FICTIONAL DOCUMENT-REVIEW EXERCISE — NOT AN AUTHENTIC RECORD
All people, organizations, identifiers, legal conclusions, clinical parameters,
and events are invented for text retrieval practice. Do not use as professional
advice, an authoritative standard, a real filing, or an operational instruction.

RECORD 3: EXFILTRATION ATTEMPT & IOC SUMMARY MEMO (EXCERPT)
Author: CISO Crisis Taskforce / Legal Incident Response Team
Date: 2026-08-14 06:30:00Z
Classification: Attorney-Client Privileged Work-Product (In Anticipation of Litigation)

1. EXFILTRATION TRIAGE & CONTAINMENT ACTION
1.1 At 04:02:11Z, egress alerts triggered on network sensor TAP-03 for anomalous outbound traffic from NAS-RECORDS-04 to external IP `203.0.113.84` over port 443 (Rclone binary masquerading as `svchost_update.exe`).
1.2 Incident Command ordered immediate disconnection of all enterprise WAN circuits at 04:05:00Z, severing the exfiltration session after 3.2 GB of a 44 GB archive was transmitted.
1.3 Regulatory Reporting Clock: SEC Form 8-K four-business-day material incident disclosure clock initiated. HIPAA breach notification clock (HHS OCR 60-day rule) initiated.

2. VERIFIED INDICATORS OF COMPROMISE (IOCs)
- Initial Compromise IP: 203.0.113.195
- C2 Listening IP / Port: 198.51.100.88:8443
- Exfiltration Destination IP: 203.0.113.84:443
- Dropped Stager Hash (SHA-256): 3c9b8821a7df09c84e2079da152b992160d5c07bfa762b3294ee1280fae41d8e
- Exfiltration Staging File: C:\Windows\Temp\perflogs_dat.cab (3.2 GB transmitted before physical WAN sever)
- Stolen Credentials: Account `svc_backup_admin` (Domain Admin privileges abused for volume shadow copy deletion)
