{
  "artifact": "2.56.57.108",
  "artifact_type": "ip",
  "session_id": "6f1651e0-2db5-42f4-9749-2e0f20d3b464",
  "suspicion_score": 79,
  "verdict": "highly suspicious",
  "summary": "2.56.57.108 was classified as ip. Investigation verdict is highly suspicious with score 79/100. Sources checked successfully: local-db, virustotal, otx, urlscan, abuseipdb, censys. Found 2 ATT&CK technique lead(s) and 0 actor lead(s).",
  "actors": [],
  "techniques": [
    {
      "attack_id": "T1102",
      "name": "Web Service",
      "tactics": [
        "command-and-control"
      ],
      "url": "https://attack.mitre.org/techniques/T1102",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    },
    {
      "attack_id": "T1560",
      "name": "Archive Collected Data",
      "tactics": [
        "collection"
      ],
      "url": "https://attack.mitre.org/techniques/T1560",
      "evidence_sources": [
        "otx (submitted indicator; provider-reported lead, not packet execution proof)"
      ]
    }
  ],
  "sources": [
    {
      "source": "local-db",
      "status": "ok",
      "summary": "Found 0 local IOC record(s).",
      "technique_ids": [],
      "actors": []
    },
    {
      "source": "virustotal",
      "status": "ok",
      "summary": "2 engines marked malicious and 1 suspicious; 53 harmless, 33 undetected.",
      "technique_ids": [],
      "actors": []
    },
    {
      "source": "threatfox",
      "status": "not_found",
      "summary": "ThreatFox returned 0 record(s).",
      "technique_ids": [],
      "actors": []
    },
    {
      "source": "malwarebazaar",
      "status": "skipped",
      "summary": "MalwareBazaar is hash-focused; input is not a hash.",
      "technique_ids": [],
      "actors": []
    },
    {
      "source": "otx",
      "status": "ok",
      "summary": "OTX returned 5 pulse(s).",
      "technique_ids": [
        "T1102",
        "T1560"
      ],
      "actors": []
    },
    {
      "source": "urlscan",
      "status": "ok",
      "summary": "urlscan returned 5 scan result(s). urlscan activity analysis found 3 suspicious pattern(s).",
      "technique_ids": [],
      "actors": []
    },
    {
      "source": "greynoise",
      "status": "not_found",
      "summary": "GreyNoise classification: unknown.",
      "technique_ids": [],
      "actors": []
    },
    {
      "source": "abuseipdb",
      "status": "ok",
      "summary": "AbuseIPDB confidence score: 0/100.",
      "technique_ids": [],
      "actors": []
    },
    {
      "source": "shodan",
      "status": "not_found",
      "summary": "Shodan returned 0 open port(s).",
      "technique_ids": [],
      "actors": []
    },
    {
      "source": "censys",
      "status": "ok",
      "summary": "Censys host lookup returned 0 service(s).",
      "technique_ids": [],
      "actors": []
    }
  ],
  "graph_counts": {
    "nodes": 10,
    "edges": 14
  },
  "public_note": "Derived platform summary, not the complete provider response. Bulk provider raw data, unrelated pivots and AI-input duplicates are not redistributed. Original response SHA-256 is recorded for provenance, not independently verifiable from this derivative.",
  "original_sha256": "327d9a993b7ad03ff46ea5c8b80b99a2e9c511a65fe2f5c951f8fd3b13fee8d9"
}
