Edit tour

Windows Analysis Report
Lockheed Martin 1LMX Supplier Webinar.ics

Overview

General Information

Sample name:Lockheed Martin 1LMX Supplier Webinar.ics
Analysis ID:1649534
MD5:a920d8e569fca7869ac85038af40fad1
SHA1:ad5477bc33c573ca2d21fff27504d399aae4d7b0
SHA256:5244cd9cca8c36c424657ac62a9b51b19746540457658a1d5850757ff9b2bb4d
Infos:

Detection

Score:1
Range:0 - 100
Confidence:100%

Signatures

Sigma detected: Office Autorun Keys Modification
Stores large binary data to the registry

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64_ra
  • OUTLOOK.EXE (PID: 7024 cmdline: "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" /ical "C:\Users\user\Desktop\Lockheed Martin 1LMX Supplier Webinar.ics" MD5: 91A5292942864110ED734005B7E005C0)
  • rundll32.exe (PID: 6812 cmdline: C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding MD5: EF3179D498793BF4234F708D3BE28633)
  • OUTLOOK.EXE (PID: 6760 cmdline: "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" /ical "C:\Users\user\Desktop\Lockheed Martin 1LMX Supplier Webinar.ics" MD5: 91A5292942864110ED734005B7E005C0)
  • cleanup
No yara matches
Source: Registry Key setAuthor: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): Data: Details: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 , EventID: 13, EventType: SetValue, Image: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE, ProcessId: 7024, TargetObject: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Outlook\Addins\OneNote.OutlookAddin\1
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: classification engineClassification label: clean1.winICS@3/2@0/32
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEFile created: C:\Users\user\Documents\Outlook Files\~Outlook Data File - NoEmail.pst.tmp
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEFile created: C:\Users\user\AppData\Local\Temp\Outlook Logging\OUTLOOK_16_0_16827_20130-20250326T1646220639-7024.etl
Source: C:\Windows\System32\rundll32.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Source: unknownProcess created: C:\Windows\System32\rundll32.exe C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding
Source: unknownProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" /ical "C:\Users\user\Desktop\Lockheed Martin 1LMX Supplier Webinar.ics"
Source: unknownProcess created: C:\Windows\System32\rundll32.exe C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding
Source: unknownProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" /ical "C:\Users\user\Desktop\Lockheed Martin 1LMX Supplier Webinar.ics"
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}\InprocServer32
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Common
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEKey value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\IdentityCRL\Immersive\production\Token\{2B379600-B42B-4FE9-A59C-A312FB934935} DeviceTicket
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Masquerading
OS Credential Dumping3
System Information Discovery
Remote ServicesData from Local SystemData ObfuscationExfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Modify Registry
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
Rundll32
Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
Process Injection
NTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
s-0005.dual-s-dc-msedge.net
52.123.131.14
truefalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    20.189.173.8
    unknownUnited States
    8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
    23.40.179.190
    unknownUnited States
    16625AKAMAI-ASUSfalse
    52.123.131.14
    s-0005.dual-s-dc-msedge.netUnited States
    8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
    Joe Sandbox version:42.0.0 Malachite
    Analysis ID:1649534
    Start date and time:2025-03-26 21:45:52 +01:00
    Joe Sandbox product:CloudBasic
    Overall analysis duration:
    Hypervisor based Inspection enabled:false
    Report type:full
    Cookbook file name:defaultwindowsinteractivecookbook.jbs
    Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
    Number of analysed new started processes analysed:15
    Number of new started drivers analysed:0
    Number of existing processes analysed:0
    Number of existing drivers analysed:0
    Number of injected processes analysed:0
    Technologies:
    • EGA enabled
    Analysis Mode:stream
    Analysis stop reason:Timeout
    Sample name:Lockheed Martin 1LMX Supplier Webinar.ics
    Detection:CLEAN
    Classification:clean1.winICS@3/2@0/32
    Cookbook Comments:
    • Found application associated with file extension: .ics
    • Exclude process from analysis (whitelisted): svchost.exe
    • Excluded IPs from analysis (whitelisted): 23.40.179.190, 23.40.179.166, 52.123.131.14
    • Excluded domains from analysis (whitelisted): ecs.office.com, omex.cdn.office.net, dual-s-0005-office.config.skype.com, ecs.office.trafficmanager.net, omex.cdn.office.net.akamaized.net, a1864.dscd.akamai.net
    • Not all processes where analyzed, report is missing behavior information
    • Report size getting too big, too many NtQueryAttributesFile calls found.
    • Report size getting too big, too many NtQueryValueKey calls found.
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
    File Type:data
    Category:dropped
    Size (bytes):16384
    Entropy (8bit):3.5763337019441446
    Encrypted:false
    SSDEEP:
    MD5:9EAD86B83322143A43050AD9B3812482
    SHA1:F09646D9330A597948EF7106C14AAC657E348E75
    SHA-256:3239D30BFD74934ACCA59636203EB2AD2890D6E04CA1441F34EBE0A71712C71F
    SHA-512:F41010959D41A44E0B88ED580BE9ADA0CE27E2AF72B22ED7277C0FDCFDF3298528A5C4FF77EA9B776FB37E10C00384F1B8B4F6C10B95B7CFF72CE8C0DC679ED3
    Malicious:false
    Reputation:unknown
    Preview:............................................................................`.......h...G..1....................eJ......*.1....Zb..2...................................,...@.t.z.r.e.s...d.l.l.,.-.1.1.2.......................................................@.t.z.r.e.s...d.l.l.,.-.1.1.1...............................................................8...........G..1............v.2._.O.U.T.L.O.O.K.:.1.a.6.8.:.5.1.4.c.f.7.a.d.5.c.2.5.4.7.3.5.b.f.9.f.8.6.a.1.1.8.0.c.e.3.c.b...C.:.\.U.s.e.r.s.\.c.a.l.i.\.A.p.p.D.a.t.a.\.L.o.c.a.l.\.T.e.m.p.\.O.u.t.l.o.o.k. .L.o.g.g.i.n.g.\.O.U.T.L.O.O.K._.1.6._.0._.1.6.8.2.7._.2.0.1.3.0.-.2.0.2.5.0.3.2.6.T.1.6.4.6.4.8.0.1.4.7.-.6.7.6.0...e.t.l.......P.P.....h....).1............................................................................................................................................................................................................................................................................................................
    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
    File Type:HTML document, ASCII text, with CRLF line terminators
    Category:dropped
    Size (bytes):13768
    Entropy (8bit):5.279683728378242
    Encrypted:false
    SSDEEP:
    MD5:A57139114CD50937D82F7EE145737BF1
    SHA1:E881D16C3158A64F68E6C2D7C94BB9509B48F3AA
    SHA-256:17424A7DABFDAC4AB7FB1E1F092BD23CBCDC70EC2748FED2083891D786EFEA36
    SHA-512:33095E345977B2BF0B8118B350F3D16E8163B3428825D5764DB919740C1FBC12B11D96C6A8EC9E115A43949835370FD9E15D8A8AA7E91054764A3785B2C4255D
    Malicious:false
    Reputation:unknown
    Preview:<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML//EN">....<html>..<head>....<style>....a....{color:windowtext;}....body...{margin-top:0px;margin-right:0px;margin-left:0px;}.......CalendarSubjectLocation ..{} .....CalendarStartEnd ..{} .....InboxCount ... {font-weight:bold;} ..........InboxCountZero ... {font-weight:normal;}.....options.. {color:black;font-family:Tahoma;font-size:8pt;text-decoration:none;}.....date... {margin-bottom:4px;color:#3b3b3b;font-family:Arial;..... font-size:11pt;font-weight:bold; }.....itemNormal ..{font-size:8pt;.font-family:Tahoma; text-decoration:none;color:windowtext; } .....times ... {font-size:7pt; line-height:11pt; font-family:Tahoma; text-decoration:none; cursor:hand; color:buttonshadow;}.....PastTimes .. {color:buttonshadow; line-height:11pt; font-size:7pt; ...... text-decoration:none; cursor:hand; }...SplitDayTimes.. {color:#a7cdf0; font-size:7pt; line-height:11pt; ...... text-decoration:none; cur
    File type:vCalendar calendar file
    Entropy (8bit):5.38775667485883
    TrID:
    • iCalendar - vCalendar (13006/1) 100.00%
    File name:Lockheed Martin 1LMX Supplier Webinar.ics
    File size:46'229 bytes
    MD5:a920d8e569fca7869ac85038af40fad1
    SHA1:ad5477bc33c573ca2d21fff27504d399aae4d7b0
    SHA256:5244cd9cca8c36c424657ac62a9b51b19746540457658a1d5850757ff9b2bb4d
    SHA512:a57abd912f918d5a5f222c2e8ebf6961cb16d7e339aad290f8902e7e846f0a11dc712033afda6e0d28c6deb0752e5fa86666e6303555c193e57220151b2a2198
    SSDEEP:384:FH0jPHASwm8bxCrZXzUXTgDEwqSBR/XR1AykGRhin+Sji9Xnjc:FUjPv8ErtzUXTTwP/HAyDG+Sji9XI
    TLSH:91230684FC645D4733B2B2EA6F30E0F41A679238D8092297F0A5F65D38C3968C7E6567
    File Content Preview:BEGIN:VCALENDAR..PRODID:-//Microsoft Corporation//Outlook 16.0 MIMEDIR//EN..VERSION:2.0..METHOD:REQUEST..X-MS-OLK-FORCEINSPECTOROPEN:TRUE..BEGIN:VTIMEZONE..TZID:Central Standard Time..BEGIN:STANDARD..DTSTART:16011104T020000..RRULE:FREQ=YEARLY;BYDAY=1SU;BY
    Icon Hash:69a88280a28280a2