Windows
Analysis Report
possible SPAM## Msig Insurance Europe Complete via-Sign Monday January 2025.msg
Overview
General Information
Detection
Score: | 60 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64_ra
- OUTLOOK.EXE (PID: 6296 cmdline:
"C:\Progra m Files (x 86)\Micros oft Office \Root\Offi ce16\OUTLO OK.EXE" /f "C:\Users \user\Desk top\possib le SPAM## Msig Insur ance Europ e Complete via-Sign Monday Jan uary 2025. msg" MD5: 91A5292942864110ED734005B7E005C0) - ai.exe (PID: 6956 cmdline:
"C:\Progra m Files (x 86)\Micros oft Office \root\vfs\ ProgramFil esCommonX6 4\Microsof t Shared\O ffice16\ai .exe" "A05 F6BD5-041F -46BD-9253 -1B44E9353 620" "38B9 395B-988F- 4BFE-9C5C- 269149A534 C2" "6296" "C:\Progr am Files ( x86)\Micro soft Offic e\Root\Off ice16\OUTL OOK.EXE" " WordCombin edFloatieL reOnline.o nnx" MD5: EC652BEDD90E089D9406AFED89A8A8BD) - Acrobat.exe (PID: 6880 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user \AppData\L ocal\Micro soft\Windo ws\INetCac he\Content .Outlook\X A0VT943\Ms ig Insuran ce Europe. pdf" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 4480 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 5476 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=22 52 --field -trial-han dle=1576,i ,719282823 7008726935 ,783026012 0330607894 ,131072 -- disable-fe atures=Bac kForwardCa che,Calcul ateNativeW inOcclusio n,WinUseBr owserSpell Checker /p refetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - chrome.exe (PID: 7896 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed --sing le-argumen t https:// embeds.bee hiiv.com/1 ac29d4e-2f b8-419c-84 98-f07b405 bca74 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 8084 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2188 --fi eld-trial- handle=184 0,i,625536 7966592730 10,1368938 4045628339 821,262144 --disable -features= Optimizati onGuideMod elDownload ing,Optimi zationHint s,Optimiza tionHintsF etching,Op timization TargetPred iction /pr efetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
Source: | Author: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): |
Source: | Author: frack113: |
Click to jump to signature section
Phishing |
---|
Source: | Joe Sandbox AI: |
Source: | Joe Sandbox AI: |
Source: | Joe Sandbox AI: |
Source: | Joe Sandbox AI: | ||
Source: | Joe Sandbox AI: | ||
Source: | Joe Sandbox AI: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | Classification: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | Directory created: |
Source: | HTTPS traffic detected: |
Source: | Memory has grown: |
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: |
Source: | Classification label: |
Source: | File created: |
Source: | File created: |
Source: | File created: |
Source: | File read: |
Source: | Key opened: |
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: |
Source: | Section loaded: | ||
Source: | Section loaded: | ||
Source: | Section loaded: | ||
Source: | Section loaded: | ||
Source: | Section loaded: | ||
Source: | Section loaded: | ||
Source: | Section loaded: | ||
Source: | Section loaded: | ||
Source: | Section loaded: |
Source: | Key value queried: |
Source: | Window found: |
Source: | Window detected: |
Source: | Key opened: |
Source: | Directory created: |
Source: | File created: | ||
Source: | File created: | ||
Source: | File created: | ||
Source: | File created: | ||
Source: | File created: | ||
Source: | File created: | ||
Source: | File created: |
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: |
Source: | Process information queried: |
Source: | Queries volume information: |
Source: | Key value queried: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | 1 Drive-by Compromise | Windows Management Instrumentation | 31 Browser Extensions | 1 Process Injection | 3 Masquerading | OS Credential Dumping | 1 Process Discovery | Remote Services | Data from Local System | 2 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | 1 Registry Run Keys / Startup Folder | 1 Registry Run Keys / Startup Folder | 1 Process Injection | LSASS Memory | 1 File and Directory Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | 1 DLL Side-Loading | 1 DLL Side-Loading | 1 DLL Side-Loading | Security Account Manager | 13 System Information Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | 2 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | 1 Extra Window Memory Injection | 1 Extra Window Memory Injection | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
chrome.cloudflare-dns.com | 162.159.61.3 | true | false | high | |
bg.microsoft.map.fastly.net | 199.232.214.172 | true | false | high | |
beehiiv.com | 104.18.68.40 | true | true | unknown | |
sigbed.goodus.net | 24.199.124.2 | true | true | unknown | |
www.google.com | 216.58.206.36 | true | false | high | |
ae879450.bosssellame.pages.dev | 104.21.112.1 | true | true | unknown | |
x1.i.lencr.org | unknown | unknown | false | high | |
client.px-cloud.net | unknown | unknown | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true | unknown | ||
false | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
142.250.186.170 | unknown | United States | 15169 | GOOGLEUS | false | |
2.16.168.101 | unknown | European Union | 20940 | AKAMAI-ASN1EU | false | |
216.58.206.36 | www.google.com | United States | 15169 | GOOGLEUS | false | |
2.23.209.38 | unknown | European Union | 1273 | CWVodafoneGroupPLCEU | false | |
24.199.124.2 | sigbed.goodus.net | United States | 12271 | TWC-12271-NYCUS | true | |
64.233.166.84 | unknown | United States | 15169 | GOOGLEUS | false | |
162.159.61.3 | chrome.cloudflare-dns.com | United States | 13335 | CLOUDFLARENETUS | false | |
104.21.112.1 | ae879450.bosssellame.pages.dev | United States | 13335 | CLOUDFLARENETUS | true | |
23.209.209.135 | unknown | United States | 23693 | TELKOMSEL-ASN-IDPTTelekomunikasiSelularID | false | |
199.232.214.172 | bg.microsoft.map.fastly.net | United States | 54113 | FASTLYUS | false | |
104.18.68.40 | beehiiv.com | United States | 13335 | CLOUDFLARENETUS | true | |
142.250.184.202 | unknown | United States | 15169 | GOOGLEUS | false | |
52.113.194.132 | unknown | United States | 8068 | MICROSOFT-CORP-MSN-AS-BLOCKUS | false | |
54.224.241.105 | unknown | United States | 14618 | AMAZON-AESUS | false | |
1.1.1.1 | unknown | Australia | 13335 | CLOUDFLARENETUS | false | |
216.58.206.67 | unknown | United States | 15169 | GOOGLEUS | false | |
142.250.185.110 | unknown | United States | 15169 | GOOGLEUS | false | |
2.23.240.205 | unknown | European Union | 8781 | QA-ISPQA | false | |
216.58.206.46 | unknown | United States | 15169 | GOOGLEUS | false | |
23.47.168.24 | unknown | United States | 16625 | AKAMAI-ASUS | false | |
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
52.109.28.48 | unknown | United States | 8075 | MICROSOFT-CORP-MSN-AS-BLOCKUS | false | |
142.250.185.195 | unknown | United States | 15169 | GOOGLEUS | false | |
142.250.186.40 | unknown | United States | 15169 | GOOGLEUS | false | |
142.250.186.100 | unknown | United States | 15169 | GOOGLEUS | false | |
104.18.69.40 | unknown | United States | 13335 | CLOUDFLARENETUS | false | |
142.250.184.232 | unknown | United States | 15169 | GOOGLEUS | false | |
172.217.16.195 | unknown | United States | 15169 | GOOGLEUS | false | |
52.109.76.243 | unknown | United States | 8075 | MICROSOFT-CORP-MSN-AS-BLOCKUS | false | |
20.44.10.123 | unknown | United States | 8075 | MICROSOFT-CORP-MSN-AS-BLOCKUS | false |
IP |
---|
192.168.2.16 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1590527 |
Start date and time: | 2025-01-14 08:30:04 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowsinteractivecookbook.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 21 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | stream |
Analysis stop reason: | Timeout |
Sample name: | possible SPAM## Msig Insurance Europe Complete via-Sign Monday January 2025.msg |
Detection: | MAL |
Classification: | mal60.phis.winMSG@37/54@13/252 |
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 52.113.194.132, 52.109.76.243, 2.16.168.101, 2.16.168.119, 20.190.160.14, 20.190.160.22, 20.190.160.17, 40.126.32.68, 40.126.32.134, 40.126.32.72, 40.126.32.136, 40.126.32.74
- Excluded domains from analysis (whitelisted): ecs.office.com, omex.cdn.office.net, prdv4a.aadg.msidentity.com, www.tm.v4.a.prd.aadg.akadns.net, ctldl.windowsupdate.com, prod.roaming1.live.com.akadns.net, s-0005-office.config.skype.com, eur.roaming1.live.com.akadns.net, neu-azsc-000.roaming.officeapps.live.com, login.msa.msidentity.com, ecs-office.s-0005.s-msedge.net, roaming.officeapps.live.com, s-0005.s-msedge.net, login.live.com, osiprod-neu-buff-azsc-000.northeurope.cloudapp.azure.com, ecs.office.trafficmanager.net, omex.cdn.office.net.akamaized.net, a1864.dscd.akamai.net, www.tm.lg.prod.aadmsa.trafficmanager.net
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtQueryAttributesFile calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- Report size getting too big, too many NtSetValueKey calls found.
- VT rate limit hit for: beehiiv.com
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.2271925795334555 |
Encrypted: | false |
SSDEEP: | |
MD5: | 554867DAB0EB17D97E84501451114DCB |
SHA1: | 7C7EBA766608191257FB238345A80D913F80528B |
SHA-256: | 728E0C351B39076C9355909684CD43008EA0A15D461779245545D476D6A86379 |
SHA-512: | 79DB1642D972538159EA3C0BDD43EF6366BFB11223BC657D8C917E09DAF6E5120329FF956D9CAA83AF06A35F2B8459340FE51E3BA8BAADE5B0BBA3286B4F8744 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 331 |
Entropy (8bit): | 5.141211460013571 |
Encrypted: | false |
SSDEEP: | |
MD5: | 91AAD8E814E8FF553470AF97AC6FBC77 |
SHA1: | 4E04231E2D0651962566286716C158C628F10E19 |
SHA-256: | 147ECE238125FFF0D8DC5CA17AE8981886353EE2F159164D369D95360A1089A2 |
SHA-512: | C3609887C723AA7576AE1125C68C7D1595CD94BC8FDBEE29AB166F9254330C105E2D6FB00D8F406A38074B367C5DDA1A43F93C4CA4714379EDF54AC915386E9B |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\656ce715-396e-414a-85f1-0a0b1b81247f.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 403 |
Entropy (8bit): | 4.976199622864144 |
Encrypted: | false |
SSDEEP: | |
MD5: | DA9E1E48B2B930A471D004527B8737F7 |
SHA1: | 2544261907F48AD570E1D062498DCE8BBED62E90 |
SHA-256: | EC34FA11E9D30A981956B60E73535788F9C8F0FD5EF092BE8948F077647D75E7 |
SHA-512: | AF7C5A0482A8788F25CC555A814378B8B37768B75D502F19D9588A5AAC0B1D8954B33C0A4B8B48DCE2B9E7D8A40C39270C207A4530B16A9EC1E2A1A75EE975E0 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 0 |
Entropy (8bit): | 0.0 |
Encrypted: | false |
SSDEEP: | |
MD5: | 4C313FE514B5F4E7E89329630909F8DC |
SHA1: | 916EED77EC8C9DC90C64FF1E5CC9D04D4674EE56 |
SHA-256: | 1EE7C151EF264F91FCDCCB6644F62DC33E27A4E829DAAB748DA1DE4426400873 |
SHA-512: | 1726CAFCBA0121691DFA87A7298E6610BC4C7FD900867FD1B1710811E764918585E56788E08B7CA2CEE001F5DFD110E1BE6F6BBD7C2A7B7E2FC87D3DED210205 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State~RF5af5d3.TMP (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 0 |
Entropy (8bit): | 0.0 |
Encrypted: | false |
SSDEEP: | |
MD5: | 4C313FE514B5F4E7E89329630909F8DC |
SHA1: | 916EED77EC8C9DC90C64FF1E5CC9D04D4674EE56 |
SHA-256: | 1EE7C151EF264F91FCDCCB6644F62DC33E27A4E829DAAB748DA1DE4426400873 |
SHA-512: | 1726CAFCBA0121691DFA87A7298E6610BC4C7FD900867FD1B1710811E764918585E56788E08B7CA2CEE001F5DFD110E1BE6F6BBD7C2A7B7E2FC87D3DED210205 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\d648935c-a20c-4b3e-82a9-711ae49ba5c1.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 403 |
Entropy (8bit): | 4.953858338552356 |
Encrypted: | false |
SSDEEP: | |
MD5: | 4C313FE514B5F4E7E89329630909F8DC |
SHA1: | 916EED77EC8C9DC90C64FF1E5CC9D04D4674EE56 |
SHA-256: | 1EE7C151EF264F91FCDCCB6644F62DC33E27A4E829DAAB748DA1DE4426400873 |
SHA-512: | 1726CAFCBA0121691DFA87A7298E6610BC4C7FD900867FD1B1710811E764918585E56788E08B7CA2CEE001F5DFD110E1BE6F6BBD7C2A7B7E2FC87D3DED210205 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4099 |
Entropy (8bit): | 5.229799407420896 |
Encrypted: | false |
SSDEEP: | |
MD5: | EE4FC8320E3DC77BF2D3B11BB0CFF6F7 |
SHA1: | C71BEDBE11CFFCC6CC42B7DF3BA28EDFE2B1B228 |
SHA-256: | 2C9EF6A4C4F1431317BEDEEFCA763D1FB310B15804CBD123DB412DF54A02F2B0 |
SHA-512: | E9BF283CA8D73CC081D119916285F258D2D21C12ECFB963938B6DE1241937445587135AAE15E1556D2C0F34B5A0D998E5F9BF4F804C342DEBEC51B1C3534E99C |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 319 |
Entropy (8bit): | 5.164076164514441 |
Encrypted: | false |
SSDEEP: | |
MD5: | C34190B92416596844B29F2E3028E445 |
SHA1: | 21C77ABE15ECCF0DD98C169F56B67F6EAAFED693 |
SHA-256: | D260FEA405C7B69918218AD2394A7E9FB4F4B3229D9026F051DED33186B32B77 |
SHA-512: | C2F23938B272847A807D18FB8715580BA30AB2E5ACEBBE09B9D93ABA2BBEC87D93614152F4BCDFFCD738C959E3F70B526FD4F5446E014CB7882AAE2D0D0DD501 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\Acrobat\DC\ConnectorIcons\icon-250114073052Z-171.bmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71190 |
Entropy (8bit): | 0.45963394576981464 |
Encrypted: | false |
SSDEEP: | |
MD5: | 527DE7D6A9168BDC23205148899A33B1 |
SHA1: | 6FE451891192430D3FC17D7FCCEC1CB8CEFAA155 |
SHA-256: | 6AB53CE20228C2BDF2B6F1BF7ABF41255258217093A23B6A7B03761CEAF90BBA |
SHA-512: | E39D4C311F11E2413FBD23C3A0C775B4A65899BA842928F633711C1BA6BACBFE18F2FBE2BE35CC74E4D445C089095F05ACA33F4BACBCC8F3AA56F99A999BDDCD |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 57344 |
Entropy (8bit): | 3.291927920232006 |
Encrypted: | false |
SSDEEP: | |
MD5: | A4D5FECEFE05F21D6F81ACF4D9A788CF |
SHA1: | 1A9AC236C80F2A2809F7DE374072E2FCCA5A775C |
SHA-256: | 83BE4623D80FFB402FBDEC4125671DF532845A3828A1B378D99BD243A4FD8FF2 |
SHA-512: | FF106C6B9E1EA4B1F3E3AB01FAEA21BA24A885E63DDF0C36EB0A8C3C89A9430FE676039C076C50D7C46DC4E809F6A7E35A4BFED64D9033FEBD6121AC547AA5E9 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16928 |
Entropy (8bit): | 1.216029127506309 |
Encrypted: | false |
SSDEEP: | |
MD5: | B61D661E6F976005A24E1EAD38CBEE2F |
SHA1: | 1B0FB8589410CD73977ABB4D734F3540BC8AE62C |
SHA-256: | 0996631EA0AAA19EB359B1400C4FC000F096C0D9B9D603F03BF092D0AF0C66C1 |
SHA-512: | 11B78576596814C639CBAFEE77DFFFB88054F95FD2596816E99D413F2AD59207E52B773309A5461E36D8698EF20BBCFE371602F9117213E80001F9F84E4036FD |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71954 |
Entropy (8bit): | 7.996617769952133 |
Encrypted: | true |
SSDEEP: | |
MD5: | 49AEBF8CBD62D92AC215B2923FB1B9F5 |
SHA1: | 1723BE06719828DDA65AD804298D0431F6AFF976 |
SHA-256: | B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F |
SHA-512: | BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.7464849065063075 |
Encrypted: | false |
SSDEEP: | |
MD5: | 30967EDA396E15A0A3746CBDED2E0A76 |
SHA1: | 74D55EBC3B167FBED6F06D71B3C077C2A3739A4E |
SHA-256: | 342DE2A54E8EA27650B21CC4F48782AE0669BF483FDBFF6293D70C7BAC1ECF3A |
SHA-512: | 1ABED4B6C02B69FC33334CACA0698C600BD96A1613131A0BAA52E23B33F88F684A3394FBCAE6B4342ADE498F4AF36DDB55D14474DE5CC231CE32A90D692F6FFC |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 328 |
Entropy (8bit): | 3.2421047741749685 |
Encrypted: | false |
SSDEEP: | |
MD5: | C40596AF4A89D6EAA10B0F69DB1A93B8 |
SHA1: | CB1AC91566AE720AD193D362C9C1A54B9E1E77F9 |
SHA-256: | 7C50DEAF1452EFEA29E6FA8A8682C01019490389D9E561EFB63516A67FCEC538 |
SHA-512: | 398ED16176015D81DF9963782A2C8C3E63062A529D715831C3B8AFF0D81C829965A10223867610FBB33F6DA3FECF3E14DF37CCB7FAE63A8ACC457B885A37874A |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1969 |
Entropy (8bit): | 5.0600221295835635 |
Encrypted: | false |
SSDEEP: | |
MD5: | F2D50CD24A91925DE45986AF767BD2B3 |
SHA1: | 4C80AF7B77C214C8E99FCEA98DFBA36836A5ED68 |
SHA-256: | F1EE357225532594AFD610A28870D8679DF71AF3CE691504243358BB80DBE2A2 |
SHA-512: | 0C9CC89BE1CEAB999006AE966FE051A24B9049A9AC8A2DF80B5E3A97E91DB67B2C91A2DC6D95F83E736C39DC2D2E834BB808015EF896A6293CD4D44F06A98A59 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 0.9886756149599703 |
Encrypted: | false |
SSDEEP: | |
MD5: | 6D9275B450A5EBAC38409381863D7157 |
SHA1: | 98B797243A2899C0341040EABA7FFF46D1935F8D |
SHA-256: | 46457FF0D4886A8B416E0FA0DACD549BAA4BCED7C0062BADB75CDB6518BED67A |
SHA-512: | C1D744583E8EDE7E666E6AF9CE1E180A10423187DA4DA131C32B2B2AB64A857E11950B52C68F7015C669440F8ECB52ED432ECAC370FF27143C47747716FB7F39 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.3448588494264335 |
Encrypted: | false |
SSDEEP: | |
MD5: | 8A5CDFFE198288AAC7701FD51F7843C6 |
SHA1: | DBF132FFB11AE2C9391F379DC1F7947823F851C8 |
SHA-256: | A33B0DE3C69B5E48FD4FEE8DE726D54DC1DC73F1EFD78738382B93FC83B2BF09 |
SHA-512: | FDC57F2989F243CD746A529692191F0DD853D0F0622EB48BB47809F935F7D5260ED6004E918B53F075C44BC95EFEED323CBDF0130E8E895D94A5A94D17363F01 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66726 |
Entropy (8bit): | 5.392739213842091 |
Encrypted: | false |
SSDEEP: | |
MD5: | C5027DDF0A86F422B4585AC13F1FF744 |
SHA1: | 589D0E5297CB8EC9A0CEEAF8F0255410F30D21E8 |
SHA-256: | BE70923E8F6C910F2053FB614FC84EBF3CC3D805F6B4DD9CF4DDEB811F5E0A1D |
SHA-512: | 76E4E4E73922646C0959E21B7234FD292245B9DE21E87B40BF2F7B8A82860A20D02862D7B0ABAFCAC54B363984A1A9F357F4655F83438DDA1B2D8CE7A9D0D286 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.5146815864506182 |
Encrypted: | false |
SSDEEP: | |
MD5: | 9542C87F05616E8FC939797A746000FA |
SHA1: | D3331A59E8025FB950850BC002CEBE34DBFD79CB |
SHA-256: | C266EA33AB11381B6926C1B3BCE608E0C675E2C690EA3AAF5A7AC3E8809C8B91 |
SHA-512: | 570ABFF5060BF55C97E6D2057B400E87640F739FCE43A51C7CC20A8F01E40D4DA9462FA9F06A8EA5F32614AA65D36C1FB0AF11935651A412ABA4E6318CD82332 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Temp\Outlook Logging\OUTLOOK_16_0_16827_20130-20250114T0230330649-6296.etl
Download File
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | modified |
Size (bytes): | 94208 |
Entropy (8bit): | 4.462131884027503 |
Encrypted: | false |
SSDEEP: | |
MD5: | D23B40926931EF482BBAB09A45EA59CF |
SHA1: | 70256697FD249EF3226D90947A03B6CF7477E6D3 |
SHA-256: | 419F75899918126FC9F9D6228D662C9C4349968364BE2DCF1F4FCA7205A2F1C8 |
SHA-512: | BAEA081D1112B1E366EFB2C79768A855E1B395EEADF4B469D2287CC58F740AE505A37801526BD141E5E8BEDFFDA3D8B7A702828E91218308ED48562EA15FB0A0 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 358 |
Entropy (8bit): | 5.047106920883875 |
Encrypted: | false |
SSDEEP: | |
MD5: | 71FABB4DC25431780729A4EB04A250E3 |
SHA1: | BFA3BC24AD0AA9B6AEEADBF92AF4D0ECA9059CD5 |
SHA-256: | 2BFC628BE0CA55E5179B67BCC35508D4C66A73E77F2EDAA40E9320F6A69E13B1 |
SHA-512: | C7D93B7B4E1DECFF41C3B708F307BCCC4C48DD6EEE17B09631914F2FD4AB9E9E01601E0A67B093DF0C34ED2C862E75AC34F896F0854C8A517F982B7E5BBCDAA4 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2025-01-14 02-30-50-234.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.353642815103214 |
Encrypted: | false |
SSDEEP: | |
MD5: | 91F06491552FC977E9E8AF47786EE7C1 |
SHA1: | 8FEB27904897FFCC2BE1A985D479D7F75F11CEFC |
SHA-256: | 06582F9F48220653B0CB355A53A9B145DA049C536D00095C57FCB3E941BA90BB |
SHA-512: | A63E6E0D25B88EBB6602885AB8E91167D37267B24516A11F7492F48876D3DDCAE44FFC386E146F3CF6EB4FA6AF251602143F254687B17FCFE6F00783095C5082 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15114 |
Entropy (8bit): | 5.373262786942185 |
Encrypted: | false |
SSDEEP: | |
MD5: | 35DDDAA688BC5E0C91306C8CC0B5006E |
SHA1: | 541B5C7728D90F2BC648AFE31FE5D68F75BF3ADB |
SHA-256: | 63044A6E8165693672E2BBE0ECED3B0689488D58FB323CCEA0C45F9A0F5181A0 |
SHA-512: | 3E4F1B4D782EFE0A4280D11925F5A925B27765752DA996A296F37A0B55FC298F6132AECACEA0DC8C9B4C07CA4A27B6322F5860BF01360B29B293DE6A9059FAD6 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 29752 |
Entropy (8bit): | 5.4147699728150815 |
Encrypted: | false |
SSDEEP: | |
MD5: | 221E657E9E371A64705611838B8E1B16 |
SHA1: | 41591E4629FF8ED507500A463300A3B1AFD7EE89 |
SHA-256: | 16506AAEDFB92147AE9D03C6F78CEC2B0D5C1A997CA6D9A117D4C5FF545374F2 |
SHA-512: | F5040FCCB330C5C2A0910006F192FE032D2D88EDA833B9BF436C5FD58A734E186A27557F378615A00F2A83D1988B51F9E81E011CA05808229950508F684DD5A7 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | |
MD5: | 3A49135134665364308390AC398006F1 |
SHA1: | 28EF4CE5690BF8A9E048AF7D30688120DAC6F126 |
SHA-256: | D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B |
SHA-512: | BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | |
MD5: | E787F9888A1628BE8234F19E8EE26D68 |
SHA1: | 44D5180C06ADBBDAADDBCE350CE4DEC997CD83E5 |
SHA-256: | 3A09F3799148DA49F039A35AEDD22F368FB35B8D6022C4691C10606F704DAF80 |
SHA-512: | EE9B602898706CC0F33AA570E29A79A58ED748E1B738D74DF0C8C8DF193E23421B47AC8C862623ED774289D94FA90662A4CC436B80479D6420433D81752E9CA9 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | |
MD5: | 2748FBA76941F77C5C3D831E358162F1 |
SHA1: | 55B46C404506F24FF3DD04DFE8FE23DD2198B31A |
SHA-256: | 34B4238DCB7D63037437D1BDEE226F43DA4C899E1814E4F725A2DE8A0BDDC36F |
SHA-512: | 66CDF567E0183A0275F323D2B01C9098D1099C94595A1C88DA8CB8811D0FCF884D53C8C5E864322B8584336DA4279501F1CC12CC9D96FB0CE3444138A2A97BDC |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 163840 |
Entropy (8bit): | 0.36987224073407865 |
Encrypted: | false |
SSDEEP: | |
MD5: | 85C973C7B34E073C040B7AEA7EF1CE37 |
SHA1: | 8EB3D88A5E3D1243C75BCD727059CDC7201156FD |
SHA-256: | 3303FF9EC86E215B3ABEE591925C22F6E164A38774FEDA5C938E9E68A87F5BB0 |
SHA-512: | F24B2A1AB2AC6438F1123294BB14C3FA84E6FDCF0189E863D324F15D6C68048FB032321B55DB0B1D89306D621F94C5B17603481D06C5788A48D7C0CB1544E373 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2673 |
Entropy (8bit): | 3.981982780188927 |
Encrypted: | false |
SSDEEP: | |
MD5: | 70C3D9ED39B20D89F2B4595F398E6E49 |
SHA1: | 8283067F076D8B9CF3226E8153BCCCDCC09CCDE3 |
SHA-256: | 344AF3A4A96E3F1B76293C380E30C8E1BFF4A297F3890A1291BC2F523FEF5E27 |
SHA-512: | B119AFFEAC0000A0FCE567031F88ED1F1277774008B2C6C4B67C3CB876931FE36856432307C9A69A0C3D7C3E65504D90AA1E8640E32F7AB61CC7E0A820E1C7E3 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2675 |
Entropy (8bit): | 3.993314921481439 |
Encrypted: | false |
SSDEEP: | |
MD5: | 8343972C3A9230D704B2B744CA299844 |
SHA1: | 9F17C204544A60FD4D7F8CCEECDC9C0B99DABEE2 |
SHA-256: | AAADC7F2D5EBF79134A36B896519B89F167C9AE4F6F01A0C505D7A2D856364E1 |
SHA-512: | C81EE02EEE6ECFD8996657F681C8031D024484AB6F9215D9888B0FDD672CFD36A06B55917A8C5CC7FCD5E4F3DE1F9983A1C0FF72707A01B93F061D2242BD0D72 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2689 |
Entropy (8bit): | 4.010086964299569 |
Encrypted: | false |
SSDEEP: | |
MD5: | C26BAA53C5418829957027E1A21A96CE |
SHA1: | 7306E259AD994C03F7170322D9C42C4B3449C2CF |
SHA-256: | E8616942B1519C5B39C4F0456E96F2B670FBE2ABEB90C2C556631C492137361F |
SHA-512: | EEFD31960F31D905565A2B37421F25550B597A1D36788377D63386ED768972B59E6A34FD64636092BD530197F76F4C12D73057EB5DAA2B0D9D53552559EBA7DE |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.9963634148644935 |
Encrypted: | false |
SSDEEP: | |
MD5: | E4F33B169C6E14A96C71BBDEE5686413 |
SHA1: | B9FD40A0ED7C295573CEB07CCB66767741B733EE |
SHA-256: | B63B9FC214D9340C854BF1249C5123AFF89C7DB653E1513655F2B62AFC2B6431 |
SHA-512: | 001FAEEDDD34262B95F38FD713D51683A74C26B13A5E9290B4713D7CB23E1AFE9C6669F826C22FBC6E387ADD6EF8561139295203848A746989C9A040B0F5CEDA |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.984088609713395 |
Encrypted: | false |
SSDEEP: | |
MD5: | CE866F0606D71E288E0F82AA40F56814 |
SHA1: | 4EBA94C2A63041001F0DE1F56E6EA0E9EB74AB20 |
SHA-256: | 0FE38B130F4848FCD94147A3901C68C8911EF759C3723DBDC51502647C733B41 |
SHA-512: | A73DC4473B111EA2449459ACA49E326352E11A7219F6332A5BA05C2F7690EBE00C5BDBFD7507E954DB7B9AB614D22F9137B9F3BD60444930C25030814DCBBBC9 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2679 |
Entropy (8bit): | 3.9950707357106725 |
Encrypted: | false |
SSDEEP: | |
MD5: | B4B5E22A62FA182F80C56FE4D54A54CE |
SHA1: | 64BFEC7153031775FE4C9D4161C9D5410815F15C |
SHA-256: | B6811ACDFBD738F3466ADAD422064CB273AC9D49258C6035D32DECDAB842A880 |
SHA-512: | ACC8889D72B12503E52C436F9BFDD242F9379A1D6F3F255DA16839B4FE6AE8BCC0B06DED2B4BE776DBC6040584F3ACDCDD90444EB9F8BD13A16964B230D85D46 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 271360 |
Entropy (8bit): | 1.521295078925998 |
Encrypted: | false |
SSDEEP: | |
MD5: | E74F4664F974537243CB22B1C12B4E40 |
SHA1: | 4A0AC92D720BE8AD279F0A73D3F8C8B6AB74365B |
SHA-256: | 35851BAE9EC7FE30632B4B5FE3E6B9A72D83B9CB3FD19F2EA5DD32A8F9F122E6 |
SHA-512: | 01E4268F71A36A02B80E179AE860524E85DFDB23A643F52DD28BD3AFA8187044ECEE9F6FAF53CF96754C86E190EB66A7099ECD56E4FFF25ECB403EF6DAA07A40 |
Malicious: | true |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 131072 |
Entropy (8bit): | 1.1199443677818595 |
Encrypted: | false |
SSDEEP: | |
MD5: | 51C60C09112FE60C71B821C13E8BA9DB |
SHA1: | 6779675643CE911438E41137A612E682C69440B2 |
SHA-256: | 48C75A3DAE647B4B96CFACEAAE4B2F5A2C41C63069E03316B7B4C0D915A1D01F |
SHA-512: | 010B9F935A6FCA3F2F88C8A273E6F937B94B49854EF67CA4163DB299EB1C747DEA5AA66F960439542FC2F672E73D9722B26EF6BD3044A1BEA07423062137F885 |
Malicious: | true |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 875 |
Entropy (8bit): | 5.041341926266165 |
Encrypted: | false |
SSDEEP: | |
MD5: | 25C2BAF2B0F9A2F234E0BC51932B2BA4 |
SHA1: | 62CF79A6AE2CAE4609E1A9868A7B36288C40D711 |
SHA-256: | 08E465434224BBEDEDB00133E19A8DD5835EFD104BB69EC579EC6EA7344B3642 |
SHA-512: | 81325F6934FB15E95ABCD7429BE2E4E4D189120EFC0D687C929F1EE30065DAE624532AB2DEDF50FA47B9EBB31CA65158387CAFFC1D908067D187D572DC2B264B |
Malicious: | false |
Reputation: | unknown |
URL: | https://embeds.beehiiv.com/api/embeds/1ac29d4e-2fb8-419c-8498-f07b405bca74 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 48 |
Entropy (8bit): | 4.172995052579129 |
Encrypted: | false |
SSDEEP: | |
MD5: | 61DD07FB5A9C83D8BA6C6E53452707E8 |
SHA1: | 5C2085BBF6B50EAF00423E0178459ADF0B7CD7FA |
SHA-256: | 72D94A42F3D544F369B9A7DA8D2E5370B2C3C1634165DCC72A53FB443BE40933 |
SHA-512: | E85111BE6D081D4C9DC3D3F002D8BE5D21B4E89C41FD21FD2C90FF497E5C449FF4B3A2031EBA0A4E84A48FFDB758D306955AB0E750D992CE1EAE7A903EB8288B |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 407212 |
Entropy (8bit): | 5.309927954712754 |
Encrypted: | false |
SSDEEP: | |
MD5: | F206300056CFC9EB4D68EA680EB40E2E |
SHA1: | 865E1CF766AB18CAFBBD6261AC40A98794AEDD22 |
SHA-256: | DBD56CB4F17CEDEA5D4F6925BB16E6276885AEC2DAB2876F510F58AADE1DA50F |
SHA-512: | D2C806662770723455077B773F5CE546F2D6E9982D0EA1DA05C948A3A55167935E1019EA865DA902C0798299F9C04DFD62D34E2C6124CCF38F363E0A0DC4963C |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 48444 |
Entropy (8bit): | 7.995593685409469 |
Encrypted: | true |
SSDEEP: | |
MD5: | 8E433C0592F77BEB6DC527D7B90BE120 |
SHA1: | D7402416753AE1BB4CBD4B10D33A0C10517838BD |
SHA-256: | F052EE44C3728DFD23ABA8A4567150BC314D23903026FBB6AD089422C2DF56AF |
SHA-512: | 5E90F48B923BB95AEB49691D03DADE8825C119B2FA28977EA170C41548900F4E0165E2869F97C7A9380D7FF8FF331A1DA855500E5F7B0DFD2B9ABD77A386BBF3 |
Malicious: | false |
Reputation: | unknown |
URL: | https://fonts.gstatic.com/s/inter/v18/UcC73FwrK3iLTeHuS_nVMrMxCp50SjIa1ZL7.woff2 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 2683 |
Entropy (8bit): | 5.041618768419983 |
Encrypted: | false |
SSDEEP: | |
MD5: | 429FDE044420C0E44BDF9AE199F3AA86 |
SHA1: | 8A66DEA178707D2D1EEC3CD72EA57ADB07CB3E2B |
SHA-256: | B9423E66CBB9B281699BE16E2D93EC7D813127D66369F8A8D1B95D567E5C6E90 |
SHA-512: | 87306383742B1D8295B289B855F4F84D723AB86D71D9C2F2D9B1AB947B17CBF0F5D5B5AF766CD260955904047E3C4FD1385529F45A5E52C08CA75EBDD168715D |
Malicious: | false |
Reputation: | unknown |
URL: | https://ae879450.bosssellame.pages.dev/?email=mg%40michaelgorski.net |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 215965 |
Entropy (8bit): | 5.553526111646605 |
Encrypted: | false |
SSDEEP: | |
MD5: | 7CF547C37E06827152BCE33004D835FB |
SHA1: | 957B7EED4373957E630A665DE057B409B8E364E4 |
SHA-256: | 3540F036552FA08D117BA8E2CEBE5AA5E616F5E36206D18FA0B9A610996109A9 |
SHA-512: | 7DCACCF8037871D971CFE157AB4C69C74A2428365585B551AD16D73231A85E773AC2D7AFEE23972E9A9E2B2DB5DB6A30B99103D47DE3D64547F6FD5116CF1425 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 215965 |
Entropy (8bit): | 5.553530700063075 |
Encrypted: | false |
SSDEEP: | |
MD5: | 866EC42A0A9B396EA8C6A65DF41463D3 |
SHA1: | 8F189199128FF9964FB28BDF579E245BE0821294 |
SHA-256: | 01FBE3738CC15171176E20EAC3F45B00DE54EB32B5777E411FD9610E8FF33F58 |
SHA-512: | F342791E0474B1E40011DF6C7E289553F4760A718C6F89E902EDBC429458CFFFDB7132D5D66C646079D07BCE134AC82E25FEE5C2C42AEF97E984ACAF50541713 |
Malicious: | false |
Reputation: | unknown |
URL: | https://www.googletagmanager.com/gtm.js?id=GTM-WJXL7FH |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 6193 |
Entropy (8bit): | 5.401714743814202 |
Encrypted: | false |
SSDEEP: | |
MD5: | F2D1D2937C3546E15C471236646AC74E |
SHA1: | DD8D90F6D4AC8D72C718C10424788612689D89DB |
SHA-256: | 719D2FC548145FA8D8361205F6FCB49EEFC54C71FBB18E6320A60A263F40637A |
SHA-512: | 7B400281407249F805AB4695E0B7D3CDF4F7F5F776F9F7E60872D5208B7324DADDDAD79D76AC9991C74563520FB6BFF3A6343C8C10591C9EB5682733592668A4 |
Malicious: | false |
Reputation: | unknown |
URL: | https://fonts.googleapis.com/css2?family=Open+Sans&display=swap |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 19640 |
Entropy (8bit): | 5.315086402900025 |
Encrypted: | false |
SSDEEP: | |
MD5: | EE5EB442007B1AD4908D8CE77B3C2BCE |
SHA1: | 2EA314AE1A13AA52E98671B7626096CE20FE0146 |
SHA-256: | 79685D88E77FB6073EB2186384A792A094B89FE9BF66DF5B6B86AD6373FC3EEE |
SHA-512: | 0C63CFEF1C8FE8300689AE6F5394A4370A57120D43FAA8CBC5BBDDB8BADA7B1E1E8B4405D13F16D96B4608A1018FD72128672D7A06D34F4D7F45C202A9C59FE9 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 1190 |
Entropy (8bit): | 7.4470853307878535 |
Encrypted: | false |
SSDEEP: | |
MD5: | 4E97D5BF55BFF7ACB4D84150EBDA36F4 |
SHA1: | 13D3974361E0FEE926A1F802864A2963D81890EB |
SHA-256: | D0A7847D7E1C08556B23C28A518F817A50D0AD93476D5E8073DAD12476C03E29 |
SHA-512: | F43CCA3A2CF7E621FF9CFE2F163FF94CA29C08C7B1D833625A8DFFC2F687CF2F9AC9E6925AF05D46C5EC037D2513DDCB90361849A50A7CC15E60F138AD2C3C1E |
Malicious: | false |
Reputation: | unknown |
URL: | https://embeds.beehiiv.com/img/favicon.png |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8687 |
Entropy (8bit): | 5.739104440898457 |
Encrypted: | false |
SSDEEP: | |
MD5: | BFA0F92E19AD1C0CA3A98757A40FAFCC |
SHA1: | E6E408B6B1B71C7688DEAD57B1EE7562C8BFFC02 |
SHA-256: | A310BDF0C5FB3D662CF64F5A9400BDC64204EAF57AD6E0FF8E59253BDFB514D1 |
SHA-512: | D7C3AEFBE1EB1F283BC6D1494B1C79B1FEDA27E223E91EE6143152A1A3A7F4F5FCF6E7366445F6588395B45ACF6FF18210DB592AF9C51F021B8A61DDAB6728E5 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 32 |
Entropy (8bit): | 4.226409765557392 |
Encrypted: | false |
SSDEEP: | |
MD5: | 5C93A7F764F155630BD9601D168ED517 |
SHA1: | FE87E4E1C5F23BCAC2136E82A3128B73EA0787B8 |
SHA-256: | BF025AEAB7A252165820B7073FA6ABFD16A03E359A5F857CCBE2864887D8F703 |
SHA-512: | 4DCA8044D0EAC9A72E30E06E7BC6C5EBCF7402FB0FBBA41DE9FD76B54C9AA44DA757CE9FEC2F285CD5AE9C624DC6685C4449F6CAE12FF9FC6C4C0EF8BEC6EB76 |
Malicious: | false |
Reputation: | unknown |
URL: | https://content-autofill.googleapis.com/v1/pages/ChVDaHJvbWUvMTE3LjAuNTkzOC4xMzISEAn4zwBqHfU0RBIFDYOoWz0=?alt=proto |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 4634 |
Entropy (8bit): | 5.480036073913163 |
Encrypted: | false |
SSDEEP: | |
MD5: | 763FAD1B6C7F1F100F3F7817A1A46BEE |
SHA1: | 497713E40EA271ACBB9799D9D6ADC80DC4A4F7F2 |
SHA-256: | 2732ADDB6AA3B51DD9FB55A3C6D225921ED6963E928493A1F8EF64DDD312FD0E |
SHA-512: | 46586336F5B664E3E0F3378D22B11879B1A0953B27026D0D8836DCB65703EBFA7811771084A520610E3FFC55206EEEEF43D90DDD0BA4C96566207D8C0C7F078B |
Malicious: | false |
Reputation: | unknown |
URL: | "https://fonts.googleapis.com/css?family=Inter:400,700" |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 3686 |
Entropy (8bit): | 5.378631719572775 |
Encrypted: | false |
SSDEEP: | |
MD5: | D723A0415498B6B91211576DD5A62350 |
SHA1: | 398D2D20B010C2F3BEBEA7BA6338A59F3FA3DDE6 |
SHA-256: | D1EA586C521948824740A8DC3F884B5F6741C74EE96F29BCBF9E972A48ED7C4F |
SHA-512: | E766F6E9B52C527DD09959441AFE85486520605DD9F0478A557FA93B096A518B319F0EE8A18FF927BCDF8E9B21BAF414092A78CE2595C1A5817CCD25FFCDDF1B |
Malicious: | false |
Reputation: | unknown |
URL: | https://embeds.beehiiv.com/1ac29d4e-2fb8-419c-8498-f07b405bca74 |
Preview: |
File type: | |
Entropy (8bit): | 6.414400232083493 |
TrID: |
|
File name: | possible SPAM## Msig Insurance Europe Complete via-Sign Monday January 2025.msg |
File size: | 125'440 bytes |
MD5: | 44f22be45aa7a6597e01273c9a2d35ed |
SHA1: | 4618e5427e37589714c9289dda123dad3588a815 |
SHA256: | 9bc8dbfa26e0bcc66aafa8091d8b4388f0f56a3c586abd5640099f9d80a4fd5b |
SHA512: | 683ef7ee6271eebbf099881ee7837164b7170565b5d9bf27f166ad0d21b9d3d2a3860fd2eb2c924da373dda175612ce1045d6a6cfcb4fb94c5de3f672b17ff79 |
SSDEEP: | 3072:jcwROT1Hve/B82bCjAUgR93ov4cQt990hDcR0G8:gwROvWywCEUgH3gQt/0hDceG8 |
TLSH: | F7C31A2475F94608F277EF3189F69087893A7CD2ED68964F2195330E0471D81EA63B7B |
File Content Preview: | ........................>.......................................................k.............................................................................................................................................................................. |
Subject: | [possible SPAM:##] Msig Insurance Europe Complete via-Sign Monday January 2025 |
From: | =?UTF-8?Q?Msig Insurance Europe Online Notification?= <info@malhs.co.uk> |
To: | <christian.fink@msig-europe.com> |
Cc: | |
BCC: | |
Date: | Tue, 14 Jan 2025 07:51:32 +0100 |
Communications: |
|
Attachments: |
|
Key | Value |
---|---|
Received | from [65.21.250.207] (65.21.250.207) by |
DESR20008.de.msig-europe.local (2a00 | da9:13:1801::39) with Microsoft SMTP |
15.2.1544.4 via Mailbox Transport; Tue, 14 Jan 2025 07 | 51:50 +0100 |
DESR10008.de.msig-europe.local (2a00 | da9:13:1801::38) with Microsoft SMTP |
15.2.1544.4; Tue, 14 Jan 2025 07 | 51:50 +0100 |
Transport; Tue, 14 Jan 2025 07 | 51:50 +0100 |
for <christian.fink@msig-europe.com>; Tue, 14 Jan 2025 07 | 51:47 +0100 (CET) |
Tue, 14 Jan 2025 07 | 51:50 +0100 (CET) |
Authentication-Results | mailcc99.retarus.de; dkim=pass reason="good |
ARC-Seal | i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; |
ARC-Message-Signature | i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; |
h=From | Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; |
ARC-Authentication-Results | i=1; mx.microsoft.com 1; spf=fail (sender ip is |
DKIM-Signature | v=1; a=rsa-sha256; c=relaxed/relaxed; |
by DM6PR10MB4282.namprd10.prod.outlook.com (2603 | 10b6:5:222::11) with |
2025 06 | 51:34 +0000 |
(2603 | 10b6:806:20::29) with Microsoft SMTP Server (version=TLS1_3, |
14 Jan 2025 06 | 51:34 +0000 |
X-MS-Exchange-Authentication-Results | spf=fail (sender IP is 65.21.250.207) |
Received-SPF | Fail (protection.outlook.com: domain of malhs.co.uk does not |
via Frontend Transport; Tue, 14 Jan 2025 06 | 51:33 +0000 |
Content-Type | multipart/mixed; boundary="===============3431075377736621667==" |
MIME-Version | 1.0 |
From | =?UTF-8?Q?Msig Insurance Europe Online Notification?= <info@malhs.co.uk> |
To | <christian.fink@msig-europe.com> |
Subject | [possible SPAM:##] =?UTF-8?Q?Msig Insurance Europe Complete via-Sign Monday January |
Date | Tue, 14 Jan 2025 06:51:32 -0000 |
Message-ID | <173683749208.12996.13617349650493360933@malhs.co.uk> |
X-Accept-Language | en-us, en |
X-EOPAttributedMessage | 0 |
X-MS-PublicTrafficType | |
X-MS-TrafficTypeDiagnostic | SN1PEPF00036F42:EE_|DM6PR10MB4282:EE_ |
X-MS-Office365-Filtering-Correlation-Id | 9781ec40-4abd-4e07-bf74-08dd3467e25d |
X-MS-Exchange-SenderADCheck | 1 |
X-MS-Exchange-AntiSpam-Relay | 0 |
X-Microsoft-Antispam | BCL:0;ARA:13230040|36860700013|82310400026|1800799024|376014|8096899003|7053199007; |
X-Microsoft-Antispam-Message-Info | =?utf-8?B?ZC95bjFoKzRvVjlETXNnbVFCL0JLQThSeDl6K1FkUi95ckVabHhHKzdsQ1kv?= |
X-Forefront-Antispam-Report | CIP:65.21.250.207;CTRY:FI;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:[65.21.250.207];PTR:static.207.250.21.65.clients.your-server.de;CAT:NONE;SFS:(13230040)(36860700013)(82310400026)(1800799024)(376014)(8096899003)(7053199007);DIR:OUT;SFP:1102; |
X-MS-Exchange-CrossTenant-OriginalArrivalTime | 14 Jan 2025 06:51:33.4611 |
X-MS-Exchange-CrossTenant-Network-Message-Id | 9781ec40-4abd-4e07-bf74-08dd3467e25d |
X-MS-Exchange-CrossTenant-Id | 9db59932-68eb-45eb-854b-c226d702cfd0 |
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp | TenantId=9db59932-68eb-45eb-854b-c226d702cfd0;Ip=[65.21.250.207];Helo=[[65.21.250.207]] |
X-MS-Exchange-CrossTenant-AuthSource | SN1PEPF00036F42.namprd05.prod.outlook.com |
X-MS-Exchange-CrossTenant-AuthAs | Anonymous |
X-MS-Exchange-CrossTenant-FromEntityHeader | HybridOnPrem |
X-MS-Exchange-Transport-CrossTenantHeadersStamped | DM6PR10MB4282 |
X-RMX-ID | 20250114-075147-CtRcnQLWLfTf-0@in12.fraix1 |
X-RMX-SOURCE | 40.107.93.134 |
X-RMX-TransportEncryption | established=true, protocol=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384 (256/256 bits) |
X-RMX-Spam | Probability=34%, Report=' |
Return-Path | info@malhs.co.uk |
X-MS-Exchange-Organization-Network-Message-Id | 5da7c026-d83e-4bf8-8f48-08dd3467ec23 |
X-MS-Exchange-Organization-AuthSource | DESR20008.de.msig-europe.local |
X-MS-Exchange-Organization-AuthAs | Internal |
X-MS-Exchange-Organization-AuthMechanism | 10 |
X-MS-Exchange-Organization-AVStamp-Enterprise | 1.0 |
X-MS-Exchange-Organization-AVStamp-Mailbox | SMEXJnq?;1983500;0;This mail has |
X-MS-Exchange-Organization-SCL | 0 |
X-MS-Exchange-Transport-EndToEndLatency | 00:00:00.3320539 |
X-MS-Exchange-Processed-By-BccFoldering | 15.02.1544.004 |
date | Tue, 14 Jan 2025 07:51:32 +0100 |
Icon Hash: | c4e1928eacb280a2 |