File name:

Receipt ID RE72244-4K_44.msg

Full analysis: https://app.any.run/tasks/c55e28d2-3235-4738-8777-caf2be33d956
Verdict: Malicious activity
Analysis date: August 27, 2021, 14:16:04
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/vnd.ms-outlook
File info: CDFV2 Microsoft Outlook Message
MD5:

7A7D96D954491263175E1E55687737AD

SHA1:

818836EFC65B3731651AD04524978B077B3D4B46

SHA256:

78985034BB83B0CF6F96EAE338D45086C6EB9FA211A49D985B294CB9367ACB29

SSDEEP:

1536:bhq56cPhkV90FKMp9AfXBMo04B1abW3WCQMxW9zO5DQaQVuW941a:bhcPhkV90FKK9wBw4B1amizgQaKV41a

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msg | Outlook Message (58.9)
.oft | Outlook Form Template (34.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
35
Monitored processes
1
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start outlook.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2568"C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE" /f "C:\Users\admin\AppData\Local\Temp\Receipt ID RE72244-4K_44.msg"C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXEExplorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Outlook
Exit code:
0
Version:
14.0.6025.1000
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\microsoft office\office14\outlook.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
1 678
Read events
1 634
Write events
43
Delete events
1

Modification events

(PID) Process:(2568) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1033
Value:
Off
(PID) Process:(2568) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1041
Value:
Off
(PID) Process:(2568) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1046
Value:
Off
(PID) Process:(2568) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1036
Value:
Off
(PID) Process:(2568) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1031
Value:
Off
(PID) Process:(2568) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1040
Value:
Off
(PID) Process:(2568) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1049
Value:
Off
(PID) Process:(2568) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:3082
Value:
Off
(PID) Process:(2568) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1042
Value:
Off
(PID) Process:(2568) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1055
Value:
Off
Executable files
0
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
2568OUTLOOK.EXEC:\Users\admin\AppData\Local\Temp\CVR91E7.tmp.cvr
MD5:
SHA256:
2568OUTLOOK.EXEC:\Users\admin\Documents\Outlook Files\Outlook Data File - NoMail.pst
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
119
TCP/UDP connections
48
DNS requests
40
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
HEAD
200
173.194.187.202:80
http://r5---sn-4g5e6nze.gvt1.com/edgedl/release2/chrome_component/gpe7ohs3f5omwhxxpxvcdvkwva_1.3.36.101/ihnlcenocehgdaegdmhbidjhnhdchfmm_1.3.36.101_win_adeodp7n5nw3wgk7xjdln2w2sgsq.crx3?cms_redirect=yes&mh=DH&mip=45.132.226.1&mm=28&mn=sn-4g5e6nze&ms=nvh&mt=1630073298&mv=m&mvi=5&pl=25&rmhost=r1---sn-4g5e6nze.gvt1.com&shardbypass=yes&smhost=r1---sn-4g5lznes.gvt1.com
US
whitelisted
GET
206
173.194.187.202:80
http://r5---sn-4g5e6nze.gvt1.com/edgedl/release2/chrome_component/gpe7ohs3f5omwhxxpxvcdvkwva_1.3.36.101/ihnlcenocehgdaegdmhbidjhnhdchfmm_1.3.36.101_win_adeodp7n5nw3wgk7xjdln2w2sgsq.crx3?cms_redirect=yes&mh=DH&mip=45.132.226.1&mm=28&mn=sn-4g5e6nze&ms=nvh&mt=1630073298&mv=m&mvi=5&pl=25&rmhost=r1---sn-4g5e6nze.gvt1.com&shardbypass=yes&smhost=r1---sn-4g5lznes.gvt1.com
US
binary
5.64 Kb
whitelisted
GET
200
74.125.160.198:80
http://r1---sn-4g5lznez.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvNzI0QUFXNV9zT2RvdUwyMERESEZGVmJnQQ/1.0.0.6_nmmhkkegccagdldgiimedpiccmgmieda.crx?cms_redirect=yes&mh=e_&mip=45.132.226.1&mm=28&mn=sn-4g5lznez&ms=nvh&mt=1630073298&mv=m&mvi=1&pl=25&rmhost=r3---sn-4g5lznez.gvt1.com&shardbypass=yes&smhost=r3---sn-4g5e6nzz.gvt1.com
US
crx
242 Kb
whitelisted
GET
302
142.250.186.142:80
http://redirector.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvNzI0QUFXNV9zT2RvdUwyMERESEZGVmJnQQ/1.0.0.6_nmmhkkegccagdldgiimedpiccmgmieda.crx
US
html
592 b
whitelisted
GET
64.4.26.155:80
http://config.messenger.msn.com/config/msgrconfig.asmx?op=GetOlcConfig
US
whitelisted
GET
302
142.250.186.142:80
http://redirector.gvt1.com/edgedl/release2/chrome_component/gpe7ohs3f5omwhxxpxvcdvkwva_1.3.36.101/ihnlcenocehgdaegdmhbidjhnhdchfmm_1.3.36.101_win_adeodp7n5nw3wgk7xjdln2w2sgsq.crx3
US
html
611 b
whitelisted
GET
206
173.194.187.202:80
http://r5---sn-4g5e6nze.gvt1.com/edgedl/release2/chrome_component/gpe7ohs3f5omwhxxpxvcdvkwva_1.3.36.101/ihnlcenocehgdaegdmhbidjhnhdchfmm_1.3.36.101_win_adeodp7n5nw3wgk7xjdln2w2sgsq.crx3?cms_redirect=yes&mh=DH&mip=45.132.226.1&mm=28&mn=sn-4g5e6nze&ms=nvh&mt=1630073298&mv=m&mvi=5&pl=25&rmhost=r1---sn-4g5e6nze.gvt1.com&shardbypass=yes&smhost=r1---sn-4g5lznes.gvt1.com
US
binary
20.7 Kb
whitelisted
GET
302
142.250.186.142:80
http://redirector.gvt1.com/edgedl/release2/chrome_component/gpe7ohs3f5omwhxxpxvcdvkwva_1.3.36.101/ihnlcenocehgdaegdmhbidjhnhdchfmm_1.3.36.101_win_adeodp7n5nw3wgk7xjdln2w2sgsq.crx3
US
html
611 b
whitelisted
GET
206
173.194.188.202:80
http://r5---sn-4g5ednsd.gvt1.com/edgedl/release2/chrome_component/gpe7ohs3f5omwhxxpxvcdvkwva_1.3.36.101/ihnlcenocehgdaegdmhbidjhnhdchfmm_1.3.36.101_win_adeodp7n5nw3wgk7xjdln2w2sgsq.crx3?cms_redirect=yes&mh=DH&mip=45.132.226.1&mm=28&mn=sn-4g5ednsd&ms=nvh&mt=1630073450&mv=u&mvi=5&pl=25&rmhost=r1---sn-4g5ednsd.gvt1.com&shardbypass=yes&smhost=r1---sn-4g5ednsl.gvt1.com
US
binary
9.42 Kb
whitelisted
GET
302
142.250.186.142:80
http://redirector.gvt1.com/edgedl/release2/chrome_component/gpe7ohs3f5omwhxxpxvcdvkwva_1.3.36.101/ihnlcenocehgdaegdmhbidjhnhdchfmm_1.3.36.101_win_adeodp7n5nw3wgk7xjdln2w2sgsq.crx3
US
html
611 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
64.4.26.155:80
config.messenger.msn.com
Microsoft Corporation
US
whitelisted
216.58.212.131:443
clientservices.googleapis.com
Google Inc.
US
whitelisted
142.250.185.110:443
clients2.google.com
Google Inc.
US
whitelisted
216.58.212.132:443
www.google.com
Google Inc.
US
whitelisted
172.217.16.138:443
fonts.googleapis.com
Google Inc.
US
whitelisted
142.250.186.142:80
redirector.gvt1.com
Google Inc.
US
whitelisted
142.250.185.99:443
update.googleapis.com
Google Inc.
US
whitelisted
142.250.184.195:443
ssl.gstatic.com
Google Inc.
US
whitelisted
74.125.160.198:80
r1---sn-4g5lznez.gvt1.com
Google Inc.
US
whitelisted
173.194.187.202:80
r5---sn-4g5e6nze.gvt1.com
Google Inc.
US
whitelisted

DNS requests

Domain
IP
Reputation
config.messenger.msn.com
  • 64.4.26.155
whitelisted
clientservices.googleapis.com
  • 216.58.212.131
whitelisted
accounts.google.com
  • 142.250.186.45
shared
www.google.com
  • 216.58.212.132
malicious
clients2.google.com
  • 142.250.185.110
whitelisted
fonts.googleapis.com
  • 172.217.16.138
whitelisted
www.gstatic.com
  • 142.250.185.227
whitelisted
fonts.gstatic.com
  • 142.250.186.35
whitelisted
apis.google.com
  • 142.250.185.206
whitelisted
update.googleapis.com
  • 142.250.185.99
whitelisted

Threats

No threats detected
No debug info