Edit tour

Windows Analysis Report
https://attachments.office.net/owa/tgibbs@Hensley.com/service.svc/s/GetAttachmentThumbnail?id=AAMkADgzNmFhNjQ5LTRlODktNDAwNC05YmNmLWY1YjBiOWY4YjVlZgBGAAAAAAAQyTkhQyDeRbmqEQP7YN7hBwCilU2fRgNGQ54Hblxt0RJhAAAYVNm4AAAYxQNzU2dnQrP86tSpYFIIAxlMIxl5AAABEgAQALQPWuNNA3JCl1e5%2Bp5B9H8%3D&thumbnailType=2&token

Overview

General Information

Sample URL:https://attachments.office.net/owa/tgibbs@Hensley.com/service.svc/s/GetAttachmentThumbnail?id=AAMkADgzNmFhNjQ5LTRlODktNDAwNC05YmNmLWY1YjBiOWY4YjVlZgBGAAAAAAAQyTkhQyDeRbmqEQP7YN7hBwCilU2fRgNGQ54Hblxt0R
Analysis ID:1315932

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

URL contains potential PII (phishing indication)

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64_ra
  • chrome.exe (PID: 6124 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://attachments.office.net/owa/tgibbs@Hensley.com/service.svc/s/GetAttachmentThumbnail?id=AAMkADgzNmFhNjQ5LTRlODktNDAwNC05YmNmLWY1YjBiOWY4YjVlZgBGAAAAAAAQyTkhQyDeRbmqEQP7YN7hBwCilU2fRgNGQ54Hblxt0RJhAAAYVNm4AAAYxQNzU2dnQrP86tSpYFIIAxlMIxl5AAABEgAQALQPWuNNA3JCl1e5%2Bp5B9H8%3D&thumbnailType=2&token=eyJhbGciOiJSUzI1NiIsImtpZCI6IjczRkI5QkJFRjYzNjc4RDRGN0U4NEI0NDBCQUJCMTJBMzM5RDlGOTgiLCJ0eXAiOiJKV1QiLCJ4NXQiOiJjX3VidnZZMmVOVDM2RXRFQzZ1eEtqT2RuNWcifQ.eyJvcmlnaW4iOiJodHRwczovL291dGxvb2sub2ZmaWNlLmNvbSIsInVjIjoiYWY0NjE0MDkyYmU1NDM3Njk5Yzc0YWQ0ZGM1YmY2NjQiLCJ2ZXIiOiJFeGNoYW5nZS5DYWxsYmFjay5WMSIsImFwcGN0eHNlbmRlciI6Ik93YURvd25sb2FkQDdlYzg5NDIxLTRiOWQtNDQ0My05ZTc0LTZlOGVkNGJkZWMxNiIsImlzc3JpbmciOiJXVyIsImFwcGN0eCI6IntcIm1zZXhjaHByb3RcIjpcIm93YVwiLFwicHVpZFwiOlwiMTE1MzkwNjY2MDgzMzY4OTI5MFwiLFwic2NvcGVcIjpcIk93YURvd25sb2FkXCIsXCJvaWRcIjpcIjY5Yzc5YjhkLTU2OTYtNDI0OC04M2EwLThhMzAxZjdhYzhmM1wiLFwicHJpbWFyeXNpZFwiOlwiUy0xLTUtMjEtMjE4MTAwNTI3OC0yMzEyMDgwODQyLTEzMzMxODQ4MDctMzMyMjE3MFwifSIsIm5iZiI6MTY5NTkxMjc1NCwiZXhwIjoxNjk1OTEzMzU0LCJpc3MiOiIwMDAwMDAwMi0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDBAN2VjODk0MjEtNGI5ZC00NDQzLTllNzQtNmU4ZWQ0YmRlYzE2IiwiYXVkIjoiMDAwMDAwMDItMDAwMC0wZmYxLWNlMDAtMDAwMDAwMDAwMDAwL2F0dGFjaG1lbnRzLm9mZmljZS5uZXRAN2VjODk0MjEtNGI5ZC00NDQzLTllNzQtNmU4ZWQ0YmRlYzE2IiwiaGFwcCI6Im93YSJ9.Qm6T4klUEX7x_SYyloLIeJ-BAYAH1F1ilqhQI_pcqbMx0D_-VUPoenRHqUmu5m4GFDlJztyvMiyFhcs4wJ0Br5owMIaHhMwtvY0h0j_U-9yCkOY987yl7FxMDyuBGTA7DrMJFydFfe68PziUxfhLWcn_JGoysTqXW6lYMim1PFjTtQPkIQmrGYFGAVdHjxMPDdOX8-dre7ZHpruSBVGM1ezVDv546cSsJ-tWTtdipIl9bViVtuD2jfwiN10eN0ts3QlbYtvFudn3uJHEmGMU_8FvRDN7ddIFTS4i94bZsBmZBIkyRD6pnnjZAUSzHBHNo1806smDGbhzU8CX9XhxVg&X-OWA-CANARY=MallLIVB50iC3YjN013a2sCkMqsywNsY_GoZ0PIfjtns9RLYHdWy20_KQBzI-Owi_hDoSZlrRP8.&owa=outlook.office.com&scriptVer=20230915006.20&animation=true MD5: 7BC7B4AEDC055BB02BCB52710132E9E1)
    • chrome.exe (PID: 5756 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1592 --field-trial-handle=1800,i,7124171202341282985,811105926499202913,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 7BC7B4AEDC055BB02BCB52710132E9E1)
  • cleanup
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://attachments.office.net/owa/tgibbs@Hensley.com/service.svc/s/GetAttachmentThumbnail?id=AAMkADgzNmFhNjQ5LTRlODktNDAwNC05YmNmLWY1YjBiOWY4YjVlZgBGAAAAAAAQyTkhQyDeRbmqEQP7YN7hBwCilU2fRgNGQ54Hblxt0RJhAAAYVNm4AAAYxQNzU2dnQrP86tSpYFIIAxlMIxl5AAABEgAQALQPWuNNA3JCl1e5%2Bp5B9H8%3D&thumbnailType=2&token=eyJhbGciOiJSUzI1NiIsImtpZCI6IjczRkI5QkJFRjYzNjc4RDRGN0U4NEI0NDBCQUJCMTJBMzM5RDlGOTgiLCJ0eXAiOiJKV1QiLCJ4NXQiOiJjX3VidnZZMmVOVDM2RXRFQzZ1eEtqT2RuNWcifQ.eyJvcmlnaW4iOiJodHRwczovL291dGxvb2sub2ZmaWNlLmNvbSIsInVjIjoiYWY0NjE0MDkyYmU1NDM3Njk5Yzc0YWQ0ZGM1YmY2NjQiLCJ2ZXIiOiJFeGNoYW5nZS5DYWxsYmFjay5WMSIsImFwcGN0eHNlbmRlciI6Ik93YURvd25sb2FkQDdlYzg5NDIxLTRiOWQtNDQ0My05ZTc0LTZlOGVkNGJkZWMxNiIsImlzc3JpbmciOiJXVyIsImFwcGN0eCI6IntcIm1zZXhjaHByb3RcIjpcIm93YVwiLFwicHVpZFwiOlwiMTE1MzkwNjY2MDgzMzY4OTI5MFwiLFwic2NvcGVcIjpcIk93YURvd25sb2FkXCIsXCJvaWRcIjpcIjY5Yzc5YjhkLTU2OTYtNDI0OC04M2EwLThhMzAxZjdhYzhmM1wiLFwicHJpbWFyeXNpZFwiOlwiUy0xLTUtMjEtMjE4MTAwNTI3OC0yMzEyMDgwODQyLTEzMzMxODQ4MDctMzMyMjE3MFwifSIsIm5iZiI6MTY5NTkxMjc1NCwiZXhwIjoxNjk1OTEzMzU0LCJpc3MiOiIwMDAwMDAwMi0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDBAN2VjODk0MjEtNGI5ZC00NDQzLTllNzQtNmU4ZWQ0YmRlYzE2IiwiYXVkIjoiMDAwMDAwMDItMDAwMC0wZmYxLWNlMDAtMDAwMDAwMDAwMDAwL2F0dGFjaG1lbnRzLm9mZmljZS5uZXRAN2VjODk0MjEtNGI5ZC00NDQzLTllNzQtNmU4ZWQ0YmRlYzE2IiwiaGFwcCI6Im93YSJ9.Qm6T4klUEX7x_SYyloLIeJ-BAYAH1F1ilqhQI_pcqbMx0D_-VUPoenRHqUmu5m4GFDlJztyvMiyFhcs4wJ0Br5owMIaHhMwtvY0h0j_U-9yCkOY987yl7FxMDyuBGTA7DrMJFydFfe68PziUxfhLWcn_JGoysTqXW6lYMim1PFjTtQPkIQmrGYFGAVdHjxMPDdOX8-dre7ZHpruSBVGM1ezVDv546cSsJ-tWTtdipIl9bViVtuD2jfwiN10eN0ts3QlbYtvFudn3uJHEmGMU_8FvRDN7ddIFTS4i94bZsBmZBIkyRD6pnnjZAUSzHBHNo1806smDGbhzU8CX9XhxVg&X-OWA-CANARY=MallLIVB50iC3YjN013a2sCkMqsywNsY_GoZ0PIfjtns9RLYHdWy20_KQBzI-Owi_hDoSZlrRP8.&owa=outlook.office.com&scriptVer=20230915006.20&animation=trueSample URL: PII: tgibbs@Hensley.com
Source: https://attachments.office.net/owa/tgibbs@Hensley.com/service.svc/s/GetAttachmentThumbnail?id=AAMkADgzNmFhNjQ5LTRlODktNDAwNC05YmNmLWY1YjBiOWY4YjVlZgBGAAAAAAAQyTkhQyDeRbmqEQP7YN7hBwCilU2fRgNGQ54Hblxt0RJhAAAYVNm4AAAYxQNzU2dnQrP86tSpYFIIAxlMIxl5AAABEgAQALQPWuNNA3JCl1e5%2Bp5B9H8%3D&thumbnailType=2&token=eyJhbGciOiJSUzI1NiIsImtpZCI6IjczRkI5QkJFRjYzNjc4RDRGN0U4NEI0NDBCQUJCMTJBMzM5RDlGOTgiLCJ0eXAiOiJKV1QiLCJ4NXQiOiJjX3VidnZZMmVOVDM2RXRFQzZ1eEtqT2RuNWcifQ.eyJvcmlnaW4iOiJodHRwczovL291dGxvb2sub2ZmaWNlLmNvbSIsInVjIjoiYWY0NjE0MDkyYmU1NDM3Njk5Yzc0YWQ0ZGM1YmY2NjQiLCJ2ZXIiOiJFeGNoYW5nZS5DYWxsYmFjay5WMSIsImFwcGN0eHNlbmRlciI6Ik93YURvd25sb2FkQDdlYzg5NDIxLTRiOWQtNDQ0My05ZTc0LTZlOGVkNGJkZWMxNiIsImlzc3JpbmciOiJXVyIsImFwcGN0eCI6IntcIm1zZXhjaHByb3RcIjpcIm93YVwiLFwicHVpZFwiOlwiMTE1MzkwNjY2MDgzMzY4OTI5MFwiLFwic2NvcGVcIjpcIk93YURvd25sb2FkXCIsXCJvaWRcIjpcIjY5Yzc5YjhkLTU2OTYtNDI0OC04M2EwLThhMzAxZjdhYzhmM1wiLFwicHJpbWFyeXNpZFwiOlwiUy0xLTUtMjEtMjE4MTAwNTI3OC0yMzEyMDgwODQyLTEzMzMxODQ4MDctMzMyMjE3MFwifSIsIm5iZiI6MTY5NTkxMjc1NCwiZXhwIjoxNjk1OTEzMzU0LCJpc3MiOiIwMDAwMDAwMi0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDBAN2VjODk0MjEtNGI5ZC00NDQzLTllNzQtNmU4ZWQ0YmRlYzE2IiwiYXVkIjoiMDAwMDAwMDItMDAwMC0wZmYxLWNlMDAtMDAwMDAwMDAwMDAwL2F0dGFjaG1lbnRzLm9mZmljZS5uZXRAN2VjODk0MjEtNGI5ZC00NDQzLTllNzQtNmU4ZWQ0YmRlYzE2IiwiaGFwcCI6Im93YSJ9.Qm6T4klUEX7x_SYyloLIeJ-BAYAH1F1ilqhQI_pcqbMx0D_-VUPoenRHqUmu5m4GFDlJztyvMiyFhcs4wJ0Br5owMIaHhMwtvY0h0j_U-9yCkOY987yl7FxMDyuBGTA7DrMJFydFfe68PziUxfhLWcn_JGoysTqXW6lYMim1PFjTtQPkIQmrGYFGAVdHjxMPDdOX8-dre7ZHpruSBVGM1ezVDv546cSsJ-tWTtdipIl9bViVtuD2jfwiN10eN0ts3QlbYtvFudn3uJHEmGMU_8FvRDN7ddIFTS4i94bZsBmZBIkyRD6pnnjZAUSzHBHNo1806smDGbhzU8CX9XhxVg&X-OWA-CANARY=MallLIVB50iC3YjN013a2sCkMqsywNsY_GoZ0PIfjtns9RLYHdWy20_KQBzI-Owi_hDoSZlrRP8.&owa=outlook.office.com&scriptVer=20230915006.20&animation=trueSample URL: PII: tgibbs@Hensley.com
Source: https://attachments.office.net/owa/tgibbs@Hensley.com/service.svc/s/GetAttachmentThumbnail?id=AAMkADgzNmFhNjQ5LTRlODktNDAwNC05YmNmLWY1YjBiOWY4YjVlZgBGAAAAAAAQyTkhQyDeRbmqEQP7YN7hBwCilU2fRgNGQ54Hblxt0RJhAAAYVNm4AAAYxQNzU2dnQrP86tSpYFIIAxlMIxl5AAABEgAQALQPWuNNA3JCl1e5%2Bp5B9H8%3D&thumbnailType=2&token=eyJhbGciOiJSUzI1NiIsImtpZCI6IjczRkI5QkJFRjYzNjc4RDRGN0U4NEI0NDBCQUJCMTJBMzM5RDlGOTgiLCJ0eXAiOiJKV1QiLCJ4NXQiOiJjX3VidnZZMmVOVDM2RXRFQzZ1eEtqT2RuNWcifQ.eyJvcmlnaW4iOiJodHRwczovL291dGxvb2sub2ZmaWNlLmNvbSIsInVjIjoiYWY0NjE0MDkyYmU1NDM3Njk5Yzc0YWQ0ZGM1YmY2NjQiLCJ2ZXIiOiJFeGNoYW5nZS5DYWxsYmFjay5WMSIsImFwcGN0eHNlbmRlciI6Ik93YURvd25sb2FkQDdlYzg5NDIxLTRiOWQtNDQ0My05ZTc0LTZlOGVkNGJkZWMxNiIsImlzc3JpbmciOiJXVyIsImFwcGN0eCI6IntcIm1zZXhjaHByb3RcIjpcIm93YVwiLFwicHVpZFwiOlwiMTE1MzkwNjY2MDgzMzY4OTI5MFwiLFwic2NvcGVcIjpcIk93YURvd25sb2FkXCIsXCJvaWRcIjpcIjY5Yzc5YjhkLTU2OTYtNDI0OC04M2EwLThhMzAxZjdhYzhmM1wiLFwicHJpbWFyeXNpZFwiOlwiUy0xLTUtMjEtMjE4MTAwNTI3OC0yMzEyMDgwODQyLTEzMzMxODQ4MDctMzMyMjE3MFwifSIsIm5iZiI6MTY5NTkxMjc1NCwiZXhwIjoxNjk1OTEzMzU0LCJpc3MiOiIwMDAwMDAwMi0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDBAN2VjODk0MjEtNGI5ZC00NDQzLTllNzQtNmU4ZWQ0YmRlYzE2IiwiYXVkIjoiMDAwMDAwMDItMDAwMC0wZmYxLWNlMDAtMDAwMDAwMDAwMDAwL2F0dGFjaG1lbnRzLm9mZmljZS5uZXRAN2VjODk0MjEtNGI5ZC00NDQzLTllNzQtNmU4ZWQ0YmRlYzE2IiwiaGFwcCI6Im93YSJ9.Qm6T4klUEX7x_SYyloLIeJ-BAYAH1F1ilqhQI_pcqbMx0D_-VUPoenRHqUmu5m4GFDlJztyvMiyFhcs4wJ0Br5owMIaHhMwtvY0h0j_U-9yCkOY987yl7FxMDyuBGTA7DrMJFydFfe68PziUxfhLWcn_JGoysTqXW6lYMim1PFjTtQPkIQmrGYFGAVdHjxMPDdOX8-dre7ZHpruSBVGM1ezVDv546cSsJ-tWTtdipIl9bViVtuD2jfwiN10eN0ts3QlbYtvFudn3uJHEmGMU_8FvRDN7ddIFTS4i94bZsBmZBIkyRD6pnnjZAUSzHBHNo1806smDGbhzU8CX9XhxVg&X-OWA-CANARY=MallLIVB50iC3YjN013a2sCkMqsywNsY_GoZ0PIfjtns9RLYHdWy20_KQBzI-Owi_hDoSZlrRP8.&owa=outlook.office.com&scriptVer=20230915006.20&animation=trueSample URL: PII: tgibbs@Hensley.com
Source: https://attachments.office.net/owa/tgibbs@Hensley.com/service.svc/s/GetAttachmentThumbnail?id=AAMkADgzNmFhNjQ5LTRlODktNDAwNC05YmNmLWY1YjBiOWY4YjVlZgBGAAAAAAAQyTkhQyDeRbmqEQP7YN7hBwCilU2fRgNGQ54Hblxt0RJhAAAYVNm4AAAYxQNzU2dnQrP86tSpYFIIAxlMIxl5AAABEgAQALQPWuNNA3JCl1e5%2Bp5B9H8%3D&thumbnailType=2&token=eyJhbGciOiJSUzI1NiIsImtpZCI6IjczRkI5QkJFRjYzNjc4RDRGN0U4NEI0NDBCQUJCMTJBMzM5RDlGOTgiLCJ0eXAiOiJKV1QiLCJ4NXQiOiJjX3VidnZZMmVOVDM2RXRFQzZ1eEtqT2RuNWcifQ.eyJvcmlnaW4iOiJodHRwczovL291dGxvb2sub2ZmaWNlLmNvbSIsInVjIjoiYWY0NjE0MDkyYmU1NDM3Njk5Yzc0YWQ0ZGM1YmY2NjQiLCJ2ZXIiOiJFeGNoYW5nZS5DYWxsYmFjay5WMSIsImFwcGN0eHNlbmRlciI6Ik93YURvd25sb2FkQDdlYzg5NDIxLTRiOWQtNDQ0My05ZTc0LTZlOGVkNGJkZWMxNiIsImlzc3JpbmciOiJXVyIsImFwcGN0eCI6IntcIm1zZXhjaHByb3RcIjpcIm93YVwiLFwicHVpZFwiOlwiMTE1MzkwNjY2MDgzMzY4OTI5MFwiLFwic2NvcGVcIjpcIk93YURvd25sb2FkXCIsXCJvaWRcIjpcIjY5Yzc5YjhkLTU2OTYtNDI0OC04M2EwLThhMzAxZjdhYzhmM1wiLFwicHJpbWFyeXNpZFwiOlwiUy0xLTUtMjEtMjE4MTAwNTI3OC0yMzEyMDgwODQyLTEzMzMxODQ4MDctMzMyMjE3MFwifSIsIm5iZiI6MTY5NTkxMjc1NCwiZXhwIjoxNjk1OTEzMzU0LCJpc3MiOiIwMDAwMDAwMi0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDBAN2VjODk0MjEtNGI5ZC00NDQzLTllNzQtNmU4ZWQ0YmRlYzE2IiwiYXVkIjoiMDAwMDAwMDItMDAwMC0wZmYxLWNlMDAtMDAwMDAwMDAwMDAwL2F0dGFjaG1lbnRzLm9mZmljZS5uZXRAN2VjODk0MjEtNGI5ZC00NDQzLTllNzQtNmU4ZWQ0YmRlYzE2IiwiaGFwcCI6Im93YSJ9.Qm6T4klUEX7x_SYyloLIeJ-BAYAH1F1ilqhQI_pcqbMx0D_-VUPoenRHqUmu5m4GFDlJztyvMiyFhcs4wJ0Br5owMIaHhMwtvY0h0j_U-9yCkOY987yl7FxMDyuBGTA7DrMJFydFfe68PziUxfhLWcn_JGoysTqXW6lYMim1PFjTtQPkIQmrGYFGAVdHjxMPDdOX8-dre7ZHpruSBVGM1ezVDv546cSsJ-tWTtdipIl9bViVtuD2jfwiN10eN0ts3QlbYtvFudn3uJHEmGMU_8FvRDN7ddIFTS4i94bZsBmZBIkyRD6pnnjZAUSzHBHNo1806smDGbhzU8CX9XhxVg&X-OWA-CANARY=MallLIVB50iC3YjN013a2sCkMqsywNsY_GoZ0PIfjtns9RLYHdWy20_KQBzI-Owi_hDoSZlrRP8.&owa=outlook.office.com&scriptVer=20230915006.20&animation=trueSample URL: PII: tgibbs@Hensley.com
Source: https://attachments.office.net/owa/tgibbs@Hensley.com/service.svc/s/GetAttachmentThumbnail?id=AAMkADgzNmFhNjQ5LTRlODktNDAwNC05YmNmLWY1YjBiOWY4YjVlZgBGAAAAAAAQyTkhQyDeRbmqEQP7YN7hBwCilU2fRgNGQ54Hblxt0RJhAAAYVNm4AAAYxQNzU2dnQrP86tSpYFIIAxlMIxl5AAABEgAQALQPWuNNA3JCl1e5%2Bp5B9H8%3D&thumbnailType=2&token=eyJhbGciOiJSUzI1NiIsImtpZCI6IjczRkI5QkJFRjYzNjc4RDRGN0U4NEI0NDBCQUJCMTJBMzM5RDlGOTgiLCJ0eXAiOiJKV1QiLCJ4NXQiOiJjX3VidnZZMmVOVDM2RXRFQzZ1eEtqT2RuNWcifQ.eyJvcmlnaW4iOiJodHRwczovL291dGxvb2sub2ZmaWNlLmNvbSIsInVjIjoiYWY0NjE0MDkyYmU1NDM3Njk5Yzc0YWQ0ZGM1YmY2NjQiLCJ2ZXIiOiJFeGNoYW5nZS5DYWxsYmFjay5WMSIsImFwcGN0eHNlbmRlciI6Ik93YURvd25sb2FkQDdlYzg5NDIxLTRiOWQtNDQ0My05ZTc0LTZlOGVkNGJkZWMxNiIsImlzc3JpbmciOiJXVyIsImFwcGN0eCI6IntcIm1zZXhjaHByb3RcIjpcIm93YVwiLFwicHVpZFwiOlwiMTE1MzkwNjY2MDgzMzY4OTI5MFwiLFwic2NvcGVcIjpcIk93YURvd25sb2FkXCIsXCJvaWRcIjpcIjY5Yzc5YjhkLTU2OTYtNDI0OC04M2EwLThhMzAxZjdhYzhmM1wiLFwicHJpbWFyeXNpZFwiOlwiUy0xLTUtMjEtMjE4MTAwNTI3OC0yMzEyMDgwODQyLTEzMzMxODQ4MDctMzMyMjE3MFwifSIsIm5iZiI6MTY5NTkxMjc1NCwiZXhwIjoxNjk1OTEzMzU0LCJpc3MiOiIwMDAwMDAwMi0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDBAN2VjODk0MjEtNGI5ZC00NDQzLTllNzQtNmU4ZWQ0YmRlYzE2IiwiYXVkIjoiMDAwMDAwMDItMDAwMC0wZmYxLWNlMDAtMDAwMDAwMDAwMDAwL2F0dGFjaG1lbnRzLm9mZmljZS5uZXRAN2VjODk0MjEtNGI5ZC00NDQzLTllNzQtNmU4ZWQ0YmRlYzE2IiwiaGFwcCI6Im93YSJ9.Qm6T4klUEX7x_SYyloLIeJ-BAYAH1F1ilqhQI_pcqbMx0D_-VUPoenRHqUmu5m4GFDlJztyvMiyFhcs4wJ0Br5owMIaHhMwtvY0h0j_U-9yCkOY987yl7FxMDyuBGTA7DrMJFydFfe68PziUxfhLWcn_JGoysTqXW6lYMim1PFjTtQPkIQmrGYFGAVdHjxMPDdOX8-dre7ZHpruSBVGM1ezVDv546cSsJ-tWTtdipIl9bViVtuD2jfwiN10eN0ts3QlbYtvFudn3uJHEmGMU_8FvRDN7ddIFTS4i94bZsBmZBIkyRD6pnnjZAUSzHBHNo1806smDGbhzU8CX9XhxVg&X-OWA-CANARY=MallLIVB50iC3YjN013a2sCkMqsywNsY_GoZ0PIfjtns9RLYHdWy20_KQBzI-Owi_hDoSZlrRP8.&owa=outlook.office.com&scriptVer=20230915006.20&animation=trueSample URL: PII: tgibbs@Hensley.com
Source: https://attachments.office.net/owa/tgibbs@Hensley.com/service.svc/s/GetAttachmentThumbnail?id=AAMkADgzNmFhNjQ5LTRlODktNDAwNC05YmNmLWY1YjBiOWY4YjVlZgBGAAAAAAAQyTkhQyDeRbmqEQP7YN7hBwCilU2fRgNGQ54Hblxt0RJhAAAYVNm4AAAYxQNzU2dnQrP86tSpYFIIAxlMIxl5AAABEgAQALQPWuNNA3JCl1e5%2Bp5B9H8%3D&thumbnailType=2&token=eyJhbGciOiJSUzI1NiIsImtpZCI6IjczRkI5QkJFRjYzNjc4RDRGN0U4NEI0NDBCQUJCMTJBMzM5RDlGOTgiLCJ0eXAiOiJKV1QiLCJ4NXQiOiJjX3VidnZZMmVOVDM2RXRFQzZ1eEtqT2RuNWcifQ.eyJvcmlnaW4iOiJodHRwczovL291dGxvb2sub2ZmaWNlLmNvbSIsInVjIjoiYWY0NjE0MDkyYmU1NDM3Njk5Yzc0YWQ0ZGM1YmY2NjQiLCJ2ZXIiOiJFeGNoYW5nZS5DYWxsYmFjay5WMSIsImFwcGN0eHNlbmRlciI6Ik93YURvd25sb2FkQDdlYzg5NDIxLTRiOWQtNDQ0My05ZTc0LTZlOGVkNGJkZWMxNiIsImlzc3JpbmciOiJXVyIsImFwcGN0eCI6IntcIm1zZXhjaHByb3RcIjpcIm93YVwiLFwicHVpZFwiOlwiMTE1MzkwNjY2MDgzMzY4OTI5MFwiLFwic2NvcGVcIjpcIk93YURvd25sb2FkXCIsXCJvaWRcIjpcIjY5Yzc5YjhkLTU2OTYtNDI0OC04M2EwLThhMzAxZjdhYzhmM1wiLFwicHJpbWFyeXNpZFwiOlwiUy0xLTUtMjEtMjE4MTAwNTI3OC0yMzEyMDgwODQyLTEzMzMxODQ4MDctMzMyMjE3MFwifSIsIm5iZiI6MTY5NTkxMjc1NCwiZXhwIjoxNjk1OTEzMzU0LCJpc3MiOiIwMDAwMDAwMi0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDBAN2VjODk0MjEtNGI5ZC00NDQzLTllNzQtNmU4ZWQ0YmRlYzE2IiwiYXVkIjoiMDAwMDAwMDItMDAwMC0wZmYxLWNlMDAtMDAwMDAwMDAwMDAwL2F0dGFjaG1lbnRzLm9mZmljZS5uZXRAN2VjODk0MjEtNGI5ZC00NDQzLTllNzQtNmU4ZWQ0YmRlYzE2IiwiaGFwcCI6Im93YSJ9.Qm6T4klUEX7x_SYyloLIeJ-BAYAH1F1ilqhQI_pcqbMx0D_-VUPoenRHqUmu5m4GFDlJztyvMiyFhcs4wJ0Br5owMIaHhMwtvY0h0j_U-9yCkOY987yl7FxMDyuBGTA7DrMJFydFfe68PziUxfhLWcn_JGoysTqXW6lYMim1PFjTtQPkIQmrGYFGAVdHjxMPDdOX8-dre7ZHpruSBVGM1ezVDv546cSsJ-tWTtdipIl9bViVtuD2jfwiN10eN0ts3QlbYtvFudn3uJHEmGMU_8FvRDN7ddIFTS4i94bZsBmZBIkyRD6pnnjZAUSzHBHNo1806smDGbhzU8CX9XhxVg&X-OWA-CANARY=MallLIVB50iC3YjN013a2sCkMqsywNsY_GoZ0PIfjtns9RLYHdWy20_KQBzI-Owi_hDoSZlrRP8.&owa=outlook.office.com&scriptVer=20230915006.20&animation=trueSample URL: PII: tgibbs@Hensley.com
Source: https://attachments.office.net/owa/tgibbs@Hensley.com/service.svc/s/GetAttachmentThumbnail?id=AAMkADgzNmFhNjQ5LTRlODktNDAwNC05YmNmLWY1YjBiOWY4YjVlZgBGAAAAAAAQyTkhQyDeRbmqEQP7YN7hBwCilU2fRgNGQ54Hblxt0RJhAAAYVNm4AAAYxQNzU2dnQrP86tSpYFIIAxlMIxl5AAABEgAQALQPWuNNA3JCl1e5%2Bp5B9H8%3D&thumbnailType=2&token=eyJhbGciOiJSUzI1NiIsImtpZCI6IjczRkI5QkJFRjYzNjc4RDRGN0U4NEI0NDBCQUJCMTJBMzM5RDlGOTgiLCJ0eXAiOiJKV1QiLCJ4NXQiOiJjX3VidnZZMmVOVDM2RXRFQzZ1eEtqT2RuNWcifQ.eyJvcmlnaW4iOiJodHRwczovL291dGxvb2sub2ZmaWNlLmNvbSIsInVjIjoiYWY0NjE0MDkyYmU1NDM3Njk5Yzc0YWQ0ZGM1YmY2NjQiLCJ2ZXIiOiJFeGNoYW5nZS5DYWxsYmFjay5WMSIsImFwcGN0eHNlbmRlciI6Ik93YURvd25sb2FkQDdlYzg5NDIxLTRiOWQtNDQ0My05ZTc0LTZlOGVkNGJkZWMxNiIsImlzc3JpbmciOiJXVyIsImFwcGN0eCI6IntcIm1zZXhjaHByb3RcIjpcIm93YVwiLFwicHVpZFwiOlwiMTE1MzkwNjY2MDgzMzY4OTI5MFwiLFwic2NvcGVcIjpcIk93YURvd25sb2FkXCIsXCJvaWRcIjpcIjY5Yzc5YjhkLTU2OTYtNDI0OC04M2EwLThhMzAxZjdhYzhmM1wiLFwicHJpbWFyeXNpZFwiOlwiUy0xLTUtMjEtMjE4MTAwNTI3OC0yMzEyMDgwODQyLTEzMzMxODQ4MDctMzMyMjE3MFwifSIsIm5iZiI6MTY5NTkxMjc1NCwiZXhwIjoxNjk1OTEzMzU0LCJpc3MiOiIwMDAwMDAwMi0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDBAN2VjODk0MjEtNGI5ZC00NDQzLTllNzQtNmU4ZWQ0YmRlYzE2IiwiYXVkIjoiMDAwMDAwMDItMDAwMC0wZmYxLWNlMDAtMDAwMDAwMDAwMDAwL2F0dGFjaG1lbnRzLm9mZmljZS5uZXRAN2VjODk0MjEtNGI5ZC00NDQzLTllNzQtNmU4ZWQ0YmRlYzE2IiwiaGFwcCI6Im93YSJ9.Qm6T4klUEX7x_SYyloLIeJ-BAYAH1F1ilqhQI_pcqbMx0D_-VUPoenRHqUmu5m4GFDlJztyvMiyFhcs4wJ0Br5owMIaHhMwtvY0h0j_U-9yCkOY987yl7FxMDyuBGTA7DrMJFydFfe68PziUxfhLWcn_JGoysTqXW6lYMim1PFjTtQPkIQmrGYFGAVdHjxMPDdOX8-dre7ZHpruSBVGM1ezVDv546cSsJ-tWTtdipIl9bViVtuD2jfwiN10eN0ts3QlbYtvFudn3uJHEmGMU_8FvRDN7ddIFTS4i94bZsBmZBIkyRD6pnnjZAUSzHBHNo1806smDGbhzU8CX9XhxVg&X-OWA-CANARY=MallLIVB50iC3YjN013a2sCkMqsywNsY_GoZ0PIfjtns9RLYHdWy20_KQBzI-Owi_hDoSZlrRP8.&owa=outlook.office.com&scriptVer=20230915006.20&animation=trueSample URL: PII: tgibbs@Hensley.com
Source: https://attachments.office.net/owa/tgibbs@Hensley.com/service.svc/s/GetAttachmentThumbnail?id=AAMkADgzNmFhNjQ5LTRlODktNDAwNC05YmNmLWY1YjBiOWY4YjVlZgBGAAAAAAAQyTkhQyDeRbmqEQP7YN7hBwCilU2fRgNGQ54Hblxt0RJhAAAYVNm4AAAYxQNzU2dnQrP86tSpYFIIAxlMIxl5AAABEgAQALQPWuNNA3JCl1e5%2Bp5B9H8%3D&thumbnailType=2&token=eyJhbGciOiJSUzI1NiIsImtpZCI6IjczRkI5QkJFRjYzNjc4RDRGN0U4NEI0NDBCQUJCMTJBMzM5RDlGOTgiLCJ0eXAiOiJKV1QiLCJ4NXQiOiJjX3VidnZZMmVOVDM2RXRFQzZ1eEtqT2RuNWcifQ.eyJvcmlnaW4iOiJodHRwczovL291dGxvb2sub2ZmaWNlLmNvbSIsInVjIjoiYWY0NjE0MDkyYmU1NDM3Njk5Yzc0YWQ0ZGM1YmY2NjQiLCJ2ZXIiOiJFeGNoYW5nZS5DYWxsYmFjay5WMSIsImFwcGN0eHNlbmRlciI6Ik93YURvd25sb2FkQDdlYzg5NDIxLTRiOWQtNDQ0My05ZTc0LTZlOGVkNGJkZWMxNiIsImlzc3JpbmciOiJXVyIsImFwcGN0eCI6IntcIm1zZXhjaHByb3RcIjpcIm93YVwiLFwicHVpZFwiOlwiMTE1MzkwNjY2MDgzMzY4OTI5MFwiLFwic2NvcGVcIjpcIk93YURvd25sb2FkXCIsXCJvaWRcIjpcIjY5Yzc5YjhkLTU2OTYtNDI0OC04M2EwLThhMzAxZjdhYzhmM1wiLFwicHJpbWFyeXNpZFwiOlwiUy0xLTUtMjEtMjE4MTAwNTI3OC0yMzEyMDgwODQyLTEzMzMxODQ4MDctMzMyMjE3MFwifSIsIm5iZiI6MTY5NTkxMjc1NCwiZXhwIjoxNjk1OTEzMzU0LCJpc3MiOiIwMDAwMDAwMi0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDBAN2VjODk0MjEtNGI5ZC00NDQzLTllNzQtNmU4ZWQ0YmRlYzE2IiwiYXVkIjoiMDAwMDAwMDItMDAwMC0wZmYxLWNlMDAtMDAwMDAwMDAwMDAwL2F0dGFjaG1lbnRzLm9mZmljZS5uZXRAN2VjODk0MjEtNGI5ZC00NDQzLTllNzQtNmU4ZWQ0YmRlYzE2IiwiaGFwcCI6Im93YSJ9.Qm6T4klUEX7x_SYyloLIeJ-BAYAH1F1ilqhQI_pcqbMx0D_-VUPoenRHqUmu5m4GFDlJztyvMiyFhcs4wJ0Br5owMIaHhMwtvY0h0j_U-9yCkOY987yl7FxMDyuBGTA7DrMJFydFfe68PziUxfhLWcn_JGoysTqXW6lYMim1PFjTtQPkIQmrGYFGAVdHjxMPDdOX8-dre7ZHpruSBVGM1ezVDv546cSsJ-tWTtdipIl9bViVtuD2jfwiN10eN0ts3QlbYtvFudn3uJHEmGMU_8FvRDN7ddIFTS4i94bZsBmZBIkyRD6pnnjZAUSzHBHNo1806smDGbhzU8CX9XhxVg&X-OWA-CANARY=MallLIVB50iC3YjN013a2sCkMqsywNsY_GoZ0PIfjtns9RLYHdWy20_KQBzI-Owi_hDoSZlrRP8.&owa=outlook.office.com&scriptVer=20230915006.20&animation=trueSample URL: PII: tgibbs@Hensley.com
Source: https://attachments.office.net/owa/tgibbs@Hensley.com/service.svc/s/GetAttachmentThumbnail?id=AAMkADgzNmFhNjQ5LTRlODktNDAwNC05YmNmLWY1YjBiOWY4YjVlZgBGAAAAAAAQyTkhQyDeRbmqEQP7YN7hBwCilU2fRgNGQ54Hblxt0RJhAAAYVNm4AAAYxQNzU2dnQrP86tSpYFIIAxlMIxl5AAABEgAQALQPWuNNA3JCl1e5%2Bp5B9H8%3D&thumbnailType=2&token=eyJhbGciOiJSUzI1NiIsImtpZCI6IjczRkI5QkJFRjYzNjc4RDRGN0U4NEI0NDBCQUJCMTJBMzM5RDlGOTgiLCJ0eXAiOiJKV1QiLCJ4NXQiOiJjX3VidnZZMmVOVDM2RXRFQzZ1eEtqT2RuNWcifQ.eyJvcmlnaW4iOiJodHRwczovL291dGxvb2sub2ZmaWNlLmNvbSIsInVjIjoiYWY0NjE0MDkyYmU1NDM3Njk5Yzc0YWQ0ZGM1YmY2NjQiLCJ2ZXIiOiJFeGNoYW5nZS5DYWxsYmFjay5WMSIsImFwcGN0eHNlbmRlciI6Ik93YURvd25sb2FkQDdlYzg5NDIxLTRiOWQtNDQ0My05ZTc0LTZlOGVkNGJkZWMxNiIsImlzc3JpbmciOiJXVyIsImFwcGN0eCI6IntcIm1zZXhjaHByb3RcIjpcIm93YVwiLFwicHVpZFwiOlwiMTE1MzkwNjY2MDgzMzY4OTI5MFwiLFwic2NvcGVcIjpcIk93YURvd25sb2FkXCIsXCJvaWRcIjpcIjY5Yzc5YjhkLTU2OTYtNDI0OC04M2EwLThhMzAxZjdhYzhmM1wiLFwicHJpbWFyeXNpZFwiOlwiUy0xLTUtMjEtMjE4MTAwNTI3OC0yMzEyMDgwODQyLTEzMzMxODQ4MDctMzMyMjE3MFwifSIsIm5iZiI6MTY5NTkxMjc1NCwiZXhwIjoxNjk1OTEzMzU0LCJpc3MiOiIwMDAwMDAwMi0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDBAN2VjODk0MjEtNGI5ZC00NDQzLTllNzQtNmU4ZWQ0YmRlYzE2IiwiYXVkIjoiMDAwMDAwMDItMDAwMC0wZmYxLWNlMDAtMDAwMDAwMDAwMDAwL2F0dGFjaG1lbnRzLm9mZmljZS5uZXRAN2VjODk0MjEtNGI5ZC00NDQzLTllNzQtNmU4ZWQ0YmRlYzE2IiwiaGFwcCI6Im93YSJ9.Qm6T4klUEX7x_SYyloLIeJ-BAYAH1F1ilqhQI_pcqbMx0D_-VUPoenRHqUmu5m4GFDlJztyvMiyFhcs4wJ0Br5owMIaHhMwtvY0h0j_U-9yCkOY987yl7FxMDyuBGTA7DrMJFydFfe68PziUxfhLWcn_JGoysTqXW6lYMim1PFjTtQPkIQmrGYFGAVdHjxMPDdOX8-dre7ZHpruSBVGM1ezVDv546cSsJ-tWTtdipIl9bViVtuD2jfwiN10eN0ts3QlbYtvFudn3uJHEmGMU_8FvRDN7ddIFTS4i94bZsBmZBIkyRD6pnnjZAUSzHBHNo1806smDGbhzU8CX9XhxVg&X-OWA-CANARY=MallLIVB50iC3YjN013a2sCkMqsywNsY_GoZ0PIfjtns9RLYHdWy20_KQBzI-Owi_hDoSZlrRP8.&owa=outlook.office.com&scriptVer=20230915006.20&animation=trueSample URL: PII: tgibbs@Hensley.com
Source: https://attachments.office.net/owa/tgibbs@Hensley.com/service.svc/s/GetAttachmentThumbnail?id=AAMkADgzNmFhNjQ5LTRlODktNDAwNC05YmNmLWY1YjBiOWY4YjVlZgBGAAAAAAAQyTkhQyDeRbmqEQP7YN7hBwCilU2fRgNGQ54Hblxt0RJhAAAYVNm4AAAYxQNzU2dnQrP86tSpYFIIAxlMIxl5AAABEgAQALQPWuNNA3JCl1e5%2Bp5B9H8%3D&thumbnailType=2&token=eyJhbGciOiJSUzI1NiIsImtpZCI6IjczRkI5QkJFRjYzNjc4RDRGN0U4NEI0NDBCQUJCMTJBMzM5RDlGOTgiLCJ0eXAiOiJKV1QiLCJ4NXQiOiJjX3VidnZZMmVOVDM2RXRFQzZ1eEtqT2RuNWcifQ.eyJvcmlnaW4iOiJodHRwczovL291dGxvb2sub2ZmaWNlLmNvbSIsInVjIjoiYWY0NjE0MDkyYmU1NDM3Njk5Yzc0YWQ0ZGM1YmY2NjQiLCJ2ZXIiOiJFeGNoYW5nZS5DYWxsYmFjay5WMSIsImFwcGN0eHNlbmRlciI6Ik93YURvd25sb2FkQDdlYzg5NDIxLTRiOWQtNDQ0My05ZTc0LTZlOGVkNGJkZWMxNiIsImlzc3JpbmciOiJXVyIsImFwcGN0eCI6IntcIm1zZXhjaHByb3RcIjpcIm93YVwiLFwicHVpZFwiOlwiMTE1MzkwNjY2MDgzMzY4OTI5MFwiLFwic2NvcGVcIjpcIk93YURvd25sb2FkXCIsXCJvaWRcIjpcIjY5Yzc5YjhkLTU2OTYtNDI0OC04M2EwLThhMzAxZjdhYzhmM1wiLFwicHJpbWFyeXNpZFwiOlwiUy0xLTUtMjEtMjE4MTAwNTI3OC0yMzEyMDgwODQyLTEzMzMxODQ4MDctMzMyMjE3MFwifSIsIm5iZiI6MTY5NTkxMjc1NCwiZXhwIjoxNjk1OTEzMzU0LCJpc3MiOiIwMDAwMDAwMi0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDBAN2VjODk0MjEtNGI5ZC00NDQzLTllNzQtNmU4ZWQ0YmRlYzE2IiwiYXVkIjoiMDAwMDAwMDItMDAwMC0wZmYxLWNlMDAtMDAwMDAwMDAwMDAwL2F0dGFjaG1lbnRzLm9mZmljZS5uZXRAN2VjODk0MjEtNGI5ZC00NDQzLTllNzQtNmU4ZWQ0YmRlYzE2IiwiaGFwcCI6Im93YSJ9.Qm6T4klUEX7x_SYyloLIeJ-BAYAH1F1ilqhQI_pcqbMx0D_-VUPoenRHqUmu5m4GFDlJztyvMiyFhcs4wJ0Br5owMIaHhMwtvY0h0j_U-9yCkOY987yl7FxMDyuBGTA7DrMJFydFfe68PziUxfhLWcn_JGoysTqXW6lYMim1PFjTtQPkIQmrGYFGAVdHjxMPDdOX8-dre7ZHpruSBVGM1ezVDv546cSsJ-tWTtdipIl9bViVtuD2jfwiN10eN0ts3QlbYtvFudn3uJHEmGMU_8FvRDN7ddIFTS4i94bZsBmZBIkyRD6pnnjZAUSzHBHNo1806smDGbhzU8CX9XhxVg&X-OWA-CANARY=MallLIVB50iC3YjN013a2sCkMqsywNsY_GoZ0PIfjtns9RLYHdWy20_KQBzI-Owi_hDoSZlrRP8.&owa=outlook.office.com&scriptVer=20230915006.20&animation=trueSample URL: PII: tgibbs@Hensley.com
Source: https://attachments.office.net/owa/tgibbs@Hensley.com/service.svc/s/GetAttachmentThumbnail?id=AAMkADgzNmFhNjQ5LTRlODktNDAwNC05YmNmLWY1YjBiOWY4YjVlZgBGAAAAAAAQyTkhQyDeRbmqEQP7YN7hBwCilU2fRgNGQ54Hblxt0RJhAAAYVNm4AAAYxQNzU2dnQrP86tSpYFIIAxlMIxl5AAABEgAQALQPWuNNA3JCl1e5%2Bp5B9H8%3D&thumbnailType=2&token=eyJhbGciOiJSUzI1NiIsImtpZCI6IjczRkI5QkJFRjYzNjc4RDRGN0U4NEI0NDBCQUJCMTJBMzM5RDlGOTgiLCJ0eXAiOiJKV1QiLCJ4NXQiOiJjX3VidnZZMmVOVDM2RXRFQzZ1eEtqT2RuNWcifQ.eyJvcmlnaW4iOiJodHRwczovL291dGxvb2sub2ZmaWNlLmNvbSIsInVjIjoiYWY0NjE0MDkyYmU1NDM3Njk5Yzc0YWQ0ZGM1YmY2NjQiLCJ2ZXIiOiJFeGNoYW5nZS5DYWxsYmFjay5WMSIsImFwcGN0eHNlbmRlciI6Ik93YURvd25sb2FkQDdlYzg5NDIxLTRiOWQtNDQ0My05ZTc0LTZlOGVkNGJkZWMxNiIsImlzc3JpbmciOiJXVyIsImFwcGN0eCI6IntcIm1zZXhjaHByb3RcIjpcIm93YVwiLFwicHVpZFwiOlwiMTE1MzkwNjY2MDgzMzY4OTI5MFwiLFwic2NvcGVcIjpcIk93YURvd25sb2FkXCIsXCJvaWRcIjpcIjY5Yzc5YjhkLTU2OTYtNDI0OC04M2EwLThhMzAxZjdhYzhmM1wiLFwicHJpbWFyeXNpZFwiOlwiUy0xLTUtMjEtMjE4MTAwNTI3OC0yMzEyMDgwODQyLTEzMzMxODQ4MDctMzMyMjE3MFwifSIsIm5iZiI6MTY5NTkxMjc1NCwiZXhwIjoxNjk1OTEzMzU0LCJpc3MiOiIwMDAwMDAwMi0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDBAN2VjODk0MjEtNGI5ZC00NDQzLTllNzQtNmU4ZWQ0YmRlYzE2IiwiYXVkIjoiMDAwMDAwMDItMDAwMC0wZmYxLWNlMDAtMDAwMDAwMDAwMDAwL2F0dGFjaG1lbnRzLm9mZmljZS5uZXRAN2VjODk0MjEtNGI5ZC00NDQzLTllNzQtNmU4ZWQ0YmRlYzE2IiwiaGFwcCI6Im93YSJ9.Qm6T4klUEX7x_SYyloLIeJ-BAYAH1F1ilqhQI_pcqbMx0D_-VUPoenRHqUmu5m4GFDlJztyvMiyFhcs4wJ0Br5owMIaHhMwtvY0h0j_U-9yCkOY987yl7FxMDyuBGTA7DrMJFydFfe68PziUxfhLWcn_JGoysTqXW6lYMim1PFjTtQPkIQmrGYFGAVdHjxMPDdOX8-dre7ZHpruSBVGM1ezVDv546cSsJ-tWTtdipIl9bViVtuD2jfwiN10eN0ts3QlbYtvFudn3uJHEmGMU_8FvRDN7ddIFTS4i94bZsBmZBIkyRD6pnnjZAUSzHBHNo1806smDGbhzU8CX9XhxVg&X-OWA-CANARY=MallLIVB50iC3YjN013a2sCkMqsywNsY_GoZ0PIfjtns9RLYHdWy20_KQBzI-Owi_hDoSZlrRP8.&owa=outlook.office.com&scriptVer=20230915006.20&animation=trueSample URL: PII: tgibbs@Hensley.com
Source: https://attachments.office.net/owa/tgibbs@Hensley.com/service.svc/s/GetAttachmentThumbnail?id=AAMkADgzNmFhNjQ5LTRlODktNDAwNC05YmNmLWY1YjBiOWY4YjVlZgBGAAAAAAAQyTkhQyDeRbmqEQP7YN7hBwCilU2fRgNGQ54Hblxt0RJhAAAYVNm4AAAYxQNzU2dnQrP86tSpYFIIAxlMIxl5AAABEgAQALQPWuNNA3JCl1e5%2Bp5B9H8%3D&thumbnailType=2&token=eyJhbGciOiJSUzI1NiIsImtpZCI6IjczRkI5QkJFRjYzNjc4RDRGN0U4NEI0NDBCQUJCMTJBMzM5RDlGOTgiLCJ0eXAiOiJKV1QiLCJ4NXQiOiJjX3VidnZZMmVOVDM2RXRFQzZ1eEtqT2RuNWcifQ.eyJvcmlnaW4iOiJodHRwczovL291dGxvb2sub2ZmaWNlLmNvbSIsInVjIjoiYWY0NjE0MDkyYmU1NDM3Njk5Yzc0YWQ0ZGM1YmY2NjQiLCJ2ZXIiOiJFeGNoYW5nZS5DYWxsYmFjay5WMSIsImFwcGN0eHNlbmRlciI6Ik93YURvd25sb2FkQDdlYzg5NDIxLTRiOWQtNDQ0My05ZTc0LTZlOGVkNGJkZWMxNiIsImlzc3JpbmciOiJXVyIsImFwcGN0eCI6IntcIm1zZXhjaHByb3RcIjpcIm93YVwiLFwicHVpZFwiOlwiMTE1MzkwNjY2MDgzMzY4OTI5MFwiLFwic2NvcGVcIjpcIk93YURvd25sb2FkXCIsXCJvaWRcIjpcIjY5Yzc5YjhkLTU2OTYtNDI0OC04M2EwLThhMzAxZjdhYzhmM1wiLFwicHJpbWFyeXNpZFwiOlwiUy0xLTUtMjEtMjE4MTAwNTI3OC0yMzEyMDgwODQyLTEzMzMxODQ4MDctMzMyMjE3MFwifSIsIm5iZiI6MTY5NTkxMjc1NCwiZXhwIjoxNjk1OTEzMzU0LCJpc3MiOiIwMDAwMDAwMi0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDBAN2VjODk0MjEtNGI5ZC00NDQzLTllNzQtNmU4ZWQ0YmRlYzE2IiwiYXVkIjoiMDAwMDAwMDItMDAwMC0wZmYxLWNlMDAtMDAwMDAwMDAwMDAwL2F0dGFjaG1lbnRzLm9mZmljZS5uZXRAN2VjODk0MjEtNGI5ZC00NDQzLTllNzQtNmU4ZWQ0YmRlYzE2IiwiaGFwcCI6Im93YSJ9.Qm6T4klUEX7x_SYyloLIeJ-BAYAH1F1ilqhQI_pcqbMx0D_-VUPoenRHqUmu5m4GFDlJztyvMiyFhcs4wJ0Br5owMIaHhMwtvY0h0j_U-9yCkOY987yl7FxMDyuBGTA7DrMJFydFfe68PziUxfhLWcn_JGoysTqXW6lYMim1PFjTtQPkIQmrGYFGAVdHjxMPDdOX8-dre7ZHpruSBVGM1ezVDv546cSsJ-tWTtdipIl9bViVtuD2jfwiN10eN0ts3QlbYtvFudn3uJHEmGMU_8FvRDN7ddIFTS4i94bZsBmZBIkyRD6pnnjZAUSzHBHNo1806smDGbhzU8CX9XhxVg&X-OWA-CANARY=MallLIVB50iC3YjN013a2sCkMqsywNsY_GoZ0PIfjtns9RLYHdWy20_KQBzI-Owi_hDoSZlrRP8.&owa=outlook.office.com&scriptVer=20230915006.20&animation=trueSample URL: PII: tgibbs@Hensley.com
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdater
Source: unknownDNS traffic detected: queries for: accounts.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49695 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49695
Source: unknownNetwork traffic detected: HTTP traffic on port 49694 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49694
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49693
Source: unknownNetwork traffic detected: HTTP traffic on port 49693 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: classification engineClassification label: clean0.win@20/3@5/91
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdater
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://attachments.office.net/owa/tgibbs@Hensley.com/service.svc/s/GetAttachmentThumbnail?id=AAMkADgzNmFhNjQ5LTRlODktNDAwNC05YmNmLWY1YjBiOWY4YjVlZgBGAAAAAAAQyTkhQyDeRbmqEQP7YN7hBwCilU2fRgNGQ54Hblxt0RJhAAAYVNm4AAAYxQNzU2dnQrP86tSpYFIIAxlMIxl5AAABEgAQALQPWuNNA3JCl1e5%2Bp5B9H8%3D&thumbnailType=2&token=eyJhbGciOiJSUzI1NiIsImtpZCI6IjczRkI5QkJFRjYzNjc4RDRGN0U4NEI0NDBCQUJCMTJBMzM5RDlGOTgiLCJ0eXAiOiJKV1QiLCJ4NXQiOiJjX3VidnZZMmVOVDM2RXRFQzZ1eEtqT2RuNWcifQ.eyJvcmlnaW4iOiJodHRwczovL291dGxvb2sub2ZmaWNlLmNvbSIsInVjIjoiYWY0NjE0MDkyYmU1NDM3Njk5Yzc0YWQ0ZGM1YmY2NjQiLCJ2ZXIiOiJFeGNoYW5nZS5DYWxsYmFjay5WMSIsImFwcGN0eHNlbmRlciI6Ik93YURvd25sb2FkQDdlYzg5NDIxLTRiOWQtNDQ0My05ZTc0LTZlOGVkNGJkZWMxNiIsImlzc3JpbmciOiJXVyIsImFwcGN0eCI6IntcIm1zZXhjaHByb3RcIjpcIm93YVwiLFwicHVpZFwiOlwiMTE1MzkwNjY2MDgzMzY4OTI5MFwiLFwic2NvcGVcIjpcIk93YURvd25sb2FkXCIsXCJvaWRcIjpcIjY5Yzc5YjhkLTU2OTYtNDI0OC04M2EwLThhMzAxZjdhYzhmM1wiLFwicHJpbWFyeXNpZFwiOlwiUy0xLTUtMjEtMjE4MTAwNTI3OC0yMzEyMDgwODQyLTEzMzMxODQ4MDctMzMyMjE3MFwifSIsIm5iZiI6MTY5NTkxMjc1NCwiZXhwIjoxNjk1OTEzMzU0LCJpc3MiOiIwMDAwMDAwMi0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDBAN2VjODk0MjEtNGI5ZC00NDQzLTllNzQtNmU4ZWQ0YmRlYzE2IiwiYXVkIjoiMDAwMDAwMDItMDAwMC0wZmYxLWNlMDAtMDAwMDAwMDAwMDAwL2F0dGFjaG1lbnRzLm9mZmljZS5uZXRAN2VjODk0MjEtNGI5ZC00NDQzLTllNzQtNmU4ZWQ0YmRlYzE2IiwiaGFwcCI6Im93YSJ9.Qm6T4klUEX7x_SYyloLIeJ-BAYAH1F1ilqhQI_pcqbMx0D_-VUPoenRHqUmu5m4GFDlJztyvMiyFhcs4wJ0Br5owMIaHhMwtvY0h0j_U-9yCkOY987yl7FxMDyuBGTA7DrMJFydFfe68PziUxfhLWcn_JGoysTqXW6lYMim1PFjTtQPkIQmrGYFGAVdHjxMPDdOX8-dre7ZHpruSBVGM1ezVDv546cSsJ-tWTtdipIl9bViVtuD2jfwiN10eN0ts3QlbYtvFudn3uJHEmGMU_8FvRDN7ddIFTS4i94bZsBmZBIkyRD6pnnjZAUSzHBHNo1806smDGbhzU8CX9XhxVg&X-OWA-CANARY=MallLIVB50iC3YjN013a2sCkMqsywNsY_GoZ0PIfjtns9RLYHdWy20_KQBzI-Owi_hDoSZlrRP8.&owa=outlook.office.com&scriptVer=20230915006.20&animation=true
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1592 --field-trial-handle=1800,i,7124171202341282985,811105926499202913,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1592 --field-trial-handle=1800,i,7124171202341282985,811105926499202913,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\Downloads\f83cff8b-45be-4702-aea4-b0ece4b94188.tmp
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdater
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
3
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium2
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth1
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration2
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://attachments.office.net/owa/tgibbs@Hensley.com/service.svc/s/GetAttachmentThumbnail?id=AAMkADgzNmFhNjQ5LTRlODktNDAwNC05YmNmLWY1YjBiOWY4YjVlZgBGAAAAAAAQyTkhQyDeRbmqEQP7YN7hBwCilU2fRgNGQ54Hblxt0RJhAAAYVNm4AAAYxQNzU2dnQrP86tSpYFIIAxlMIxl5AAABEgAQALQPWuNNA3JCl1e5%2Bp5B9H8%3D&thumbnailType=2&token=eyJhbGciOiJSUzI1NiIsImtpZCI6IjczRkI5QkJFRjYzNjc4RDRGN0U4NEI0NDBCQUJCMTJBMzM5RDlGOTgiLCJ0eXAiOiJKV1QiLCJ4NXQiOiJjX3VidnZZMmVOVDM2RXRFQzZ1eEtqT2RuNWcifQ.eyJvcmlnaW4iOiJodHRwczovL291dGxvb2sub2ZmaWNlLmNvbSIsInVjIjoiYWY0NjE0MDkyYmU1NDM3Njk5Yzc0YWQ0ZGM1YmY2NjQiLCJ2ZXIiOiJFeGNoYW5nZS5DYWxsYmFjay5WMSIsImFwcGN0eHNlbmRlciI6Ik93YURvd25sb2FkQDdlYzg5NDIxLTRiOWQtNDQ0My05ZTc0LTZlOGVkNGJkZWMxNiIsImlzc3JpbmciOiJXVyIsImFwcGN0eCI6IntcIm1zZXhjaHByb3RcIjpcIm93YVwiLFwicHVpZFwiOlwiMTE1MzkwNjY2MDgzMzY4OTI5MFwiLFwic2NvcGVcIjpcIk93YURvd25sb2FkXCIsXCJvaWRcIjpcIjY5Yzc5YjhkLTU2OTYtNDI0OC04M2EwLThhMzAxZjdhYzhmM1wiLFwicHJpbWFyeXNpZFwiOlwiUy0xLTUtMjEtMjE4MTAwNTI3OC0yMzEyMDgwODQyLTEzMzMxODQ4MDctMzMyMjE3MFwifSIsIm5iZiI6MTY5NTkxMjc1NCwiZXhwIjoxNjk1OTEzMzU0LCJpc3MiOiIwMDAwMDAwMi0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDBAN2VjODk0MjEtNGI5ZC00NDQzLTllNzQtNmU4ZWQ0YmRlYzE2IiwiYXVkIjoiMDAwMDAwMDItMDAwMC0wZmYxLWNlMDAtMDAwMDAwMDAwMDAwL2F0dGFjaG1lbnRzLm9mZmljZS5uZXRAN2VjODk0MjEtNGI5ZC00NDQzLTllNzQtNmU4ZWQ0YmRlYzE2IiwiaGFwcCI6Im93YSJ9.Qm6T4klUEX7x_SYyloLIeJ-BAYAH1F1ilqhQI_pcqbMx0D_-VUPoenRHqUmu5m4GFDlJztyvMiyFhcs4wJ0Br5owMIaHhMwtvY0h0j_U-9yCkOY987yl7FxMDyuBGTA7DrMJFydFfe68PziUxfhLWcn_JGoysTqXW6lYMim1PFjTtQPkIQmrGYFGAVdHjxMPDdOX8-dre7ZHpruSBVGM1ezVDv546cSsJ-tWTtdipIl9bViVtuD2jfwiN10eN0ts3QlbYtvFudn3uJHEmGMU_8FvRDN7ddIFTS4i94bZsBmZBIkyRD6pnnjZAUSzHBHNo1806smDGbhzU8CX9XhxVg&X-OWA-CANARY=MallLIVB50iC3YjN013a2sCkMqsywNsY_GoZ0PIfjtns9RLYHdWy20_KQBzI-Owi_hDoSZlrRP8.&owa=outlook.office.com&scriptVer=20230915006.20&animation=true0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
SJC-efz.ms-acdc.office.com
52.96.110.50
truefalse
    high
    accounts.google.com
    142.250.68.109
    truefalse
      high
      www.google.com
      142.250.217.132
      truefalse
        high
        clients.l.google.com
        142.250.72.238
        truefalse
          high
          clients2.google.com
          unknown
          unknownfalse
            high
            attachments.office.net
            unknown
            unknownfalse
              high
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              9.9.9.9
              unknownUnited States
              19281QUAD9-AS-1USfalse
              142.250.72.238
              clients.l.google.comUnited States
              15169GOOGLEUSfalse
              172.217.12.131
              unknownUnited States
              15169GOOGLEUSfalse
              1.1.1.1
              unknownAustralia
              13335CLOUDFLARENETUSfalse
              172.217.12.132
              unknownUnited States
              15169GOOGLEUSfalse
              239.255.255.250
              unknownReserved
              unknownunknownfalse
              142.250.68.109
              accounts.google.comUnited States
              15169GOOGLEUSfalse
              52.96.110.50
              SJC-efz.ms-acdc.office.comUnited States
              8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
              142.250.68.35
              unknownUnited States
              15169GOOGLEUSfalse
              142.250.68.3
              unknownUnited States
              15169GOOGLEUSfalse
              Joe Sandbox Version:38.0.0 Beryl
              Analysis ID:1315932
              Start date and time:2023-09-28 16:54:41 +02:00
              Joe Sandbox Product:CloudBasic
              Overall analysis duration:
              Hypervisor based Inspection enabled:false
              Report type:full
              Cookbook file name:defaultwindowsinteractivecookbook.jbs
              Sample URL:https://attachments.office.net/owa/tgibbs@Hensley.com/service.svc/s/GetAttachmentThumbnail?id=AAMkADgzNmFhNjQ5LTRlODktNDAwNC05YmNmLWY1YjBiOWY4YjVlZgBGAAAAAAAQyTkhQyDeRbmqEQP7YN7hBwCilU2fRgNGQ54Hblxt0RJhAAAYVNm4AAAYxQNzU2dnQrP86tSpYFIIAxlMIxl5AAABEgAQALQPWuNNA3JCl1e5%2Bp5B9H8%3D&thumbnailType=2&token=eyJhbGciOiJSUzI1NiIsImtpZCI6IjczRkI5QkJFRjYzNjc4RDRGN0U4NEI0NDBCQUJCMTJBMzM5RDlGOTgiLCJ0eXAiOiJKV1QiLCJ4NXQiOiJjX3VidnZZMmVOVDM2RXRFQzZ1eEtqT2RuNWcifQ.eyJvcmlnaW4iOiJodHRwczovL291dGxvb2sub2ZmaWNlLmNvbSIsInVjIjoiYWY0NjE0MDkyYmU1NDM3Njk5Yzc0YWQ0ZGM1YmY2NjQiLCJ2ZXIiOiJFeGNoYW5nZS5DYWxsYmFjay5WMSIsImFwcGN0eHNlbmRlciI6Ik93YURvd25sb2FkQDdlYzg5NDIxLTRiOWQtNDQ0My05ZTc0LTZlOGVkNGJkZWMxNiIsImlzc3JpbmciOiJXVyIsImFwcGN0eCI6IntcIm1zZXhjaHByb3RcIjpcIm93YVwiLFwicHVpZFwiOlwiMTE1MzkwNjY2MDgzMzY4OTI5MFwiLFwic2NvcGVcIjpcIk93YURvd25sb2FkXCIsXCJvaWRcIjpcIjY5Yzc5YjhkLTU2OTYtNDI0OC04M2EwLThhMzAxZjdhYzhmM1wiLFwicHJpbWFyeXNpZFwiOlwiUy0xLTUtMjEtMjE4MTAwNTI3OC0yMzEyMDgwODQyLTEzMzMxODQ4MDctMzMyMjE3MFwifSIsIm5iZiI6MTY5NTkxMjc1NCwiZXhwIjoxNjk1OTEzMzU0LCJpc3MiOiIwMDAwMDAwMi0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDBAN2VjODk0MjEtNGI5ZC00NDQzLTllNzQtNmU4ZWQ0YmRlYzE2IiwiYXVkIjoiMDAwMDAwMDItMDAwMC0wZmYxLWNlMDAtMDAwMDAwMDAwMDAwL2F0dGFjaG1lbnRzLm9mZmljZS5uZXRAN2VjODk0MjEtNGI5ZC00NDQzLTllNzQtNmU4ZWQ0YmRlYzE2IiwiaGFwcCI6Im93YSJ9.Qm6T4klUEX7x_SYyloLIeJ-BAYAH1F1ilqhQI_pcqbMx0D_-VUPoenRHqUmu5m4GFDlJztyvMiyFhcs4wJ0Br5owMIaHhMwtvY0h0j_U-9yCkOY987yl7FxMDyuBGTA7DrMJFydFfe68PziUxfhLWcn_JGoysTqXW6lYMim1PFjTtQPkIQmrGYFGAVdHjxMPDdOX8-dre7ZHpruSBVGM1ezVDv546cSsJ-tWTtdipIl9bViVtuD2jfwiN10eN0ts3QlbYtvFudn3uJHEmGMU_8FvRDN7ddIFTS4i94bZsBmZBIkyRD6pnnjZAUSzHBHNo1806smDGbhzU8CX9XhxVg&X-OWA-CANARY=MallLIVB50iC3YjN013a2sCkMqsywNsY_GoZ0PIfjtns9RLYHdWy20_KQBzI-Owi_hDoSZlrRP8.&owa=outlook.office.com&scriΡtVer=20230915006.20&animation=true
              Analysis system description:Windows 10 64 bit version 1909 (MS Office 2019, IE 11, Chrome 104, Firefox 88, Adobe Reader DC 21, Java 8 u291, 7-Zip)
              Number of analysed new started processes analysed:20
              Number of new started drivers analysed:0
              Number of existing processes analysed:0
              Number of existing drivers analysed:0
              Number of injected processes analysed:0
              Technologies:
              • EGA enabled
              Analysis Mode:stream
              Analysis stop reason:Timeout
              Detection:CLEAN
              Classification:clean0.win@20/3@5/91
              • Exclude process from analysis (whitelisted): dllhost.exe, SIHClient.exe, SgrmBroker.exe, usocoreworker.exe, svchost.exe
              • Excluded IPs from analysis (whitelisted): 142.250.68.3, 34.104.35.123
              • Excluded domains from analysis (whitelisted): fs.microsoft.com, edgedl.me.gvt1.com, slscr.update.microsoft.com, clientservices.googleapis.com
              • Not all processes where analyzed, report is missing behavior information
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:PNG image data, 858 x 720, 8-bit/color RGBA, non-interlaced
              Category:dropped
              Size (bytes):43231
              Entropy (8bit):7.945641087526721
              Encrypted:false
              SSDEEP:
              MD5:AB0C503774F985CFC9A7E808248F3898
              SHA1:23E63224C00DAE8B7FA2D6A1762BC4C8E48800F6
              SHA-256:1BA9F6B93FE640DF512015C02CF2C387902D361893410C21284DB4A752DE6006
              SHA-512:A53AAB326634D49D9F641C3EACFDF15AB3A26F94D812DA88B6BFB4BB1A8BD5C04F793D3B3393B9501B0BA10AD074E490F23DAC04519437D94D09114F065E5807
              Malicious:false
              Reputation:low
              Preview:.PNG........IHDR...Z................?iCCPICC Profile..H..W.XS...[......H...".H..E..*..I.Pb...;...ZP...].Qt-...Ql.b.."*...]y....+..;......;s......bq6..@.(O.......$=..`.H..l..\1+::..2.......Y{.A.....Z4..\..H4..\^..G..+xbI..D.o>#O,..m....2....2.....6q1l.[.P.r..t..B...K..j}.;..B...L..rr..!N....!..{.....7..!M.7}.+."/*A.\q6w.....]r...>.`.fH.bds.y..5-\.....R#. ..../....dH.....!/..s...;.A...B."..P.i....p..3.y.8.. ^*...U.l.L.Q.Bk.$l..?....|=.f...o2...>.V....1.b.|aB$.j.;.f.+m..d.#.m$..Y.....D...},?M..../..../.-C.T.Cy.qa..`-<.<~8..@.....N...._....;.\ ..U.|....(...qv...7.d..x3.]s.c.c.<. ..x.8/:N.'^......._."....&.....L l..w..........A...H....5...? ...q..^....!Vqu.i..|..,........T>J4.-.<.......`.....=?.~gX..P2.A.L.AKb01..F.!......G.k...'.58......v.c.MB...Ta.dX..@...Q."..\.VP....}.:T....p.].....=.A...[...0.......#;.Q..9.l3|......,.?.G.k.P..C=.....>....-...a..k..`'.:..Nc..e.....'..5.-F.O.........e2..../O0S....i.Y.azF......&G.s..tvrv.@.}Q...2....q.;.h...G.........
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:PNG image data, 858 x 720, 8-bit/color RGBA, non-interlaced
              Category:dropped
              Size (bytes):69275
              Entropy (8bit):7.863711608516148
              Encrypted:false
              SSDEEP:
              MD5:AB2881B058CD76F3A050B27E846352AF
              SHA1:EBEDA9344B670D1E30204632521CA715DE9EEEA7
              SHA-256:BB5496FFE0EECC9266B3352E009B96AB1F8406DA068D2A971CFE615E38DB3260
              SHA-512:D70F99DD98CA47A674DD95BC3C2FA1CFB088850F7E577C23BB143A7F39405894BD045DFD8431A152919688AC6CD80D80632D8DC6D21331E2C7929EBA35FD0B64
              Malicious:false
              Reputation:low
              Preview:.PNG........IHDR...Z................?iCCPICC Profile..H..W.XS...[......H...".H..E..*..I.Pb...;...ZP...].Qt-...Ql.b.."*...]y....+..;......;s......bq6..@.(O.......$=..`.H..l..\1+::..2.......Y{.A.....Z4..\..H4..\^..G..+xbI..D.o>#O,..m....2....2.....6q1l.[.P.r..t..B...K..j}.;..B...L..rr..!N....!..{.....7..!M.7}.+."/*A.\q6w.....]r...>.`.fH.bds.y..5-\.....R#. ..../....dH.....!/..s...;.A...B."..P.i....p..3.y.8.. ^*...U.l.L.Q.Bk.$l..?....|=.f...o2...>.V....1.b.|aB$.j.;.f.+m..d.#.m$..Y.....D...},?M..../..../.-C.T.Cy.qa..`-<.<~8..@.....N...._....;.\ ..U.|....(...qv...7.d..x3.]s.c.c.<. ..x.8/:N.'^......._."....&.....L l..w..........A...H....5...? ...q..^....!Vqu.i..|..,........T>J4.-.<.......`.....=?.~gX..P2.A.L.AKb01..F.!......G.k...'.58......v.c.MB...Ta.dX..@...Q."..\.VP....}.:T....p.].....=.A...[...0.......#;.Q..9.l3|......,.?.G.k.P..C=.....>....-...a..k..`'.:..Nc..e.....'..5.-F.O.........e2..../O0S....i.Y.azF......&G.s..tvrv.@.}Q...2....q.;.h...G.........
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:PNG image data, 858 x 720, 8-bit/color RGBA, non-interlaced
              Category:dropped
              Size (bytes):69275
              Entropy (8bit):7.863711608516148
              Encrypted:false
              SSDEEP:
              MD5:AB2881B058CD76F3A050B27E846352AF
              SHA1:EBEDA9344B670D1E30204632521CA715DE9EEEA7
              SHA-256:BB5496FFE0EECC9266B3352E009B96AB1F8406DA068D2A971CFE615E38DB3260
              SHA-512:D70F99DD98CA47A674DD95BC3C2FA1CFB088850F7E577C23BB143A7F39405894BD045DFD8431A152919688AC6CD80D80632D8DC6D21331E2C7929EBA35FD0B64
              Malicious:false
              Reputation:low
              Preview:.PNG........IHDR...Z................?iCCPICC Profile..H..W.XS...[......H...".H..E..*..I.Pb...;...ZP...].Qt-...Ql.b.."*...]y....+..;......;s......bq6..@.(O.......$=..`.H..l..\1+::..2.......Y{.A.....Z4..\..H4..\^..G..+xbI..D.o>#O,..m....2....2.....6q1l.[.P.r..t..B...K..j}.;..B...L..rr..!N....!..{.....7..!M.7}.+."/*A.\q6w.....]r...>.`.fH.bds.y..5-\.....R#. ..../....dH.....!/..s...;.A...B."..P.i....p..3.y.8.. ^*...U.l.L.Q.Bk.$l..?....|=.f...o2...>.V....1.b.|aB$.j.;.f.+m..d.#.m$..Y.....D...},?M..../..../.-C.T.Cy.qa..`-<.<~8..@.....N...._....;.\ ..U.|....(...qv...7.d..x3.]s.c.c.<. ..x.8/:N.'^......._."....&.....L l..w..........A...H....5...? ...q..^....!Vqu.i..|..,........T>J4.-.<.......`.....=?.~gX..P2.A.L.AKb01..F.!......G.k...'.58......v.c.MB...Ta.dX..@...Q."..\.VP....}.:T....p.].....=.A...[...0.......#;.Q..9.l3|......,.?.G.k.P..C=.....>....-...a..k..`'.:..Nc..e.....'..5.-F.O.........e2..../O0S....i.Y.azF......&G.s..tvrv.@.}Q...2....q.;.h...G.........
              No static file info