Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
POSTA CERTIFICATA PRESTITI FINTECH FINO A 5 MILIONI DI EURO - BLOCCA PE... (633Ko).msg

Overview

General Information

Sample name:POSTA CERTIFICATA PRESTITI FINTECH FINO A 5 MILIONI DI EURO - BLOCCA PE... (633Ko).msg
Analysis ID:1591686
MD5:61bbf0d8b4d262cc6cd74de20cb03b8c
SHA1:9636df2387670fbb3ddea8d5e4caf1d165508fdf
SHA256:162b6e7f1d51486bea455b33767d3758e6fec17c911cdffc43ef177f398e29ca
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

AI detected suspicious elements in Email content
AI detected suspicious elements in Email header
Creates a window with clipboard capturing capabilities
Queries the volume information (name, serial number etc) of a device
Sigma detected: Office Autorun Keys Modification
Sigma detected: Suspicious Office Outbound Connections
Stores large binary data to the registry

Classification

  • System is w10x64_ra
  • OUTLOOK.EXE (PID: 7024 cmdline: "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" /f "C:\Users\user\Desktop\POSTA CERTIFICATA PRESTITI FINTECH FINO A 5 MILIONI DI EURO - BLOCCA PE... (633Ko).msg" MD5: 91A5292942864110ED734005B7E005C0)
    • ai.exe (PID: 6260 cmdline: "C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe" "5DAEF219-A1EB-4BE4-BCD4-54A26FCDC6D6" "DF5D7C9B-6059-4375-8162-D333735CEC7D" "7024" "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" "WordCombinedFloatieLreOnline.onnx" MD5: EC652BEDD90E089D9406AFED89A8A8BD)
  • cleanup
No yara matches
Source: Registry Key setAuthor: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): Data: Details: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 , EventID: 13, EventType: SetValue, Image: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE, ProcessId: 7024, TargetObject: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Outlook\Addins\OneNote.OutlookAddin\1
Source: Network ConnectionAuthor: X__Junior (Nextron Systems): Data: DestinationIp: 192.168.2.16, DestinationIsIpv6: false, DestinationPort: 49697, EventID: 3, Image: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE, Initiated: true, ProcessId: 7024, Protocol: tcp, SourceIp: 109.70.240.130, SourceIsIpv6: false, SourcePort: 80
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

Phishing

barindex
Source: EmailJoe Sandbox AI: Detected potential phishing email: The subject line is overly promotional and written in all caps, a common spam/phishing tactic. The message promotes financial services with unrealistic guarantees and loan amounts, typical of financial scams. The sender uses a PEC (certified email) service but the content appears to be unsolicited commercial messaging
Source: EmailJoe Sandbox AI: Detected suspicious elements in Email header: Suspicious IP origin from dynamic-adsl residential network, unusual for legitimate business email. Claims to be from arubapec.it (Italian certified email) but sent from Tisuser ISP network. Proofpoint spam score is suspiciously low (0) despite red flags. Message appears to be digitally signed but originates from unexpected network. Mismatch between return-path domain (arubapec.it) and actual sending infrastructure. Dynamic IP address usage suggests potential malicious activity masquerading as legitimate business service
Source: EmailClassification: Lure-Based Attack
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /VA/AUTH-ROOT/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSw4x5v4bTlizjNRmTdkYSy7q0R9gQUUtiIOsifeGbtifN7OHCUyQICNtACEGgEO9xMsFqJEX4b%2FWkncfc%3D HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Microsoft-CryptoAPI/10.0Host: ocsp07.actalis.it
Source: global trafficHTTP traffic detected: GET /OCSP/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ0IUzpe7WXs2Kz%2F8Hu0KjsJ0iwvgQUpf2FBQ7D8dZlSiBs4ttNYJMriqACEBrFm5M%2FFFBkmWPhM9eNZcw%3D HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Microsoft-CryptoAPI/10.0Host: ca1.agid.gov.it
Source: global trafficDNS traffic detected: DNS query: ocsp07.actalis.it
Source: global trafficDNS traffic detected: DNS query: ca1.agid.gov.it
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEWindow created: window name: CLIPBRDWNDCLASS
Source: classification engineClassification label: mal48.winMSG@3/9@2/34
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEFile created: C:\Users\user\Documents\Outlook Files\~Outlook Data File - NoEmail.pst.tmp
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEFile created: C:\Users\user\AppData\Local\Temp\Outlook Logging\OUTLOOK_16_0_16827_20130-20250115T0403160908-7024.etl
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEFile read: C:\Users\desktop.ini
Source: unknownProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" /f "C:\Users\user\Desktop\POSTA CERTIFICATA PRESTITI FINTECH FINO A 5 MILIONI DI EURO - BLOCCA PE... (633Ko).msg"
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe "C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe" "5DAEF219-A1EB-4BE4-BCD4-54A26FCDC6D6" "DF5D7C9B-6059-4375-8162-D333735CEC7D" "7024" "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" "WordCombinedFloatieLreOnline.onnx"
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe "C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe" "5DAEF219-A1EB-4BE4-BCD4-54A26FCDC6D6" "DF5D7C9B-6059-4375-8162-D333735CEC7D" "7024" "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" "WordCombinedFloatieLreOnline.onnx"
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: apphelp.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: c2r64.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: userenv.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: msasn1.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: kernel.appcore.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: cryptsp.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: rsaenh.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: cryptbase.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: gpapi.dll
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}\InprocServer32
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEWindow found: window name: SysTabControl32
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Common
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F373B387065A28848AF2F34ACE192BDDC78E9CAC Blob
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information queried: ProcessInformation
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeQueries volume information: C:\Program Files (x86)\Microsoft Office\root\Office16\AI\WordCombinedFloatieLreOnline.onnx VolumeInformation
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation11
Browser Extensions
1
Process Injection
1
Masquerading
OS Credential Dumping1
Process Discovery
Remote Services1
Clipboard Data
2
Non-Application Layer Protocol
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/Job1
DLL Side-Loading
1
DLL Side-Loading
1
Modify Registry
LSASS Memory1
File and Directory Discovery
Remote Desktop ProtocolData from Removable Media2
Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
Process Injection
Security Account Manager12
System Information Discovery
SMB/Windows Admin SharesData from Network Shared Drive1
Ingress Tool Transfer
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
DLL Side-Loading
NTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
ocsp.actalis.it
109.70.240.130
truefalse
    unknown
    ca1.agid.gov.it
    93.39.128.41
    truefalse
      unknown
      ocsp07.actalis.it
      unknown
      unknownfalse
        unknown
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        52.113.194.132
        unknownUnited States
        8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
        93.39.128.41
        ca1.agid.gov.itItaly
        12874FASTWEBITfalse
        109.70.240.130
        ocsp.actalis.itItaly
        31034ARUBA-ASNITfalse
        52.109.68.130
        unknownUnited States
        8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
        52.109.89.19
        unknownUnited States
        8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
        2.16.168.101
        unknownEuropean Union
        20940AKAMAI-ASN1EUfalse
        20.42.65.85
        unknownUnited States
        8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
        Joe Sandbox version:42.0.0 Malachite
        Analysis ID:1591686
        Start date and time:2025-01-15 10:02:47 +01:00
        Joe Sandbox product:CloudBasic
        Overall analysis duration:
        Hypervisor based Inspection enabled:false
        Report type:full
        Cookbook file name:defaultwindowsinteractivecookbook.jbs
        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
        Number of analysed new started processes analysed:13
        Number of new started drivers analysed:0
        Number of existing processes analysed:0
        Number of existing drivers analysed:0
        Number of injected processes analysed:0
        Technologies:
        • EGA enabled
        Analysis Mode:stream
        Analysis stop reason:Timeout
        Sample name:POSTA CERTIFICATA PRESTITI FINTECH FINO A 5 MILIONI DI EURO - BLOCCA PE... (633Ko).msg
        Detection:MAL
        Classification:mal48.winMSG@3/9@2/34
        Cookbook Comments:
        • Found application associated with file extension: .msg
        • Exclude process from analysis (whitelisted): dllhost.exe, svchost.exe
        • Excluded IPs from analysis (whitelisted): 52.113.194.132
        • Excluded domains from analysis (whitelisted): ecs.office.com, s-0005.s-msedge.net, ecs.office.trafficmanager.net, s-0005-office.config.skype.com, ecs-office.s-0005.s-msedge.net
        • Report size getting too big, too many NtQueryAttributesFile calls found.
        • Report size getting too big, too many NtQueryValueKey calls found.
        • Report size getting too big, too many NtReadVirtualMemory calls found.
        • Report size getting too big, too many NtSetValueKey calls found.
        • VT rate limit hit for: ocsp.actalis.it
        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
        File Type:DIY-Thermocam raw data (Lepton 3.x), scale 32000-0, spot sensor temperature 0.000000, unit celsius, color scheme 0, userbration: offset -9223372036854775808.000000, slope 0.000476
        Category:modified
        Size (bytes):98304
        Entropy (8bit):4.447933607328755
        Encrypted:false
        SSDEEP:
        MD5:C675D93D85EC71FB12614E2D9186D214
        SHA1:43CCA8F657155C83752059F7606BA54926363179
        SHA-256:2994FC821A52F5F0417EF5253BED8BF06E6642DDA20B3DDBFCD6A160A5D01091
        SHA-512:1E06CAA20D68C43F5108370DA5B3092F9C2FE434EB8A66883969D2798C1EB3BEE639EBD6AA227659507ED188370FB67468C8340D4ED5A732C2ED3452B7B276CE
        Malicious:false
        Reputation:unknown
        Preview:............................................................................`...t...p...6N.P,g..................eJ..............Zb..2...................................,...@.t.z.r.e.s...d.l.l.,.-.1.1.2.......................................................@.t.z.r.e.s...d.l.l.,.-.1.1.1..............................................................Q.Y..........6N.P,g..........v.2._.O.U.T.L.O.O.K.:.1.b.7.0.:.0.f.1.9.1.c.d.2.5.9.5.d.4.8.1.2.9.0.2.d.5.1.6.a.7.8.d.4.f.c.0.3...C.:.\.U.s.e.r.s.\.c.a.l.i.\.A.p.p.D.a.t.a.\.L.o.c.a.l.\.T.e.m.p.\.O.u.t.l.o.o.k. .L.o.g.g.i.n.g.\.O.U.T.L.O.O.K._.1.6._.0._.1.6.8.2.7._.2.0.1.3.0.-.2.0.2.5.0.1.1.5.T.0.4.0.3.1.6.0.9.0.8.-.7.0.2.4...e.t.l.......P.P.t...p...R..P,g..........................................................................................................................................................................................................................................................................................................
        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
        Category:dropped
        Size (bytes):314
        Entropy (8bit):4.803822695545621
        Encrypted:false
        SSDEEP:
        MD5:6B7A472A22FBDBFF4B2B08DDB4F43735
        SHA1:C6DF700168D3F5A90FF2713B78F8EF1446927102
        SHA-256:65F3CDBC4390C81B94FA960B7362917443FC1E6A51E3F81E4CB4C4DFA09DA4BE
        SHA-512:8D2E00954422F124CB1A7B969A728B3A6C9FB11C44623C1CDA33F2364E1C7CB101F6BF6C980E5F26368594F6CECED5C3D5E5A43327387554567BCDB5F1036740
        Malicious:false
        Reputation:unknown
        Preview:<?xml version="1.0" encoding="UTF-8" standalone="yes"?>..<a:clrMap xmlns:a="http://schemas.openxmlformats.org/drawingml/2006/main" bg1="lt1" tx1="dk1" bg2="lt2" tx2="dk2" accent1="accent1" accent2="accent2" accent3="accent3" accent4="accent4" accent5="accent5" accent6="accent6" hlink="hlink" folHlink="folHlink"/>
        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
        File Type:Microsoft OOXML
        Category:dropped
        Size (bytes):3333
        Entropy (8bit):7.6659475365317356
        Encrypted:false
        SSDEEP:
        MD5:E3315CA1DC2EEB890D5EB1B49ADEA574
        SHA1:FEA00932B7078DE0D074A90C1FBC778052F8EC30
        SHA-256:2AFE945199ADDFEB66BA84A14AB7031AF3A06A3F4307A36200AFE3EE96A84084
        SHA-512:A1FF2DF192A36A15575B664A843D0E098ECDD07728DC56A370E6E54E85E730601DF78DD540BE0CFF3DCB5837E60BF325375CB93F75C0B4D10885483D29A87948
        Malicious:false
        Reputation:unknown
        Preview:PK..........!.................[Content_Types].xml...N.0.E.H...-J..@.%...|..$....U..L.TB. .l,.3..;.r.......J..B+$..G]..7O.V....<a.......(7..I..R.{.pgL.=..r.....8..5v&.....uQ...8..C......X=....$..?6N.JC........F..B..'...+...Y.T....^e5.5.. ......._.g .-.;.....Yl....|6^.N...`.?.....[........PK..........!........6......._rels/.rels...j.0.....}Q...%v/..C/.}..(.h".....O..........=...... ......C?.h.v=......%.[xp..{._.P.<.1..H.0.....O.R.Bd....JE.4b$...q_......6L...R.7`.......0.O...,.E.n7.Li.b../.S...e...............PK..........!.ky..............theme/theme/themeManager.xml..M.. .@.}.w..7c.(Eb.....C..A......7....K.Y,....e.....|,....H..,l.....x.....I.sQ}#..... .+.!.,.^.$j=.GW...).E.+&..8........PK..........!.{C.]..... ......theme/theme/theme1.xml.Y_.......;......,..i$y...%;.c..io..n.Z...{.K pw.%..<....A.....l..Hu.h.-......v..L.W....*u...eJ....aY.....flN...?..+....esDY.{.....{...]t$..b..3q.z~"..Z.3.F..[...[0."..<..9...).6j.V5E$......bAf.*........L.50.|.T
        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
        File Type:HTML document, ASCII text, with CRLF line terminators
        Category:dropped
        Size (bytes):79758
        Entropy (8bit):4.419259296590074
        Encrypted:false
        SSDEEP:
        MD5:405E855F8AD6A36031D0C96FB5772C29
        SHA1:56E2AB7EFA315E6A04118C9B9D02A07AC2201703
        SHA-256:2ADA35F1EC35B7B170FBC6A2712C2983867A0040E71996A1ED93E6E25A4B0A3C
        SHA-512:B19C4A6273555A6C2ED3B4614303F66CAF23D6E9575354A0D7973B234512D5FADB81757A00A5B2DB3AD9E1331CC2636B217B946D61A8C906BF5525514306E982
        Malicious:false
        Reputation:unknown
        Preview:------0C4107273EEF3CA7DAEE97AA7E8660C5..Content-Type: multipart/mixed; boundary="----------=_1734010315-48531-830"..Content-Transfer-Encoding: binary..MIME-Version: 1.0....------------=_1734010315-48531-830..Content-Type: multipart/alternative;.. boundary="----------=_1734010315-48531-831"..Content-Transfer-Encoding: binary....------------=_1734010315-48531-831..Content-Type: text/plain; charset="iso-8859-1"..Content-Disposition: inline..Content-Transfer-Encoding: quoted-printable....--Questo =E8 un Messaggio di Posta Certificata--....Il giorno 12/12/2024 alle ore 14:31:55 (+0100) il messaggio con Oggetto.."PRESTITI FINTECH FINO A 5 MILIONI DI EURO - BLOCCA PER 3 MESI LA GARANZIA =..STATALE MCC FINO ALL'80% - IN ALLEGATO IL CALENDARIO DELLE DELIBERE PER L'A=..NNO 2024 - VALUTIAMO RICHIESTE IN PRESENZA DI PICCOLI SCONFINI TECNICI IN C=..R - Per info chiama subito l'800985228" =E8 stato inviato dal mittente "con=..sulenzaeurofintech@arubapec.it"..e indirizzato a:..dataprotection@socotec.
        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
        File Type:CDFV2 Microsoft Outlook Message
        Category:dropped
        Size (bytes):2560
        Entropy (8bit):1.2985458422463787
        Encrypted:false
        SSDEEP:
        MD5:07B767AD7CBF773183B063B3109332D0
        SHA1:533C4CF5DD815331EE5FC4952B8EEB15B7FA116C
        SHA-256:EB25C425148EA70E0FA81711405C952C9C8738E31E0757F1E175F876B44E63B4
        SHA-512:B06DD5FF33729E4C25924820A6EB2474805E74D062F3BD6BFD0B84694E51A61D47865BEAB5D02C2B27A60AA576B2DF1619C22AACF8DF96E6E66A3CFA9498F655
        Malicious:false
        Reputation:unknown
        Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
        File Type:data
        Category:dropped
        Size (bytes):155648
        Entropy (8bit):0.3852019066586091
        Encrypted:false
        SSDEEP:
        MD5:C1480F4D0E56F5A3AED8A882BAF6EE25
        SHA1:4A941D4E084544BC2B268591250625F672E51F18
        SHA-256:4FB0F2302194EF875614024C4A26F55B4445B594EEFF3EF97A6F430664AFE5D9
        SHA-512:2639408866C074D8F73D13B82E377AD6C87E788898704C6A0AA6AFA11E342026F3B781E663EEDD91299E3B0748CF3AA3ADB99F22D4F9F4586587757CE6B92C89
        Malicious:false
        Reputation:unknown
        Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
        File Type:data
        Category:dropped
        Size (bytes):417792
        Entropy (8bit):3.218644165317827
        Encrypted:false
        SSDEEP:
        MD5:F3EDA817693490D5DA3BD490F3B68602
        SHA1:E24D355BBE8B5DADE53C7024DD84E096446FCC55
        SHA-256:3A73E134A6C40FC047B19B0FE1E74A4BFC618F1F48B8806B07A4125962A73AAD
        SHA-512:B389755CE0499EAA114EC1ED69F73E10D4DE7E8B2998F885399F38D86902EBCF15411D07436CAC15DE20A26C69B9D19D72537F40A91F7FF17A6FFB8CADABF6C3
        Malicious:false
        Reputation:unknown
        Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
        File Type:Microsoft Outlook email folder (>=2003)
        Category:dropped
        Size (bytes):271360
        Entropy (8bit):1.5582913682380375
        Encrypted:false
        SSDEEP:
        MD5:1A27AAAC734F94CD0D9E7CAC174E122C
        SHA1:F01E4D90A8B035BBCF41426B60385A328CFC2962
        SHA-256:C6BE3EF894BA11F17301F8EB9E22E2D52B6B0398093386D95AC45CB4A26A890B
        SHA-512:C798EB66223D6C1FBDB5E8B8DA96060C023FA9241DAFD2318137FEFD69CAD2AE78BBB6274E5BC1C4D17216BD4F2BDED62A5151878BA260B4F7365957D13CA48C
        Malicious:true
        Reputation:unknown
        Preview:!BDNQ..\SM......\...+...................\................@...........@...@...................................@...........................................................................$.......D.......>..........................................................................................................................................................................................................................................................................................................................H.......@.0.........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
        File Type:data
        Category:dropped
        Size (bytes):131072
        Entropy (8bit):1.0944863380346845
        Encrypted:false
        SSDEEP:
        MD5:6F26F193E6EC9BC0BB20283A85AC795C
        SHA1:29637EAC46D155FCFC6CDC4486ADDBA3AAC68A62
        SHA-256:19670C718F2E2BA92538EF908A8AF594F8DF5C9B40C8373A8BCE588B27F9B3D7
        SHA-512:5C9429A57128EAFF54063856A4AF3B84ECD4AB418EA85CC5C2DB827D26A6DC272702DEAC1B1B33C3B4B1765B6BE34F05F54434667B870BA9F873F3E0C6686EB4
        Malicious:true
        Reputation:unknown
        Preview:*.,.0...S.......p...@..P,g.......D............#.......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................h..D........f.0...T.......p...@..P,g.......B............#.........................................................................................................................................................................................................................................................................................................................................................................................................
        File type:CDFV2 Microsoft Outlook Message
        Entropy (8bit):4.6756522101268025
        TrID:
        • Outlook Message (71009/1) 58.92%
        • Outlook Form Template (41509/1) 34.44%
        • Generic OLE2 / Multistream Compound File (8008/1) 6.64%
        File name:POSTA CERTIFICATA PRESTITI FINTECH FINO A 5 MILIONI DI EURO - BLOCCA PE... (633Ko).msg
        File size:122'880 bytes
        MD5:61bbf0d8b4d262cc6cd74de20cb03b8c
        SHA1:9636df2387670fbb3ddea8d5e4caf1d165508fdf
        SHA256:162b6e7f1d51486bea455b33767d3758e6fec17c911cdffc43ef177f398e29ca
        SHA512:eccfec3c090100fac345a257f5551258b3b9cc407efff03be61380490b8f21159fa0f58e44b06560e0d18882b86007897335c2b44908c846079fff1ff7e4d760
        SSDEEP:3072:I8FheRwxZSeNQRyxpwPNlnIZCkukytHvkIKF:IXRyxwNlnhkmBe
        TLSH:86C3D51569D60151F1B3CFB1ADE76667EA253C8BED05866A319C330E0FF58006A32B7E
        File Content Preview:........................>.......................................................L..............................................................................................................................................................................
        Subject:POSTA CERTIFICATA: PRESTITI FINTECH FINO A 5 MILIONI DI EURO - BLOCCA PER 3 MESI LA GARANZIA STATALE MCC FINO ALL'80% - IN ALLEGATO IL CALENDARIO DELLE DELIBERE PER L'ANNO 2024 - VALUTIAMO RICHIESTE IN PRESENZA DI PICCOLI SCONFINI TECNICI IN CR - Per info chiama subito l'800985228
        From:"Per conto di: consulenzaeurofintech@arubapec.it" <posta-certificata@pec.aruba.it>
        To:dataprotection@socotec.com
        Cc:
        BCC:
        Date:Thu, 12 Dec 2024 14:31:55 +0100
        Communications:
        • Messaggio di posta certificata ________________________________ Il giorno 12/12/2024 alle ore 14:31:55 (+0100) il messaggio "PRESTITI FINTECH FINO A 5 MILIONI DI EURO - BLOCCA PER 3 MESI LA GARANZIA STATALE MCC FINO ALL'80% - IN ALLEGATO IL CALENDARIO DELLE DELIBERE PER L'ANNO 2024 - VALUTIAMO RICHIESTE IN PRESENZA DI PICCOLI SCONFINI TECNICI IN CR - Per info chiama subito l'800985228" stato inviato da "consulenzaeurofintech@arubapec.it" indirizzato a: dataprotection@socotec.com Il messaggio originale incluso in allegato. Identificativo messaggio: opec210312.20241212143155.48531.169.1.51@pec.aruba.it
        Attachments:
        Key Value
        Receivedfrom dynamic-adsl-84-220-244-24.clienti.tiscali.it
        by DU0PR03MB8695.eurprd03.prod.outlook.com (260310a6:10:3ee::10) with
        2024 1331:58 +0000
        (260310a6:20b:5e0::13) with Microsoft SMTP Server (version=TLS1_3,
        12 Dec 2024 1331:57 +0000
        Authentication-Resultsspf=fail (sender IP is 91.207.212.148)
        Received-SPFFail (protection.outlook.com: domain of arubapec.it does not
        15.20.8251.15 via Frontend Transport; Thu, 12 Dec 2024 1331:57 +0000
        for <dataprotection@socotec.com>; Thu, 12 Dec 2024 1431:55 +0100 (CET)
        Authentication-Results-Originalppops.net; spf=pass
        <dataprotection@socotec.com>; Thu, 12 Dec 2024 1431:55 +0100 (CET)
        SubjectPOSTA CERTIFICATA: PRESTITI FINTECH FINO A 5 MILIONI DI EURO -
        X-Riferimento-Message-ID<4Y8D0C2fmXzclc9@smtps.pec.aruba.it>
        DateThu, 12 Dec 2024 14:31:55 +0100
        Message-ID<opec210312.20241212143155.48531.169.1.51@pec.aruba.it>
        Reply-To"contatto@eurofin.org" <contatto@eurofin.org>
        Todataprotection@socotec.com
        X-Trasportoposta-certificata
        From"Per conto di: consulenzaeurofintech@arubapec.it" <posta-certificata@pec.aruba.it>
        Content-Typemultipart/signed; protocol="application/x-pkcs7-signature"; micalg="sha1"; boundary="----0C4107273EEF3CA7DAEE97AA7E8660C5"
        X-Proofpoint-GUIDMO01P8AtBXOXGnkih3qii25dyzBkqne8
        X-Proofpoint-ORIG-GUIDMO01P8AtBXOXGnkih3qii25dyzBkqne8
        X-CLX-Response1TFkXHxoYEQpMehcbExsRCllEF2ZwRmlAH1tnQ0l8EQpYWBdhbmBQHhlEb1p QXREKeE4XbX0cYGR/QkZCBWIRCnhLF2FuYFAeGURvWlBdEQp4TBdpUBpIfx5TXGhNbhEKeUwXb2 8fW2BlEx5dRm8RCkNIFwcTHREKQ1kXBxsfHhEKQ0kXGgQaGhoRCllNF2dmchEKWUkXGxsccRgbE
        X-CLX-ShadesMLX
        X-Proofpoint-SPF-Resultpass
        X-Proofpoint-SPF-Recordv=spf1 ip4:62.149.158.0/24 ip4:62.149.157.0/24 ip4:62.149.156.0/24
        ip495.110.216.0/24 ip4:95.110.223.0/24 ip4:80.88.94.0/24 -all
        X-Proofpoint-Virus-Versionvendor=baseguard
        engine=ICAP2.0.293,Aquarius:18.0.1057,Hydra:6.0.680,FMLib:17.12.68.34
        X-Proofpoint-Spam-Detailsrule=inbound_notspam policy=inbound score=0 clxscore=502 suspectscore=0
        Return-Pathconsulenzaeurofintech@arubapec.it
        X-MS-Exchange-Organization-ExpirationStartTime12 Dec 2024 13:31:57.7852
        X-MS-Exchange-Organization-ExpirationStartTimeReasonOriginalSubmit
        X-MS-Exchange-Organization-ExpirationInterval1:00:00:00.0000000
        X-MS-Exchange-Organization-ExpirationIntervalReasonOriginalSubmit
        X-MS-Exchange-Organization-Network-Message-Id2eeacc6e-e673-43d3-56cc-08dd1ab159fe
        X-EOPAttributedMessage0
        X-EOPTenantAttributedMessage33135fa5-f5a7-4d5c-8632-9a17d4acfa5b:0
        X-MS-Exchange-Organization-MessageDirectionalityIncoming
        X-MS-Exchange-SkipListedInternetSenderip=[80.88.94.21];domain=smtps.pec.aruba.it
        X-MS-PublicTrafficTypeEmail
        X-MS-TrafficTypeDiagnosticAMS0EPF0000019E:EE_|DU0PR03MB8695:EE_
        X-MS-Exchange-Organization-AuthSourceAMS0EPF0000019E.eurprd05.prod.outlook.com
        X-MS-Exchange-Organization-AuthAsAnonymous
        X-MS-Office365-Filtering-Correlation-Id2eeacc6e-e673-43d3-56cc-08dd1ab159fe
        X-MS-Exchange-AtpMessagePropertiesSA|SL
        MIME-Version1.0
        dateThu, 12 Dec 2024 14:31:55 +0100

        Icon Hash:c4e1928eacb280a2