File name: | Spam email.eml |
Full analysis: | https://app.any.run/tasks/b1dc3a45-176e-411f-a4d0-a98fcd139cc9 |
Verdict: | Malicious activity |
Analysis date: | August 13, 2019, 16:55:41 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | message/rfc822 |
File info: | RFC 822 mail, ASCII text, with very long lines, with CRLF line terminators |
MD5: | 3C69E39BCF1715176B85ED28B2A082FA |
SHA1: | B4A4A5F007514F2C8BE83DD3A04A083A03743DD3 |
SHA256: | C4A876A6C5C32B55D13FCB1CDDFB157EE9EB65C4E8E4E06C04A4BAB2123ACE43 |
SSDEEP: | 1536:3EhXdh/g4lF6PUPstNa9DLJC9nks7kMAR6Gw+1mCCb7FwgomVb0KUGkrHU+UGTmW:3EvhdlcPUPws9L4lt7HARsx3NmeCdeG3 |
.eml | | | E-Mail message (Var. 5) (100) |
---|
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
3976 | "C:\PROGRA~1\MICROS~1\Office14\OUTLOOK.EXE" /eml "C:\Users\admin\AppData\Local\Temp\Spam email.eml" | C:\PROGRA~1\MICROS~1\Office14\OUTLOOK.EXE | explorer.exe | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Outlook Version: 14.0.6025.1000 | ||||
2976 | "C:\Program Files\Internet Explorer\iexplore.exe" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Outlook\RXFG39Z3\email.mht | C:\Program Files\Internet Explorer\iexplore.exe | OUTLOOK.EXE | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Version: 8.00.7600.16385 (win7_rtm.090713-1255) | ||||
3048 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2976 CREDAT:71937 | C:\Program Files\Internet Explorer\iexplore.exe | — | iexplore.exe |
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Version: 8.00.7600.16385 (win7_rtm.090713-1255) | ||||
1436 | "C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE" -Embedding | C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE | — | svchost.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Outlook Exit code: 0 Version: 14.0.6025.1000 |
PID | Process | Filename | Type | |
---|---|---|---|---|
3976 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Temp\CVRCD5B.tmp.cvr | — | |
MD5:— | SHA256:— | |||
3976 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Temp\~DFA8440E3497392D25.TMP | — | |
MD5:— | SHA256:— | |||
3976 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\E7EE02F7.dat | image | |
MD5:A45D327CE2CB38FF13D60346A178058F | SHA256:A802D58C3AC5BD8EC9D30BFE97B83C25BB519C60C12E8F77ABF9E14D813F6C21 | |||
3976 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\F66CD74E.dat | image | |
MD5:D04FC3484E83DA5813285F4463A90780 | SHA256:318E914AFDB58C7723D263A8B88604B1FD2AD59D58EC81E95D430ABDEE8866C6 | |||
3976 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\E663908C.dat | image | |
MD5:7801E28F9E57B0358E8E724F2DAB4BAE | SHA256:F991740C95261FDBFE159768BB85791F43F0414DE0C6FBBB28EC4CB8794FE678 | |||
3976 | OUTLOOK.EXE | C:\Users\admin\AppData\Roaming\Microsoft\Templates\~$rmalEmail.dotm | pgc | |
MD5:EF229E775189EFA239B936830DA5A9EF | SHA256:76186553416169D19C60D66ECE42FAF2705A2522EBEF56D56CB246A2C90A0E87 | |||
3976 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\5A9A0098.dat | image | |
MD5:EE2E87B8F7C2B0F71487A7EB3B01A75D | SHA256:8EC8CBB3A984117A34625E7CAAA46980012E334299C498322B469195EEBD751C | |||
3976 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\1266227A.dat | image | |
MD5:3B6F09613923C1E8A7F6C0C5C32841DF | SHA256:3163214F00E0E56A41A2D232368E90C067DFEF24D8F93129D39013C046881A6C | |||
3976 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Outlook\RXFG39Z3\Untitled attachment 00003 eml (5 65 KB).msg | msg | |
MD5:DC32D017DC881CC0E493F47C1EF9B99C | SHA256:551E34437761D847D06A073F8B12CDB82640D26535C21B480FC3C6BD6CB7F45F | |||
3976 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\FED65C33.dat | image | |
MD5:646066ADFF74FE6D2E2A596014647723 | SHA256:7856649DA3AD6D2A838FFE060AC9552778659F819D27268271B6F009F6FC3A30 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
3976 | OUTLOOK.EXE | GET | — | 64.4.26.155:80 | http://config.messenger.msn.com/config/msgrconfig.asmx?op=GetOlcConfig | US | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
2976 | iexplore.exe | 204.79.197.200:80 | www.bing.com | Microsoft Corporation | US | whitelisted |
3976 | OUTLOOK.EXE | 64.4.26.155:80 | config.messenger.msn.com | Microsoft Corporation | US | whitelisted |
Domain | IP | Reputation |
---|---|---|
config.messenger.msn.com |
| whitelisted |
www.bing.com |
| whitelisted |
dns.msftncsi.com |
| shared |