File name:

source (2).eml

Full analysis: https://app.any.run/tasks/f20a7e92-4e7c-4630-8ce7-f52b5cd02407
Verdict: Malicious activity
Analysis date: September 07, 2019, 16:03:49
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: message/rfc822
File info: RFC 822 mail, ASCII text, with very long lines, with CRLF line terminators
MD5:

30A3FDA65E1632707C9ACF875A60A704

SHA1:

E14AD184186E12F844AFCD8009D34542B6AA942F

SHA256:

617853F67E81BA6667DDF75F7BE744F2C5918A9107D6680B112534234C22D84A

SSDEEP:

768:11lAi9tGOCYBqFqMqBqRqLqTqnqWqiqsqhqdqInSqWqLnPqfjzF4mzk:OApW5Kc40OHjn6WrnS7onPc94mg

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Creates files in the user directory

      • OUTLOOK.EXE (PID: 3580)
    • Reads Internet Cache Settings

      • OUTLOOK.EXE (PID: 3580)
    • Starts Internet Explorer

      • OUTLOOK.EXE (PID: 3580)
    • Executed via COM

      • FlashUtil32_26_0_0_131_ActiveX.exe (PID: 3924)
      • FlashUtil32_26_0_0_131_ActiveX.exe (PID: 576)
  • INFO

    • Changes internet zones settings

      • iexplore.exe (PID: 3116)
      • iexplore.exe (PID: 2444)
      • iexplore.exe (PID: 2540)
    • Reads Internet Cache Settings

      • iexplore.exe (PID: 3832)
      • iexplore.exe (PID: 3160)
      • iexplore.exe (PID: 1752)
      • iexplore.exe (PID: 2540)
    • Creates files in the user directory

      • iexplore.exe (PID: 3832)
      • iexplore.exe (PID: 3116)
      • iexplore.exe (PID: 3160)
      • FlashUtil32_26_0_0_131_ActiveX.exe (PID: 3924)
      • iexplore.exe (PID: 1752)
      • FlashUtil32_26_0_0_131_ActiveX.exe (PID: 576)
      • iexplore.exe (PID: 2540)
    • Reads internet explorer settings

      • iexplore.exe (PID: 3832)
      • iexplore.exe (PID: 3160)
      • iexplore.exe (PID: 1752)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 3116)
    • Application launched itself

      • iexplore.exe (PID: 2444)
    • Adds / modifies Windows certificates

      • iexplore.exe (PID: 2444)
      • iexplore.exe (PID: 2540)
    • Changes settings of System certificates

      • iexplore.exe (PID: 2444)
      • iexplore.exe (PID: 2540)
    • Dropped object may contain Bitcoin addresses

      • iexplore.exe (PID: 1752)
    • Reads Microsoft Office registry keys

      • OUTLOOK.EXE (PID: 3580)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.eml | E-Mail message (Var. 5) (100)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
45
Monitored processes
9
Malicious processes
0
Suspicious processes
1

Behavior graph

Click at the process to see the details
start outlook.exe iexplore.exe iexplore.exe iexplore.exe iexplore.exe flashutil32_26_0_0_131_activex.exe no specs iexplore.exe iexplore.exe flashutil32_26_0_0_131_activex.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
576C:\Windows\system32\Macromed\Flash\FlashUtil32_26_0_0_131_ActiveX.exe -EmbeddingC:\Windows\system32\Macromed\Flash\FlashUtil32_26_0_0_131_ActiveX.exesvchost.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
MEDIUM
Description:
Adobe® Flash® Player Installer/Uninstaller 26.0 r0
Exit code:
0
Version:
26,0,0,131
Modules
Images
c:\windows\system32\macromed\flash\flashutil32_26_0_0_131_activex.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1752"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2540 CREDAT:71937C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2444"C:\Program Files\Internet Explorer\iexplore.exe" https://gcc01.safelinks.protection.outlook.com/?url=https%3A%2F%2Famzn.to%2F2lDs0y0&data=02%7C01%7Cmary.miller%40education.ohio.gov%7C75c5d7884f8447dcf68708d732a1a205%7C50f8fcc494d84f0784eb36ed57c7c8a2%7C0%7C1%7C637033542099280094&sdata=zCXr7RA9q4OG%2FsOZBdVjv%2BfvUlrdrVaf47rqlqVR70Q%3D&reserved=0C:\Program Files\Internet Explorer\iexplore.exe
OUTLOOK.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
1
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2540"C:\Program Files\Internet Explorer\iexplore.exe" https://gcc01.safelinks.protection.outlook.com/?url=http%3A%2F%2Fec2-52-26-194-35.us-west-2.compute.amazonaws.com%2Fx%2Fd%3Fc%3D4927557%26l%3Df8246896-0f47-46b7-9cc4-d8556f6b1623%26r%3D6be7fe2e-32ff-44f6-81ba-c066c2dff28e&data=02%7C01%7Cmary.miller%40education.ohio.gov%7C75c5d7884f8447dcf68708d732a1a205%7C50f8fcc494d84f0784eb36ed57c7c8a2%7C0%7C1%7C637033542099290101&sdata=k5RWUSo4QOhuVGkLD1yvqfbUf38VKiu7i0LBSvzcyTc%3D&reserved=0C:\Program Files\Internet Explorer\iexplore.exe
OUTLOOK.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
1
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3116"C:\Program Files\Internet Explorer\iexplore.exe" https://gcc01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fyoutu.be%2FpzR74VRCArc&data=02%7C01%7Cmary.miller%40education.ohio.gov%7C75c5d7884f8447dcf68708d732a1a205%7C50f8fcc494d84f0784eb36ed57c7c8a2%7C0%7C1%7C637033542099270086&sdata=ynJBn8JAKp1nLN%2BBc1LwpbnxRjjm2fFLc3l8QnFjSEQ%3D&reserved=0C:\Program Files\Internet Explorer\iexplore.exe
OUTLOOK.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
1
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3160"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2444 CREDAT:71937C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
3221225547
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3580"C:\PROGRA~1\MICROS~1\Office14\OUTLOOK.EXE" /eml "C:\Users\admin\AppData\Local\Temp\source (2).eml"C:\PROGRA~1\MICROS~1\Office14\OUTLOOK.EXE
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Outlook
Exit code:
0
Version:
14.0.6025.1000
Modules
Images
c:\progra~1\micros~1\office14\outlook.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3832"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3116 CREDAT:71937C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3924C:\Windows\system32\Macromed\Flash\FlashUtil32_26_0_0_131_ActiveX.exe -EmbeddingC:\Windows\system32\Macromed\Flash\FlashUtil32_26_0_0_131_ActiveX.exesvchost.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
MEDIUM
Description:
Adobe® Flash® Player Installer/Uninstaller 26.0 r0
Exit code:
0
Version:
26,0,0,131
Modules
Images
c:\windows\system32\macromed\flash\flashutil32_26_0_0_131_activex.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\lpk.dll
c:\windows\system32\advapi32.dll
Total events
2 824
Read events
2 177
Write events
618
Delete events
29

Modification events

(PID) Process:(3580) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1033
Value:
Off
(PID) Process:(3580) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1033
Value:
On
(PID) Process:(3580) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Resiliency\StartupItems
Operation:writeName:<=$
Value:
3C3D2400FC0D0000010000000000000000000000
(PID) Process:(3580) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook
Operation:writeName:MTTT
Value:
FC0D000022DA56DF9565D50100000000
(PID) Process:(3580) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\SQM
Operation:writeName:SQMSessionNumber
Value:
0
(PID) Process:(3580) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\SQM
Operation:writeName:SQMSessionDate
Value:
220204800
(PID) Process:(3580) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\NoMail\0a0d020000000000c000000000000046
Operation:writeName:00030429
Value:
03000000
(PID) Process:(3580) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\NoMail\9375CFF0413111d3B88A00104B2A6676
Operation:writeName:{ED475418-B0D6-11D2-8C3B-00104B2A6676}
Value:
(PID) Process:(3580) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\NoMail\9375CFF0413111d3B88A00104B2A6676
Operation:writeName:LastChangeVer
Value:
1200000000000000
(PID) Process:(3580) OUTLOOK.EXEKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109A10090400000000000F01FEC\Usage
Operation:writeName:OutlookMAPI2Intl_1033
Value:
1327955989
Executable files
0
Suspicious files
11
Text files
173
Unknown types
29

Dropped files

PID
Process
Filename
Type
3580OUTLOOK.EXEC:\Users\admin\AppData\Local\Temp\CVR9D8D.tmp.cvr
MD5:
SHA256:
3116iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\favicon[1].ico
MD5:
SHA256:
3116iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
MD5:
SHA256:
3832iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\admin@youtube[2].txt
MD5:
SHA256:
3580OUTLOOK.EXEC:\Users\admin\AppData\Roaming\Microsoft\Templates\~$rmalEmail.dotmpgc
MD5:
SHA256:
3832iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\index.datdat
MD5:
SHA256:
3832iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\admin@youtube[1].txttext
MD5:
SHA256:
3580OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Outlook\RoamCache\Stream_AvailabilityOptions_2_D9227A2EAB9E8C479809A2FCA5E9E1A8.datxml
MD5:EEAA832C12F20DE6AAAA9C7B77626E72
SHA256:C4C9A90F2C961D9EE79CF08FBEE647ED7DE0202288E876C7BAAD00F4CA29CA16
3832iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\QUHPP6BX\watch[1].htmhtml
MD5:
SHA256:
3832iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\index.datdat
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
72
DNS requests
33
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3580
OUTLOOK.EXE
GET
64.4.26.155:80
http://config.messenger.msn.com/config/msgrconfig.asmx?op=GetOlcConfig
US
whitelisted
1752
iexplore.exe
GET
302
191.101.164.106:80
http://go.lenhurag.com/match-6013/36615/159136232/1567872322/mf_dc22d40f-ea1b-412e-8b4e-a2812beafc0c/dHMxNTEtaW50ZXJuYXRpb25hbC1nZW5lcmFs/?thru=404236_147150_13954_CH_D
DE
suspicious
2444
iexplore.exe
GET
200
13.35.254.229:80
http://d2lo25i6d3q8zm.cloudfront.net/browser-plugins/AmazonSearchSuggestionsOSD.DPIE.xml
US
xml
1.18 Kb
shared
1752
iexplore.exe
GET
302
52.26.194.35:80
http://ec2-52-26-194-35.us-west-2.compute.amazonaws.com/x/d?c=4927557&l=f8246896-0f47-46b7-9cc4-d8556f6b1623&r=6be7fe2e-32ff-44f6-81ba-c066c2dff28e
US
html
231 b
shared
1752
iexplore.exe
GET
200
191.101.164.106:80
http://go.lenhurag.com/ts151-international-general?thru=404236_147150_13954_CH_D
DE
html
350 b
suspicious
3160
iexplore.exe
GET
200
13.107.4.50:80
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
US
compressed
57.0 Kb
whitelisted
3160
iexplore.exe
GET
200
13.35.254.34:80
http://x.ss2.us/x.cer
US
der
1.27 Kb
whitelisted
3116
iexplore.exe
GET
200
204.79.197.200:80
http://www.bing.com/favicon.ico
US
image
237 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3580
OUTLOOK.EXE
64.4.26.155:80
config.messenger.msn.com
Microsoft Corporation
US
whitelisted
3116
iexplore.exe
204.79.197.200:80
www.bing.com
Microsoft Corporation
US
whitelisted
3832
iexplore.exe
216.58.205.238:443
youtu.be
Google Inc.
US
whitelisted
3832
iexplore.exe
172.217.22.110:443
www.youtube.com
Google Inc.
US
whitelisted
3832
iexplore.exe
172.217.22.35:443
fonts.gstatic.com
Google Inc.
US
whitelisted
3832
iexplore.exe
172.217.18.174:443
www.youtube.com
Google Inc.
US
whitelisted
3832
iexplore.exe
173.194.160.73:443
r4---sn-1gi7znes.googlevideo.com
Google Inc.
US
whitelisted
3832
iexplore.exe
172.217.21.237:443
accounts.google.com
Google Inc.
US
whitelisted
3116
iexplore.exe
172.217.22.110:443
www.youtube.com
Google Inc.
US
whitelisted
3160
iexplore.exe
104.47.62.28:443
gcc01.safelinks.protection.outlook.com
Microsoft Corporation
US
unknown

DNS requests

Domain
IP
Reputation
config.messenger.msn.com
  • 64.4.26.155
whitelisted
gcc01.safelinks.protection.outlook.com
  • 104.47.62.28
  • 104.47.63.28
whitelisted
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
youtu.be
  • 216.58.205.238
shared
www.youtube.com
  • 172.217.22.110
  • 216.58.210.14
  • 172.217.16.206
  • 172.217.18.110
  • 172.217.23.174
  • 172.217.21.206
  • 216.58.205.238
  • 172.217.21.238
  • 172.217.22.14
  • 172.217.18.14
  • 172.217.18.174
  • 172.217.23.142
  • 216.58.207.46
  • 216.58.207.78
  • 216.58.208.46
  • 172.217.16.142
whitelisted
s.ytimg.com
  • 172.217.18.174
whitelisted
fonts.gstatic.com
  • 172.217.22.35
whitelisted
r4---sn-1gi7znes.googlevideo.com
  • 173.194.160.73
whitelisted
accounts.google.com
  • 172.217.21.237
shared
ssl.gstatic.com
  • 216.58.210.3
whitelisted

Threats

PID
Process
Class
Message
1060
svchost.exe
Potentially Bad Traffic
ET DNS Query for .to TLD
1752
iexplore.exe
Potentially Bad Traffic
ET INFO Observed Let's Encrypt Certificate for Suspicious TLD (.xyz)
No debug info