| File name: | 7224479d-4135-8df0-d999-435344d5a68c.eml |
| Full analysis: | https://app.any.run/tasks/4486cd1d-4c65-43c0-b138-b2b887580c77 |
| Verdict: | Malicious activity |
| Analysis date: | March 05, 2024, 08:00:59 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | text/plain |
| File info: | ASCII text, with very long lines (705), with CRLF line terminators |
| MD5: | 3DA213AB7D727A737B812E4A6784EEBF |
| SHA1: | 67B50C7BAF23864EAE7F2DE8AA4395D0868BEA68 |
| SHA256: | F06E13CD49A1887942A22B0B4B42C16EC330311DC5BBB3B66F9B9B7EEBE492B1 |
| SSDEEP: | 768:b6hrrBAl/6nMa/4TldIWAJoh8S/PL6qVwFZXqxsABa5uDcEHj9g5W/b4EeEsnCm:b6hHBQ/WM+44wGNFZXusABa5uIK9g5Wq |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 296 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3780 --field-trial-handle=1312,i,1572534008220502994,1553722730727900428,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1216 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1468 --field-trial-handle=1312,i,1572534008220502994,1553722730727900428,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1384 | "C:\PROGRA~1\MICROS~1\Office14\OUTLOOK.EXE" /eml "C:\Users\admin\AppData\Local\Temp\7224479d-4135-8df0-d999-435344d5a68c.eml" | C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Outlook Exit code: 0 Version: 14.0.6025.1000 Modules
| |||||||||||||||
| 1424 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=29 --mojo-platform-channel-handle=4040 --field-trial-handle=1312,i,1572534008220502994,1553722730727900428,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1544 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3680 --field-trial-handle=1312,i,1572534008220502994,1553722730727900428,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1584 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3700 --field-trial-handle=1312,i,1572534008220502994,1553722730727900428,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1656 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1484 --field-trial-handle=1312,i,1572534008220502994,1553722730727900428,131072 /prefetch:3 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | msedge.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1768 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --first-renderer-process --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2216 --field-trial-handle=1312,i,1572534008220502994,1553722730727900428,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 2088 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=4136 --field-trial-handle=1312,i,1572534008220502994,1553722730727900428,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 2184 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1688 --field-trial-handle=1312,i,1572534008220502994,1553722730727900428,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| (PID) Process: | (1384) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1033 |
Value: Off | |||
| (PID) Process: | (1384) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1041 |
Value: Off | |||
| (PID) Process: | (1384) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1046 |
Value: Off | |||
| (PID) Process: | (1384) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1036 |
Value: Off | |||
| (PID) Process: | (1384) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1031 |
Value: Off | |||
| (PID) Process: | (1384) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1040 |
Value: Off | |||
| (PID) Process: | (1384) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1049 |
Value: Off | |||
| (PID) Process: | (1384) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 3082 |
Value: Off | |||
| (PID) Process: | (1384) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1042 |
Value: Off | |||
| (PID) Process: | (1384) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1055 |
Value: Off | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1384 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Temp\CVRF6E3.tmp.cvr | — | |
MD5:— | SHA256:— | |||
| 1384 | OUTLOOK.EXE | C:\Users\admin\Documents\Outlook Files\Outlook Data File - NoMail.pst | — | |
MD5:— | SHA256:— | |||
| 2232 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF180b46.TMP | — | |
MD5:— | SHA256:— | |||
| 2232 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 1384 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Outlook\61IL6J1V\e-Mail Purchase Order.html | html | |
MD5:F809AB68E7401218EB6E7A39B6B54DD2 | SHA256:41DAFCC1251E923E964150AD88213002907FC36E316DDD4CF81B3BE65B6D8F6A | |||
| 2232 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old~RF180b84.TMP | — | |
MD5:— | SHA256:— | |||
| 2232 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old | — | |
MD5:— | SHA256:— | |||
| 2232 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old~RF180b94.TMP | — | |
MD5:— | SHA256:— | |||
| 1384 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Microsoft\Outlook\mapisvc.inf | text | |
MD5:F3B25701FE362EC84616A93A45CE9998 | SHA256:B3D510EF04275CA8E698E5B3CBB0ECE3949EF9252F0CDC839E9EE347409A2209 | |||
| 2232 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old~RF180bc3.TMP | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1656 | msedge.exe | GET | 302 | 103.224.182.206:80 | http://dinnza.com/f2.php?e=vazivmgksRpr4N832vO3EX49fmNGSEJBY2xwMWo2a0NRNXNESHFnc2NKWEdFR3VuTlExbCsyczk3Z0Q4UktFdmdxYWFnREFiSkRXb3ltMTBFbVA3VXlRR0ZvTmtTRVUzeHNaNndKMmhTekNQSmgwRGgxSXRUZEQvaHlZcmJ4MHhoS1Vqa2ZSVnNkQlFIOU9Ja2N4N2IrdWsrMFRkQlRsZW1wWjFOWDhRRHo3QksyZWcwV0NpTXVwL05kTWtJRmxvQTFGWjZBRmVBcFpNQkN3ekVPL2R4Njh1aW90SHc5OWMwWDZWSzQ1b0EwR3FiT2xhUGloT1o4RVVucFRFbmFGb3VNV3dQSDVyc0FGSzQ2YVZQUW1neTV1V1V0TmhnK0pzblpORGpGRTVqTERkbTdhVGpCS0FjZUp4N0xzcXdTL2NwOWNoM3p6L05Tby9xM3pWcVdLTWtpTnpKRHJYZGRyNWlkcnJzeTR0ZXZGM1QyY3JNdHFTU1lMYVFzb0VteXFNUWFzVFVHbHZ3Vy9Mci92YkNpMDExZElkakwvakRNNWdQVFE2eUx4MXQ2OHJDOGhTK0h1d0lidnNMZzZUVjVmT09Gdjg0WndkMHBNSjhCME4yVk5QVnpiRXpBRE53OGVpZ1BnL1M2TEM5U0JucjJFUEx4bjBqK2g0L0JwZnFNRFhHak9HRHg1bTNxYUp0Z0NTMWZlUUhLbTlJWjlJYlVNT3NncG9xOFVGeUtyQ1FyQ05jdVhMaVVoTVlnZlNYQzhvUnJ4TVIxaUVtUzMyNDJlaU1sSk41SXlwaXdnaGt5QkRFL3kzTCtpSGtzZVVPbWdlV2Y3Z2tUR1F4a1RpQjdLb3E3aUZ5Qkk4clJQVEgrbEVOdHIwd0FxT1hPdCtiM1IyWmp1Q3FpN3dMMHplS2dMQnR4bmdEdG5DVkVqSjUzYXRHN0JzUVJWeDd1TGsybVVSZ0NwcnJReTNqbk5vOW5HaWMwMnM1Qk1xdVAvdW9TRnlrNkpnenRhK2YrVk9abktzUUJJc1EvdlNMZXlaR1NMY3dGWkJOYiszRmJIdzZ5RUpEUHJkQnFUKzNNWVN0UWkwVVVlNmZOR2kxTmgxOXdSUm51aCtaalg5Tnc2TlduRWdzWVc5ZS9SQjBySFEvczFsR1RndzMvRUcwcC9LSkFRQkJiM01rcUloTkF5NHdhVjh2aUJtU3M0Mnl6RFkvK1VPbC9YMUhuVWRoK0ZsbzZlZFhPVU1UeWhOWkp1VWJ0MjlLdEQ4c0FZYXpQVTRVN3owem9lQ2dJYkZ2SUJLY0FEamFTdmUrRGwwK01PL3JrWGJVTWlvMmpHai9GMGVjREtlS1FpM1JvKzNhQWx5dC9Rbll4YjNMeE9BVHJmRkZtdmhzSHI2dzNYUHZ4RExKSTk3QzJkVXBPRXRnPT0%3D&vs=1280:589&ds=1280:720&sl=0:0&os=f&nos=f | unknown | — | — | unknown |
1656 | msedge.exe | GET | 302 | 78.41.204.35:80 | http://virustoal.com/ | unknown | text | 11 b | unknown |
1656 | msedge.exe | GET | 200 | 103.224.182.206:80 | http://dinnza.com/f.php?e=dZVu%2B3jLREBQkG2yLD30OH49fkxOMTh3SGhxVG4vMmRpdTB4N1FYVTJLQ0I2TTI0eWtXT2hQSll5eTBPb2daUExaVld2d2taNlNNc2ZyVlNDZjQ1N1J1a251bEtNMVVmTVVNM2hWRTB5amJhSzBGN1pPNTVXeEJyL1NlbUZLRFhmcDJueGRFVlFqVTFVNWFpYkNvc093NzdodVZvcUtCQWVSaHpDWW1reWpjaDdta0xGUnppeTdlaTV0S2FzZWRaaXJoVDMzTE51VlR1MUxYaElPZjB4NnB3MVJDTkg4V0svbEJtOEZYYU1mNG1TeklHWWZyTWFxTWFwT0FvbWVpeXdNU21LeWFrbnExWlhqRi9aaG1TN0hBQXk3elVoVHc1eEdUam9ZZHRaVXJxSHB0UVdQL1FZcVplcWwrUlh4cjBZa2FmSUVVSWp2c29CeGxYMngzK2NLZllUVnZSbDBiZDBCcHczOUJYRk5OUWs0TTAxekxiWVVWa1JLV3MrL1RZd1NtWkFsT0tqMUU1V3ZIUHUrS1JWbWthVUQ5RHJCcmR5R05kTlRJYkUxZkVDQUZ0Z2ZvcFJoc1BQVXY1R29lVktoclkrdjBzQitWelNHOERBazlqOERuTlNlUDBmZkdBQ0RLNVdDNXJHVld1WXhSd243RCtpWlAvbUpDVUQxZDBPVEF3ZnpSVlh4VUFLaHhCdWlRMktpNVVyV0owbmdRbjhQZ3VmcjE2RldGK1pnVzVPQ0VkL2RMS2ZsOE1iemNxZ0lWV0IvU3dJVzFXd3BIZzFmU2dpelBBcHdkTHlZTzVOK3R0Z0ZiWmNhcC90R3NZSFhnWForNHAvYUtqSlBKN1ZBeVdjK0h0RThFZ1VoT3NxUHk2RHpwSm5RNWtha1NEell6Y3RvaEpEbXNLOHBnNkxpQ1U5S29yRmVIaDNaVmxPOENkRFhpRHN2QzhaODJpZ0orTHpNS0pZVVVJS09tbDFZV2JSRkxLN3g4SFA0RzRsakxpNDB1YnhmWTg2SFpnbU4vazhkQTY4YTQzVkRjajVBU0JYZXlVeEdIdW5Ed1RnbURmT1BuaGltNkE3a0lpeHZYMWx4UkxXUHZaK25haHVhY1g4WmROL0xXbm9SNFBKSXV0eC9PN1hQcmJwMHNmUkRiT0Vjb3FHd3VjV1gzRm81ckhBM0lBa1V4cE51aTFHV3BhNlpnd2JGb3BrZ3IzQ1VVNjc0SURncGdtRVZGUmpOVDBhZTd3VEZxNTJIOXdieW4yd1hoL1l1ekxmZU9yaFhQNWkvQ3R4MGRCQXlWK1FOWmdWcU4xa0pPdlN0amp3NzBESHhYN0E9PQ%3D%3D | unknown | compressed | 1.44 Kb | unknown |
1656 | msedge.exe | GET | — | 216.239.38.21:80 | http://virustotal.com/ | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
1384 | OUTLOOK.EXE | 64.4.26.155:80 | config.messenger.msn.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
2232 | msedge.exe | 239.255.255.250:1900 | — | — | — | unknown |
1656 | msedge.exe | 13.107.42.16:443 | config.edge.skype.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
1656 | msedge.exe | 204.79.197.239:443 | edge.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
2232 | msedge.exe | 224.0.0.251:5353 | — | — | — | unknown |
1656 | msedge.exe | 152.199.21.175:443 | msedgeextensions.sf.tlu.dl.delivery.mp.microsoft.com | EDGECAST | DE | whitelisted |
1656 | msedge.exe | 23.39.223.178:443 | www.bing.com | Akamai International B.V. | US | unknown |
Domain | IP | Reputation |
|---|---|---|
config.messenger.msn.com |
| whitelisted |
config.edge.skype.com |
| whitelisted |
edge.microsoft.com |
| whitelisted |
msedgeextensions.sf.tlu.dl.delivery.mp.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
self.events.data.microsoft.com |
| whitelisted |
ntp.msn.com |
| whitelisted |
assets.msn.com |
| whitelisted |
img-s-msn-com.akamaized.net |
| whitelisted |
sb.scorecardresearch.com |
| shared |
PID | Process | Class | Message |
|---|---|---|---|
1656 | msedge.exe | Potentially Bad Traffic | ET HUNTING Observed Let's Encrypt Certificate for Suspicious TLD (.xyz) |
Process | Message |
|---|---|
msedge.exe | [0305/080230.157:ERROR:exception_handler_server.cc(527)] ConnectNamedPipe: The pipe is being closed. (0xE8)
|