Try VMRay Platform
Malicious
Classifications

Spyware Injector

Threat Names

Mal/Generic-S AgentTesla AgentTesla.v4

Remarks (1/1)

(0x02000008): One or more processes crashed during the analysis. Analysis results may be incomplete.

General

2.67 KB total sent, 5.28 KB total received
3 ports: 80, 443, 53
3 contacted IP addresses
0 URLs extracted
3 files downloaded
1 malicious hosts detected

DNS

113 Bytes sent, 209 Bytes received
2 queries for 2 domains
1 name server contacted
0 queries returned errors

HTTP/S

2.56 KB sent, 5.08 KB received
2 URLs, 2 contacted servers
2 sessions detected

2 Hosts

discord.com443
ip-api.com80
HTTP Requests (1)DNS Requests (1)WHOIS
POSThttps://discord.com/api/webhooks/1202330946817237022/1d5Ynow6yHbMqcRfr75qQjJVcSQnFlKpV4g5H2hHiKoRW33XeyZHnl-7hxdTf95oiy9f404162.159.128.233443
Malicious
RequestResponseFunction Log (26)PCAP Stream (3)

General Information

Timestamp165.009000
URLhttps://discord.com/api/webhooks/1202330946817237022/1d5Ynow6yHbMqcRfr75qQjJVcSQnFlKpV4g5H2hHiKoRW33XeyZHnl-7hxdTf95oiy9f
Original URLhttps://discord.com/api/webhooks/1202330946817237022/1d5Ynow6yHbMqcRfr75qQjJVcSQnFlKpV4g5H2hHiKoRW33XeyZHnl-7hxdTf95oiy9f
Version1.1
MethodPOST

Request Headers

Content-Typemultipart/form-data; boundary="----------794a7b62a967425eb20c93944cf21ed2"
User-AgentMozilla/5.0 (Windows NT 10.0; Win64; x64; rv:99.0) Gecko/20100101 Firefox/99.0
Hostdiscord.com
Content-Length1173
Expect100-continue
ConnectionKeep-Alive

URL Reputation Information

Reputation Status
N/A
Threat Data-
First Seen-
Last Seen-
Categoriesentertainment, social_networking

File Reputation Information

Filename: N/A
Reputation Status:
N/A
First Seen:-
Last Seen:-
Names:-
Families:-
Classifications: -
Function Logfile
Exit-Icon

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting \"security.fileuri.strict_origin_policy\".


    
Before

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting \"security.fileuri.strict_origin_policy\".


    
After

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting \"security.fileuri.strict_origin_policy\".


    
Screenshot
Expand-Icon
Exit-Icon
icon_left
icon_left
image