Our call: Is Phising Email.msg safe?Suspicious
Outlook message shows suspicious runtime behaviour but zero antivirus detections.
- 1 high-confidence signature or behavior rule matched this file.Derived · Signature and behavior rules
- 0 of 74 antivirus engines flagged the file.Observed · Antivirus analysis
- The hash has been submitted 4 times from 1 source.Derived · Saved report facts
c24e3287ccf64fcf5a…6640258d76Before opening
Do not run it until the source and publisher can be verified independently.
If you already ran it
Close it, scan the device, and watch for unexpected processes or security alerts.
Coverage & freshness
Antivirus
Complete0 of 74 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Complete2 contacted hosts were cross-checked.
YARA
Complete3 signature or behavior rules matched.
External intel
Complete3 of 3 independent reference sources completed.
Attack story
Runtime observations grouped by stage. Arrows show sequence, not proven causality.
Input file
The submitted object
- FileObserved
Phising Email.msg
c24e3287ccf6…258d76
01Uploaded file
Processes
Runtime execution
- ProcessObserved
Observed process
C:\Windows\Explorer.EXE
02Isolated runtime analysis - ProcessObserved
Observed process
wmiadap.exe /F /T /R
03Isolated runtime analysis
Files
Created or changed
- Written fileObserved
WmiApRpl_new.h
C:\Windows\System32\wbem\Performance\WmiApRpl_new.h
04Isolated runtime analysis - Written fileObserved
WmiApRpl.h
C:\Windows\System32\wbem\Performance\WmiApRpl.h
05Isolated runtime analysis
Network
Hosts contacted
- Contacted hostObserved
52.110.6.8
Contact observed during runtime.
06Isolated runtime analysis - Contacted hostObserved
216.145.217.37
Contact observed during runtime.
07Isolated runtime analysis
7 recorded facts from one runtime window. Every fact remains independently traceable in the evidence ledger below.
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
1 high-confidence signature or behavior rule matched this file.
Verdict inputView chapterProvenanceDerivedSourceSignature and behavior rulesObserved at - 02
0 of 74 antivirus engines flagged the file.
ProvenanceObservedSourceAntivirus analysisObserved at - 03
The hash has been submitted 4 times from 1 source.
ProvenanceDerivedSourceSaved report factsObserved at
Intelligence
The complete saved assessment, kept intact and grounded in the scan evidence.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
The file triggered sandbox heuristics for process injection and credential access, yet no engine flagged it malicious. Medium prevalence and lack of external intelligence leave the risk level uncertain.
Zero detections across 74 engines rules out known malware signatures. However, the sandbox recorded LSASS reads, process injection, and direct-IP connections—techniques that legitimate Outlook usage rarely exhibits. The absence of malicious children, known-bad hosts, and external-intel hits prevents a definitive malicious call. Medium prevalence and the .msg container format further complicate classification, resulting in a borderline mixed-signal assessment.
What We Detected
74 engines scanned the Outlook .msg file; none returned a malicious or suspicious result. Sandbox execution surfaced six MITRE techniques typically associated with credential theft and defence evasion, including LSASS memory access and process injection.
Threat Behavior
The sample contacted three external IP addresses without domain names and wrote multiple WMI performance files. Ten child files were spawned, all classified unknown. No persistence mechanisms or registry modifications were observed.
What To Do Now
Treat the message as potentially risky. Open only in a segregated environment, verify the sender through an independent channel, and avoid enabling any macros or embedded content. Consider re-scanning with updated definitions or submitting the file to additional threat-intel services.
Where this verdict could be wrong2 caveats
- Sandbox observed LSASS access and direct-IP traffic, which could indicate credential dumping or C2 activity, but no malicious sandbox verdict or known-malicious hosts were recorded.
- If the .msg file contained an embedded malicious attachment or macro, the current scan would not have detected it; the 10 dropped children were all unknown.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- Zero engine detections
- No malicious dropped children
- No known-malicious contacted hosts
- LSASS access observed in sandbox
- Process injection indicators
- Direct-IP network traffic
- Recently submitted sample (19 days)
Do not open the message on production systems; inspect the sender and content in an isolated environment before deciding on further action.
Behavior
Plain-English impact first, then the observed runtime evidence.
What this file does
Observed actions and their security significance
High concern: Accessed operating-system credential data, which can expose saved passwords.
High concern: Injected code into another process, a technique that can conceal execution.
High concern: Searched files or settings where passwords and keys may be stored.
High concern: Attempted to impair or bypass security controls.
Moderate concern: Communicated over a common application protocol; malware can use this for command-and-control.
Note: Reads your Windows user-account details.
Note: Collects details about your system.
These are observed capabilities from an isolated analysis. A technique does not prove malicious intent on its own, and the file never ran on your device.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 52.110.6.8
- 216.145.217.37
- 108.156.224.87
- https://image-processing-service.au-1.mimecastcybergraph.com/v2/banners?e=v4piKlh60PAPoPESQGiUygIFY7M-IdzdwgLb0-gAvZpTPxTAo3a5ciaHeK1PYNY6go0vuBEnFH0mQeA5Q24EuX233PSM62537GFTogEjOpEqyHFfNmzJ3b_rkb4Qtsx0W30HlkJfDnu-SPXdfnZNmGqlfiE41TjNdsoaPcMgKu7hN_SXcGF04hq6QVf8g-GAJOO6GGm7gIb11TYU-YnWjbU-scWwrgYUy7BDWqDSMVHOlVUyYfAnxvYjMiTJHBG1_AFzA7mE9hol9ujIfv_C0TU8CV1fnTORdfwV2KLqDtp3Lu5CZbcLWGe65dyu3A50z6blnBk57qHCudFLnAnFJIQ-B9iJGnOJdniWCTqprb8oBYOtFLKitpsi_nKpRAlPxEZFyCVsggKIBsHHwEwUWZX6MxXvKZzEi0GCkqKMFC7JMFLcGxgGtCyti3E=
- https://banner.au-1.mimecastcybergraph.com/BXxLT4HtNrigBPppauYU8A_1780881818-144605a979850af985ffb56b5adaf1b1a75d73b85bb6db156f52deae.png
- C:\Windows\System32\wbem\Performance\WmiApRpl_new.h
- C:\Windows\System32\wbem\Performance\WmiApRpl.h
- C:\Windows\System32\wbem\Performance\WmiApRpl_new.ini
- C:\Windows\System32\wbem\Performance\WmiApRpl.ini
- C:\Windows\System32\perfc009.dat
- C:\Windows\System32\wbem\Performance\WmiApRpl.h
- C:\Windows\System32\wbem\Performance\WmiApRpl_new.h
- C:\Windows\System32\wbem\Performance\WmiApRpl.ini
- C:\Windows\System32\wbem\Performance\WmiApRpl_new.ini
- C:\Windows\INF\WmiApRpl\0009\WmiApRpl.ini
- Global\ADAP_WMI_ENTRY
- Global\RefreshRA_Mutex
- Global\RefreshRA_Mutex_Lib
- Global\RefreshRA_Mutex_Flag
- Installing
Files this sample writes at runtime
This file drops 10 children at runtime. None are currently flagged malicious in our cache.
- 458d7b862c71abbdfffd…5093edNever scannednever seen before
- a48c02fd36302685b5fb…ffa0a8Never scannednever seen before
- 055fb0442e2f3e787ae4…921c88Never scannednever seen before
- 97da3c982874ec87dcba…014346Never scannednever seen before
- 71e7f7b8deb46f98c972…d00f28Never scannednever seen before
- 89b2a9ad7d42f90b4a97…503e07Never scannednever seen before
- 6539622808a7d841b85d…c774ecNever scannednever seen before
- 260d54ebc92d8a772234…a9829cNever scannednever seen before
- 104ef282a2f46d748560…8cd56aNever scannednever seen before
- eb16c763abed997b0987…212c0eNever scannednever seen before
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Detection sources at a glance
The available sources did not agree on a named threat category.
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
Signatures and behavior heuristics
A community signature or high-severity behavioral heuristic matched. Signatures identify known patterns; heuristics are strong leads but are not proof on their own.
The saved runtime evidence maps this activity to MITRE T1055 (Process Injection). The mapping supports possible process injection, but it does not prove the exact injection method or the operator's intent.
EvidenceC:\Windows\Explorer.EXESandbox observed process activity targeting LSASS (Windows credential store). Legitimate software has no business reading LSASS memory — this is Mimikatz-shape behaviour.
EvidenceC:\Windows\system32\lsass.exeThe sample contacted 3 external IP address(es) and no application domain was recorded. Direct-IP traffic can also occur in legitimate installers and infrastructure, so treat this as supporting evidence only and correlate it with host reputation and runtime behavior before calling it command-and-control.
Evidence52.110.6.8 · 216.145.217.37 · 108.156.224.87
0 of 74 engines flagged this file
View all 74 engine results
PE structure
Not applicablePE structure analysis applies to Windows executable formats, not this file type.
How widely this file has been seen
Moderate prevalence — neither rare nor common. No strong prior applies.
Fingerprint and provenance
- File name
- Phising Email.msg
- Format
- Outlook
- Code signing
- Not applicable to this file type
- Size
- 1.2 MB
- Last analyzed
- Jul 24, 2026, 7:41 AM UTC
c24e3287ccf64fcf5a9c7ab6db474f792ececee1d24b3885701d846640258d76Safety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
We couldn't fully clear this file. Treat it with caution.
Don't run it unless you're certain it came from a source you trust.
Check where you got it — an email attachment or a random download link is a red flag.
If you're unsure, delete it. You can always re-download a clean copy from the official source.
If you're still unsure, scan it again in a day or two — detections often catch up on newer files.
Safety FAQ
- Phising Email.msg is suspicious — treat it as unsafe until you're sure. No antivirus engine flagged it; the cautious verdict comes from other saved evidence such as identity, prevalence, signing, or runtime signals. Don't open it unless you fully trust where it came from, and prefer downloading the software fresh from its official site.
- Phising Email.msg is a file, about 1.2 MB. We identify a file by its cryptographic hash rather than its name, because the same filename can be reused by completely different files — the hash below is the reliable fingerprint.
- None — 0 of 74 antivirus engines flagged Phising Email.msg. That's reassuring, though it is not proof that a file is safe, so we also weigh its behaviour, identity, and reputation.
- Act quickly. 1) Disconnect the device from the internet to stop the malware communicating or spreading. 2) Run a full scan with reputable anti-malware software (such as Malwarebytes) and quarantine everything it finds. 3) Change your important passwords from a DIFFERENT, clean device — many threats log keystrokes or steal saved credentials. 4) If you bank or shop on this device, watch closely for fraud and alert your bank. 5) For a confirmed infection, the most reliable fix is to back up your personal files and reinstall the operating system for a clean start.
- To remove Phising Email.msg: 1) restart into Safe Mode (Safe Mode with Networking if you need to download a tool) so the malware doesn't auto-start. 2) Run a full scan with reputable anti-malware software and let it quarantine or delete the detections. 3) Delete the original Phising Email.msg file and empty the Recycle Bin/Trash. 4) Check your browser extensions, startup items, and scheduled tasks for anything unfamiliar. 5) Reboot and scan again to confirm it's gone. If detections keep coming back, a clean operating-system reinstall is the most dependable cure.
- The SHA-256 hash of Phising Email.msg is c24e3287ccf64fcf5a9c7ab6db474f792ececee1d24b3885701d846640258d76, and its MD5 is 98dc898ccd6bf72a3592f98029e76a90. This hash is the file's unique fingerprint — two files with the same SHA-256 are identical. Use it to confirm you're looking at exactly this file (not just one with the same name) when comparing against antivirus databases or a download's published checksum.
- This report reflects the scan run on July 24, 2026. Because a file's hash never changes, the identity of Phising Email.msg is fixed — but antivirus coverage improves over time, so a file that looks clean today can pick up detections later (and vice-versa). If you need the latest picture, MalwareTips staff can re-run the analysis from scratch.