Threat Actors — Malware
CASE-20260821-1240
MEDIUM
OPEN
Assignee: unassigned · Opened 14h ago
Opened from malware Threat Actors
Entities
5
linked to case
IoCs
4
indicators
Entity types
2
dimensions
Evidence events
3
chain of custody
➕ Add anything to this case
Attach any entity — region, country, APT, source, MITRE technique, IoC, nation-state, campaign, data point, mission domain, CVE, malware, ransomware — and all linked entities are pulled in automatically.
🔎 IoC (4)
| Indicator | Role | Source | |
|---|---|---|---|
a0c8c5ccd0c4c5d3cbe0c5d4c4c18ecfd28ed4c8 | indicator | pivot | search · workbench |
d3bbb6bfa3b7b6a0b893b6a7b7b2fdbca1fda7bb | indicator | pivot | search · workbench |
adc5c8c1ddc9c8dec6edc8d9c9cc83c2df83d9c5 | indicator | pivot | search · workbench |
8ce4e9e0fce8e9ffe7cce9f8e8eda2e3fea2f8e4 | indicator | pivot | search · workbench |
🦠 Malware (1)
🤖 Case Operations
📜 Chain of Evidence (tamper-evident, hash-chained)
| When | Actor | Action | Entity | Source | Hash |
|---|---|---|---|---|---|
| 2026-08-21 00:58:55 | analyst | expand | malware: Threat Actors | graph+live · 4 linked entities pulled | 105b072e22 |
| 2026-08-21 00:58:51 | analyst | add | malware: Threat Actors | manual · primary | 0c0b7ea648 |
| 2026-08-21 00:58:51 | analyst | open | malware: Threat Actors | analyst · case created | 6c80fa7176 |
Each record's hash chains to the previous, so any tampering is detectable. Export the full trail via the Evidence report.
📝 Case Notes (0)
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports
🤖 AI Copilot
⚡ AI Skills
🔍 Lookup & Enrich
📚 Docs & Reports
💡 Recommendations
- Attach all related IoCs as artifacts
- Run a response playbook per case type
- Escalate to legal when needed