{
  "artifact": "163.172.50.82",
  "artifact_type": "ip",
  "session_id": "28f3673b-6918-4d37-a37c-1ec91202489a",
  "suspicion_score": 75,
  "verdict": "highly suspicious",
  "summary": "163.172.50.82 was classified as ip. Investigation verdict is highly suspicious with score 75/100. Sources checked successfully: local-db, virustotal, otx, urlscan, abuseipdb, shodan, censys. Found 21 ATT&CK technique lead(s) and 0 actor lead(s).",
  "actors": [],
  "techniques": [
    {
      "attack_id": "T1045",
      "name": "",
      "tactics": [],
      "url": "https://attack.mitre.org/techniques/T1045/",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1055",
      "name": "Process Injection",
      "tactics": [
        "stealth",
        "privilege-escalation"
      ],
      "url": "https://attack.mitre.org/techniques/T1055",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1129",
      "name": "Shared Modules",
      "tactics": [
        "execution"
      ],
      "url": "https://attack.mitre.org/techniques/T1129",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1143",
      "name": "",
      "tactics": [],
      "url": "https://attack.mitre.org/techniques/T1143/",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1057",
      "name": "Process Discovery",
      "tactics": [
        "discovery"
      ],
      "url": "https://attack.mitre.org/techniques/T1057",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1105",
      "name": "Ingress Tool Transfer",
      "tactics": [
        "command-and-control"
      ],
      "url": "https://attack.mitre.org/techniques/T1105",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1071",
      "name": "Application Layer Protocol",
      "tactics": [
        "command-and-control"
      ],
      "url": "https://attack.mitre.org/techniques/T1071",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1071.001",
      "name": "Web Protocols",
      "tactics": [
        "command-and-control"
      ],
      "url": "https://attack.mitre.org/techniques/T1071/001",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1071.004",
      "name": "DNS",
      "tactics": [
        "command-and-control"
      ],
      "url": "https://attack.mitre.org/techniques/T1071/004",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1491",
      "name": "Defacement",
      "tactics": [
        "impact"
      ],
      "url": "https://attack.mitre.org/techniques/T1491",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1491.001",
      "name": "Internal Defacement",
      "tactics": [
        "impact"
      ],
      "url": "https://attack.mitre.org/techniques/T1491/001",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1156",
      "name": "",
      "tactics": [],
      "url": "https://attack.mitre.org/techniques/T1156/",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1399",
      "name": "",
      "tactics": [],
      "url": "https://attack.mitre.org/techniques/T1399/",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1027",
      "name": "Obfuscated Files or Information",
      "tactics": [
        "stealth"
      ],
      "url": "https://attack.mitre.org/techniques/T1027",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1053",
      "name": "Scheduled Task/Job",
      "tactics": [
        "execution",
        "persistence",
        "privilege-escalation"
      ],
      "url": "https://attack.mitre.org/techniques/T1053",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1080",
      "name": "Taint Shared Content",
      "tactics": [
        "lateral-movement"
      ],
      "url": "https://attack.mitre.org/techniques/T1080",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1102",
      "name": "Web Service",
      "tactics": [
        "command-and-control"
      ],
      "url": "https://attack.mitre.org/techniques/T1102",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1210",
      "name": "Exploitation of Remote Services",
      "tactics": [
        "lateral-movement"
      ],
      "url": "https://attack.mitre.org/techniques/T1210",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1486",
      "name": "Data Encrypted for Impact",
      "tactics": [
        "impact"
      ],
      "url": "https://attack.mitre.org/techniques/T1486",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1490",
      "name": "Inhibit System Recovery",
      "tactics": [
        "impact"
      ],
      "url": "https://attack.mitre.org/techniques/T1490",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1566",
      "name": "Phishing",
      "tactics": [
        "initial-access"
      ],
      "url": "https://attack.mitre.org/techniques/T1566",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    }
  ],
  "sources": [
    {
      "source": "local-db",
      "status": "ok",
      "summary": "Found 0 local IOC record(s).",
      "technique_ids": [],
      "actors": []
    },
    {
      "source": "virustotal",
      "status": "ok",
      "summary": "11 engines marked malicious and 0 suspicious; 46 harmless, 32 undetected.",
      "technique_ids": [],
      "actors": []
    },
    {
      "source": "threatfox",
      "status": "not_found",
      "summary": "ThreatFox returned 0 record(s).",
      "technique_ids": [],
      "actors": []
    },
    {
      "source": "malwarebazaar",
      "status": "skipped",
      "summary": "MalwareBazaar is hash-focused; input is not a hash.",
      "technique_ids": [],
      "actors": []
    },
    {
      "source": "otx",
      "status": "ok",
      "summary": "OTX returned 50 pulse(s).",
      "technique_ids": [
        "T1045",
        "T1055",
        "T1129",
        "T1143",
        "T1057",
        "T1105",
        "T1071",
        "T1071.001",
        "T1071.004",
        "T1491",
        "T1491.001",
        "T1156",
        "T1399",
        "T1027",
        "T1053",
        "T1080",
        "T1102",
        "T1210",
        "T1486",
        "T1490",
        "T1566"
      ],
      "actors": []
    },
    {
      "source": "urlscan",
      "status": "ok",
      "summary": "urlscan returned 9 scan result(s). urlscan activity analysis found 1 suspicious pattern(s).",
      "technique_ids": [],
      "actors": []
    },
    {
      "source": "greynoise",
      "status": "not_found",
      "summary": "GreyNoise classification: unknown.",
      "technique_ids": [],
      "actors": []
    },
    {
      "source": "abuseipdb",
      "status": "ok",
      "summary": "AbuseIPDB confidence score: 0/100.",
      "technique_ids": [],
      "actors": []
    },
    {
      "source": "shodan",
      "status": "ok",
      "summary": "Shodan returned 98 open port(s).",
      "technique_ids": [],
      "actors": []
    },
    {
      "source": "censys",
      "status": "ok",
      "summary": "Censys host lookup returned 48 service(s).",
      "technique_ids": [],
      "actors": []
    }
  ],
  "graph_counts": {
    "nodes": 13,
    "edges": 17
  },
  "public_note": "Derived platform summary, not the complete provider response. Bulk provider raw data, unrelated pivots and AI-input duplicates are not redistributed. Original response SHA-256 is recorded for provenance, not independently verifiable from this derivative.",
  "original_sha256": "6965223c34419f39da32a9e6f69797ba195a8fe74150469fe0fd12b3147dd6ba"
}
