PSYC-OTX-6a20a73fc005e1fc15255876
▶ case journeyOTX: The Demon Arrives Later: A Havoc Stager Hides Behind Microsoft Defender DLP
The full record for one case — how Classifyline rated it, what Scoutline observed, the evidence Sealine encrypted, where Routeline may send it, and every ledger entry it produced.
how to use this view
How to use. Read the cards top-to-bottom — classification, observables, sealed package, routes, ledger. Hit ▶ case journey for the animated walk-through.
What you're seeing. Every worker line's output for this one case: how it was rated, what was observed, what was encrypted and to whom, where it would route, and the audit rows it produced.
Why it matters. Nothing sensitive leaves psyc without a human seeing the full reasoning chain — this page is that chain, for one case.
Classification
- Severity
- medium
- TLP
- GREEN
- Incident type
- malware
- Internal class
- D
Confidence
- Level
- medium
- Source reliability
- C
- Information credibility
- 3
Source
- Type
- threat_intel
- Reference
- https://otx.alienvault.com/pulse/6a20a73fc005e1fc15255876
- Observed
- 2026-06-03 22:14 UTC
- Ingested
- 2026-06-07 00:17 UTC
Observables
Domains
thomphon.come4wxbrg5277.com49xb5hoiqsr.comjh038x18gy9.com
IPs
194.62.55.81
Hashes
fb3630822b70bacb56aa4cec29b5a0e3e9acb3920809e70310a4003385a6d34a0743154262c5ccf24794168ee331feeefc6539386715307ee44d5d9b6b321077d24216d0b82747e9406a696da76960183926145f9621947e34a772137f5e22a6f2357e70f359803d42298d016c7e1631e9fba6c7e01e5df1eb8fb9ff7eb3df4e3578e1588846a805ee806fa6151b5801d0acb88879a93d378300e2ee7665736e7d4fb94f6b4623690daea67ed52e97705cb102f443988ff605f2a9c4898244dceca5c297008e7c07a5c6fc9070c03121d702ef093b4a8e508b712040d87fed361d09357b6a096fdc35cd5c873eed15665d6b3c879d20c8cf01e6bca0005512cfd2c637235d62ad766f961f9b8563f6a0e6db2ec0a343470385991b4df826afbc1fc515870c681bf3e1b7947e2248bbcfe9918db2978117e91134de20bd42fd6aced6b0f4441085bb9c54a32da9ab4ba14c6e21daf6e34fd61d54923f87baacd0afd5f1ed45a9867daf3bc64152cef460a06b164c8183e490db39146d4749a82c2cd88d5280a61714836f5f07a16df190911c5b952af2998dbbcda910b3b1c49400d979bdb1b29b2859f2120580f101f40e8e13de0b3b7bc29675e2c31098a03cae8cded2822c56dd85f52bba09d9285cb2db3e6317227530b848ea143afb067c9eefc66d1fca7f18a91f49affb569b41bcde043f91567e7f5cc9f2016aeddf8cc958de72460256c9c1cceef527d880862e8bc29e3ae4e2d478af97dcafd411806dc41555455860b8584d761303a7ae5487117944e2a24d74fa3e91ad8f8400776b22df0de0a40ff372973639c8a1974cfb75084b8e3b85f9ab9038e0acce43c031f27fdc14505e0cebe360579e1ba0326762cbe0948e50b5f920da51fdef1b51389a6a2007e4f06d16beac0ec2cb01391f80ad5e392343386cae3ceb82ec150201b43dad62e56164771db696827a30ae07d0d4c580ac76ac3ffb63353c9b6b8519b2f2902825eaf62f2db1eb8aaa520a347a3f5f2ed2f503a22f68c4951c78c737b996509ce2873f96781c9f9b12d8b537e065585c573ecc082aacbfd31564eb4442897e3b772dfa4f7af109bec8924d609c3fc64a67630a7b206a6880c893a863e45ffa6d0c22cb04646ef549d61065659575cb45a67b4d0c70e7361709fb036b8ec32dc76fa3138f00616156962f4f6ee4050ac0c5192961c9f34568ca68fd7d384886720c8e576c3ca9d68cb5f08b9d066964414cff647beeecb75affb5b5a9198c1497481b2fea007ea5f13eafbfce9abf0dab1facd7afeb70dc34925a78e6c69f14d7b0dabff5c67e54cf87aba2f799ea5df9ec08690385d0972aefb59dfa9d1f3e719d9284af8af075b1cef9cc149f5cfe98e06f9f7fb6d29dd271830c02250f9d29b38a57b22f0a442e4e731525aeada927ea2f562b258b5cd3fc997d537ab92b7ebe2d42349a6f9234e20e58b54e241596dfb2b87451b42f6bbaea95
Routes
2 allowed · 2 blocked
MISP-Community
priority 2 · stix_indicators · max_tlp AMBER
URLhaus
priority 3 · malware_url_report · max_tlp GREEN
CERT-Bund
country_mismatch
AbuseIPDB
tlp_exceeded