top title background image
flash

http://Received: from QB1PR01MB2481.CANPRD01.PROD.OUTLOOK.COM (2603:10b6:c00:1::46) by YQXPR0101MB1640.CANPRD01.PROD.OUTLOOK.COM with HTTPS via YQBPR0101CA0069.CANPRD01.PROD.OUTLOOK.COM; Wed, 15 Apr 2020 14:14:45 +0000 Authentication-Results: sait.ca; dkim=none (message not signed) header.d=none;sait.ca; dmarc=none action=none header.from=sait.ca; Received: from QB1PR01MB3601.CANPRD01.PROD.OUTLOOK.COM (52.132.88.27) by QB1PR01MB2481.CANPRD01.PROD.OUTLOOK.COM (52.132.86.21) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2900.17; Wed, 15 Apr 2020 14:14:45 +0000 Received: from QB1PR01MB3601.CANPRD01.PROD.OUTLOOK.COM ([fe80::f8fd:e356:d821:982]) by QB1PR01MB3601.CANPRD01.PROD.OUTLOOK.COM ([fe80::f8fd:e356:d821:982%7]) with mapi id 15.20.2900.028; Wed, 15 Apr 2020 14:14:45 +0000 Content-Type: application/ms-tnef;%20name=%22winmail.dat%22%20Content-Transfer-Encoding:%20binary%20From:%20Annie%20Wang%20%3Cannie.wang@sait.ca%3E%20To:%20Paul%20Usama%20%3CPaul.Usama@sait.ca%3E%20CC:%20Khalid%20Hamid%20%3Ckhalid.hamid@sait.ca%3E%20Subject:%20FW:%20Request%20Thread-Topic:%20Request%20Thread-Index:%20AQHWEyzA4jgENnq9JEOiN/CHgRpn/qh6ObZg%20Date:%20Wed,%2015%20Apr%202020%2014:14:44%20+0000%20Message-ID:%20%20%3CQB1PR01MB36014112F306F488D7D5C13D85DB0@QB1PR01MB3601.CANPRD01.PROD.OUTLOOK.COM%3E%20References:%20%20%3CCAK09crAjxKAOqfXUbr8do0QpyYyx=gJQf2O=k8hcOe6rxyjxHg@mail.gmail.com%3E%20In-Reply-To:%20%20%3CCAK09crAjxKAOqfXUbr8do0QpyYyx=gJQf2O=k8hcOe6rxyjxHg@mail.gmail.com%3E%20Accept-Language:%20en-CA,%20en-US%20Content-Language:%20en-US%20X-MS-Has-Attach:%20X-MS-Exchange-Organization-SCL:%20-1%20X-MS-TNEF-Correlator:%20%20%3CQB1PR01MB36014112F306F488D7D5C13D85DB0@QB1PR01MB3601.CANPRD01.PROD.OUTLOOK.COM%3E%20MIME-Version:%201.0%20X-MS-Exchange-Organization-MessageDirectionality:%20Originating%20X-MS-Exchange-Organization-AuthSource:%20QB1PR01MB3601.CANPRD01.PROD.OUTLOOK.COM%20X-MS-Exchange-Organization-A... (truncated)

Status: finished
Submission Time: 2020-04-15 16:41:14 +02:00
Suspicious

Comments

Tags

Details

  • Analysis ID:
    222758
  • API (Web) ID:
    342179
  • Analysis Started:
    2020-04-15 17:04:48 +02:00
  • Analysis Finished:
    2020-04-15 17:06:24 +02:00
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
suspicious
Score: 21
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

IPs

IP Country Detection
184.64.99.125
Canada
52.132.88.27
United States
52.132.86.21
United States

Dropped files

Name File Type Hashes Detection
C:\Users\user\Desktop\cmdline.out
ASCII text, with very long lines, with CRLF line terminators
#