File name: | Notification Message.msg |
Full analysis: | https://app.any.run/tasks/8ccac56a-514d-4bbd-b9bd-221ff8481539 |
Verdict: | Malicious activity |
Analysis date: | October 09, 2019, 18:39:47 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/vnd.ms-outlook |
File info: | CDFV2 Microsoft Outlook Message |
MD5: | 4276E687459D017218329692D0115137 |
SHA1: | 9B357028EAB0366719451E5BB7359D4CDC528428 |
SHA256: | BB902F056434CED2BA0F133D4025184FE40819D29240DCE52DBD3FABF6E64E8A |
SSDEEP: | 768:YC6kWsKmWsKH6fWsKm6u2igDNhSwddjPTm0r1zWsKWI78S8+q:/W+WQWLLTm0hzWV |
.msg | | | Outlook Message (58.9) |
---|---|---|
.oft | | | Outlook Form Template (34.4) |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
2920 | "C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE" /f "C:\Users\admin\AppData\Local\Temp\Notification Message.msg" | C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE | explorer.exe | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Outlook Version: 14.0.6025.1000 | ||||
2176 | "C:\Program Files\Internet Explorer\iexplore.exe" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Outlook\YU1TESW2\Quarantine Portal Report.html | C:\Program Files\Internet Explorer\iexplore.exe | OUTLOOK.EXE | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Version: 8.00.7600.16385 (win7_rtm.090713-1255) | ||||
3000 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2176 CREDAT:71937 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | |
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Version: 8.00.7600.16385 (win7_rtm.090713-1255) |
PID | Process | Filename | Type | |
---|---|---|---|---|
2920 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Temp\CVR6EC.tmp.cvr | — | |
MD5:— | SHA256:— | |||
2920 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Outlook\YU1TESW2\Quarantine Portal Report (2).html\:Zone.Identifier:$DATA | — | |
MD5:— | SHA256:— | |||
2920 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Microsoft\Outlook\RoamCache\Stream_Calendar_2_FB7D11256E6A8144BC69AF8B918BD480.dat | xml | |
MD5:B21ED3BD946332FF6EBC41A87776C6BB | SHA256:B1AAC4E817CD10670B785EF8E5523C4A883F44138E50486987DC73054A46F6F4 | |||
2920 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\84CEDA13.dat | image | |
MD5:E53CBBE659B59290D233033F4D2BDA5E | SHA256:3B3643B321C6D24AE4B058C6D337A75DBA8E54819D5166958B6F313EF37B786D | |||
3000 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\index.dat | dat | |
MD5:C596B5A3B473452289D7DA3833F31BC1 | SHA256:69F0D8DEB4D93361383686523879201CCD5878B4DDFE493C3D8113ABF4B50F24 | |||
2920 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Temp\StructuredQuery.log | text | |
MD5:CD13D2B3D42CDB1854C45419867622EC | SHA256:E0DA0D5BD5C19AC0D601E1CDF4C35BBA11241C00DD2697B847C30401422E0992 | |||
2920 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\{6D057F3A-070E-42F8-A678-AE6B4C469B04}\{1C306CB1-771E-4B4B-A902-86E897877F5B}.png | image | |
MD5:7D80C0A7E3849818695EAF4989186A3C | SHA256:72DC527D78A8E99331409803811CC2D287E812C008A1C869A6AEA69D7A44B597 | |||
2920 | OUTLOOK.EXE | C:\Users\admin\AppData\Roaming\Microsoft\Templates\~$rmalEmail.dotm | pgc | |
MD5:CDAEE685ED683576D4450A949D58F4C8 | SHA256:99E110815439068A91830164B891555D4F4A68D143CD514E9B5B403C7560C028 | |||
2176 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012019092020190921\index.dat | — | |
MD5:— | SHA256:— | |||
2176 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\favicon[1].ico | — | |
MD5:— | SHA256:— |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
2920 | OUTLOOK.EXE | GET | — | 64.4.26.155:80 | http://config.messenger.msn.com/config/msgrconfig.asmx?op=GetOlcConfig | US | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
2176 | iexplore.exe | 204.79.197.200:80 | www.bing.com | Microsoft Corporation | US | whitelisted |
3000 | iexplore.exe | 208.91.197.27:443 | invisiblesolarsystems.com | Confluence Networks Inc | US | malicious |
2920 | OUTLOOK.EXE | 64.4.26.155:80 | config.messenger.msn.com | Microsoft Corporation | US | whitelisted |
Domain | IP | Reputation |
---|---|---|
config.messenger.msn.com |
| whitelisted |
invisiblesolarsystems.com |
| malicious |
www.bing.com |
| whitelisted |