File name: | V-Message Attached from 6508681-SILENTCODERSTIMEZONE.msg |
Full analysis: | https://app.any.run/tasks/fc8c45e8-88b4-4145-aa8f-62ed91a0d596 |
Verdict: | Malicious activity |
Analysis date: | July 22, 2022, 12:29:55 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
MIME: | application/vnd.ms-outlook |
File info: | CDFV2 Microsoft Outlook Message |
MD5: | E8DC6E56B71577C62066FCE787342F46 |
SHA1: | B8AD7852CE674C58FEC3FA079D96C9B5D5074D71 |
SHA256: | F0A7AF54B1D96957F161C63FCFCBAB1ED4F4C914DC5BC25566A7758456D67326 |
SSDEEP: | 768:fnfnTUjMhTc6xgz9dZx6DZWsKRWsKB+bWsKOvkhQt5QObDymAeEX1tTyDNhoYDSM:/fnTUr9wVW5WJwWzhg59HyMi1OYW2N |
.msg | | | Outlook Message (58.9) |
---|---|---|
.oft | | | Outlook Form Template (34.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
2948 | "C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE" /f "C:\Users\admin\AppData\Local\Temp\V-Message Attached from 6508681-SILENTCODERSTIMEZONE.msg" | C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE | Explorer.EXE | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Outlook Version: 14.0.6025.1000 Modules
| |||||||||||||||
3168 | C:\Windows\system32\prevhost.exe {F8B8412B-DEA3-4130-B36C-5E8BE73106AC} -Embedding | C:\Windows\system32\prevhost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Preview Handler Surrogate Host Version: 6.1.7601.17562 (win7sp1_gdr.110217-1504) Modules
|
(PID) Process: | (2948) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
Operation: | write | Name: | 1033 |
Value: Off | |||
(PID) Process: | (2948) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
Operation: | write | Name: | 1041 |
Value: Off | |||
(PID) Process: | (2948) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
Operation: | write | Name: | 1046 |
Value: Off | |||
(PID) Process: | (2948) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
Operation: | write | Name: | 1036 |
Value: Off | |||
(PID) Process: | (2948) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
Operation: | write | Name: | 1031 |
Value: Off | |||
(PID) Process: | (2948) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
Operation: | write | Name: | 1040 |
Value: Off | |||
(PID) Process: | (2948) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
Operation: | write | Name: | 1049 |
Value: Off | |||
(PID) Process: | (2948) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
Operation: | write | Name: | 3082 |
Value: Off | |||
(PID) Process: | (2948) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
Operation: | write | Name: | 1042 |
Value: Off | |||
(PID) Process: | (2948) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
Operation: | write | Name: | 1055 |
Value: Off |
PID | Process | Filename | Type | |
---|---|---|---|---|
2948 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Temp\CVRD99E.tmp.cvr | — | |
MD5:— | SHA256:— | |||
2948 | OUTLOOK.EXE | C:\Users\admin\Documents\Outlook Files\Outlook Data File - NoMail.pst | — | |
MD5:— | SHA256:— | |||
2948 | OUTLOOK.EXE | C:\Users\admin\AppData\Roaming\Microsoft\Templates\~$rmalEmail.dotm | pgc | |
MD5:CA23E49C661547C456B336EFF0564438 | SHA256:828B5770AEDB727E63528CBD2B3A65B3AC4B36429908BBD5D8494E91C65BC973 | |||
3168 | prevhost.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\wbk4430.tmp | html | |
MD5:CC84ED7B3A5453C19764D93EB2355D19 | SHA256:A8E4F5FEFBB356945C4D730920220C85DEBA49F40C04AFCDD0982D5452654829 | |||
2948 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Outlook\3VTFGODL\ MessageIDT076861# (2).HTM | html | |
MD5:CC84ED7B3A5453C19764D93EB2355D19 | SHA256:A8E4F5FEFBB356945C4D730920220C85DEBA49F40C04AFCDD0982D5452654829 | |||
2948 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Temp\outlook logging\firstrun.log | text | |
MD5:3D60886DF038A91A0105DEEB880E2E41 | SHA256:3221BBC9CFAE2E83EDBC35A06F412624BB865EDB23791177CC1F63B4C7081B56 | |||
2948 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Outlook\3VTFGODL\ MessageIDT076861#.HTM | html | |
MD5:CC84ED7B3A5453C19764D93EB2355D19 | SHA256:A8E4F5FEFBB356945C4D730920220C85DEBA49F40C04AFCDD0982D5452654829 | |||
3168 | prevhost.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\wbk868A.tmp | html | |
MD5:CC84ED7B3A5453C19764D93EB2355D19 | SHA256:A8E4F5FEFBB356945C4D730920220C85DEBA49F40C04AFCDD0982D5452654829 | |||
2948 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Microsoft\Outlook\RoamCache\Stream_TCPrefs_2_FD829EB148B17544A61118F89054DE94.dat | xml | |
MD5:F194B1FA12F9B6F46A47391FAE8BEEC2 | SHA256:FCD8D7E030BE6EA7588E5C6CB568E3F1BDFC263942074B693942A27DF9521A74 | |||
2948 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Microsoft\Outlook\RoamCache\Stream_AvailabilityOptions_2_1C43A0FBCB7D3545BF37BC2323E9EA81.dat | xml | |
MD5:EEAA832C12F20DE6AAAA9C7B77626E72 | SHA256:C4C9A90F2C961D9EE79CF08FBEE647ED7DE0202288E876C7BAAD00F4CA29CA16 |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
2948 | OUTLOOK.EXE | 64.4.26.155:80 | config.messenger.msn.com | Microsoft Corporation | US | whitelisted |
Domain | IP | Reputation |
---|---|---|
config.messenger.msn.com |
| whitelisted |