← Back to list

⭐ SOC250 — APT35 HyperScrape Data Exfiltration Tool Detected — LetsDefend Walkthrough

By Owais Ali Khan

Owais Ali Khan · 2026-02-12 14:37 · 10 claps · 2.6 min read
#apt35 #cyberattack #letsdefendio #letsdefend-writeup #investigation
Open on Medium ↗
Wiki topics: 🔒 · Cybersecurity

⭐ SOC250 — APT35 HyperScrape Data Exfiltration Tool Detected — LetsDefend Walkthrough

By Owais Ali Khan

Full Investigation Report

Alert triggered reason is “Unusual or suspicious patterns of behavior linked to the hash have been identified, indicating potential malicious intent.”

👇File Hash Is flagged malicious by VirusTotal.

👇File is also executed at EndPoint.

Contain the Endpoint.

Lets check Log Management

According to log Arthur downloaded multiple mails at Dec, 27, 2023, 11:21 AM.

Then at 11:22 AM, that malicious exe file is executed and contacted 136.243.108.14.

IP 136.243.108.14 is also flagged malicious by VirusTotal. Which means it is the C2 server.

Lets Create a Case

As given in the alert, APT35 extract emails from victim’s mailboxes. So select Gather Victim Identity Information.

Yes the IP was External.

also IP was suspicious.

During the investigation, we did not find any other endpoint except Arthur.

So, the answer is NO

Add C2 Address, File Hash and Victim IP in artifacts.

Add Analyst Note:

A malicious executable EmailDownloader.exe was executed on host 172.16.17.72 (Arthur). The file was located in the user’s Downloads directory and was likely executed by the user, indicating social engineering or phishing. Analysis indicates the binary functions as a HyperScrape-like email extraction tool, used to download the victim’s entire mailbox from the Exchange server. The extracted data was then sent to an external IP address 136.243.108.14, controlled by the attacker.

Details:

Host: 172.16.17.72 (Arthur)

Process: EmailDownloader.exe (Downloads directory)

Parent Process: Explorer.exe — indicates interactive execution

Behavior: Connected to Exchange and downloaded mailbox contents

Malicious External IP: 136.243.108.14 (attacker infrastructure)

Impact: Full mailbox compromise — potential data exfiltration


메타데이터
post_id
b20ae23b19ab
slug
soc250-apt35-hyperscrape-data-exfiltration-tool-detected-letsdefend-walkthrough-b20ae23b19ab
url
https://medium.com/@owaisalikhan081/soc250-apt35-hyperscrape-data-exfiltration-tool-detected-letsdefend-walkthrough-b20ae23b19ab
canonical_url
https://medium.com/@owaisalikhan081/soc250-apt35-hyperscrape-data-exfiltration-tool-detected-letsdefend-walkthrough-b20ae23b19ab
author_url
https://medium.com/@owaisalikhan081
status
ok
fetched_at
2026-06-22 12:55:45