analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

Image File Received 29092020 IFR ID 004647839873.msg

Full analysis: https://app.any.run/tasks/b0e1f961-34b0-453b-9c02-3f62f281abf2
Verdict: Malicious activity
Analysis date: September 30, 2020, 06:59:03
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/vnd.ms-outlook
File info: CDFV2 Microsoft Outlook Message
MD5:

D74EE106DCBF5C20B56101BE13544264

SHA1:

ABC8F7F565DB125BF5C2F0D2EB61158527E61E88

SHA256:

18618EFCD4DC8ED4A414E0D252D65A72C00DB9E39DF549C25C57B2476E07E94A

SSDEEP:

768:5OoOsN6NsKCsK+Y1rycuEAxDDBbd0nPOuz5TZq9J2Fg/LdUoom64wKT8iUZ:pWa2Y1rycujlDOPU2C2oR

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Unusual execution from Microsoft Office

      • OUTLOOK.EXE (PID: 2612)
  • SUSPICIOUS

    • Starts Internet Explorer

      • OUTLOOK.EXE (PID: 2612)
    • Creates files in the user directory

      • OUTLOOK.EXE (PID: 2612)
  • INFO

    • Reads Internet Cache Settings

      • iexplore.exe (PID: 2820)
      • iexplore.exe (PID: 3080)
      • OUTLOOK.EXE (PID: 2612)
      • iexplore.exe (PID: 2440)
      • iexplore.exe (PID: 3484)
    • Changes internet zones settings

      • iexplore.exe (PID: 3080)
    • Application launched itself

      • iexplore.exe (PID: 3080)
    • Reads Microsoft Office registry keys

      • OUTLOOK.EXE (PID: 2612)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 2820)
      • iexplore.exe (PID: 3080)
    • Reads internet explorer settings

      • iexplore.exe (PID: 2820)
      • iexplore.exe (PID: 3484)
      • iexplore.exe (PID: 2440)
    • Changes settings of System certificates

      • iexplore.exe (PID: 3080)
    • Adds / modifies Windows certificates

      • iexplore.exe (PID: 3080)
    • Creates files in the user directory

      • iexplore.exe (PID: 2820)
      • iexplore.exe (PID: 3484)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msg | Outlook Message (58.9)
.oft | Outlook Form Template (34.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
42
Monitored processes
5
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start outlook.exe iexplore.exe iexplore.exe iexplore.exe iexplore.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2612"C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE" /f "C:\Users\admin\AppData\Local\Temp\Image File Received 29092020 IFR ID 004647839873.msg"C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Outlook
Version:
14.0.6025.1000
3080"C:\Program Files\Internet Explorer\iexplore.exe" https://mail.yandex.com/re.jsx?h=a,aI7DMOvhTZ3ynw7s3HoYlg&l=aHR0cHM6Ly9wdWIubHVjaWRwcmVzcy5jb20vZDVjNWE2MDUtYzhlMC00ZWM0LWExNDktNDIzNjQ0YmU0NjEzLwC:\Program Files\Internet Explorer\iexplore.exe
OUTLOOK.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
2820"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3080 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
3489660927
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
3484"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3080 CREDAT:1709316 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
2440"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3080 CREDAT:1578248 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exeiexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Total events
2 437
Read events
1 706
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
31
Text files
89
Unknown types
22

Dropped files

PID
Process
Filename
Type
2612OUTLOOK.EXEC:\Users\admin\AppData\Local\Temp\CVRAF8F.tmp.cvr
MD5:
SHA256:
2820iexplore.exeC:\Users\admin\AppData\Local\Temp\Low\CabD874.tmp
MD5:
SHA256:
2612OUTLOOK.EXEC:\Users\admin\AppData\Roaming\Microsoft\Templates\~$rmalEmail.dotmpgc
MD5:3C0FB11081575977E5D863E99746B4DA
SHA256:893CD4886D3E56B0206424F6E375EC1576585DD78B020AE30C4171BB90626362
2820iexplore.exeC:\Users\admin\AppData\Local\Temp\Low\TarD875.tmp
MD5:
SHA256:
2820iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\1B1F4BA66CDBFEC85A20E11BF729AF23_AA85F8F9DAFF33153B5AEC2E983B94B6der
MD5:BF03F35791909EA75D3157E53EED722A
SHA256:0C5E56AE9A067AA0D8EE8AE0868459E197B10459A9C9EA6CCF74FDE18270D742
3080iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
MD5:
SHA256:
2612OUTLOOK.EXEC:\Users\admin\AppData\Local\Temp\outlook logging\firstrun.logtext
MD5:F74FE5F93BE2D2DD5A66603D0CFFC8A5
SHA256:74196E39D61CC2A6ABCAC9F471CABDD0BB3CB9F2DB8E1C7988D186C343FE478C
2820iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E887E036775F4159E2816B7B9E527E5F_CF8153DC44FEDCAC05D3FB121BE5ABB1binary
MD5:097DFCB4C2CC516AB96F7E336EC8AF8D
SHA256:3C85FA4AD207412F8E4940B50910CF8DE5104F1B97B3851AE476D16A2412B20B
2612OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Outlook\RoamCache\Stream_WorkHours_1_919E764577E2734AAD64147A354A02E2.datxml
MD5:807EF0FC900FEB3DA82927990083D6E7
SHA256:4411E7DC978011222764943081500FFF0E43CBF7CCD44264BD1AB6306CA68913
2820iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\1B1F4BA66CDBFEC85A20E11BF729AF23_AA85F8F9DAFF33153B5AEC2E983B94B6binary
MD5:C5C3DC57450464392E0C65F134685883
SHA256:D7F1C754A481D988F78F0F2363D31CF3289977D365FE1D0E3B89E921098F7373
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
14
TCP/UDP connections
36
DNS requests
14
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2820
iexplore.exe
GET
200
151.139.236.246:80
http://subca.ocsp-certum.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTYOkzrrCGQj08njZXbUQQpkoUmuQQUCHbNywf%2FJPbFze27kLzihDdGdfcCEQDkBUeDDgxkUpdvejVJwN1I
US
der
1.63 Kb
whitelisted
2820
iexplore.exe
GET
200
5.45.205.245:80
http://yandex.ocsp-responder.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBStniMGfahyWUWDEeSLUFbNR9JLAgQUN1zjGeCyjqGoTtLPq9Dc4wtcNU0CEGMmPh%2BpF%2FVdy5Q2h0nEnQk%3D
RU
der
1.48 Kb
whitelisted
2820
iexplore.exe
GET
200
5.45.205.245:80
http://yandex.ocsp-responder.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBStniMGfahyWUWDEeSLUFbNR9JLAgQUN1zjGeCyjqGoTtLPq9Dc4wtcNU0CECp5lw5VJUdi1sZ3IDVGUzE%3D
RU
der
1.48 Kb
whitelisted
2820
iexplore.exe
GET
200
5.45.205.245:80
http://yandex.ocsp-responder.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBStniMGfahyWUWDEeSLUFbNR9JLAgQUN1zjGeCyjqGoTtLPq9Dc4wtcNU0CEHP3E9TXO%2BCrXEp%2Fr6%2BwXiA%3D
RU
der
1.48 Kb
whitelisted
2820
iexplore.exe
GET
200
5.45.205.245:80
http://yandex.ocsp-responder.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBStniMGfahyWUWDEeSLUFbNR9JLAgQUN1zjGeCyjqGoTtLPq9Dc4wtcNU0CECp5lw5VJUdi1sZ3IDVGUzE%3D
RU
der
1.48 Kb
whitelisted
2820
iexplore.exe
GET
200
151.139.236.246:80
http://subca.ocsp-certum.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBR5iK7tYk9tqQEoeQhZNkKcAol9bgQUjEPEy22YwaechGnr30oNYJY6w%2FsCEQCTkoVAAWVxX5R%2FKI%2FvyZso
US
der
1.58 Kb
whitelisted
2820
iexplore.exe
GET
200
5.45.205.245:80
http://yandex.ocsp-responder.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBStniMGfahyWUWDEeSLUFbNR9JLAgQUN1zjGeCyjqGoTtLPq9Dc4wtcNU0CEC6Tkdyfl26sf%2Br5Aa05wdc%3D
RU
der
1.48 Kb
whitelisted
1052
svchost.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAo3h2ReX7SMIk79G%2B0UDDw%3D
US
der
1.47 Kb
whitelisted
3080
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8sEMlbBsCTf7jUSfg%2BhWk%3D
US
der
1.47 Kb
whitelisted
3080
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8sEMlbBsCTf7jUSfg%2BhWk%3D
US
der
1.47 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2820
iexplore.exe
77.88.21.37:443
mail.yandex.com
YANDEX LLC
RU
whitelisted
3080
iexplore.exe
204.79.197.200:80
www.bing.com
Microsoft Corporation
US
whitelisted
2820
iexplore.exe
87.250.251.119:443
mc.yandex.ru
YANDEX LLC
RU
whitelisted
2820
iexplore.exe
5.45.205.245:80
yandex.ocsp-responder.com
YANDEX LLC
RU
whitelisted
2820
iexplore.exe
178.154.131.215:443
yastatic.net
YANDEX LLC
RU
whitelisted
178.154.131.215:443
yastatic.net
YANDEX LLC
RU
whitelisted
2612
OUTLOOK.EXE
64.4.26.155:80
config.messenger.msn.com
Microsoft Corporation
US
whitelisted
2820
iexplore.exe
151.139.236.246:80
subca.ocsp-certum.com
netDNA
US
unknown
2820
iexplore.exe
87.250.250.254:443
mc.admetrica.ru
YANDEX LLC
RU
unknown
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted

DNS requests

Domain
IP
Reputation
config.messenger.msn.com
  • 64.4.26.155
whitelisted
mail.yandex.com
  • 77.88.21.37
shared
subca.ocsp-certum.com
  • 151.139.236.246
whitelisted
yandex.ocsp-responder.com
  • 5.45.205.245
  • 5.45.205.241
  • 5.45.205.244
  • 5.45.205.242
  • 5.45.205.243
whitelisted
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
yastatic.net
  • 178.154.131.215
  • 178.154.131.216
  • 178.154.131.217
whitelisted
mc.yandex.ru
  • 87.250.251.119
  • 87.250.250.119
  • 77.88.21.119
  • 93.158.134.119
whitelisted
mc.admetrica.ru
  • 87.250.250.254
unknown
ocsp.digicert.com
  • 93.184.220.29
whitelisted

Threats

No threats detected
No debug info