analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

7d5931cd-730e-4a0c-e819-08da55ec68b7_b0c413a6-dc9d-af40-0414-2e4a79e9001d.eml

Full analysis: https://app.any.run/tasks/aeeff4d1-59ef-438e-a8a2-dadcf9e4886b
Verdict: Malicious activity
Analysis date: June 27, 2022, 12:56:45
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: message/rfc822
File info: RFC 822 mail, ASCII text, with very long lines, with CRLF line terminators
MD5:

96EB49902C222D8C11D0D263223D4D32

SHA1:

D8293ADEA0A34683177D186F9B6BB908A420CA24

SHA256:

A3C4CDE951500FA498ABB16ECEC80CABC495C1100690A1C5AE83ED3AE63BD846

SSDEEP:

192:QN7Nb20R01go/rmv+I1ZIroCo3xXY/JKIC7T9jjZtq:QNNa0m1rmvJIs/BbL7T9ji

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads the computer name

      • OUTLOOK.EXE (PID: 2596)
    • Checks supported languages

      • OUTLOOK.EXE (PID: 2596)
    • Creates files in the user directory

      • OUTLOOK.EXE (PID: 2596)
    • Searches for installed software

      • OUTLOOK.EXE (PID: 2596)
    • Modifies files in Chrome extension folder

      • chrome.exe (PID: 2860)
  • INFO

    • Checks supported languages

      • chrome.exe (PID: 2860)
      • chrome.exe (PID: 2896)
      • chrome.exe (PID: 1116)
      • chrome.exe (PID: 1584)
      • chrome.exe (PID: 1840)
      • chrome.exe (PID: 2304)
      • chrome.exe (PID: 296)
      • chrome.exe (PID: 696)
      • chrome.exe (PID: 2652)
      • chrome.exe (PID: 1272)
      • chrome.exe (PID: 3576)
      • chrome.exe (PID: 376)
      • chrome.exe (PID: 3856)
    • Manual execution by user

      • chrome.exe (PID: 2860)
    • Reads the computer name

      • chrome.exe (PID: 2860)
      • chrome.exe (PID: 1584)
      • chrome.exe (PID: 1116)
      • chrome.exe (PID: 1840)
      • chrome.exe (PID: 3856)
    • Reads the hosts file

      • chrome.exe (PID: 2860)
      • chrome.exe (PID: 1116)
    • Application launched itself

      • chrome.exe (PID: 2860)
    • Reads settings of System Certificates

      • chrome.exe (PID: 1116)
    • Reads Microsoft Office registry keys

      • OUTLOOK.EXE (PID: 2596)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.eml | E-Mail message (Var. 5) (100)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
51
Monitored processes
14
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start outlook.exe chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2596"C:\PROGRA~1\MICROS~1\Office14\OUTLOOK.EXE" /eml "C:\Users\admin\AppData\Local\Temp\7d5931cd-730e-4a0c-e819-08da55ec68b7_b0c413a6-dc9d-af40-0414-2e4a79e9001d.eml"C:\PROGRA~1\MICROS~1\Office14\OUTLOOK.EXE
Explorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Outlook
Version:
14.0.6025.1000
2860"C:\Program Files\Google\Chrome\Application\chrome.exe" --single-argument C:\Users\admin\Desktop\GBW02JKABNZXSOER_pdf.htmlC:\Program Files\Google\Chrome\Application\chrome.exe
Explorer.EXE
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
3221225547
Version:
86.0.4240.198
2896"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=86.0.4240.198 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd4,0x6803d988,0x6803d998,0x6803d9a4C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
86.0.4240.198
1584"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1056,12414317522375746030,6270984319598394997,131072 --enable-features=PasswordImport --gpu-preferences=MAAAAAAAAADgAAAwAAAAAAAAAAAAAAAAAABgAAAAAAAQAAAAAAAAAAAAAAAAAAAAKAAAAAQAAAAgAAAAAAAAACgAAAAAAAAAMAAAAAAAAAA4AAAAAAAAABAAAAAAAAAAAAAAAAUAAAAQAAAAAAAAAAAAAAAGAAAAEAAAAAAAAAABAAAABQAAABAAAAAAAAAAAQAAAAYAAAA= --mojo-platform-channel-handle=1064 /prefetch:2C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
86.0.4240.198
1116"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1056,12414317522375746030,6270984319598394997,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=network --mojo-platform-channel-handle=1332 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exe
chrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
86.0.4240.198
296"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1056,12414317522375746030,6270984319598394997,131072 --enable-features=PasswordImport --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=1932 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
86.0.4240.198
2304"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1056,12414317522375746030,6270984319598394997,131072 --enable-features=PasswordImport --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=1948 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
86.0.4240.198
696"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1056,12414317522375746030,6270984319598394997,131072 --enable-features=PasswordImport --lang=en-US --extension-process --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=4 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2280 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
86.0.4240.198
1840"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1056,12414317522375746030,6270984319598394997,131072 --enable-features=PasswordImport --gpu-preferences=MAAAAAAAAADgAAAwAAAAAAAAAAAAAAAAAABgAAAAAAAQAAAAAAAAAAAAAAAAAAAAKAAAAAQAAAAgAAAAAAAAACgAAAAAAAAAMAAAAAAAAAA4AAAAAAAAABAAAAAAAAAAAAAAAAUAAAAQAAAAAAAAAAAAAAAGAAAAEAAAAAAAAAABAAAABQAAABAAAAAAAAAAAQAAAAYAAAA= --use-gl=swiftshader-webgl --mojo-platform-channel-handle=1132 /prefetch:2C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
86.0.4240.198
2652"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1056,12414317522375746030,6270984319598394997,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=8 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=1980 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
86.0.4240.198
Total events
14 574
Read events
13 851
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
126
Text files
129
Unknown types
11

Dropped files

PID
Process
Filename
Type
2596OUTLOOK.EXEC:\Users\admin\AppData\Local\Temp\CVR5A3C.tmp.cvr
MD5:
SHA256:
2596OUTLOOK.EXEC:\Users\admin\Documents\Outlook Files\Outlook Data File - NoMail.pst
MD5:
SHA256:
2860chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-62B9A92F-B2C.pma
MD5:
SHA256:
2596OUTLOOK.EXEC:\Users\admin\AppData\Local\Temp\outlook logging\firstrun.logtext
MD5:7997C4669E74232D35B113A98C457A25
SHA256:F1F1B191B60A8D2A0BC2769B0B477F86C8C57C4564ECFE0BD012B1BCE9FA0237
2596OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Outlook\8GCY8WKV\GBW02JKABNZXSOER_pdf (2).htmltext
MD5:392156571CA5C3238298268BF2F8FCBB
SHA256:E392C21BC42BF6782CF8B5518A1EB8339ADA8F66156FCFAF8D0164FF470FE4B3
2596OUTLOOK.EXEC:\Users\admin\Desktop\GBW02JKABNZXSOER_pdf.htmltext
MD5:392156571CA5C3238298268BF2F8FCBB
SHA256:E392C21BC42BF6782CF8B5518A1EB8339ADA8F66156FCFAF8D0164FF470FE4B3
2596OUTLOOK.EXEC:\Users\admin\AppData\Roaming\Microsoft\Templates\~$rmalEmail.dotmpgc
MD5:947A2B99579CDC74C5FD2D769BB78909
SHA256:C6229B9FE625219D2C7B2DE1E7B4401CFBD84C20339113FD77D39734973A28C4
2596OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Outlook\8GCY8WKV\GBW02JKABNZXSOER_pdf.htmltext
MD5:392156571CA5C3238298268BF2F8FCBB
SHA256:E392C21BC42BF6782CF8B5518A1EB8339ADA8F66156FCFAF8D0164FF470FE4B3
2596OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Outlook\8GCY8WKV\GBW02JKABNZXSOER_pdf.html:Zone.Identifiertext
MD5:FBCCF14D504B7B2DBCB5A5BDA75BD93B
SHA256:EACD09517CE90D34BA562171D15AC40D302F0E691B439F91BE1B6406E25F5913
2596OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Outlook\mapisvc.inftext
MD5:F3B25701FE362EC84616A93A45CE9998
SHA256:B3D510EF04275CA8E698E5B3CBB0ECE3949EF9252F0CDC839E9EE347409A2209
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
20
DNS requests
10
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2596
OUTLOOK.EXE
GET
64.4.26.155:80
http://config.messenger.msn.com/config/msgrconfig.asmx?op=GetOlcConfig
US
whitelisted
1116
chrome.exe
GET
200
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvNzI0QUFXNV9zT2RvdUwyMERESEZGVmJnQQ/1.0.0.6_nmmhkkegccagdldgiimedpiccmgmieda.crx
US
crx
242 Kb
whitelisted
1116
chrome.exe
GET
200
67.27.157.254:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?add8aae188c19605
US
compressed
60.0 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1116
chrome.exe
172.217.16.142:443
clients2.google.com
Google Inc.
US
whitelisted
2596
OUTLOOK.EXE
64.4.26.155:80
config.messenger.msn.com
Microsoft Corporation
US
whitelisted
1116
chrome.exe
142.250.185.67:443
clientservices.googleapis.com
Google Inc.
US
whitelisted
1116
chrome.exe
216.58.212.163:443
update.googleapis.com
Google Inc.
US
whitelisted
1116
chrome.exe
172.217.16.193:443
clients2.googleusercontent.com
Google Inc.
US
whitelisted
1116
chrome.exe
67.27.157.254:80
ctldl.windowsupdate.com
Level 3 Communications, Inc.
US
suspicious
1116
chrome.exe
34.104.35.123:80
edgedl.me.gvt1.com
US
whitelisted
1116
chrome.exe
142.250.185.163:443
ssl.gstatic.com
Google Inc.
US
whitelisted
1116
chrome.exe
51.210.237.197:443
mshawery.com
GB
unknown
1116
chrome.exe
142.250.184.205:443
accounts.google.com
Google Inc.
US
whitelisted

DNS requests

Domain
IP
Reputation
config.messenger.msn.com
  • 64.4.26.155
whitelisted
clientservices.googleapis.com
  • 142.250.185.67
whitelisted
clients2.google.com
  • 172.217.16.142
whitelisted
accounts.google.com
  • 142.250.184.205
shared
clients2.googleusercontent.com
  • 172.217.16.193
whitelisted
mshawery.com
  • 51.210.237.197
unknown
ctldl.windowsupdate.com
  • 67.27.157.254
  • 8.248.145.254
  • 8.253.204.249
  • 67.27.157.126
  • 8.248.149.254
whitelisted
ssl.gstatic.com
  • 142.250.185.163
whitelisted
update.googleapis.com
  • 216.58.212.163
whitelisted
edgedl.me.gvt1.com
  • 34.104.35.123
whitelisted

Threats

No threats detected
No debug info