File name: | FW_ Reminder - Unsubmitted Expense Report.msg |
Full analysis: | https://app.any.run/tasks/fc6cb4e4-7582-4673-9ee4-3c6bdbec0f75 |
Verdict: | Malicious activity |
Analysis date: | March 30, 2020, 20:25:48 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/vnd.ms-outlook |
File info: | CDFV2 Microsoft Outlook Message |
MD5: | 1F1BFDFB0B60C5FEA61CD94DAC9F202A |
SHA1: | 311CAD1338DCD0785F00FD0CAAC35E8EC87412E8 |
SHA256: | 247BE8658A41F2B9159FDF6916021B751C15465E6E1B183DEC5AA091E36F4D62 |
SSDEEP: | 768:IMrM4YMsKfsKCbKunCgYR/0rsKwgRcn+8etsK3sK+fIjKF/l26WROm:sMXajXcnDet/Gl26aOm |
.msg | | | Outlook Message (58.9) |
---|---|---|
.oft | | | Outlook Form Template (34.4) |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
3596 | "C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE" /f "C:\Users\admin\AppData\Local\Temp\FW_ Reminder - Unsubmitted Expense Report.msg" | C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE | explorer.exe | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Outlook Version: 14.0.6025.1000 | ||||
2808 | "C:\Program Files\Internet Explorer\iexplore.exe" https://idp.avnet.com/isam/sps/classic/saml20/logininitial?PartnerId=https://us.api.concursolutions.com/saml2 | C:\Program Files\Internet Explorer\iexplore.exe | OUTLOOK.EXE | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Version: 11.00.9600.16428 (winblue_gdr.131013-1700) | ||||
1392 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2808 CREDAT:267521 /prefetch:2 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | |
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Version: 11.00.9600.16428 (winblue_gdr.131013-1700) |
PID | Process | Filename | Type | |
---|---|---|---|---|
3596 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Temp\CVR7B14.tmp.cvr | — | |
MD5:— | SHA256:— | |||
1392 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\Low\CabD24C.tmp | — | |
MD5:— | SHA256:— | |||
1392 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\Low\TarD24D.tmp | — | |
MD5:— | SHA256:— | |||
2808 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico | — | |
MD5:— | SHA256:— | |||
3596 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Temp\outlook logging\firstrun.log | text | |
MD5:D4D32FA3EF6CB89B2E962E640D5126D6 | SHA256:68449B852025AC0D22BF5FFFB4BD28004ABAE05DE4F91CBA13CB1609D0BB96FF | |||
3596 | OUTLOOK.EXE | C:\Users\admin\AppData\Roaming\Microsoft\Templates\~$rmalEmail.dotm | pgc | |
MD5:1E0F0E9ADF00002D88534EFF42F0E8ED | SHA256:04B3CE45818D5E91B0BC73DBC195C0675718BC8EFEE359DF5BF5BE0583B89420 | |||
1392 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\5054D3D7526395AFD1BB54714B2BD386_CC7526819148E7E79E04FC07A202DB8B | der | |
MD5:B331F5F6D14445CD93F8AB4D4BA8A295 | SHA256:007394C36EF91BE85AD6809EC25D3D81132B55A130345C2782F24D2F962E10EC | |||
1392 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\auth[1].htm | html | |
MD5:44DB30A1C6D502BDD4EA00FD0E715F4D | SHA256:26FE6BC9A5AB957FD5A9B9974F9869B111DCF6425E87F074764BD79DDF6DAD48 | |||
1392 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\A37B8BA80004D3266CB4D93B2052DC10_9930CFFA1A8DC7DD2E91B8BAFFAF726D | binary | |
MD5:A403E24074B8656245BAD55CDA4A9D38 | SHA256:D544385EE9357D3886F3CBF0631AA39C019D62AE346CD4B759BA98B1F4605A63 | |||
1392 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\9EC3B71635F8BA3FC68DE181A104A0EF_F6C39EF89D8A3A72327D8412589658B2 | der | |
MD5:07107A0A2191B1F1F36A144C96FD39AE | SHA256:AC8CBF631399F3761411FBDC1AAEE7E85F5A0AC8E0B5EB11F38F780DFED58C50 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
3596 | OUTLOOK.EXE | GET | — | 64.4.26.155:80 | http://config.messenger.msn.com/config/msgrconfig.asmx?op=GetOlcConfig | US | — | — | whitelisted |
1392 | iexplore.exe | GET | 200 | 151.139.128.14:80 | http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEH1bUSa0droR23QWC7xTDac%3D | US | der | 727 b | whitelisted |
1392 | iexplore.exe | GET | 200 | 151.139.128.14:80 | http://ocsp.trust-provider.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBR8sWZUnKvbRO5iJhat9GV793rVlAQUrb2YejS0Jvf6xCZU7wO94CTLVBoCEENSAj%2F6qJAfE5%2Fj9OXBRE4%3D | US | der | 471 b | whitelisted |
1392 | iexplore.exe | GET | 200 | 151.139.128.14:80 | http://ocsp.comodoca4.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrJdiQ%2Ficg9B19asFe73bPYs%2BreAQUdXGnGUgZvJ2d6kFH35TESHeZ03kCEFslzmkHxCZVZtM5DJmpVK0%3D | US | der | 313 b | whitelisted |
1392 | iexplore.exe | GET | 200 | 151.139.128.14:80 | http://ocsp.trust-provider.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBR8sWZUnKvbRO5iJhat9GV793rVlAQUrb2YejS0Jvf6xCZU7wO94CTLVBoCEENSAj%2F6qJAfE5%2Fj9OXBRE4%3D | US | der | 471 b | whitelisted |
1392 | iexplore.exe | GET | 200 | 151.139.128.14:80 | http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBReAhtobFzTvhaRmVeJ38QUchY9AwQUu69%2BAj36pvE8hI6t7jiY7NkyMtQCECsuburZdTZsFIpu26N8jAc%3D | US | der | 727 b | whitelisted |
1392 | iexplore.exe | GET | 200 | 151.139.128.14:80 | http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBR8sWZUnKvbRO5iJhat9GV793rVlAQUrb2YejS0Jvf6xCZU7wO94CTLVBoCEBPqKHBb9OztDDZjCYBhQzY%3D | US | der | 471 b | whitelisted |
1392 | iexplore.exe | GET | 200 | 23.45.103.47:80 | http://ocsp.entrust.net/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBTLXNCzDvBhHecWjg70iJhBW0InywQUanImetAe733nO2lR1GyNn5ASZqsCDA7pTMMAAAAAUdN3hQ%3D%3D | NL | der | 1.55 Kb | whitelisted |
1392 | iexplore.exe | GET | 200 | 151.139.128.14:80 | http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBR8sWZUnKvbRO5iJhat9GV793rVlAQUrb2YejS0Jvf6xCZU7wO94CTLVBoCECdm7lbrSfOOq9dwovyE3iI%3D | US | der | 471 b | whitelisted |
1392 | iexplore.exe | GET | 200 | 151.139.128.14:80 | http://ocsp.comodoca4.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTOpjOEf6LG1z52jqAxwDlTxoaOCgQUQAlhZ%2FC8g3FP3hIILG%2FU1Ct2PZYCEQCNmx6n%2FS%2FCc0UBRhCdwaxd | US | der | 280 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
1392 | iexplore.exe | 23.45.103.47:80 | ocsp.entrust.net | Akamai International B.V. | NL | unknown |
3596 | OUTLOOK.EXE | 64.4.26.155:80 | config.messenger.msn.com | Microsoft Corporation | US | whitelisted |
1392 | iexplore.exe | 209.197.3.15:443 | maxcdn.bootstrapcdn.com | Highwinds Network Group, Inc. | US | whitelisted |
1392 | iexplore.exe | 12.9.136.86:443 | idp.avnet.com | Avnet Inc. | US | unknown |
2808 | iexplore.exe | 204.79.197.200:80 | www.bing.com | Microsoft Corporation | US | whitelisted |
2808 | iexplore.exe | 13.107.21.200:80 | www.bing.com | Microsoft Corporation | US | whitelisted |
2808 | iexplore.exe | 152.199.19.161:443 | iecvlist.microsoft.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
2808 | iexplore.exe | 12.9.136.86:443 | idp.avnet.com | Avnet Inc. | US | unknown |
1392 | iexplore.exe | 209.197.3.24:443 | code.jquery.com | Highwinds Network Group, Inc. | US | malicious |
1392 | iexplore.exe | 151.139.128.14:80 | ocsp.trust-provider.com | Highwinds Network Group, Inc. | US | suspicious |
Domain | IP | Reputation |
---|---|---|
config.messenger.msn.com |
| whitelisted |
idp.avnet.com |
| unknown |
api.bing.com |
| whitelisted |
www.bing.com |
| whitelisted |
ocsp.entrust.net |
| whitelisted |
maxcdn.bootstrapcdn.com |
| whitelisted |
code.jquery.com |
| whitelisted |
cdnjs.cloudflare.com |
| whitelisted |
ocsp.trust-provider.com |
| whitelisted |
ocsp.usertrust.com |
| whitelisted |