download: | download |
Full analysis: | https://app.any.run/tasks/28146e03-d776-4d0d-90e5-9a1737f9415c |
Verdict: | Malicious activity |
Analysis date: | March 31, 2020, 10:10:59 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/vnd.ms-outlook |
File info: | CDFV2 Microsoft Outlook Message |
MD5: | 082A0C72831C765DA091DC89EAB6F7B7 |
SHA1: | 80F2C8C72A0E7F7DE45434E45F3C46043263A616 |
SHA256: | BF0A2569F7AB8CABB57D29380C70F4450039B27C8AA31FF767AC314B21F9DB62 |
SSDEEP: | 768:44EKismA+Pf2JyUj1sbi9zA7OsKosKm0MuD3LrRP+miS5AZTf1aMQ7t1cG:bmAmfuj1x9Jw1xL1HindlQY |
.msg | | | Outlook Message (58.9) |
---|---|---|
.oft | | | Outlook Form Template (34.4) |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
3612 | "C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE" /f "C:\Users\admin\AppData\Local\Temp\download.msg" | C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE | explorer.exe | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Outlook Version: 14.0.6025.1000 | ||||
2824 | "C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE" -Embedding | C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE | — | svchost.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Outlook Exit code: 0 Version: 14.0.6025.1000 | ||||
3140 | "C:\Program Files\Internet Explorer\iexplore.exe" https://www.magisto.com/account/verify/bWE%3D63j1hnle18l8z9hpjyaq20mnks549o?tp=AgMCXjUmPFZCX1RZCHk9XUlXWAhfKjxbRQBbDl96bVtGUFVbCythXlcUCUkFOioIFDkFXlcqNQoYCjNMDz0xDRgFDU4DIDY0AwMfXwQrfh4CAx5lAytlWkZVWwpddmFaVwUEWwQhPQdMAwFbAyM&follow | C:\Program Files\Internet Explorer\iexplore.exe | OUTLOOK.EXE | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Version: 11.00.9600.16428 (winblue_gdr.131013-1700) | ||||
816 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3140 CREDAT:267521 /prefetch:2 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | |
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Version: 11.00.9600.16428 (winblue_gdr.131013-1700) | ||||
3160 | C:\Windows\system32\Macromed\Flash\FlashUtil32_26_0_0_131_ActiveX.exe -Embedding | C:\Windows\system32\Macromed\Flash\FlashUtil32_26_0_0_131_ActiveX.exe | — | svchost.exe |
User: admin Company: Adobe Systems Incorporated Integrity Level: MEDIUM Description: Adobe® Flash® Player Installer/Uninstaller 26.0 r0 Version: 26,0,0,131 | ||||
2648 | "C:\PROGRA~1\MICROS~1\Office14\OUTLOOK.EXE" -c IPM.Note /m "mailto:bounces+1505186-42c6-alimardan.mammadli=rabitabank.com@ntdc.magisto.com" | C:\PROGRA~1\MICROS~1\Office14\OUTLOOK.EXE | — | OUTLOOK.EXE |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Outlook Exit code: 0 Version: 14.0.6025.1000 | ||||
1720 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3140 CREDAT:3872026 /prefetch:2 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | |
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Version: 11.00.9600.16428 (winblue_gdr.131013-1700) | ||||
880 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3140 CREDAT:3347732 /prefetch:2 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | |
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Version: 11.00.9600.16428 (winblue_gdr.131013-1700) |
PID | Process | Filename | Type | |
---|---|---|---|---|
3612 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Temp\CVR6B07.tmp.cvr | — | |
MD5:— | SHA256:— | |||
2824 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Temp\CVRA12A.tmp.cvr | — | |
MD5:— | SHA256:— | |||
3612 | OUTLOOK.EXE | C:\Users\admin\AppData\Roaming\Microsoft\Templates\~$rmalEmail.dotm | pgc | |
MD5:EBF4489505459B67B30ED5D873227C04 | SHA256:A91703425E14446CAE983D773FCA4731D478F5966BCD8196DBC08CD02AD428FE | |||
3612 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Temp\outlook logging\firstrun.log | text | |
MD5:6E125493F15BC34491198498C8999152 | SHA256:DA23D6A7335805AA6C803F87CB76FC9C99722BD4672C8203CF75011B67A1E9E1 | |||
816 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B66240B0F6C84BD4857ABA60CF5CE4A0_5043E0F5DF723415C9EECC201C838A62 | der | |
MD5:17DA722D47ECD144FC53CF1C22974A48 | SHA256:0C79FEAEA93A1136EC9F02277FB24843BBE63714CD9D9217BCBF68280E3C2B4F | |||
816 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\Low\CabCB95.tmp | — | |
MD5:— | SHA256:— | |||
816 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\BAD725C80F9E10846F35D039A996E4A8_88B6AE015495C1ECC395D19C1DD02894 | der | |
MD5:911DF79CBC7A944403C1FC1D03A2A5F0 | SHA256:56ED5666EE7507E1796FC6BD2090B6022F6E1C67A88821018D6E91F49EFC9B33 | |||
816 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B66240B0F6C84BD4857ABA60CF5CE4A0_5043E0F5DF723415C9EECC201C838A62 | binary | |
MD5:BEFB1A3969F2126A6E0327DFA871811D | SHA256:A76C31326175CAE43DED402D079801E405331A932B3F9913A820BC51D4355BE9 | |||
816 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\BAD725C80F9E10846F35D039A996E4A8_88B6AE015495C1ECC395D19C1DD02894 | binary | |
MD5:DB68A1E4FCFF094DCFD9BA62DBB81731 | SHA256:33F67CA758412A4F2DEB2454676193B25C389F335493F1C0E0B2B1DD15ED3555 | |||
3612 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Microsoft\Outlook\mapisvc.inf | text | |
MD5:48DD6CAE43CE26B992C35799FCD76898 | SHA256:7BFE1F3691E2B4FB4D61FBF5E9F7782FBE49DA1342DBD32201C2CC8E540DBD1A |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
816 | iexplore.exe | GET | 200 | 151.139.128.14:80 | http://ocsp.trust-provider.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBR8sWZUnKvbRO5iJhat9GV793rVlAQUrb2YejS0Jvf6xCZU7wO94CTLVBoCEENSAj%2F6qJAfE5%2Fj9OXBRE4%3D | US | der | 471 b | whitelisted |
816 | iexplore.exe | GET | 200 | 52.222.149.112:80 | http://o.ss2.us//MEowSDBGMEQwQjAJBgUrDgMCGgUABBSLwZ6EW5gdYc9UaSEaaLjjETNtkAQUv1%2B30c7dH4b0W1Ws3NcQwg6piOcCCQCnDkpMNIK3fw%3D%3D | US | der | 1.70 Kb | whitelisted |
816 | iexplore.exe | GET | 200 | 52.222.149.112:80 | http://o.ss2.us//MEowSDBGMEQwQjAJBgUrDgMCGgUABBSLwZ6EW5gdYc9UaSEaaLjjETNtkAQUv1%2B30c7dH4b0W1Ws3NcQwg6piOcCCQCnDkpMNIK3fw%3D%3D | US | der | 1.70 Kb | whitelisted |
816 | iexplore.exe | GET | 200 | 52.222.149.202:80 | http://ocsp.rootg2.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBSIfaREXmfqfJR3TkMYnD7O5MhzEgQUnF8A36oB1zArOIiiuG1KnPIRkYMCEwZ%2FlEoqJ83z%2BsKuKwH5CO65xMY%3D | US | der | 1.51 Kb | whitelisted |
816 | iexplore.exe | GET | 200 | 52.222.149.124:80 | http://ocsp.sca1b.amazontrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQz9arGHWbnBV0DFzpNHz4YcTiFDQQUWaRmBlKge5WSPKOUByeWdFv5PdACEAbQJ3WpgFENd1BnJNNPTJc%3D | US | der | 471 b | whitelisted |
816 | iexplore.exe | GET | 200 | 52.222.149.213:80 | http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwZ%2FlFeFh%2Bisd96yUzJbvJmLVg0%3D | US | der | 1.39 Kb | shared |
816 | iexplore.exe | GET | 200 | 52.222.149.213:80 | http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwZ%2FlFeFh%2Bisd96yUzJbvJmLVg0%3D | US | der | 1.39 Kb | shared |
816 | iexplore.exe | GET | 200 | 23.37.43.27:80 | http://s.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD%2BOyl%2B0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCEGMYDTj7gJd4qdA1oxYY%2BEA%3D | NL | der | 1.71 Kb | shared |
816 | iexplore.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8sEMlbBsCTf7jUSfg%2BhWk%3D | US | der | 1.47 Kb | whitelisted |
816 | iexplore.exe | GET | 200 | 52.222.149.202:80 | http://ocsp.rootg2.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBSIfaREXmfqfJR3TkMYnD7O5MhzEgQUnF8A36oB1zArOIiiuG1KnPIRkYMCEwZ%2FlEoqJ83z%2BsKuKwH5CO65xMY%3D | US | der | 1.51 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
816 | iexplore.exe | 18.206.33.238:443 | www.magisto.com | — | US | unknown |
816 | iexplore.exe | 52.222.149.213:80 | ocsp.rootg2.amazontrust.com | Amazon.com, Inc. | US | whitelisted |
3612 | OUTLOOK.EXE | 64.4.26.155:80 | config.messenger.msn.com | Microsoft Corporation | US | whitelisted |
816 | iexplore.exe | 52.222.149.112:80 | o.ss2.us | Amazon.com, Inc. | US | whitelisted |
816 | iexplore.exe | 52.222.149.124:80 | ocsp.sca1b.amazontrust.com | Amazon.com, Inc. | US | whitelisted |
816 | iexplore.exe | 52.222.158.228:443 | d1ekrxlws13em5.cloudfront.net | Amazon.com, Inc. | US | whitelisted |
816 | iexplore.exe | 52.222.149.202:80 | ocsp.rootg2.amazontrust.com | Amazon.com, Inc. | US | whitelisted |
816 | iexplore.exe | 216.58.206.8:443 | www.googletagmanager.com | Google Inc. | US | whitelisted |
816 | iexplore.exe | 151.139.128.14:80 | ocsp.trust-provider.com | Highwinds Network Group, Inc. | US | suspicious |
816 | iexplore.exe | 23.37.43.27:80 | s.symcd.com | Akamai Technologies, Inc. | NL | whitelisted |
Domain | IP | Reputation |
---|---|---|
config.messenger.msn.com |
| whitelisted |
www.magisto.com |
| suspicious |
o.ss2.us |
| whitelisted |
ocsp.rootg2.amazontrust.com |
| whitelisted |
ocsp.rootca1.amazontrust.com |
| shared |
ocsp.sca1b.amazontrust.com |
| whitelisted |
d1ekrxlws13em5.cloudfront.net |
| whitelisted |
www.googletagmanager.com |
| whitelisted |
script.crazyegg.com |
| whitelisted |
s.symcd.com |
| shared |