analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

Out of Office today.eml

Full analysis: https://app.any.run/tasks/26a0b8ea-10dd-4344-b97b-871cb79c0e20
Verdict: Malicious activity
Analysis date: August 12, 2022, 20:19:15
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: message/rfc822
File info: news or mail, ASCII text, with CRLF line terminators
MD5:

879D6E9E63D5FA6F1C2D9B532E67EE99

SHA1:

9E76A2B2317F7F753403CA841EBBAD70A62B8713

SHA256:

FD4AF30262F3660E2CCDF31C06140BB6AF11232262FF7E62D9AF8676DE4D2E84

SSDEEP:

1536:5rfQaoocINN0vQ+VPCHwDCvmg//7D6q5aVFkrnwLVrJm5Ne0EaRak0O6wj:RfQVodN048PCQDL6TDp8TwOSNe0bR1D

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads the computer name

      • OUTLOOK.EXE (PID: 3328)
    • Checks supported languages

      • OUTLOOK.EXE (PID: 3328)
    • Executed via COM

      • OUTLOOK.EXE (PID: 3500)
    • Searches for installed software

      • OUTLOOK.EXE (PID: 3328)
  • INFO

    • Checks supported languages

      • OUTLOOK.EXE (PID: 3500)
      • NOTEPAD.EXE (PID: 3304)
    • Reads Microsoft Office registry keys

      • OUTLOOK.EXE (PID: 3500)
      • OUTLOOK.EXE (PID: 3328)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.eml | E-Mail message (Var. 2) (100)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start outlook.exe outlook.exe no specs notepad.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3328"C:\PROGRA~1\MICROS~1\Office14\OUTLOOK.EXE" /eml "C:\Users\admin\AppData\Local\Temp\Out of Office today.eml"C:\PROGRA~1\MICROS~1\Office14\OUTLOOK.EXE
Explorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Outlook
Version:
14.0.6025.1000
3500"C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE" -EmbeddingC:\Program Files\Microsoft Office\Office14\OUTLOOK.EXEsvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Outlook
Exit code:
0
Version:
14.0.6025.1000
3304"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Outlook\N2H6S21A\email.txtC:\Windows\system32\NOTEPAD.EXEOUTLOOK.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Total events
5 581
Read events
4 960
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
0
Text files
13
Unknown types
1

Dropped files

PID
Process
Filename
Type
3328OUTLOOK.EXEC:\Users\admin\AppData\Local\Temp\CVR81E2.tmp.cvr
MD5:
SHA256:
3328OUTLOOK.EXEC:\Users\admin\Documents\Outlook Files\Outlook Data File - NoMail.pst
MD5:
SHA256:
3500OUTLOOK.EXEC:\Users\admin\AppData\Local\Temp\CVR9A4C.tmp.cvr
MD5:
SHA256:
3328OUTLOOK.EXEC:\Users\admin\AppData\Roaming\Microsoft\Templates\~$rmalEmail.dotmpgc
MD5:83B2E2F477CE6DF28F8DB6F9DA00647A
SHA256:4E324702D10AD8DA733BBFD1AE1C5E89678C7B8B6382606DB2A61E48D4062F41
3328OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\FB677852.datimage
MD5:3461F3338445093F5FC9ABE4D5D537EF
SHA256:7D6A4B5AC4B9B2DEEF8E552DB3588FDEE018A4064F7BDD371CD8ED15E45AC3BD
3328OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Outlook\N2H6S21A\email.txthtml
MD5:DC2306F293DD6BC309B0610B9363397C
SHA256:60C4A5C756BC9FCE4BC6B4BD94E6E9EA79C064D50648086C746982331E3571D5
3328OUTLOOK.EXEC:\Users\admin\AppData\Local\Temp\outlook logging\firstrun.logtext
MD5:4F2A41F93814605B98C4D7CA15230928
SHA256:D121E9F09C45FB79992FDFE16255EF2458F476A797B140CE5CC2D317055863DD
3328OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\3BACEF1C.datimage
MD5:3461F3338445093F5FC9ABE4D5D537EF
SHA256:7D6A4B5AC4B9B2DEEF8E552DB3588FDEE018A4064F7BDD371CD8ED15E45AC3BD
3328OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\{EDE12DEC-1498-409C-80EF-11FE75BC31CF}\{1C306CB1-771E-4B4B-A902-86E897877F5B}.pngimage
MD5:4C61C12EDBC453D7AE184976E95258E1
SHA256:296526F9A716C1AA91BA5D6F69F0EB92FDF79C2CB2CFCF0CEB22B7CCBC27035F
3328OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Outlook\RoamCache\Stream_TCPrefs_2_98004FDC4EFB164A94A830030E2E3488.datxml
MD5:F194B1FA12F9B6F46A47391FAE8BEEC2
SHA256:FCD8D7E030BE6EA7588E5C6CB568E3F1BDFC263942074B693942A27DF9521A74
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
1
DNS requests
1
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3328
OUTLOOK.EXE
GET
64.4.26.155:80
http://config.messenger.msn.com/config/msgrconfig.asmx?op=GetOlcConfig
US
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3328
OUTLOOK.EXE
64.4.26.155:80
config.messenger.msn.com
Microsoft Corporation
US
whitelisted

DNS requests

Domain
IP
Reputation
config.messenger.msn.com
  • 64.4.26.155
whitelisted

Threats

No threats detected
No debug info