| File name: | PO10026369|| ANSELL 247376 - WO # 18569 - Anjana <talagaev.a.s@strexp.com> - 2025-03-21 1404.eml |
| Full analysis: | https://app.any.run/tasks/51950323-4e22-48f0-bcad-7d90fb33d138 |
| Verdict: | Malicious activity |
| Analysis date: | March 24, 2025, 12:11:57 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | message/rfc822 |
| File info: | SMTP mail, ASCII text, with very long lines (541), with CRLF line terminators |
| MD5: | C8EF76BFE239BEC5CECA8ED42535A4DA |
| SHA1: | 68B757713BC8B67CF64AD50D5A3A7DCDC9D2DD16 |
| SHA256: | AAB78ED179CBC9DEEDE9D41179FB68CA6503E5EEEACDBADD9C1F53FDA109F994 |
| SSDEEP: | 24576:HhM+UL0LtREvwryCo+9DDduBgONIGSSQUbeDrq8yyIvrV8tR+HsHIKG5Vo0/9aAu:6+6YHV1eIGVqfHw85+o01gD |
| .eml | | | E-Mail message (Var. 1) (100) |
|---|
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 5212 | "C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\ai.exe" "1AB8545A-3F8A-43BB-9C2A-99DD05E9FE61" "CD79DF5B-41DD-4A7A-8086-6FF8E0BE56C4" "5720" | C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\ai.exe | — | OUTLOOK.EXE | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Artificial Intelligence (AI) Host for the Microsoft® Windows® Operating System and Platform x64. Version: 0.12.2.0 Modules
| |||||||||||||||
| 5216 | "C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE" "C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Content.Outlook\7IYJX2OT\PO10026369-1.xls" | C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE | OUTLOOK.EXE | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Excel Version: 16.0.16026.20146 Modules
| |||||||||||||||
| 5596 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 5720 | "C:\Program Files\Microsoft Office\Root\Office16\OUTLOOK.EXE" /eml C:\Users\admin\AppData\Local\Temp\51950323-4e22-48f0-bcad-7d90fb33d138.eml | C:\Program Files\Microsoft Office\root\Office16\OUTLOOK.EXE | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Outlook Version: 16.0.16026.20146 Modules
| |||||||||||||||
| (PID) Process: | (5720) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Outlook\Diagnostics |
| Operation: | delete value | Name: | BootFailureCount |
Value: | |||
| (PID) Process: | (5720) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Outlook\Diagnostics\BootDiagnosticsDataPreviousSession |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (5720) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Outlook\Diagnostics\BootDiagnosticsDataPreviousSession |
| Operation: | write | Name: | CantBootResolution |
Value: BootSuccess | |||
| (PID) Process: | (5720) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Outlook\Diagnostics\BootDiagnosticsDataPreviousSession |
| Operation: | write | Name: | ProfileBeingOpened |
Value: Outlook | |||
| (PID) Process: | (5720) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Outlook\Diagnostics\BootDiagnosticsDataPreviousSession |
| Operation: | write | Name: | SessionId |
Value: C3D8E96E-C1AF-4750-8D52-F4E28119C131 | |||
| (PID) Process: | (5720) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Outlook\Diagnostics\BootDiagnosticsDataPreviousSession |
| Operation: | write | Name: | BootDiagnosticsLogFile |
Value: C:\Users\admin\AppData\Local\Temp\Outlook Logging\OUTLOOK_16_0_16026_20146-20240718T1116060318-1644.etl | |||
| (PID) Process: | (5720) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Outlook\Diagnostics |
| Operation: | delete value | Name: | ProfileBeingOpened |
Value: | |||
| (PID) Process: | (5720) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Outlook\Diagnostics\BootDiagnosticsData |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (5720) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Outlook\Diagnostics |
| Operation: | write | Name: | OutlookBootFlag |
Value: 1 | |||
| (PID) Process: | (5720) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages |
| Operation: | write | Name: | en-US |
Value: 2 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 5720 | OUTLOOK.EXE | C:\Users\admin\Documents\Outlook Files\Outlook1.pst | — | |
MD5:— | SHA256:— | |||
| 5720 | OUTLOOK.EXE | C:\Users\admin\AppData\Roaming\Microsoft\Templates\~$rmalEmail.dotm | binary | |
MD5:388F5E547DA61AA315D63C874B4A36D6 | SHA256:32A569935B714B40A43DDF17ECF514A2B6CC5CF3372373EB4753EC942E9B0B2E | |||
| 5720 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Temp\olkC9DA.tmp | binary | |
MD5:FD879CEA686F7AFE64711F0BAEDD939E | SHA256:B1B23E2799B2FCCC554CCDDE7E3339B536F83786ADBC7F0065CD4DC85907C920 | |||
| 5720 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Microsoft\TokenBroker\Cache\089d66ba04a8cec4bdc5267f42f39cf84278bb67.tbres | binary | |
MD5:C20F5ABD6652B3CB3D6B485ABB61D77A | SHA256:567F074B7D1D3616F255E835E20698401086B24F0C4406555AD84C49211A18FC | |||
| 5720 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\7323D16A.dat | image | |
MD5:F98616D977EED5AE716A8690F8C0C691 | SHA256:D47AFE57A2C087A46DDF4EF0EB9D3887500F296041D1ECCC474EC9F9A6917674 | |||
| 5720 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\919BDE63.dat | image | |
MD5:DE67413BF1E44B8C8FE6AF019C86E74A | SHA256:9FEF05F178AF922D4450565B6016B313004CDE8968CB031023BF4A8A003A8B9F | |||
| 5720 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\3730BD08.dat | image | |
MD5:8C36DE0FB3E6C06F1C15872632842F9A | SHA256:F870741840212C2E9FCE9265A4916A0915944FE21F298A5B37045EF7DBA20563 | |||
| 5720 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\AE92C969.dat | image | |
MD5:176A9392BD05B2B625A7A072B20F3648 | SHA256:B0621C411158845F691F0C0A2CF839DE229F11FEFD1FFAD55907749E95777EC4 | |||
| 5720 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\7D5A185F.dat | image | |
MD5:972F6590E094B5F2A6E77EC8BD2995C2 | SHA256:4BD8CB06261A4DE0FB039B5C824925886F924DADD895B00D0CEAB685BBD591AD | |||
| 5720 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\4F51056.dat | image | |
MD5:41C94B38F32DB1B0ED50B52C820DE9D3 | SHA256:5A8F0C9FB8B4243B2A11B05A85C1820C046AB13D8A59DC4D2F2CBFD569E660A0 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 51.124.78.146:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2104 | svchost.exe | 51.124.78.146:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
5496 | MoUsoCoreWorker.exe | 51.124.78.146:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
2112 | svchost.exe | 51.124.78.146:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
5720 | OUTLOOK.EXE | 52.123.130.14:443 | ecs.office.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
5720 | OUTLOOK.EXE | 23.48.23.45:443 | omex.cdn.office.net | Akamai International B.V. | DE | whitelisted |
5720 | OUTLOOK.EXE | 52.168.117.169:443 | self.events.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
5216 | EXCEL.EXE | 52.109.76.240:443 | officeclient.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
ecs.office.com |
| whitelisted |
omex.cdn.office.net |
| whitelisted |
self.events.data.microsoft.com |
| whitelisted |
officeclient.microsoft.com |
| whitelisted |
messaging.lifecycle.office.com |
| whitelisted |
activation-v2.sls.microsoft.com |
| whitelisted |