==========================================================================
  SENTINEL — CYBER FORENSICS TEST LAB — CHAIN-OF-CUSTODY EVIDENCE
==========================================================================
Case Ref         : CFL-20260829-49DEF2
Generated (UTC)  : 2026-08-29T04:07:34.024004+00:00
Stream           : GOVERNMENT  (tier GOVERNMENT)
Collector        : SENTINEL Cyber Forensics Test Lab (automated evidence collector)
Recipient        : FBI IC3 / CISA (SIMULATED handoff via authenticated channel)
Integrity SHA256 : 2541af5b257ad2bfcd070908a26ac1b0deab8e3a3b3cf4bf2e87f3ac4414bbbf

LEGAL NOTICE
--------------------------------------------------------------------------
PASSIVE defensive evidence gathered from decoy systems we own. No third-party system was accessed. No malware was executed (SIMULATED containment). Attribution is INDICATIVE ONLY. Trackers are passive. Pursuit/enforcement is performed solely by LAW ENFORCEMENT (FBI IC3 / CISA), never by the platform operator. Track-back, not hack-back.

CHAIN OF CUSTODY
--------------------------------------------------------------------------
  [1] 2026-08-29T04:07:34.024010+00:00  PhishBot 3.0
       Scanned inbound email lure (verdict Phishing, score 100).
  [2] 2026-08-29T04:07:34.024014+00:00  VigilantGuard
       Sealed artifact in simulated sandbox (sha256 f25e48c87038d2e6...); never executed.
  [3] 2026-08-29T04:07:34.024016+00:00  VigilantGuard
       Served watermarked+tokenized bait (master_keys.txt) on decoy server decoy-gov-airgap-vault.internal (VigilantGuard honeynet, isolated).
  [4] 2026-08-29T04:07:34.024018+00:00  Forensics Lab
       Documented case: verdict Malicious score 100; cure NEW_SIGNATURE (signature #1).
  [5] 2026-08-29T04:07:34.024020+00:00  Tracker Mint
       Minted passive HMAC tracker jti 75ebe2d5-7f34-4b23-9370-bb6d0505d0a6.
  [6] 2026-08-29T04:07:34.024026+00:00  SENTINEL Cyber Forensics Test Lab (automated evidence collector)
       Packaged chain-of-custody bundle to GOVERNMENT outbox stream addressed to FBI IC3 / CISA (SIMULATED handoff via authenticated channel).

FORENSICS SUMMARY
--------------------------------------------------------------------------
  Channel        : email
  PhishBot 3.0   : Phishing (score 100)
  Verdict        : Malicious (score 100) Trojan.Generic.Sim
  SHA256         : f25e48c87038d2e64597fe3f665c5a23453e09a5a5644f7e3b0133cd75774f4d
  Cure status    : NEW_SIGNATURE (signature #1)
  Mitigation     : Suggested cure (synthetic): isolate host, revoke exposed decoy credentials, block matching sha256 at endpoint controls, hand signature to responders. Do NOT execute the artifact.
  Attribution    : INDICATIVE ONLY (for law-enforcement follow-up, NOT proof): Toolmarks resemble a commodity crimeware kit (widely resold).

==========================================================================
END OF BUNDLE — pursuit/enforcement is performed by LAW ENFORCEMENT.
==========================================================================
