File name:

RE_ SOLICITUD DE COTIZACION URGENTE.eml

Full analysis: https://app.any.run/tasks/19d9f7b1-b0e5-4d33-bf33-f6375a136a74
Verdict: Malicious activity
Threats:

Agent Tesla is spyware that collects information about the actions of its victims by recording keystrokes and user interactions. It is falsely marketed as a legitimate software on the dedicated website where this malware is sold.

Analysis date: May 02, 2024, 17:43:46
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
spam
evasion
agenttesla
stealer
smtp
exfiltration
Indicators:
MIME: message/rfc822
File info: SMTP mail, Unicode text, UTF-8 text, with CRLF line terminators
MD5:

67A30F812E6DFAA9C4FBC01214FB5E7A

SHA1:

BE64250492C9861149DD375B23994FA215A31389

SHA256:

621662A893C222BB8E2B8D1A776E0516369DC8574756A98C1BF3D58F0C463226

SSDEEP:

12288:C4hU6oGo9n5mVvMw4AUydFQxn3OazaiDpJ5pg:C4mnOMkUpx35Jlpg

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Antivirus name has been found in the command line (generic signature)

      • Powershell.exe (PID: 2600)
      • Powershell.exe (PID: 2616)
      • Powershell.exe (PID: 2908)
      • Powershell.exe (PID: 3132)
    • Steals credentials from Web Browsers

      • RegAsm.exe (PID: 2384)
      • RegAsm.exe (PID: 3276)
    • AGENTTESLA has been detected (YARA)

      • RegAsm.exe (PID: 2384)
      • RegAsm.exe (PID: 3008)
      • RegAsm.exe (PID: 3276)
    • Actions looks like stealing of personal data

      • RegAsm.exe (PID: 2384)
      • RegAsm.exe (PID: 3276)
  • SUSPICIOUS

    • Starts POWERSHELL.EXE for commands execution

      • QUOTATION_MAYQTRA031244·PDF.scr (PID: 2556)
      • QUOTATION_MAYQTRA031244·PDF.scr (PID: 2692)
      • QUOTATION_MAYQTRA031244·PDF.scr (PID: 2804)
      • QUOTATION_MAYQTRA031244·PDF.scr (PID: 2756)
    • Reads the Internet Settings

      • RegAsm.exe (PID: 2300)
      • RegAsm.exe (PID: 2384)
      • RegAsm.exe (PID: 3008)
      • RegAsm.exe (PID: 3276)
    • Checks for external IP

      • RegAsm.exe (PID: 2384)
      • RegAsm.exe (PID: 3008)
      • RegAsm.exe (PID: 3276)
    • Connects to SMTP port

      • RegAsm.exe (PID: 2384)
      • RegAsm.exe (PID: 3276)
    • Accesses Microsoft Outlook profiles

      • RegAsm.exe (PID: 2384)
      • RegAsm.exe (PID: 3276)
    • Starts application with an unusual extension

      • rundll32.exe (PID: 2792)
    • Reads settings of System Certificates

      • RegAsm.exe (PID: 3276)
  • INFO

    • Manual execution by a user

      • WinRAR.exe (PID: 1072)
      • explorer.exe (PID: 1616)
      • QUOTATION_MAYQTRA031244·PDF.scr (PID: 2556)
      • QUOTATION_MAYQTRA031244·PDF.scr (PID: 2692)
      • wmpnscfg.exe (PID: 2544)
      • QUOTATION_MAYQTRA031244·PDF.scr (PID: 2756)
      • rundll32.exe (PID: 2792)
      • cmd.exe (PID: 3904)
    • The process uses the downloaded file

      • OUTLOOK.EXE (PID: 3972)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1072)
    • Checks supported languages

      • QUOTATION_MAYQTRA031244·PDF.scr (PID: 2556)
      • RegAsm.exe (PID: 2300)
      • QUOTATION_MAYQTRA031244·PDF.scr (PID: 2692)
      • RegAsm.exe (PID: 2384)
      • wmpnscfg.exe (PID: 2544)
      • RegAsm.exe (PID: 3008)
      • QUOTATION_MAYQTRA031244·PDF.scr (PID: 2804)
      • RegAsm.exe (PID: 3276)
      • QUOTATION_MAYQTRA031244·PDF.scr (PID: 2756)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 1072)
    • Reads the computer name

      • QUOTATION_MAYQTRA031244·PDF.scr (PID: 2556)
      • RegAsm.exe (PID: 2300)
      • QUOTATION_MAYQTRA031244·PDF.scr (PID: 2692)
      • RegAsm.exe (PID: 2384)
      • wmpnscfg.exe (PID: 2544)
      • QUOTATION_MAYQTRA031244·PDF.scr (PID: 2804)
      • RegAsm.exe (PID: 3008)
      • QUOTATION_MAYQTRA031244·PDF.scr (PID: 2756)
      • RegAsm.exe (PID: 3276)
    • Reads the machine GUID from the registry

      • QUOTATION_MAYQTRA031244·PDF.scr (PID: 2556)
      • RegAsm.exe (PID: 2300)
      • QUOTATION_MAYQTRA031244·PDF.scr (PID: 2692)
      • RegAsm.exe (PID: 2384)
      • QUOTATION_MAYQTRA031244·PDF.scr (PID: 2804)
      • RegAsm.exe (PID: 3008)
      • QUOTATION_MAYQTRA031244·PDF.scr (PID: 2756)
      • RegAsm.exe (PID: 3276)
    • Script raised an exception (POWERSHELL)

      • Powershell.exe (PID: 2600)
      • Powershell.exe (PID: 2616)
      • Powershell.exe (PID: 2908)
      • Powershell.exe (PID: 3132)
    • Reads Environment values

      • RegAsm.exe (PID: 2300)
      • RegAsm.exe (PID: 2384)
      • RegAsm.exe (PID: 3008)
      • RegAsm.exe (PID: 3276)
    • Reads the software policy settings

      • RegAsm.exe (PID: 3276)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

AgentTesla

(PID) Process(2384) RegAsm.exe
Protocolsmtp
Hostgator3220.hostgator.com
Port587
Usernamedworld@qlststv.com
PasswordDasco..!@@hT!3V
(PID) Process(3008) RegAsm.exe
Protocolsmtp
Hostgator3220.hostgator.com
Port587
Usernamedworld@qlststv.com
PasswordDasco..!@@hT!3V
(PID) Process(3276) RegAsm.exe
Protocolsmtp
Hostgator3220.hostgator.com
Port587
Usernamedworld@qlststv.com
PasswordDasco..!@@hT!3V
No Malware configuration.

TRiD

.eml | E-Mail message (Var. 1) (100)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
64
Monitored processes
20
Malicious processes
7
Suspicious processes
0

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
1072"C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Documents\Orden de compra.P7696.z" C:\Users\admin\Documents\C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1616"C:\Windows\explorer.exe" C:\Windows\explorer.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2288certutil -hashfile QUOTATION_MAYQTRA031244·PDF.scrC:\Windows\System32\certutil.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
CertUtil.exe
Exit code:
0
Version:
6.1.7601.18151 (win7sp1_gdr.130512-1533)
Modules
Images
c:\windows\system32\certutil.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\certcli.dll
c:\windows\system32\atl.dll
2300"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe
QUOTATION_MAYQTRA031244·PDF.scr
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft .NET Assembly Registration Utility
Exit code:
4294967295
Version:
4.8.3761.0 built by: NET48REL1
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\regasm.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
2384"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe
QUOTATION_MAYQTRA031244·PDF.scr
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft .NET Assembly Registration Utility
Exit code:
4294967295
Version:
4.8.3761.0 built by: NET48REL1
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\regasm.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
AgentTesla
(PID) Process(2384) RegAsm.exe
Protocolsmtp
Hostgator3220.hostgator.com
Port587
Usernamedworld@qlststv.com
PasswordDasco..!@@hT!3V
2544"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2556"C:\Users\admin\Documents\QUOTATION_MAYQTRA031244·PDF.scr" /SC:\Users\admin\Documents\QUOTATION_MAYQTRA031244·PDF.screxplorer.exe
User:
admin
Company:
command-line
Integrity Level:
MEDIUM
Description:
ESET
Exit code:
0
Version:
0.0.0.0
Modules
Images
c:\users\admin\documents\quotation_mayqtra031244·pdf.scr
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2600"Powershell.exe" 'C:\Users\admin\Documents\QUOTATION_MAYQTRA031244·PDF.scr' 'C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ESET.exe'C:\Windows\System32\WindowsPowerShell\v1.0\Powershell.exeQUOTATION_MAYQTRA031244·PDF.scr
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
1
Version:
10.0.14409.1005 (rs1_srvoob.161208-1155)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
2616"Powershell.exe" 'C:\Users\admin\Documents\QUOTATION_MAYQTRA031244·PDF.scr' 'C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ESET.exe'C:\Windows\System32\WindowsPowerShell\v1.0\Powershell.exeQUOTATION_MAYQTRA031244·PDF.scr
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
1
Version:
10.0.14409.1005 (rs1_srvoob.161208-1155)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
2692"C:\Users\admin\Documents\QUOTATION_MAYQTRA031244·PDF.scr" /SC:\Users\admin\Documents\QUOTATION_MAYQTRA031244·PDF.screxplorer.exe
User:
admin
Company:
command-line
Integrity Level:
MEDIUM
Description:
ESET
Exit code:
0
Version:
0.0.0.0
Modules
Images
c:\users\admin\documents\quotation_mayqtra031244·pdf.scr
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
29 596
Read events
28 934
Write events
625
Delete events
37

Modification events

(PID) Process:(3972) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1033
Value:
Off
(PID) Process:(3972) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1041
Value:
Off
(PID) Process:(3972) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1046
Value:
Off
(PID) Process:(3972) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1036
Value:
Off
(PID) Process:(3972) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1031
Value:
Off
(PID) Process:(3972) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1040
Value:
Off
(PID) Process:(3972) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1049
Value:
Off
(PID) Process:(3972) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:3082
Value:
Off
(PID) Process:(3972) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1042
Value:
Off
(PID) Process:(3972) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1055
Value:
Off
Executable files
1
Suspicious files
17
Text files
5
Unknown types
0

Dropped files

PID
Process
Filename
Type
3972OUTLOOK.EXEC:\Users\admin\AppData\Local\Temp\CVR2906.tmp.cvr
MD5:
SHA256:
3972OUTLOOK.EXEC:\Users\admin\Documents\Outlook Files\Outlook Data File - NoMail.pst
MD5:
SHA256:
3972OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Outlook\mapisvc.inftext
MD5:F3B25701FE362EC84616A93A45CE9998
SHA256:B3D510EF04275CA8E698E5B3CBB0ECE3949EF9252F0CDC839E9EE347409A2209
3972OUTLOOK.EXEC:\Users\admin\AppData\Roaming\Microsoft\Templates\~WRD0000.tmp
MD5:
SHA256:
3972OUTLOOK.EXEC:\Users\admin\AppData\Local\Temp\tmp2BA7.tmpbinary
MD5:4E5FD95E767F2AB1883CC524570657DF
SHA256:1D89B3C337672D86321E6667ED4D688E3A3904712C7C5DD21ED44655C5BF3B82
3972OUTLOOK.EXEC:\Users\admin\AppData\Roaming\Microsoft\Templates\~$rmalEmail.dotmbinary
MD5:A05630F037C05D973CA846D39DCD63B5
SHA256:BD8D2C9838535E337048066E543BD932F526E9C571942B21FE744E397DD7A7C2
3972OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\{25BD4A9C-A9F2-4998-A59A-5B677739BB7E}\{1C306CB1-771E-4B4B-A902-86E897877F5B}.pngimage
MD5:4C61C12EDBC453D7AE184976E95258E1
SHA256:296526F9A716C1AA91BA5D6F69F0EB92FDF79C2CB2CFCF0CEB22B7CCBC27035F
3972OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Outlook\DQRKK8ER\Orden de compra P7696.zlzh
MD5:1EB7788A33AEE6D74F476DC1D11E7E65
SHA256:F4D4E891C6AEDB87609BAC8028C8F545F2440C54A2D747B96499A508CC191027
3972OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Outlook\DQRKK8ER\Orden de compra P7696.z:Zone.Identifiertext
MD5:FBCCF14D504B7B2DBCB5A5BDA75BD93B
SHA256:EACD09517CE90D34BA562171D15AC40D302F0E691B439F91BE1B6406E25F5913
2792rundll32.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Themes\Custom.themetext
MD5:C1FCF55A48CAF02CBC0FEC89C8B44C9D
SHA256:1497F2B7237A7DAEF8DF4568F8BFEF1B7B8FEBE4082A797725C410DF1CE3B961
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
12
DNS requests
8
Threats
11

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3008
RegAsm.exe
GET
208.95.112.1:80
http://ip-api.com/line/?fields=hosting
US
unknown
3276
RegAsm.exe
GET
200
208.95.112.1:80
http://ip-api.com/line/?fields=hosting
US
text
6 b
unknown
2384
RegAsm.exe
GET
200
208.95.112.1:80
http://ip-api.com/line/?fields=hosting
US
text
6 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
3972
OUTLOOK.EXE
64.4.26.155:80
config.messenger.msn.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
1088
svchost.exe
224.0.0.252:5355
unknown
2300
RegAsm.exe
208.95.112.1:80
ip-api.com
TUT-AS
US
unknown
2384
RegAsm.exe
208.95.112.1:80
ip-api.com
TUT-AS
US
unknown
2384
RegAsm.exe
198.57.247.184:587
gator3220.hostgator.com
UNIFIEDLAYER-AS-1
US
unknown
3008
RegAsm.exe
208.95.112.1:80
ip-api.com
TUT-AS
US
unknown
3276
RegAsm.exe
208.95.112.1:80
ip-api.com
TUT-AS
US
unknown

DNS requests

Domain
IP
Reputation
config.messenger.msn.com
  • 64.4.26.155
whitelisted
ip-api.com
  • 208.95.112.1
shared
gator3220.hostgator.com
  • 198.57.247.184
malicious

Threats

PID
Process
Class
Message
Potential Corporate Privacy Violation
AV POLICY Internal Host Retrieving External IP Address (ip-api. com)
Device Retrieving External IP Address Detected
POLICY [ANY.RUN] External Hosting Lookup by ip-api
Device Retrieving External IP Address Detected
ET POLICY External IP Lookup ip-api.com
Potential Corporate Privacy Violation
AV POLICY Internal Host Retrieving External IP Address (ip-api. com)
Device Retrieving External IP Address Detected
POLICY [ANY.RUN] External Hosting Lookup by ip-api
Device Retrieving External IP Address Detected
ET POLICY External IP Lookup ip-api.com
Potential Corporate Privacy Violation
AV POLICY Internal Host Retrieving External IP Address (ip-api. com)
Device Retrieving External IP Address Detected
POLICY [ANY.RUN] External Hosting Lookup by ip-api
Device Retrieving External IP Address Detected
ET POLICY External IP Lookup ip-api.com
Misc activity
INFO [ANY.RUN] SMTP email client opens transfer with server (EHLO)
No debug info