File name: | Phish Alert Partners in Value Added Logistics.msg |
Full analysis: | https://app.any.run/tasks/f83d8f06-6733-4536-bc73-2848810acfe9 |
Verdict: | Malicious activity |
Analysis date: | January 24, 2022, 16:36:42 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/vnd.ms-outlook |
File info: | CDFV2 Microsoft Outlook Message |
MD5: | B76D369D2B94802C092F01303FCB8613 |
SHA1: | D42DC63FF2523E0206C468F6728FE1C61B242E3C |
SHA256: | 6C08BAF31C20C2A8FBAAA42BF4CF4175E35705448D4DE21C1BACFE3609F4F284 |
SSDEEP: | 3072:SXyIYI76kQ7jZnN5dTyM3cWvLgUy80ka2MTnEyXDb1yUK/Nt+aSCi6:aZR6kQ7jZrdTyGLgUydlEyzbQN+aSq |
.msg | | | Outlook Message (50.8) |
---|---|---|
.oft | | | Outlook Form Template (29.7) |
.doc | | | Microsoft Word document (old ver.) (13.6) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
3204 | "C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE" /f "C:\Users\admin\AppData\Local\Temp\Phish Alert Partners in Value Added Logistics.msg" | C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE | Explorer.EXE | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Outlook Version: 14.0.6025.1000 Modules
| |||||||||||||||
1648 | "C:\PROGRA~1\MICROS~1\Office14\OUTLOOK.EXE" /eml "C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Outlook\TOG97TBY\Partners in Value Added Logistics .eml" | C:\PROGRA~1\MICROS~1\Office14\OUTLOOK.EXE | — | OUTLOOK.EXE | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Outlook Exit code: 0 Version: 14.0.6025.1000 Modules
| |||||||||||||||
2752 | "C:\Program Files\Internet Explorer\iexplore.exe" https://express.adobe.com/page/nXCXwKkbifk43/ | C:\Program Files\Internet Explorer\iexplore.exe | OUTLOOK.EXE | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Exit code: 1 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
636 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2752 CREDAT:267521 /prefetch:2 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
1168 | "C:\Program Files\Internet Explorer\iexplore.exe" https://express.adobe.com/page/nXCXwKkbifk43/ | C:\Program Files\Internet Explorer\iexplore.exe | — | OUTLOOK.EXE | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
3280 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:1168 CREDAT:267521 /prefetch:2 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
|
PID | Process | Filename | Type | |
---|---|---|---|---|
3204 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Temp\CVREB1F.tmp.cvr | — | |
MD5:— | SHA256:— | |||
3204 | OUTLOOK.EXE | C:\Users\admin\Documents\Outlook Files\Outlook Data File - NoMail.pst | — | |
MD5:— | SHA256:— | |||
1648 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Temp\CVR83C.tmp.cvr | — | |
MD5:— | SHA256:— | |||
3204 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Temp\outlook logging\firstrun.log | text | |
MD5:8B5F10B9A51E4456DEC617270D7BC6DE | SHA256:0F11D7F3333972010917A54783FF4EE5CAE74FB6001FA2706ECEA28272F5ACE3 | |||
636 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7423F88C7F265F0DEFC08EA88C3BDE45_A30EA9B4E1BC5DBF09A8EF399E086D27 | der | |
MD5:CD160FB2083E2B8319C2BC34F34919BC | SHA256:6D954523FA5A003ADE3E8BAFC8ECA4B3455979882B64C2C83A23DF5B1514004F | |||
3204 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Outlook\TOG97TBY\Partners in Value Added Logistics .eml | eml | |
MD5:B5EB7B398076736DA7A64B920B0D1740 | SHA256:CAFB5AFD44754664AB6CDFB2D4E9163CA65888DC2CF20C9AF31A397A320D7B50 | |||
3204 | OUTLOOK.EXE | C:\Users\admin\AppData\Roaming\Microsoft\Templates\~$rmalEmail.dotm | pgc | |
MD5:FAFB8DFC9A9D0592588588698B193883 | SHA256:2EA6A3EAAF0DEA4CF33174FC0C89D3C02EC9A59DD7882330A980C7D84EF71E4D | |||
3204 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\B44E92B7.dat | image | |
MD5:C15A71EF393126E4B2A30B5ECE75888D | SHA256:23EA77F493AE0D43786978150DC4A3DE257B1EE9DA70454007EEAB676316D221 | |||
3204 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Outlook\TOG97TBY\Partners in Value Added Logistics (2).eml | eml | |
MD5:B5EB7B398076736DA7A64B920B0D1740 | SHA256:CAFB5AFD44754664AB6CDFB2D4E9163CA65888DC2CF20C9AF31A397A320D7B50 | |||
636 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7423F88C7F265F0DEFC08EA88C3BDE45_A30EA9B4E1BC5DBF09A8EF399E086D27 | binary | |
MD5:297D362D9129BBE367AA38873324C8F5 | SHA256:32609B7A8BBEC4DC6C98249DA0627E03BC92218526BF50CAE74BD8090699381C |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
2752 | iexplore.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8Ull8gIGmZT9XHrHiJQeI%3D | US | der | 1.47 Kb | whitelisted |
636 | iexplore.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAo1CNVcKSsBffitZcAP9%2BQ%3D | US | der | 471 b | whitelisted |
636 | iexplore.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQQX6Z6gAidtSefNc6DC0OInqPHDQQUD4BhHIIxYdUvKOeNRji0LOHG2eICEA0knq2V1auIC6zBMVRnEnU%3D | US | der | 471 b | whitelisted |
636 | iexplore.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAbY2QTVWENG9oovp1QifsQ%3D | US | der | 471 b | whitelisted |
636 | iexplore.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAH9o%2BtuynXIiEOLckvPvJE%3D | US | der | 471 b | whitelisted |
636 | iexplore.exe | GET | 200 | 209.197.3.8:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?98f83552be6cf29d | US | compressed | 4.70 Kb | whitelisted |
2752 | iexplore.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | US | der | 471 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
636 | iexplore.exe | 209.197.3.8:80 | ctldl.windowsupdate.com | Highwinds Network Group, Inc. | US | whitelisted |
636 | iexplore.exe | 2.16.186.59:443 | use.typekit.net | Akamai International B.V. | — | whitelisted |
636 | iexplore.exe | 65.9.61.57:443 | express.adobe.com | AT&T Services, Inc. | US | unknown |
636 | iexplore.exe | 65.9.61.118:443 | page.adobespark-assets.com | AT&T Services, Inc. | US | unknown |
— | — | 192.168.100.2:53 | — | — | — | whitelisted |
3204 | OUTLOOK.EXE | 64.4.26.155:80 | config.messenger.msn.com | Microsoft Corporation | US | whitelisted |
636 | iexplore.exe | 93.184.220.29:80 | ocsp.digicert.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
2752 | iexplore.exe | 65.9.61.118:443 | page.adobespark-assets.com | AT&T Services, Inc. | US | unknown |
636 | iexplore.exe | 104.111.215.74:443 | p.typekit.net | Akamai International B.V. | NL | unknown |
— | — | 13.107.22.200:443 | www.bing.com | Microsoft Corporation | US | whitelisted |
Domain | IP | Reputation |
---|---|---|
www.microsoft.com |
| whitelisted |
config.messenger.msn.com |
| whitelisted |
express.adobe.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
page.adobespark-assets.com |
| whitelisted |
use.typekit.net |
| whitelisted |
api.bing.com |
| whitelisted |
www.bing.com |
| whitelisted |
p.typekit.net |
| shared |