{
  "artifact": "157.245.142.66",
  "artifact_type": "ip",
  "session_id": "faf612e1-3438-432b-a1e7-89652376acc6",
  "suspicion_score": 70,
  "verdict": "suspicious",
  "summary": "157.245.142.66 was classified as ip. Investigation verdict is suspicious with score 70/100. Sources checked successfully: local-db, virustotal, otx, urlscan, abuseipdb, shodan, censys. Found 26 ATT&CK technique lead(s) and 0 actor lead(s).",
  "actors": [],
  "techniques": [
    {
      "attack_id": "T1140",
      "name": "Deobfuscate/Decode Files or Information",
      "tactics": [
        "stealth"
      ],
      "url": "https://attack.mitre.org/techniques/T1140",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1471",
      "name": "",
      "tactics": [],
      "url": "https://attack.mitre.org/techniques/T1471/",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1119",
      "name": "Automated Collection",
      "tactics": [
        "collection"
      ],
      "url": "https://attack.mitre.org/techniques/T1119",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1036",
      "name": "Masquerading",
      "tactics": [
        "stealth"
      ],
      "url": "https://attack.mitre.org/techniques/T1036",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1547",
      "name": "Boot or Logon Autostart Execution",
      "tactics": [
        "persistence",
        "privilege-escalation"
      ],
      "url": "https://attack.mitre.org/techniques/T1547",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1027",
      "name": "Obfuscated Files or Information",
      "tactics": [
        "stealth"
      ],
      "url": "https://attack.mitre.org/techniques/T1027",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1016",
      "name": "System Network Configuration Discovery",
      "tactics": [
        "discovery"
      ],
      "url": "https://attack.mitre.org/techniques/T1016",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1049",
      "name": "System Network Connections Discovery",
      "tactics": [
        "discovery"
      ],
      "url": "https://attack.mitre.org/techniques/T1049",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1003",
      "name": "OS Credential Dumping",
      "tactics": [
        "credential-access"
      ],
      "url": "https://attack.mitre.org/techniques/T1003",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1018",
      "name": "Remote System Discovery",
      "tactics": [
        "discovery"
      ],
      "url": "https://attack.mitre.org/techniques/T1018",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1021",
      "name": "Remote Services",
      "tactics": [
        "lateral-movement"
      ],
      "url": "https://attack.mitre.org/techniques/T1021",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1047",
      "name": "Windows Management Instrumentation",
      "tactics": [
        "execution"
      ],
      "url": "https://attack.mitre.org/techniques/T1047",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1053",
      "name": "Scheduled Task/Job",
      "tactics": [
        "execution",
        "persistence",
        "privilege-escalation"
      ],
      "url": "https://attack.mitre.org/techniques/T1053",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1055",
      "name": "Process Injection",
      "tactics": [
        "stealth",
        "privilege-escalation"
      ],
      "url": "https://attack.mitre.org/techniques/T1055",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1059",
      "name": "Command and Scripting Interpreter",
      "tactics": [
        "execution"
      ],
      "url": "https://attack.mitre.org/techniques/T1059",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1071",
      "name": "Application Layer Protocol",
      "tactics": [
        "command-and-control"
      ],
      "url": "https://attack.mitre.org/techniques/T1071",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1082",
      "name": "System Information Discovery",
      "tactics": [
        "discovery"
      ],
      "url": "https://attack.mitre.org/techniques/T1082",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1083",
      "name": "File and Directory Discovery",
      "tactics": [
        "discovery"
      ],
      "url": "https://attack.mitre.org/techniques/T1083",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1087",
      "name": "Account Discovery",
      "tactics": [
        "discovery"
      ],
      "url": "https://attack.mitre.org/techniques/T1087",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1204",
      "name": "User Execution",
      "tactics": [
        "execution"
      ],
      "url": "https://attack.mitre.org/techniques/T1204",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1218",
      "name": "System Binary Proxy Execution",
      "tactics": [
        "stealth"
      ],
      "url": "https://attack.mitre.org/techniques/T1218",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1482",
      "name": "Domain Trust Discovery",
      "tactics": [
        "discovery"
      ],
      "url": "https://attack.mitre.org/techniques/T1482",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1486",
      "name": "Data Encrypted for Impact",
      "tactics": [
        "impact"
      ],
      "url": "https://attack.mitre.org/techniques/T1486",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1518",
      "name": "Software Discovery",
      "tactics": [
        "discovery"
      ],
      "url": "https://attack.mitre.org/techniques/T1518",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1614",
      "name": "System Location Discovery",
      "tactics": [
        "discovery"
      ],
      "url": "https://attack.mitre.org/techniques/T1614",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1497",
      "name": "Virtualization/Sandbox Evasion",
      "tactics": [
        "stealth",
        "discovery"
      ],
      "url": "https://attack.mitre.org/techniques/T1497",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    }
  ],
  "sources": [
    {
      "source": "local-db",
      "status": "ok",
      "summary": "Found 0 local IOC record(s).",
      "technique_ids": [],
      "actors": []
    },
    {
      "source": "virustotal",
      "status": "ok",
      "summary": "9 engines marked malicious and 1 suspicious; 45 harmless, 34 undetected.",
      "technique_ids": [],
      "actors": []
    },
    {
      "source": "threatfox",
      "status": "not_found",
      "summary": "ThreatFox returned 0 record(s).",
      "technique_ids": [],
      "actors": []
    },
    {
      "source": "malwarebazaar",
      "status": "skipped",
      "summary": "MalwareBazaar is hash-focused; input is not a hash.",
      "technique_ids": [],
      "actors": []
    },
    {
      "source": "otx",
      "status": "ok",
      "summary": "OTX returned 19 pulse(s).",
      "technique_ids": [
        "T1140",
        "T1471",
        "T1119",
        "T1036",
        "T1547",
        "T1027",
        "T1016",
        "T1049",
        "T1003",
        "T1018",
        "T1021",
        "T1047",
        "T1053",
        "T1055",
        "T1059",
        "T1071",
        "T1082",
        "T1083",
        "T1087",
        "T1204",
        "T1218",
        "T1482",
        "T1486",
        "T1518",
        "T1614",
        "T1497"
      ],
      "actors": []
    },
    {
      "source": "urlscan",
      "status": "ok",
      "summary": "urlscan returned 3 scan result(s). urlscan activity analysis found no obvious suspicious pattern.",
      "technique_ids": [],
      "actors": []
    },
    {
      "source": "greynoise",
      "status": "not_found",
      "summary": "GreyNoise classification: unknown.",
      "technique_ids": [],
      "actors": []
    },
    {
      "source": "abuseipdb",
      "status": "ok",
      "summary": "AbuseIPDB confidence score: 0/100.",
      "technique_ids": [],
      "actors": []
    },
    {
      "source": "shodan",
      "status": "ok",
      "summary": "Shodan returned 3 open port(s).",
      "technique_ids": [],
      "actors": []
    },
    {
      "source": "censys",
      "status": "ok",
      "summary": "Censys host lookup returned 4 service(s).",
      "technique_ids": [],
      "actors": []
    }
  ],
  "graph_counts": {
    "nodes": 23,
    "edges": 25
  },
  "public_note": "Derived platform summary, not the complete provider response. Bulk provider raw data, unrelated pivots and AI-input duplicates are not redistributed. Original response SHA-256 is recorded for provenance, not independently verifiable from this derivative.",
  "original_sha256": "136c117328f9b9c9034bda8bf189421e3d18746ee2772df3d150ca34e85ab6a4"
}
