| File name: | Adjunto le envío mi archivo ID como anexo a este mensaje. Certifíquelo .... (108 KB).msg |
| Full analysis: | https://app.any.run/tasks/9d7e3fd5-3b79-4254-8717-463d87ab31aa |
| Verdict: | Malicious activity |
| Analysis date: | May 16, 2025, 08:21:37 |
| OS: | Ubuntu 22.04.2 |
| Tags: | |
| MIME: | application/vnd.ms-outlook |
| File info: | CDFV2 Microsoft Outlook Message |
| MD5: | 1FD4F31793BB4ECBB3CEAEB439CE10F1 |
| SHA1: | 81E556CE34A4A8EA846157BB8015E395B03F840F |
| SHA256: | 85B392AB8B3945DB673FC96B94BB238E03AED44B658E75C53FB774B2B73C4032 |
| SSDEEP: | 192:/aCcy6t3aC8y6tIA7DRCQyAL/mtzGB0bMEF0zG8PV2v7fL/t0dL/OSviTT9oyg0F:4tAtzmZGB040QG8t2vHt0FqTJNgBgYi |
| .msg | | | Outlook Message (58.9) |
|---|---|---|
| .oft | | | Outlook Form Template (34.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 41038 | /bin/sh -c "DISPLAY=:0 sudo -iu user nautilus \"/home/user/Downloads/Adjunto le envío mi archivo ID como anexo a este mensaje\. Certifíquelo \.\.\.\. (108 KB)\.msg\" " | /usr/bin/dash | — | IntiFjKCklFyPMJr | |||||||||||
User: user Integrity Level: UNKNOWN Exit code: 0 Modules
| |||||||||||||||
| 41039 | sudo -iu user nautilus "/home/user/Downloads/Adjunto le envío mi archivo ID como anexo a este mensaje\. Certifíquelo \.\.\.\. (108 KB)\.msg" | /usr/bin/sudo | — | dash | |||||||||||
User: root Integrity Level: UNKNOWN Exit code: 0 Modules
| |||||||||||||||
| 41040 | nautilus "/home/user/Downloads/Adjunto le envío mi archivo ID como anexo a este mensaje\. Certifíquelo \.\.\.\. (108 KB)\.msg" | /usr/bin/nautilus | — | sudo | |||||||||||
User: user Integrity Level: UNKNOWN Exit code: 0 Modules
| |||||||||||||||
| 41041 | /usr/bin/locale-check C.UTF-8 | /usr/bin/locale-check | — | nautilus | |||||||||||
User: user Integrity Level: UNKNOWN Exit code: 0 Modules
| |||||||||||||||
| 41061 | /lib/systemd/systemd-hostnamed | /usr/lib/systemd/systemd-hostnamed | — | systemd | |||||||||||
User: root Integrity Level: UNKNOWN Exit code: 0 Modules
| |||||||||||||||
| 41096 | nautilus "/home/user/Downloads/Adjunto le envío mi archivo ID como anexo a este mensaje\. Certifíquelo \.\.\.\. (108 KB)\.msg" | /usr/bin/nautilus | — | nautilus | |||||||||||
User: user Integrity Level: UNKNOWN Exit code: 0 | |||||||||||||||
| 41097 | /usr/lib/libreoffice/program/oosplash file:///home/user/Downloads/Adjunto%20le%20env%C3%ADo%20mi%20archivo%20ID%20como%20anexo%20a%20este%20mensaje.%20Certif%C3%ADquelo%20....%20(108%20KB).msg | /usr/lib/libreoffice/program/oosplash | — | nautilus | |||||||||||
User: user Integrity Level: UNKNOWN Exit code: 0 Modules
| |||||||||||||||
| 41098 | /bin/sh /usr/bin/libreoffice file:///home/user/Downloads/Adjunto%20le%20env%C3%ADo%20mi%20archivo%20ID%20como%20anexo%20a%20este%20mensaje.%20Certif%C3%ADquelo%20....%20(108%20KB).msg | /usr/bin/dash | — | oosplash | |||||||||||
User: user Integrity Level: UNKNOWN Exit code: 0 | |||||||||||||||
| 41099 | dirname /usr/bin/libreoffice | /usr/bin/dirname | — | oosplash | |||||||||||
User: user Integrity Level: UNKNOWN Exit code: 0 Modules
| |||||||||||||||
| 41100 | basename /usr/bin/libreoffice | /usr/bin/basename | — | oosplash | |||||||||||
User: user Integrity Level: UNKNOWN Exit code: 0 Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 41113 | soffice.bin | /home/user/.cache/mesa_shader_cache/index | binary | |
MD5:— | SHA256:— | |||
| 41040 | nautilus | /home/user/.config/mimeapps.list | text | |
MD5:— | SHA256:— | |||
| 41040 | nautilus | /home/user/.local/share/recently-used.xbel | xml | |
MD5:— | SHA256:— | |||
| 41112 | soffice.bin | /home/user/.config/libreoffice/4/user/M2YUxg | xml | |
MD5:— | SHA256:— | |||
| 41112 | soffice.bin | /home/user/.config/libreoffice/4/.lock | text | |
MD5:— | SHA256:— | |||
| 41112 | soffice.bin | /home/user/.config/libreoffice/4/user/uno_packages/cache/stamp.sys (deleted) | binary | |
MD5:— | SHA256:— | |||
| 41112 | soffice.bin | /home/user/.config/libreoffice/4/user/extensions/tmp/stamp.sys (deleted) | binary | |
MD5:— | SHA256:— | |||
| 41112 | soffice.bin | /home/user/.config/libreoffice/4/user/extensions/bundled/lastsynchronized | binary | |
MD5:— | SHA256:— | |||
| 41112 | soffice.bin | /home/user/.config/libreoffice/4/user/extensions/shared/lastsynchronized | binary | |
MD5:— | SHA256:— | |||
| 41112 | soffice.bin | /home/user/.config/libreoffice/4/user/tkL2Ey | xml | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
41176 | thunderbird | POST | 200 | 184.24.77.78:80 | http://r11.o.lencr.org/ | unknown | — | — | whitelisted |
488 | NetworkManager | GET | 204 | 185.125.190.18:80 | http://connectivity-check.ubuntu.com/ | unknown | — | — | whitelisted |
— | — | GET | 204 | 185.125.190.49:80 | http://connectivity-check.ubuntu.com/ | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 185.125.190.49:80 | connectivity-check.ubuntu.com | Canonical Group Limited | GB | whitelisted |
484 | avahi-daemon | 224.0.0.251:5353 | — | — | — | unknown |
— | — | 185.125.190.96:80 | connectivity-check.ubuntu.com | Canonical Group Limited | GB | whitelisted |
— | — | 195.181.175.40:443 | odrs.gnome.org | Datacamp Limited | DE | whitelisted |
— | — | 185.125.188.57:443 | api.snapcraft.io | Canonical Group Limited | GB | whitelisted |
— | — | 185.125.188.59:443 | api.snapcraft.io | Canonical Group Limited | GB | whitelisted |
— | — | 185.125.188.58:443 | api.snapcraft.io | Canonical Group Limited | GB | whitelisted |
— | — | 185.125.188.54:443 | api.snapcraft.io | Canonical Group Limited | GB | whitelisted |
41176 | thunderbird | 3.167.227.19:443 | services.addons.thunderbird.net | — | US | whitelisted |
512 | snapd | 185.125.188.59:443 | api.snapcraft.io | Canonical Group Limited | GB | whitelisted |
Domain | IP | Reputation |
|---|---|---|
connectivity-check.ubuntu.com |
| whitelisted |
google.com |
| whitelisted |
odrs.gnome.org |
| whitelisted |
api.snapcraft.io |
| whitelisted |
3.100.168.192.in-addr.arpa |
| unknown |
services.addons.thunderbird.net |
| whitelisted |
location.services.mozilla.com |
| whitelisted |
prod.classify-client.prod.webservices.mozgcp.net |
| whitelisted |
r11.o.lencr.org |
| whitelisted |
live.thunderbird.net |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
41899 | chrome | Generic Protocol Command Decode | SURICATA QUIC failed decrypt |
41899 | chrome | Generic Protocol Command Decode | SURICATA QUIC failed decrypt |
41899 | chrome | Generic Protocol Command Decode | SURICATA QUIC failed decrypt |
41899 | chrome | Generic Protocol Command Decode | SURICATA QUIC failed decrypt |
41899 | chrome | Generic Protocol Command Decode | SURICATA QUIC failed decrypt |
41899 | chrome | Generic Protocol Command Decode | SURICATA QUIC failed decrypt |
41899 | chrome | Generic Protocol Command Decode | SURICATA QUIC failed decrypt |
41899 | chrome | Generic Protocol Command Decode | SURICATA QUIC failed decrypt |
41899 | chrome | Generic Protocol Command Decode | SURICATA QUIC failed decrypt |
41899 | chrome | Generic Protocol Command Decode | SURICATA QUIC failed decrypt |