FICTIONAL DOCUMENT-REVIEW EXERCISE — NOT AN AUTHENTIC RECORD All people, organizations, identifiers, legal conclusions, clinical parameters, and events are invented for text retrieval practice. Do not use as professional advice, an authoritative standard, a real filing, or an operational instruction. RECORD 3: EXFILTRATION ATTEMPT & IOC SUMMARY MEMO (EXCERPT) Author: CISO Crisis Taskforce / Legal Incident Response Team Date: 2026-08-14 06:30:00Z Classification: Attorney-Client Privileged Work-Product (In Anticipation of Litigation) 1. EXFILTRATION TRIAGE & CONTAINMENT ACTION 1.1 At 04:02:11Z, egress alerts triggered on network sensor TAP-03 for anomalous outbound traffic from NAS-RECORDS-04 to external IP `203.0.113.84` over port 443 (Rclone binary masquerading as `svchost_update.exe`). 1.2 Incident Command ordered immediate disconnection of all enterprise WAN circuits at 04:05:00Z, severing the exfiltration session after 3.2 GB of a 44 GB archive was transmitted. 1.3 Regulatory Reporting Clock: SEC Form 8-K four-business-day material incident disclosure clock initiated. HIPAA breach notification clock (HHS OCR 60-day rule) initiated. 2. VERIFIED INDICATORS OF COMPROMISE (IOCs) - Initial Compromise IP: 203.0.113.195 - C2 Listening IP / Port: 198.51.100.88:8443 - Exfiltration Destination IP: 203.0.113.84:443 - Dropped Stager Hash (SHA-256): 3c9b8821a7df09c84e2079da152b992160d5c07bfa762b3294ee1280fae41d8e - Exfiltration Staging File: C:\Windows\Temp\perflogs_dat.cab (3.2 GB transmitted before physical WAN sever) - Stolen Credentials: Account `svc_backup_admin` (Domain Admin privileges abused for volume shadow copy deletion)