{
  "generated": "2026-07-09T21:00:23Z",
  "count": 5,
  "detections": [
    {
      "id": "a1b2c3d4e5f6",
      "family": "AgentTesla",
      "filename": "invoice_2026.exe",
      "verdict": "malicious",
      "severity": "high",
      "report": "2026/a1b2c3d4e5f6-invoice.md",
      "yara": "import \"pe\"\n\nrule malscope_agenttesla_a1b2c3d4e5f6\n{\n    meta:\n        author = \"malscope\"\n        description = \"AgentTesla - invoice_2026.exe\"\n        family = \"AgentTesla\"\n        sha256 = \"a1b2c3d4e5f60718293a4b5c6d7e8f90112233445566778899aabbccddeeff00\"\n        tlp = \"TLP:CLEAR\"\n        date = \"2026-07-09\"\n        reference = \"2026/a1b2c3d4e5f6-invoice.md\"\n    strings:\n        $s0 = \"TESLA-0725\" ascii wide\n        $s1 = \"tesla-mtx-9F2A\" ascii wide\n    condition:\n        uint16(0) == 0x5A4D and (pe.imphash() == \"8f4e2b1c9a7d6e3f0b5a4c8d2e1f7a90\" or 2 of ($s*))\n}\n",
      "sigma": "title: AgentTesla network activity - invoice_2026.exe\nid: cdb9331e-3632-57c2-85e7-638de287df5a\nstatus: experimental\ndescription: Auto-generated by malscope from analysis findings. Review before deploying.\nreferences:\n- 2026/a1b2c3d4e5f6-invoice.md\nauthor: malscope\ndate: 2026/07/09\ntags:\n- attack.t1059.003\n- attack.t1055\n- attack.t1112\n- attack.t1547\n- attack.t1071\nlogsource:\n  category: proxy\ndetection:\n  selection:\n    DestinationHostname|contains:\n    - c2[.]agent-tesla[.]top\n    - 185[.]220[.]101[.]45\n    - 45[.]83[.]13[.]4\n    c-uri|contains:\n    - /gate[.]php\n  condition: selection\nfalsepositives:\n- Unknown\nlevel: high\n---\ntitle: AgentTesla registry activity - invoice_2026.exe\nid: 79ff2780-881f-505a-91b4-1486aa2651fe\nstatus: experimental\ndescription: Auto-generated by malscope from analysis findings. Review before deploying.\nreferences:\n- 2026/a1b2c3d4e5f6-invoice.md\nauthor: malscope\ndate: 2026/07/09\ntags:\n- attack.t1059.003\n- attack.t1055\n- attack.t1112\n- attack.t1547\n- attack.t1071\nlogsource:\n  product: windows\n  category: registry_set\ndetection:\n  selection:\n    TargetObject|contains:\n    - \\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\Skype\n  condition: selection\nfalsepositives:\n- Unknown\nlevel: high\n---\ntitle: AgentTesla file activity - invoice_2026.exe\nid: 376a230e-c73a-59e1-bac5-d5dd48aa5f75\nstatus: experimental\ndescription: Auto-generated by malscope from analysis findings. Review before deploying.\nreferences:\n- 2026/a1b2c3d4e5f6-invoice.md\nauthor: malscope\ndate: 2026/07/09\ntags:\n- attack.t1059.003\n- attack.t1055\n- attack.t1112\n- attack.t1547\n- attack.t1071\nlogsource:\n  product: windows\n  category: file_event\ndetection:\n  selection:\n    TargetFilename|contains:\n    - '%AppData%\\Roaming\\Skype\\skype.exe'\n  condition: selection\nfalsepositives:\n- Unknown\nlevel: high",
      "sigma_count": 3
    },
    {
      "id": "b2c3d4e5f607",
      "family": "AgentTesla",
      "filename": "order_confirmation.exe",
      "verdict": "malicious",
      "severity": "high",
      "report": "2026/b2c3d4e5f607-order.md",
      "yara": "import \"pe\"\n\nrule malscope_agenttesla_b2c3d4e5f607\n{\n    meta:\n        author = \"malscope\"\n        description = \"AgentTesla - order_confirmation.exe\"\n        family = \"AgentTesla\"\n        sha256 = \"b2c3d4e5f60718293a4b5c6d7e8f90112233445566778899aabbccddeeff0011\"\n        tlp = \"TLP:CLEAR\"\n        date = \"2026-07-09\"\n        reference = \"2026/b2c3d4e5f607-order.md\"\n    strings:\n        $s0 = \"TESLA-0725\" ascii wide\n        $s1 = \"tesla-mtx-9F2A\" ascii wide\n    condition:\n        uint16(0) == 0x5A4D and (pe.imphash() == \"8f4e2b1c9a7d6e3f0b5a4c8d2e1f7a90\" or 2 of ($s*))\n}\n",
      "sigma": "title: AgentTesla network activity - order_confirmation.exe\nid: d0f7519d-86be-55c6-82b4-d1ed205e97a6\nstatus: experimental\ndescription: Auto-generated by malscope from analysis findings. Review before deploying.\nreferences:\n- 2026/b2c3d4e5f607-order.md\nauthor: malscope\ndate: 2026/07/09\ntags:\n- attack.t1059.003\n- attack.t1055\n- attack.t1071\n- attack.t1552\nlogsource:\n  category: proxy\ndetection:\n  selection:\n    DestinationHostname|contains:\n    - c2[.]agent-tesla[.]top\n    - 45[.]83[.]13[.]4\n    c-uri|contains:\n    - /gate[.]php\n  condition: selection\nfalsepositives:\n- Unknown\nlevel: high\n---\ntitle: AgentTesla registry activity - order_confirmation.exe\nid: fbb8202b-76b3-5937-a49a-bd29e90c5e88\nstatus: experimental\ndescription: Auto-generated by malscope from analysis findings. Review before deploying.\nreferences:\n- 2026/b2c3d4e5f607-order.md\nauthor: malscope\ndate: 2026/07/09\ntags:\n- attack.t1059.003\n- attack.t1055\n- attack.t1071\n- attack.t1552\nlogsource:\n  product: windows\n  category: registry_set\ndetection:\n  selection:\n    TargetObject|contains:\n    - \\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\Skype\n  condition: selection\nfalsepositives:\n- Unknown\nlevel: high",
      "sigma_count": 2
    },
    {
      "id": "e5f607182a3b",
      "family": "AgentTesla",
      "filename": "invoice_march.exe",
      "verdict": "malicious",
      "severity": "high",
      "report": "2026/e5f607182a3b-march.md",
      "yara": "import \"pe\"\n\nrule malscope_agenttesla_e5f607182a3b\n{\n    meta:\n        author = \"malscope\"\n        description = \"AgentTesla - invoice_march.exe\"\n        family = \"AgentTesla\"\n        sha256 = \"e5f607182a3b0718293a4b5c6d7e8f90112233445566778899aabbccddeeff05\"\n        tlp = \"TLP:CLEAR\"\n        date = \"2026-07-09\"\n        reference = \"2026/e5f607182a3b-march.md\"\n    strings:\n        $s0 = \"TESLA-0725\" ascii wide\n        $s1 = \"tesla-mtx-9F2A\" ascii wide\n    condition:\n        uint16(0) == 0x5A4D and (pe.imphash() == \"a9c1d2e3f4b5a6978c0d1e2f3a4b5c6d\" or 2 of ($s*))\n}\n",
      "sigma": "title: AgentTesla network activity - invoice_march.exe\nid: 1e73fb16-76f5-5f9e-af17-7c6271a88cac\nstatus: experimental\ndescription: Auto-generated by malscope from analysis findings. Review before deploying.\nreferences:\n- 2026/e5f607182a3b-march.md\nauthor: malscope\ndate: 2026/07/09\ntags:\n- attack.t1059.003\n- attack.t1055\n- attack.t1071\n- attack.t1547\nlogsource:\n  category: proxy\ndetection:\n  selection:\n    DestinationHostname|contains:\n    - c2[.]agent-tesla[.]top\n    - 185[.]220[.]101[.]45\n    - 45[.]83[.]13[.]4\n    c-uri|contains:\n    - /gate[.]php\n  condition: selection\nfalsepositives:\n- Unknown\nlevel: high\n---\ntitle: AgentTesla registry activity - invoice_march.exe\nid: ce81c788-e10e-5861-9ec4-f449de410ec6\nstatus: experimental\ndescription: Auto-generated by malscope from analysis findings. Review before deploying.\nreferences:\n- 2026/e5f607182a3b-march.md\nauthor: malscope\ndate: 2026/07/09\ntags:\n- attack.t1059.003\n- attack.t1055\n- attack.t1071\n- attack.t1547\nlogsource:\n  product: windows\n  category: registry_set\ndetection:\n  selection:\n    TargetObject|contains:\n    - \\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\Skype\n  condition: selection\nfalsepositives:\n- Unknown\nlevel: high\n---\ntitle: AgentTesla file activity - invoice_march.exe\nid: a3081690-a497-5b65-8e57-e99fac409c89\nstatus: experimental\ndescription: Auto-generated by malscope from analysis findings. Review before deploying.\nreferences:\n- 2026/e5f607182a3b-march.md\nauthor: malscope\ndate: 2026/07/09\ntags:\n- attack.t1059.003\n- attack.t1055\n- attack.t1071\n- attack.t1547\nlogsource:\n  product: windows\n  category: file_event\ndetection:\n  selection:\n    TargetFilename|contains:\n    - '%AppData%\\Roaming\\Skype\\skype.exe'\n  condition: selection\nfalsepositives:\n- Unknown\nlevel: high",
      "sigma_count": 3
    },
    {
      "id": "c3d4e5f60718",
      "family": "Formbook",
      "filename": "setup_x86.scr",
      "verdict": "malicious",
      "severity": "critical",
      "report": "2026/c3d4e5f60718-setup.md",
      "yara": "import \"pe\"\n\nrule malscope_formbook_c3d4e5f60718\n{\n    meta:\n        author = \"malscope\"\n        description = \"Formbook - setup_x86.scr\"\n        family = \"Formbook\"\n        sha256 = \"c3d4e5f60718293a4b5c6d7e8f90112233445566778899aabbccddeeff001122\"\n        tlp = \"TLP:CLEAR\"\n        date = \"2026-07-09\"\n        reference = \"2026/c3d4e5f60718-setup.md\"\n    strings:\n        $s0 = \"FB-DECEMBER\" ascii wide\n        $s1 = \"fb-mtx-7c\" ascii wide\n    condition:\n        uint16(0) == 0x5A4D and (pe.imphash() == \"1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e\" or 2 of ($s*))\n}\n",
      "sigma": "title: Formbook network activity - setup_x86.scr\nid: 903dc42e-e21a-58e7-89fd-09c723d852d7\nstatus: experimental\ndescription: Auto-generated by malscope from analysis findings. Review before deploying.\nreferences:\n- 2026/c3d4e5f60718-setup.md\nauthor: malscope\ndate: 2026/07/09\ntags:\n- attack.t1055\n- attack.t1027\n- attack.t1497\n- attack.t1105\n- attack.t1071\nlogsource:\n  category: proxy\ndetection:\n  selection:\n    DestinationHostname|contains:\n    - formbook-panel[.]xyz\n    - 91[.]92[.]240[.]12\n    c-uri|contains:\n    - /fb/\n  condition: selection\nfalsepositives:\n- Unknown\nlevel: critical\n---\ntitle: Formbook file activity - setup_x86.scr\nid: 2c460ced-dba8-52f0-b730-96a7abe1ec62\nstatus: experimental\ndescription: Auto-generated by malscope from analysis findings. Review before deploying.\nreferences:\n- 2026/c3d4e5f60718-setup.md\nauthor: malscope\ndate: 2026/07/09\ntags:\n- attack.t1055\n- attack.t1027\n- attack.t1497\n- attack.t1105\n- attack.t1071\nlogsource:\n  product: windows\n  category: file_event\ndetection:\n  selection:\n    TargetFilename|contains:\n    - '%Temp%\\fb\\svchost.exe'\n  condition: selection\nfalsepositives:\n- Unknown\nlevel: critical",
      "sigma_count": 2
    },
    {
      "id": "d4e5f6071829",
      "family": "",
      "filename": "resume_update.doc",
      "verdict": "suspicious",
      "severity": "medium",
      "report": "2026/d4e5f6071829-resume.md",
      "yara": "import \"hash\"\n\nrule malscope_d4e5f6071829\n{\n    meta:\n        author = \"malscope\"\n        description = \"ole - resume_update.doc\"\n        sha256 = \"d4e5f60718293a4b5c6d7e8f90112233445566778899aabbccddeeff00112233\"\n        tlp = \"TLP:CLEAR\"\n        date = \"2026-07-09\"\n        reference = \"2026/d4e5f6071829-resume.md\"\n    condition:\n        hash.sha256(0, filesize) == \"d4e5f60718293a4b5c6d7e8f90112233445566778899aabbccddeeff00112233\"\n}\n",
      "sigma": "title: ole network activity - resume_update.doc\nid: 5221db52-0ccc-551f-beb0-25c6b8ddbaac\nstatus: experimental\ndescription: Auto-generated by malscope from analysis findings. Review before deploying.\nreferences:\n- 2026/d4e5f6071829-resume.md\nauthor: malscope\ndate: 2026/07/09\ntags:\n- attack.t1059.003\n- attack.t1204\n- attack.t1027\nlogsource:\n  category: proxy\ndetection:\n  selection:\n    DestinationHostname|contains:\n    - staging[.]doc-download[.]cc\n    c-uri|contains:\n    - /p[.]php\n  condition: selection\nfalsepositives:\n- Unknown\nlevel: medium",
      "sigma_count": 1
    }
  ]
}
