise",
      "status": "skipped",
      "summary": "GreyNoise is IP-focused; input is not an IP.",
      "technique_ids": [],
      "actors": []
    },
    {
      "source": "abuseipdb",
      "status": "skipped",
      "summary": "AbuseIPDB is IP-focused; input is not an IP.",
      "technique_ids": [],
      "actors": []
    },
    {
      "source": "shodan",
      "status": "skipped",
      "summary": "Shodan host lookup is IP-focused; input is not an IP.",
      "technique_ids": [],
      "actors": []
    },
    {
      "source": "censys",
      "status": "skipped",
      "summary": "Censys host and search pivots support IP, domain, and URL inputs.",
      "technique_ids": [],
      "actors": []
    }
  ],
  "graph_counts": {
    "nodes": 1,
    "edges": 0
  },
  "public_note": "Derived platform summary, not the complete provider response. Bulk provider raw data, unrelated pivots and AI-input duplicates are not redistributed. Original response SHA-256 is recorded for provenance, not independently verifiable from this derivative.",
  "original_sha256": "0c774b9264d91b14d91e9d358ae0efc001bba5b2b47fc41b07a0c98d532cce21"
}
