========================================================================
  SENTINEL TRACK-BACK PLATFORM — FORENSIC EVIDENCE PACKAGE
========================================================================
Case ID          : SENTINEL-20260829-024455
Generated (UTC)  : 2026-08-29T02:44:55.553797+00:00
Collector        : SENTINEL Track-Back Platform (automated evidence collector)
Integrity SHA256 : 73c5424bd9acde44cebcd01436e6f34f59c2b1b02285a8a627cedea855dcc12f
Forwarded to     : outbox/ (SIMULATED — in production: CISA / FBI IC3 via authenticated channel)

LEGAL NOTICE
------------------------------------------------------------------------
This package is PASSIVE defensive evidence gathered from decoy systems owned by the operator. No system belonging to any third party was accessed. Attribution fields are INDICATIVE ONLY. Pursuit and enforcement are performed solely by LAW ENFORCEMENT (CISA / FBI IC3), never by the platform operator.

CHAIN OF CUSTODY
------------------------------------------------------------------------
  [1] 2026-08-29T02:44:55.553804+00:00  SENTINEL Track-Back Platform (automated evidence collector)
       Collected honeypot events, track-back beacons, and simulated malware analysis from local evidence store.

EVIDENCE SUMMARY
------------------------------------------------------------------------
  Attacker interaction events : 40
  Track-back beacons fired    : 3
  Samples in microscope       : 9

ATTACKER INTERACTION EVENTS (decoy honeypot log)
------------------------------------------------------------------------
  #   1 2026-08-28T23:35:55.529654+00:00  203.0.113.201   GET   /phpmyadmin  [probe]
  #   2 2026-08-28T16:08:55.529654+00:00  198.51.100.5    POST  /admin/login  [login_attempt]
        credentials tried: 'admin' / 'admin'
  #   3 2026-08-29T00:55:55.529654+00:00  203.0.113.88    GET   /files  [file_access]
  #   4 2026-08-29T00:22:55.529654+00:00  192.0.2.44      POST  /admin/login  [login_attempt]
        credentials tried: 'admin' / '12345678'
  #   5 2026-08-28T17:19:55.529654+00:00  192.0.2.130     GET   /.env  [probe]
  #   6 2026-08-28T21:15:55.529654+00:00  203.0.113.88    POST  /admin/login  [login_attempt]
        credentials tried: 'admin' / '12345678'
  #   7 2026-08-28T19:24:55.529654+00:00  203.0.113.88    GET   /  [visit]
  #   8 2026-08-29T02:05:55.529654+00:00  203.0.113.14    GET   /.env  [probe]
  #   9 2026-08-28T22:13:55.529654+00:00  203.0.113.14    POST  /admin/login  [login_attempt]
        credentials tried: 'admin' / 'password123'
  #  10 2026-08-28T18:41:55.529654+00:00  192.0.2.130     POST  /admin/login  [login_attempt]
        credentials tried: 'root' / 'toor'
  #  11 2026-08-28T21:18:55.529654+00:00  198.51.100.5    POST  /admin/login  [login_attempt]
        credentials tried: 'admin' / 'letmein'
  #  12 2026-08-28T15:07:55.529654+00:00  192.0.2.130     POST  /admin/login  [login_attempt]
        credentials tried: 'admin' / 'password123'
  #  13 2026-08-28T16:56:55.529654+00:00  198.51.100.23   POST  /admin/login  [login_attempt]
        credentials tried: 'administrator' / 'Passw0rd!'
  #  14 2026-08-28T21:29:55.529654+00:00  192.0.2.130     POST  /admin/login  [login_attempt]
        credentials tried: 'admin' / 'admin'
  #  15 2026-08-29T02:21:55.529654+00:00  203.0.113.14    POST  /admin/login  [login_attempt]
        credentials tried: 'admin' / 'letmein'
  #  16 2026-08-28T22:39:55.529654+00:00  198.51.100.5    GET   /phpmyadmin  [probe]
  #  17 2026-08-29T02:04:55.529654+00:00  203.0.113.201   GET   /admin  [probe]
  #  18 2026-08-28T21:43:55.529654+00:00  198.51.100.77   GET   /  [visit]
  #  19 2026-08-28T20:40:55.529654+00:00  203.0.113.88    POST  /admin/login  [login_attempt]
        credentials tried: 'sa' / 'sa'
  #  20 2026-08-28T20:32:55.529654+00:00  203.0.113.201   GET   /  [visit]
  #  21 2026-08-28T22:02:55.529654+00:00  203.0.113.14    POST  /admin/login  [login_attempt]
        credentials tried: 'backup' / 'backup2024'
  #  22 2026-08-29T00:28:55.529654+00:00  198.51.100.77   GET   /files  [file_access]
  #  23 2026-08-28T18:30:55.529654+00:00  198.51.100.77   GET   /files  [file_access]
  #  24 2026-08-28T17:37:55.529654+00:00  198.51.100.5    POST  /admin/login  [login_attempt]
        credentials tried: 'admin' / 'admin'
  #  25 2026-08-28T19:42:55.529654+00:00  192.0.2.44      GET   /files  [file_access]
  #  26 2026-08-28T22:25:55.529654+00:00  203.0.113.14    POST  /admin/login  [login_attempt]
        credentials tried: 'admin' / 'password123'
  #  27 2026-08-29T00:11:55.529654+00:00  198.51.100.5    POST  /admin/login  [login_attempt]
        credentials tried: 'administrator' / 'Passw0rd!'
  #  28 2026-08-28T18:05:55.529654+00:00  203.0.113.14    GET   /phpmyadmin  [probe]
  #  29 2026-08-28T19:03:55.529654+00:00  198.51.100.77   POST  /admin/login  [login_attempt]
        credentials tried: 'admin' / '12345678'
  #  30 2026-08-28T19:48:55.529654+00:00  198.51.100.5    POST  /admin/login  [login_attempt]
        credentials tried: 'admin' / 'admin'
  #  31 2026-08-29T02:10:55.529654+00:00  198.51.100.23   POST  /admin/login  [login_attempt]
        credentials tried: 'admin' / 'letmein'
  #  32 2026-08-28T20:55:55.529654+00:00  203.0.113.88    GET   /  [visit]
  #  33 2026-08-28T16:19:55.529654+00:00  198.51.100.5    GET   /api/v1/keys  [probe]
  #  34 2026-08-28T22:46:55.529654+00:00  203.0.113.88    POST  /admin/login  [login_attempt]
        credentials tried: 'administrator' / 'Passw0rd!'
  #  35 2026-08-28T16:33:55.529654+00:00  192.0.2.130     POST  /admin/login  [login_attempt]
        credentials tried: 'admin' / 'admin'
  #  36 2026-08-29T01:44:55.529654+00:00  198.51.100.77   GET   /files  [file_access]
  #  37 2026-08-29T02:12:55.529654+00:00  192.0.2.130     GET   /api/v1/keys  [probe]
  #  38 2026-08-28T21:11:55.529654+00:00  203.0.113.201   POST  /admin/login  [login_attempt]
        credentials tried: 'administrator' / 'Passw0rd!'
  #  39 2026-08-28T23:52:55.529654+00:00  192.0.2.130     POST  /admin/login  [login_attempt]
        credentials tried: 'sa' / 'sa'
  #  40 2026-08-28T18:31:55.529654+00:00  198.51.100.5    GET   /admin  [probe]

TRACK-BACK BEACONS (bait opened on attacker's own machine)
------------------------------------------------------------------------
  #   1 2026-08-29T01:32:55.534408+00:00  token=sntl-d1479ab4e1c3445a  bait=customer_db_backup.sql  reporting_ip=203.0.113.201
  #   2 2026-08-29T00:59:55.534408+00:00  token=sntl-97931408c0194c57  bait=network_diagram.pdf  reporting_ip=198.51.100.23
  #   3 2026-08-28T21:49:55.534408+00:00  token=sntl-e1417585fb9643eb  bait=master_keys.txt  reporting_ip=192.0.2.130

MALWARE MICROSCOPE — SIMULATED ANALYSIS
------------------------------------------------------------------------
  #   1 invoice_2026.doc.bin  [Malicious score=100 Trojan.Generic.Sim]
        sha256: 7686432facfe8ad003be5c72d383f64b9bc6c1482044f272563fe86e715ec4a7
        INDICATIVE ONLY (for law-enforcement follow-up, NOT proof): Toolmarks resemble a commodity crimeware kit (widely resold).
  #   2 update.js  [Malicious score=75 Trojan.Generic.Sim]
        sha256: 229d6e9abb1a1fd03bbfeb9191647ce2de49fafc2915b1b6b1a7be208b2e11c2
        INDICATIVE ONLY (for law-enforcement follow-up, NOT proof): String artifacts suggest an automated/off-the-shelf builder.
  #   3 readme.txt  [Benign score=0 None]
        sha256: be5dd501d045c445c2481229314f081ed916fba22e0bfd17795f9fd9540cfb28
        INDICATIVE ONLY (for law-enforcement follow-up, NOT proof): Locale/keyboard artifacts inconclusive; multiple regions plausible.
  #   4 cryptolocker_sim.bin  [Malicious score=90 Trojan.Generic.Sim]
        sha256: 96522d00e63c347a0102d3598eccb7c8c3bbc2de0643d443d91429df95f1c77f
        INDICATIVE ONLY (for law-enforcement follow-up, NOT proof): Reused infrastructure pattern seen in prior opportunistic campaigns.
  #   5 photo.jpg  [Benign score=0 None]
        sha256: d0ea6574f395ef77c21fabd3b0f1aa82df8f67b89fba32bda306f7e2ce6ddde9
        INDICATIVE ONLY (for law-enforcement follow-up, NOT proof): String artifacts suggest an automated/off-the-shelf builder.
  #   6 invoice_2026.doc.bin  [Malicious score=100 Trojan.Generic.Sim]
        sha256: 7686432facfe8ad003be5c72d383f64b9bc6c1482044f272563fe86e715ec4a7
        INDICATIVE ONLY (for law-enforcement follow-up, NOT proof): Toolmarks resemble a commodity crimeware kit (widely resold).
  #   7 update.js  [Malicious score=75 Trojan.Generic.Sim]
        sha256: 229d6e9abb1a1fd03bbfeb9191647ce2de49fafc2915b1b6b1a7be208b2e11c2
        INDICATIVE ONLY (for law-enforcement follow-up, NOT proof): String artifacts suggest an automated/off-the-shelf builder.
  #   8 readme.txt  [Benign score=0 None]
        sha256: be5dd501d045c445c2481229314f081ed916fba22e0bfd17795f9fd9540cfb28
        INDICATIVE ONLY (for law-enforcement follow-up, NOT proof): Locale/keyboard artifacts inconclusive; multiple regions plausible.
  #   9 cryptolocker_sim.bin  [Malicious score=90 Trojan.Generic.Sim]
        sha256: 96522d00e63c347a0102d3598eccb7c8c3bbc2de0643d443d91429df95f1c77f
        INDICATIVE ONLY (for law-enforcement follow-up, NOT proof): Reused infrastructure pattern seen in prior opportunistic campaigns.

========================================================================
END OF PACKAGE — pursuit/enforcement is performed by LAW ENFORCEMENT.
========================================================================
