⭐ SOC250 — APT35 HyperScrape Data Exfiltration Tool Detected — LetsDefend Walkthrough
By Owais Ali Khan
⭐ SOC250 — APT35 HyperScrape Data Exfiltration Tool Detected — LetsDefend Walkthrough
By Owais Ali Khan

Full Investigation Report

Alert triggered reason is “Unusual or suspicious patterns of behavior linked to the hash have been identified, indicating potential malicious intent.”
👇File Hash Is flagged malicious by VirusTotal.

👇File is also executed at EndPoint.

Contain the Endpoint.

Lets check Log Management


According to log Arthur downloaded multiple mails at Dec, 27, 2023, 11:21 AM.
Then at 11:22 AM, that malicious exe file is executed and contacted 136.243.108.14.

IP 136.243.108.14 is also flagged malicious by VirusTotal. Which means it is the C2 server.

Lets Create a Case

As given in the alert, APT35 extract emails from victim’s mailboxes. So select Gather Victim Identity Information.

Yes the IP was External.

also IP was suspicious.

During the investigation, we did not find any other endpoint except Arthur.
So, the answer is NO

Add C2 Address, File Hash and Victim IP in artifacts.

Add Analyst Note:
A malicious executable
EmailDownloader.exewas executed on host 172.16.17.72 (Arthur). The file was located in the user’s Downloads directory and was likely executed by the user, indicating social engineering or phishing. Analysis indicates the binary functions as a HyperScrape-like email extraction tool, used to download the victim’s entire mailbox from the Exchange server. The extracted data was then sent to an external IP address 136.243.108.14, controlled by the attacker.
Details:
Host: 172.16.17.72 (Arthur)
Process:
EmailDownloader.exe(Downloads directory)
Parent Process: Explorer.exe — indicates interactive execution
Behavior: Connected to Exchange and downloaded mailbox contents
Malicious External IP: 136.243.108.14 (attacker infrastructure)
Impact: Full mailbox compromise — potential data exfiltration

메타데이터
- post_id
- b20ae23b19ab
- slug
- soc250-apt35-hyperscrape-data-exfiltration-tool-detected-letsdefend-walkthrough-b20ae23b19ab
- url
- https://medium.com/@owaisalikhan081/soc250-apt35-hyperscrape-data-exfiltration-tool-detected-letsdefend-walkthrough-b20ae23b19ab
- canonical_url
- https://medium.com/@owaisalikhan081/soc250-apt35-hyperscrape-data-exfiltration-tool-detected-letsdefend-walkthrough-b20ae23b19ab
- author_url
- https://medium.com/@owaisalikhan081
- status
- ok
- fetched_at
- 2026-06-22 12:55:45