We could not retrieve intelligence data for this hash. Verify the hash value and try again.
A file hash is the densest starting point on the platform. One value resolves to antivirus verdicts, sandbox behaviour, every network indicator the sample reached for, and the attacker techniques that behaviour maps to.
These are format examples. Clicking one puts it in the search box — it does not run a search, so you choose when to spend a lookup.
These are the sections of the report, in the order you will meet them.
The headline call, and the fraction of engines behind it. Read the ratio, not just the verdict: 2/70 and 58/70 are both 'detected' and mean very different things.
Which engines flagged the sample and what each one named it. Detection names are where a family label comes from, and disagreement between engines is itself a signal worth noting.
What the sample did when it was run, rather than what it looks like on disk. Behaviour survives repacking; a static signature often does not.
The IPs, domains and URLs extracted from the sample. This is the section you pivot from -- each entry is a search of its own, and usually the next step.
Observed behaviour expressed as ATT&CK techniques, which is what lets you compare this sample to known actors and to your own detection coverage.
Which sources contributed, so you can weigh a thin result against a corroborated one. A single-source verdict is a lead, not a conclusion.
AI assistant — can make mistakes. Verify important results.