Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
Sign.one

Overview

General Information

Sample name:Sign.one
Analysis ID:1471857
MD5:f23b30e0926ea7a7d59272d04e4b8b29
SHA1:5c5d7dd08b0b2125e0d34e1bc42b7e1752d688f1
SHA256:4a85363157042e89b11ac82fcf7420ca45bf2fab748c8cdee051e623940b94f1
Infos:

Detection

HTMLPhisher
Score:68
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

AI detected phishing page
Phishing site detected (based on favicon image match)
Yara detected HtmlPhish54
Phishing site detected (based on image similarity)
Found iframes
HTML body contains low number of good links
HTML page contains hidden javascript code
HTML page contains obfuscated script src
Sigma detected: Startup Folder File Write
Stores files to the Windows start menu directory

Classification

  • System is w10x64_ra
  • ONENOTE.EXE (PID: 4816 cmdline: "C:\Program Files (x86)\Microsoft Office\Root\Office16\ONENOTE.EXE" "C:\Users\user\Desktop\Sign.one" MD5: 0061760D72416BCF5F2D9FA6564F0BEA)
    • ONENOTEM.EXE (PID: 6432 cmdline: /tsr MD5: 384774DF70AD266F59512936C77602A6)
    • chrome.exe (PID: 6820 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://ara1233mark.com/?rbmuwcdb MD5: 83395EAB5B03DEA9720F8D7AC0D15CAA)
      • chrome.exe (PID: 7072 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2200 --field-trial-handle=1904,i,15573565381678590775,4567774448021983184,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 83395EAB5B03DEA9720F8D7AC0D15CAA)
  • cleanup
SourceRuleDescriptionAuthorStrings
6.9.script.csvJoeSecurity_HtmlPhish_54Yara detected HtmlPhish_54Joe Security
    4.4.script.csvJoeSecurity_HtmlPhish_54Yara detected HtmlPhish_54Joe Security
      6.15.script.csvJoeSecurity_HtmlPhish_54Yara detected HtmlPhish_54Joe Security
        4.2.pages.csvJoeSecurity_HtmlPhish_54Yara detected HtmlPhish_54Joe Security
          6.5.pages.csvJoeSecurity_HtmlPhish_54Yara detected HtmlPhish_54Joe Security
            Click to see the 4 entries
            Source: File createdAuthor: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research): Data: EventID: 11, Image: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE, ProcessId: 4816, TargetFilename: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Send to OneNote.lnk
            No Snort rule has matched

            Click to jump to signature section

            Show All Signature Results

            Phishing

            barindex
            Source: https://rbiip.comLLM: Score: 9 brands: Microsoft Outlook Reasons: The URL 'https://rbiip.com' does not match the legitimate domain 'outlook.com' associated with Microsoft Outlook. The page prominently displays a login form, which is a common tactic used in phishing attacks to harvest user credentials. The domain name 'rbiip.com' is suspicious and unrelated to Microsoft or Outlook, indicating a high likelihood of phishing. Additionally, the use of social engineering techniques is evident as the page mimics the legitimate Outlook login page to deceive users. DOM: 6.5.pages.csv
            Source: https://rbiip.com/?x11d8elg2=aHR0cHM6Ly9sb2dpbi5taWNyb3NvZnRvbmxpbmUuY29tL2NvbW1vbi9vYXV0aDIvYXV0aG9yaXplP2NsaWVudF9pZD0wMDAwMDAwMi0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDAmcmVkaXJlY3RfdXJpPWh0dHBzJTNhJTJmJTJmb3V0bG9vay5vZmZpY2UuY29tJTJmb3dhJTJmJnJlc291cmNlPTAwMDAwMDAyLTAwMDAtMGZmMS1jZTAwLTAwMDAwMDAwMDAwMCZyZXNwb25zZV9tb2RlPWZvcm1fcG9zdCZyZXNwb25zZV90eXBlPWNvZGUraWRfdG9rZW4mc2NvcGU9b3BlbmlkJm1zYWZlZD0xJm1zYXJlZGlyPTEmY2xpZW50LXJlcXVlc3QtaWQ9NTU5ZGE4NzgtNjEzZS03ZDZjLWNhMDYtOGVlNGQ2ZDM1ZmE4JnByb3RlY3RlZHRva2VuPXRydWUmY2xhaW1zPSU3YiUyMmlkX3Rva2VuJTIyJTNhJTdiJTIyeG1zX2NjJTIyJTNhJTdiJTIydmFsdWVzJTIyJTNhJTViJTIyQ1AxJTIyJTVkJTdkJTdkJTdkJm5vbmNlPTYzODU2MzMxMDg2NzI3NjY5MC40Mzg3NjBhYy01MmI4LTRmNjMtODY1MS0zYTAwMTdiYjg3YTUmc3RhdGU9RGNzeEVvQXdDQVhSUk1mallFZ0lIendPY2NiVzB1dEw4YmJiV2tyWjA1WXFaNHBCWENIUzJXSERnSXZQS1c3Z3VFbkhjcG9QaEJ6YVNZSzUyMXB1b1RYZm83MWZ0Qjg=&sso_reload=trueMatcher: Template: microsoft matched with high similarity
            Source: https://rbiip.comMatcher: Template: microsoft matched with high similarity
            Source: Yara matchFile source: 6.9.script.csv, type: HTML
            Source: Yara matchFile source: 4.4.script.csv, type: HTML
            Source: Yara matchFile source: 6.15.script.csv, type: HTML
            Source: Yara matchFile source: 4.2.pages.csv, type: HTML
            Source: Yara matchFile source: 6.5.pages.csv, type: HTML
            Source: Yara matchFile source: 6.3.pages.csv, type: HTML
            Source: Yara matchFile source: 4.2.pages.csv, type: HTML
            Source: Yara matchFile source: 6.3.pages.csv, type: HTML
            Source: Yara matchFile source: 6.5.pages.csv, type: HTML
            Source: https://rbiip.com/?x11d8elg2=aHR0cHM6Ly9sb2dpbi5taWNyb3NvZnRvbmxpbmUuY29tL2NvbW1vbi9vYXV0aDIvYXV0aG9yaXplP2NsaWVudF9pZD0wMDAwMDAwMi0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDAmcmVkaXJlY3RfdXJpPWh0dHBzJTNhJTJmJTJmb3V0bG9vay5vZmZpY2UuY29tJTJmb3dhJTJmJnJlc291cmNlPTAwMDAwMDAyLTAwMDAtMGZmMS1jZTAwLTAwMDAwMDAwMDAwMCZyZXNwb25zZV9tb2RlPWZvcm1fcG9zdCZyZXNwb25zZV90eXBlPWNvZGUraWRfdG9rZW4mc2NvcGU9b3BlbmlkJm1zYWZlZD0xJm1zYXJlZGlyPTEmY2xpZW50LXJlcXVlc3QtaWQ9NTU5ZGE4NzgtNjEzZS03ZDZjLWNhMDYtOGVlNGQ2ZDM1ZmE4JnByb3RlY3RlZHRva2VuPXRydWUmY2xhaW1zPSU3YiUyMmlkX3Rva2VuJTIyJTNhJTdiJTIyeG1zX2NjJTIyJTNhJTdiJTIydmFsdWVzJTIyJTNhJTViJTIyQ1AxJTIyJTVkJTdkJTdkJTdkJm5vbmNlPTYzODU2MzMxMDg2NzI3NjY5MC40Mzg3NjBhYy01MmI4LTRmNjMtODY1MS0zYTAwMTdiYjg3YTUmc3RhdGU9RGNzeEVvQXdDQVhSUk1mallFZ0lIendPY2NiVzB1dEw4YmJiV2tyWjA1WXFaNHBCWENIUzJXSERnSXZQS1c3Z3VFbkhjcG9QaEJ6YVNZSzUyMXB1b1RYZm83MWZ0Qjg=&sso_reload=trueMatcher: Found strong image similarity, brand: MICROSOFT
            Source: https://rbiip.com/?x11d8elg2=aHR0cHM6Ly9sb2dpbi5taWNyb3NvZnRvbmxpbmUuY29tL2NvbW1vbi9vYXV0aDIvYXV0aG9yaXplP2NsaWVudF9pZD0wMDAwMDAwMi0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDAmcmVkaXJlY3RfdXJpPWh0dHBzJTNhJTJmJTJmb3V0bG9vay5vZmZpY2UuY29tJTJmb3dhJTJmJnJlc291cmNlPTAwMDAwMDAyLTAwMDAtMGZmMS1jZTAwLTAwMDAwMDAwMDAwMCZyZXNwb25zZV9tb2RlPWZvcm1fcG9zdCZyZXNwb25zZV90eXBlPWNvZGUraWRfdG9rZW4mc2NvcGU9b3BlbmlkJm1zYWZlZD0xJm1zYXJlZGlyPTEmY2xpZW50LXJlcXVlc3QtaWQ9NTU5ZGE4NzgtNjEzZS03ZDZjLWNhMDYtOGVlNGQ2ZDM1ZmE4JnByb3RlY3RlZHRva2VuPXRydWUmY2xhaW1zPSU3YiUyMmlkX3Rva2VuJTIyJTNhJTdiJTIyeG1zX2NjJTIyJTNhJTdiJTIydmFsdWVzJTIyJTNhJTViJTIyQ1AxJTIyJTVkJTdkJTdkJTdkJm5vbmNlPTYzODU2MzMxMDg2NzI3NjY5MC40Mzg3NjBhYy01MmI4LTRmNjMtODY1MS0zYTAwMTdiYjg3YTUmc3RhdGU9RGNzeEVvQXdDQVhSUk1mallFZ0lIendPY2NiVzB1dEw4YmJiV2tyWjA1WXFaNHBCWENIUzJXSERnSXZQS1c3Z3VFbkhjcG9QaEJ6YVNZSzUyMXB1b1RYZm83MWZ0Qjg=&sso_reload=trueHTTP Parser: Iframe src: https://outlook.office365.com/owa/prefetch.aspx
            Source: https://rbiip.com/?x11d8elg2=aHR0cHM6Ly9sb2dpbi5taWNyb3NvZnRvbmxpbmUuY29tL2NvbW1vbi9vYXV0aDIvYXV0aG9yaXplP2NsaWVudF9pZD0wMDAwMDAwMi0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDAmcmVkaXJlY3RfdXJpPWh0dHBzJTNhJTJmJTJmb3V0bG9vay5vZmZpY2UuY29tJTJmb3dhJTJmJnJlc291cmNlPTAwMDAwMDAyLTAwMDAtMGZmMS1jZTAwLTAwMDAwMDAwMDAwMCZyZXNwb25zZV9tb2RlPWZvcm1fcG9zdCZyZXNwb25zZV90eXBlPWNvZGUraWRfdG9rZW4mc2NvcGU9b3BlbmlkJm1zYWZlZD0xJm1zYXJlZGlyPTEmY2xpZW50LXJlcXVlc3QtaWQ9NTU5ZGE4NzgtNjEzZS03ZDZjLWNhMDYtOGVlNGQ2ZDM1ZmE4JnByb3RlY3RlZHRva2VuPXRydWUmY2xhaW1zPSU3YiUyMmlkX3Rva2VuJTIyJTNhJTdiJTIyeG1zX2NjJTIyJTNhJTdiJTIydmFsdWVzJTIyJTNhJTViJTIyQ1AxJTIyJTVkJTdkJTdkJTdkJm5vbmNlPTYzODU2MzMxMDg2NzI3NjY5MC40Mzg3NjBhYy01MmI4LTRmNjMtODY1MS0zYTAwMTdiYjg3YTUmc3RhdGU9RGNzeEVvQXdDQVhSUk1mallFZ0lIendPY2NiVzB1dEw4YmJiV2tyWjA1WXFaNHBCWENIUzJXSERnSXZQS1c3Z3VFbkhjcG9QaEJ6YVNZSzUyMXB1b1RYZm83MWZ0Qjg=&sso_reload=trueHTTP Parser: Iframe src: https://outlook.office365.com/owa/prefetch.aspx
            Source: https://rbiip.com/?x11d8elg2=aHR0cHM6Ly9sb2dpbi5taWNyb3NvZnRvbmxpbmUuY29tL2NvbW1vbi9vYXV0aDIvYXV0aG9yaXplP2NsaWVudF9pZD0wMDAwMDAwMi0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDAmcmVkaXJlY3RfdXJpPWh0dHBzJTNhJTJmJTJmb3V0bG9vay5vZmZpY2UuY29tJTJmb3dhJTJmJnJlc291cmNlPTAwMDAwMDAyLTAwMDAtMGZmMS1jZTAwLTAwMDAwMDAwMDAwMCZyZXNwb25zZV9tb2RlPWZvcm1fcG9zdCZyZXNwb25zZV90eXBlPWNvZGUraWRfdG9rZW4mc2NvcGU9b3BlbmlkJm1zYWZlZD0xJm1zYXJlZGlyPTEmY2xpZW50LXJlcXVlc3QtaWQ9NTU5ZGE4NzgtNjEzZS03ZDZjLWNhMDYtOGVlNGQ2ZDM1ZmE4JnByb3RlY3RlZHRva2VuPXRydWUmY2xhaW1zPSU3YiUyMmlkX3Rva2VuJTIyJTNhJTdiJTIyeG1zX2NjJTIyJTNhJTdiJTIydmFsdWVzJTIyJTNhJTViJTIyQ1AxJTIyJTVkJTdkJTdkJTdkJm5vbmNlPTYzODU2MzMxMDg2NzI3NjY5MC40Mzg3NjBhYy01MmI4LTRmNjMtODY1MS0zYTAwMTdiYjg3YTUmc3RhdGU9RGNzeEVvQXdDQVhSUk1mallFZ0lIendPY2NiVzB1dEw4YmJiV2tyWjA1WXFaNHBCWENIUzJXSERnSXZQS1c3Z3VFbkhjcG9QaEJ6YVNZSzUyMXB1b1RYZm83MWZ0Qjg=&sso_reload=trueHTTP Parser: Number of links: 0
            Source: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv0/0/zbir7/0x4AAAAAAAe5DN2aGx7A8rqu/auto/fbE/normal/auto/HTTP Parser: Base64 decoded: {"version":3,"sourceRoot":"/cfsetup_build/src/orchestrator/turnstile/templates","sources":["turnstile.scss"],"names":[],"mappings":"AAyBA;EACI;IACI;;;AAIR;EACI;IACI;;;AAIR;EACI;IAEI;;EAGJ;IACI;;;AAIR;EACI;IACI;;;AAIR;EACI;IACI;;;AAIR;EACI;IACI;;;AAIR;EACI...
            Source: https://rbiip.com/?x11d8elg2=aHR0cHM6Ly9sb2dpbi5taWNyb3NvZnRvbmxpbmUuY29tL2NvbW1vbi9vYXV0aDIvYXV0aG9yaXplP2NsaWVudF9pZD0wMDAwMDAwMi0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDAmcmVkaXJlY3RfdXJpPWh0dHBzJTNhJTJmJTJmb3V0bG9vay5vZmZpY2UuY29tJTJmb3dhJTJmJnJlc291cHTTP Parser: Script src: data:text/javascript;base64,ZnVuY3Rpb24gYygpe2lmKCFkb2N1bWVudC5xdWVyeVNlbGVjdG9yKCIuYiIpIHx8ICFkb2N1bWVudC5xdWVyeVNlbGVjdG9yKCIuZyIpKXtkb2N1bWVudC5oZWFkLmFwcGVuZENoaWxkKE9iamVjdC5hc3NpZ24oZG9jdW1lbnQuY3JlYXRlRWxlbWVudCgiZGl2Iikse2NsYXNzTGlzdDpbImIiXX
            Source: https://rbiip.com/?x11d8elg2=aHR0cHM6Ly9sb2dpbi5taWNyb3NvZnRvbmxpbmUuY29tL2NvbW1vbi9vYXV0aDIvYXV0aG9yaXplP2NsaWVudF9pZD0wMDAwMDAwMi0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDAmcmVkaXJlY3RfdXJpPWh0dHBzJTNhJTJmJTJmb3V0bG9vay5vZmZpY2UuY29tJTJmb3dhJTJmJnJlc291cHTTP Parser: Script src: data:text/javascript;base64,ZnVuY3Rpb24gYygpe2lmKCFkb2N1bWVudC5xdWVyeVNlbGVjdG9yKCIuYiIpIHx8ICFkb2N1bWVudC5xdWVyeVNlbGVjdG9yKCIuZyIpKXtkb2N1bWVudC5oZWFkLmFwcGVuZENoaWxkKE9iamVjdC5hc3NpZ24oZG9jdW1lbnQuY3JlYXRlRWxlbWVudCgiZGl2Iikse2NsYXNzTGlzdDpbImIiXX
            Source: https://rbiip.com/?x11d8elg2=aHR0cHM6Ly9sb2dpbi5taWNyb3NvZnRvbmxpbmUuY29tL2NvbW1vbi9vYXV0aDIvYXV0aG9yaXplP2NsaWVudF9pZD0wMDAwMDAwMi0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDAmcmVkaXJlY3RfdXJpPWh0dHBzJTNhJTJmJTJmb3V0bG9vay5vZmZpY2UuY29tJTJmb3dhJTJmJnJlc291cHTTP Parser: Script src: data:text/javascript;base64,ZnVuY3Rpb24gYygpe2lmKCFkb2N1bWVudC5xdWVyeVNlbGVjdG9yKCIuYiIpIHx8ICFkb2N1bWVudC5xdWVyeVNlbGVjdG9yKCIuZyIpKXtkb2N1bWVudC5oZWFkLmFwcGVuZENoaWxkKE9iamVjdC5hc3NpZ24oZG9jdW1lbnQuY3JlYXRlRWxlbWVudCgiZGl2Iikse2NsYXNzTGlzdDpbImIiXX
            Source: https://rbiip.com/?x11d8elg2=aHR0cHM6Ly9sb2dpbi5taWNyb3NvZnRvbmxpbmUuY29tL2NvbW1vbi9vYXV0aDIvYXV0aG9yaXplP2NsaWVudF9pZD0wMDAwMDAwMi0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDAmcmVkaXJlY3RfdXJpPWh0dHBzJTNhJTJmJTJmb3V0bG9vay5vZmZpY2UuY29tJTJmb3dhJTJmJnJlc291cmNlPTAwMDAwMDAyLTAwMDAtMGZmMS1jZTAwLTAwMDAwMDAwMDAwMCZyZXNwb25zZV9tb2RlPWZvcm1fcG9zdCZyZXNwb25zZV90eXBlPWNvZGUraWRfdG9rZW4mc2NvcGU9b3BlbmlkJm1zYWZlZD0xJm1zYXJlZGlyPTEmY2xpZW50LXJlcXVlc3QtaWQ9NTU5ZGE4NzgtNjEzZS03ZDZjLWNhMDYtOGVlNGQ2ZDM1ZmE4JnByb3RlY3RlZHRva2VuPXRydWUmY2xhaW1zPSU3YiUyMmlkX3Rva2VuJTIyJTNhJTdiJTIyeG1zX2NjJTIyJTNhJTdiJTIydmFsdWVzJTIyJTNhJTViJTIyQ1AxJTIyJTVkJTdkJTdkJTdkJm5vbmNlPTYzODU2MzMxMDg2NzI3NjY5MC40Mzg3NjBhYy01MmI4LTRmNjMtODY1MS0zYTAwMTdiYjg3YTUmc3RhdGU9RGNzeEVvQXdDQVhSUk1mallFZ0lIendPY2NiVzB1dEw4YmJiV2tyWjA1WXFaNHBCWENIUzJXSERnSXZQS1c3Z3VFbkhjcG9QaEJ6YVNZSzUyMXB1b1RYZm83MWZ0Qjg=&sso_reload=trueHTTP Parser: <input type="password" .../> found
            Source: https://ara1233mark.com/?rbmuwcdb=512d552bfe569d0ede3144971cee43cc2eeed49e97097aff88e5cb8febef8519b5f8da93e9770a4a506eec9ad07e92fb8f25525040407d6a6437bc53f18d11d1HTTP Parser: No favicon
            Source: https://rbiip.com/?x11d8elg2=aHR0cHM6Ly9sb2dpbi5taWNyb3NvZnRvbmxpbmUuY29tL2NvbW1vbi9vYXV0aDIvYXV0aG9yaXplP2NsaWVudF9pZD0wMDAwMDAwMi0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDAmcmVkaXJlY3RfdXJpPWh0dHBzJTNhJTJmJTJmb3V0bG9vay5vZmZpY2UuY29tJTJmb3dhJTJmJnJlc291cmNlPTAwMDAwMDAyLTAwMDAtMGZmMS1jZTAwLTAwMDAwMDAwMDAwMCZyZXNwb25zZV9tb2RlPWZvcm1fcG9zdCZyZXNwb25zZV90eXBlPWNvZGUraWRfdG9rZW4mc2NvcGU9b3BlbmlkJm1zYWZlZD0xJm1zYXJlZGlyPTEmY2xpZW50LXJlcXVlc3QtaWQ9NTU5ZGE4NzgtNjEzZS03ZDZjLWNhMDYtOGVlNGQ2ZDM1ZmE4JnByb3RlY3RlZHRva2VuPXRydWUmY2xhaW1zPSU3YiUyMmlkX3Rva2VuJTIyJTNhJTdiJTIyeG1zX2NjJTIyJTNhJTdiJTIydmFsdWVzJTIyJTNhJTViJTIyQ1AxJTIyJTVkJTdkJTdkJTdkJm5vbmNlPTYzODU2MzMxMDg2NzI3NjY5MC40Mzg3NjBhYy01MmI4LTRmNjMtODY1MS0zYTAwMTdiYjg3YTUmc3RhdGU9RGNzeEVvQXdDQVhSUk1mallFZ0lIendPY2NiVzB1dEw4YmJiV2tyWjA1WXFaNHBCWENIUzJXSERnSXZQS1c3Z3VFbkhjcG9QaEJ6YVNZSzUyMXB1b1RYZm83MWZ0Qjg=HTTP Parser: No favicon
            Source: https://rbiip.com/?x11d8elg2=aHR0cHM6Ly9sb2dpbi5taWNyb3NvZnRvbmxpbmUuY29tL2NvbW1vbi9vYXV0aDIvYXV0aG9yaXplP2NsaWVudF9pZD0wMDAwMDAwMi0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDAmcmVkaXJlY3RfdXJpPWh0dHBzJTNhJTJmJTJmb3V0bG9vay5vZmZpY2UuY29tJTJmb3dhJTJmJnJlc291cmNlPTAwMDAwMDAyLTAwMDAtMGZmMS1jZTAwLTAwMDAwMDAwMDAwMCZyZXNwb25zZV9tb2RlPWZvcm1fcG9zdCZyZXNwb25zZV90eXBlPWNvZGUraWRfdG9rZW4mc2NvcGU9b3BlbmlkJm1zYWZlZD0xJm1zYXJlZGlyPTEmY2xpZW50LXJlcXVlc3QtaWQ9NTU5ZGE4NzgtNjEzZS03ZDZjLWNhMDYtOGVlNGQ2ZDM1ZmE4JnByb3RlY3RlZHRva2VuPXRydWUmY2xhaW1zPSU3YiUyMmlkX3Rva2VuJTIyJTNhJTdiJTIyeG1zX2NjJTIyJTNhJTdiJTIydmFsdWVzJTIyJTNhJTViJTIyQ1AxJTIyJTVkJTdkJTdkJTdkJm5vbmNlPTYzODU2MzMxMDg2NzI3NjY5MC40Mzg3NjBhYy01MmI4LTRmNjMtODY1MS0zYTAwMTdiYjg3YTUmc3RhdGU9RGNzeEVvQXdDQVhSUk1mallFZ0lIendPY2NiVzB1dEw4YmJiV2tyWjA1WXFaNHBCWENIUzJXSERnSXZQS1c3Z3VFbkhjcG9QaEJ6YVNZSzUyMXB1b1RYZm83MWZ0Qjg=&sso_reload=trueHTTP Parser: No favicon
            Source: https://rbiip.com/?x11d8elg2=aHR0cHM6Ly9sb2dpbi5taWNyb3NvZnRvbmxpbmUuY29tL2NvbW1vbi9vYXV0aDIvYXV0aG9yaXplP2NsaWVudF9pZD0wMDAwMDAwMi0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDAmcmVkaXJlY3RfdXJpPWh0dHBzJTNhJTJmJTJmb3V0bG9vay5vZmZpY2UuY29tJTJmb3dhJTJmJnJlc291cmNlPTAwMDAwMDAyLTAwMDAtMGZmMS1jZTAwLTAwMDAwMDAwMDAwMCZyZXNwb25zZV9tb2RlPWZvcm1fcG9zdCZyZXNwb25zZV90eXBlPWNvZGUraWRfdG9rZW4mc2NvcGU9b3BlbmlkJm1zYWZlZD0xJm1zYXJlZGlyPTEmY2xpZW50LXJlcXVlc3QtaWQ9NTU5ZGE4NzgtNjEzZS03ZDZjLWNhMDYtOGVlNGQ2ZDM1ZmE4JnByb3RlY3RlZHRva2VuPXRydWUmY2xhaW1zPSU3YiUyMmlkX3Rva2VuJTIyJTNhJTdiJTIyeG1zX2NjJTIyJTNhJTdiJTIydmFsdWVzJTIyJTNhJTViJTIyQ1AxJTIyJTVkJTdkJTdkJTdkJm5vbmNlPTYzODU2MzMxMDg2NzI3NjY5MC40Mzg3NjBhYy01MmI4LTRmNjMtODY1MS0zYTAwMTdiYjg3YTUmc3RhdGU9RGNzeEVvQXdDQVhSUk1mallFZ0lIendPY2NiVzB1dEw4YmJiV2tyWjA1WXFaNHBCWENIUzJXSERnSXZQS1c3Z3VFbkhjcG9QaEJ6YVNZSzUyMXB1b1RYZm83MWZ0Qjg=&sso_reload=trueHTTP Parser: No favicon
            Source: https://outlook.office365.com/owa/prefetch.aspxHTTP Parser: No favicon
            Source: https://rbiip.com/?x11d8elg2=aHR0cHM6Ly9sb2dpbi5taWNyb3NvZnRvbmxpbmUuY29tL2NvbW1vbi9vYXV0aDIvYXV0aG9yaXplP2NsaWVudF9pZD0wMDAwMDAwMi0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDAmcmVkaXJlY3RfdXJpPWh0dHBzJTNhJTJmJTJmb3V0bG9vay5vZmZpY2UuY29tJTJmb3dhJTJmJnJlc291cmNlPTAwMDAwMDAyLTAwMDAtMGZmMS1jZTAwLTAwMDAwMDAwMDAwMCZyZXNwb25zZV9tb2RlPWZvcm1fcG9zdCZyZXNwb25zZV90eXBlPWNvZGUraWRfdG9rZW4mc2NvcGU9b3BlbmlkJm1zYWZlZD0xJm1zYXJlZGlyPTEmY2xpZW50LXJlcXVlc3QtaWQ9NTU5ZGE4NzgtNjEzZS03ZDZjLWNhMDYtOGVlNGQ2ZDM1ZmE4JnByb3RlY3RlZHRva2VuPXRydWUmY2xhaW1zPSU3YiUyMmlkX3Rva2VuJTIyJTNhJTdiJTIyeG1zX2NjJTIyJTNhJTdiJTIydmFsdWVzJTIyJTNhJTViJTIyQ1AxJTIyJTVkJTdkJTdkJTdkJm5vbmNlPTYzODU2MzMxMDg2NzI3NjY5MC40Mzg3NjBhYy01MmI4LTRmNjMtODY1MS0zYTAwMTdiYjg3YTUmc3RhdGU9RGNzeEVvQXdDQVhSUk1mallFZ0lIendPY2NiVzB1dEw4YmJiV2tyWjA1WXFaNHBCWENIUzJXSERnSXZQS1c3Z3VFbkhjcG9QaEJ6YVNZSzUyMXB1b1RYZm83MWZ0Qjg=&sso_reload=trueHTTP Parser: No <meta name="author".. found
            Source: https://rbiip.com/?x11d8elg2=aHR0cHM6Ly9sb2dpbi5taWNyb3NvZnRvbmxpbmUuY29tL2NvbW1vbi9vYXV0aDIvYXV0aG9yaXplP2NsaWVudF9pZD0wMDAwMDAwMi0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDAmcmVkaXJlY3RfdXJpPWh0dHBzJTNhJTJmJTJmb3V0bG9vay5vZmZpY2UuY29tJTJmb3dhJTJmJnJlc291cmNlPTAwMDAwMDAyLTAwMDAtMGZmMS1jZTAwLTAwMDAwMDAwMDAwMCZyZXNwb25zZV9tb2RlPWZvcm1fcG9zdCZyZXNwb25zZV90eXBlPWNvZGUraWRfdG9rZW4mc2NvcGU9b3BlbmlkJm1zYWZlZD0xJm1zYXJlZGlyPTEmY2xpZW50LXJlcXVlc3QtaWQ9NTU5ZGE4NzgtNjEzZS03ZDZjLWNhMDYtOGVlNGQ2ZDM1ZmE4JnByb3RlY3RlZHRva2VuPXRydWUmY2xhaW1zPSU3YiUyMmlkX3Rva2VuJTIyJTNhJTdiJTIyeG1zX2NjJTIyJTNhJTdiJTIydmFsdWVzJTIyJTNhJTViJTIyQ1AxJTIyJTVkJTdkJTdkJTdkJm5vbmNlPTYzODU2MzMxMDg2NzI3NjY5MC40Mzg3NjBhYy01MmI4LTRmNjMtODY1MS0zYTAwMTdiYjg3YTUmc3RhdGU9RGNzeEVvQXdDQVhSUk1mallFZ0lIendPY2NiVzB1dEw4YmJiV2tyWjA1WXFaNHBCWENIUzJXSERnSXZQS1c3Z3VFbkhjcG9QaEJ6YVNZSzUyMXB1b1RYZm83MWZ0Qjg=&sso_reload=trueHTTP Parser: No <meta name="author".. found
            Source: https://rbiip.com/?x11d8elg2=aHR0cHM6Ly9sb2dpbi5taWNyb3NvZnRvbmxpbmUuY29tL2NvbW1vbi9vYXV0aDIvYXV0aG9yaXplP2NsaWVudF9pZD0wMDAwMDAwMi0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDAmcmVkaXJlY3RfdXJpPWh0dHBzJTNhJTJmJTJmb3V0bG9vay5vZmZpY2UuY29tJTJmb3dhJTJmJnJlc291cmNlPTAwMDAwMDAyLTAwMDAtMGZmMS1jZTAwLTAwMDAwMDAwMDAwMCZyZXNwb25zZV9tb2RlPWZvcm1fcG9zdCZyZXNwb25zZV90eXBlPWNvZGUraWRfdG9rZW4mc2NvcGU9b3BlbmlkJm1zYWZlZD0xJm1zYXJlZGlyPTEmY2xpZW50LXJlcXVlc3QtaWQ9NTU5ZGE4NzgtNjEzZS03ZDZjLWNhMDYtOGVlNGQ2ZDM1ZmE4JnByb3RlY3RlZHRva2VuPXRydWUmY2xhaW1zPSU3YiUyMmlkX3Rva2VuJTIyJTNhJTdiJTIyeG1zX2NjJTIyJTNhJTdiJTIydmFsdWVzJTIyJTNhJTViJTIyQ1AxJTIyJTVkJTdkJTdkJTdkJm5vbmNlPTYzODU2MzMxMDg2NzI3NjY5MC40Mzg3NjBhYy01MmI4LTRmNjMtODY1MS0zYTAwMTdiYjg3YTUmc3RhdGU9RGNzeEVvQXdDQVhSUk1mallFZ0lIendPY2NiVzB1dEw4YmJiV2tyWjA1WXFaNHBCWENIUzJXSERnSXZQS1c3Z3VFbkhjcG9QaEJ6YVNZSzUyMXB1b1RYZm83MWZ0Qjg=&sso_reload=trueHTTP Parser: No <meta name="copyright".. found
            Source: https://rbiip.com/?x11d8elg2=aHR0cHM6Ly9sb2dpbi5taWNyb3NvZnRvbmxpbmUuY29tL2NvbW1vbi9vYXV0aDIvYXV0aG9yaXplP2NsaWVudF9pZD0wMDAwMDAwMi0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDAmcmVkaXJlY3RfdXJpPWh0dHBzJTNhJTJmJTJmb3V0bG9vay5vZmZpY2UuY29tJTJmb3dhJTJmJnJlc291cmNlPTAwMDAwMDAyLTAwMDAtMGZmMS1jZTAwLTAwMDAwMDAwMDAwMCZyZXNwb25zZV9tb2RlPWZvcm1fcG9zdCZyZXNwb25zZV90eXBlPWNvZGUraWRfdG9rZW4mc2NvcGU9b3BlbmlkJm1zYWZlZD0xJm1zYXJlZGlyPTEmY2xpZW50LXJlcXVlc3QtaWQ9NTU5ZGE4NzgtNjEzZS03ZDZjLWNhMDYtOGVlNGQ2ZDM1ZmE4JnByb3RlY3RlZHRva2VuPXRydWUmY2xhaW1zPSU3YiUyMmlkX3Rva2VuJTIyJTNhJTdiJTIyeG1zX2NjJTIyJTNhJTdiJTIydmFsdWVzJTIyJTNhJTViJTIyQ1AxJTIyJTVkJTdkJTdkJTdkJm5vbmNlPTYzODU2MzMxMDg2NzI3NjY5MC40Mzg3NjBhYy01MmI4LTRmNjMtODY1MS0zYTAwMTdiYjg3YTUmc3RhdGU9RGNzeEVvQXdDQVhSUk1mallFZ0lIendPY2NiVzB1dEw4YmJiV2tyWjA1WXFaNHBCWENIUzJXSERnSXZQS1c3Z3VFbkhjcG9QaEJ6YVNZSzUyMXB1b1RYZm83MWZ0Qjg=&sso_reload=trueHTTP Parser: No <meta name="copyright".. found
            Source: unknownHTTPS traffic detected: 20.190.159.71:443 -> 192.168.2.17:49703 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 20.190.159.71:443 -> 192.168.2.17:49705 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 13.85.23.86:443 -> 192.168.2.17:49711 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 2.19.104.72:443 -> 192.168.2.17:49712 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 2.19.104.72:443 -> 192.168.2.17:49713 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 13.85.23.86:443 -> 192.168.2.17:49787 version: TLS 1.2
            Source: unknownTCP traffic detected without corresponding DNS query: 20.190.159.71
            Source: unknownTCP traffic detected without corresponding DNS query: 20.190.159.71
            Source: unknownTCP traffic detected without corresponding DNS query: 20.190.159.71
            Source: unknownTCP traffic detected without corresponding DNS query: 20.190.159.71
            Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.200
            Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.200
            Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.200
            Source: unknownTCP traffic detected without corresponding DNS query: 20.190.159.71
            Source: unknownTCP traffic detected without corresponding DNS query: 20.190.159.71
            Source: unknownTCP traffic detected without corresponding DNS query: 20.190.159.71
            Source: unknownTCP traffic detected without corresponding DNS query: 20.190.159.71
            Source: unknownTCP traffic detected without corresponding DNS query: 20.190.159.71
            Source: unknownTCP traffic detected without corresponding DNS query: 20.190.159.71
            Source: unknownTCP traffic detected without corresponding DNS query: 20.190.159.71
            Source: unknownTCP traffic detected without corresponding DNS query: 20.190.159.71
            Source: unknownTCP traffic detected without corresponding DNS query: 20.190.159.71
            Source: unknownTCP traffic detected without corresponding DNS query: 20.190.159.71
            Source: unknownTCP traffic detected without corresponding DNS query: 20.190.159.71
            Source: unknownTCP traffic detected without corresponding DNS query: 20.190.159.71
            Source: unknownTCP traffic detected without corresponding DNS query: 20.190.159.71
            Source: unknownTCP traffic detected without corresponding DNS query: 20.190.159.71
            Source: unknownTCP traffic detected without corresponding DNS query: 20.190.159.71
            Source: unknownTCP traffic detected without corresponding DNS query: 20.190.159.71
            Source: unknownTCP traffic detected without corresponding DNS query: 20.190.159.71
            Source: unknownTCP traffic detected without corresponding DNS query: 20.190.159.71
            Source: unknownTCP traffic detected without corresponding DNS query: 20.190.159.71
            Source: unknownTCP traffic detected without corresponding DNS query: 20.190.159.71
            Source: unknownTCP traffic detected without corresponding DNS query: 20.190.159.71
            Source: unknownTCP traffic detected without corresponding DNS query: 20.190.159.71
            Source: unknownTCP traffic detected without corresponding DNS query: 20.190.159.71
            Source: unknownTCP traffic detected without corresponding DNS query: 20.190.159.71
            Source: unknownTCP traffic detected without corresponding DNS query: 20.190.159.71
            Source: unknownTCP traffic detected without corresponding DNS query: 20.190.159.71
            Source: unknownTCP traffic detected without corresponding DNS query: 20.190.159.71
            Source: unknownTCP traffic detected without corresponding DNS query: 20.190.159.71
            Source: unknownTCP traffic detected without corresponding DNS query: 20.190.159.71
            Source: unknownTCP traffic detected without corresponding DNS query: 20.190.159.71
            Source: unknownTCP traffic detected without corresponding DNS query: 20.190.159.71
            Source: unknownTCP traffic detected without corresponding DNS query: 20.190.159.71
            Source: unknownTCP traffic detected without corresponding DNS query: 20.190.159.71
            Source: unknownTCP traffic detected without corresponding DNS query: 20.190.159.71
            Source: unknownTCP traffic detected without corresponding DNS query: 20.190.159.71
            Source: unknownTCP traffic detected without corresponding DNS query: 20.190.159.71
            Source: unknownTCP traffic detected without corresponding DNS query: 20.190.159.71
            Source: unknownTCP traffic detected without corresponding DNS query: 20.190.159.71
            Source: unknownTCP traffic detected without corresponding DNS query: 20.190.159.71
            Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
            Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
            Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
            Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
            Source: global trafficDNS traffic detected: DNS query: ara1233mark.com
            Source: global trafficDNS traffic detected: DNS query: challenges.cloudflare.com
            Source: global trafficDNS traffic detected: DNS query: www.google.com
            Source: global trafficDNS traffic detected: DNS query: rbiip.com
            Source: global trafficDNS traffic detected: DNS query: aadcdn.msftauth.net
            Source: global trafficDNS traffic detected: DNS query: outlook.office365.com
            Source: global trafficDNS traffic detected: DNS query: r4.res.office365.com
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
            Source: unknownNetwork traffic detected: HTTP traffic on port 49766 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49746 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49769 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49720 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49734
            Source: unknownNetwork traffic detected: HTTP traffic on port 49772 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49733
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49732
            Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
            Source: unknownNetwork traffic detected: HTTP traffic on port 49732 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49691
            Source: unknownNetwork traffic detected: HTTP traffic on port 49728 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49729
            Source: unknownNetwork traffic detected: HTTP traffic on port 49752 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49728
            Source: unknownNetwork traffic detected: HTTP traffic on port 49777 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49727
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49726
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49725
            Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49724
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49723
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49722
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49720
            Source: unknownNetwork traffic detected: HTTP traffic on port 49706 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49787 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49729 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49760 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49745 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49719
            Source: unknownNetwork traffic detected: HTTP traffic on port 49751 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49680 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
            Source: unknownNetwork traffic detected: HTTP traffic on port 49774 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
            Source: unknownNetwork traffic detected: HTTP traffic on port 49757 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49782 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49734 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49677 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49726 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49765 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49768 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49723 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49706
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49705
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49704
            Source: unknownNetwork traffic detected: HTTP traffic on port 49754 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
            Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49733 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49787
            Source: unknownNetwork traffic detected: HTTP traffic on port 49676 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49782
            Source: unknownNetwork traffic detected: HTTP traffic on port 49727 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49704 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49691 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49762 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49776 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49759 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49753 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49778
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49777
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49776
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49775
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49774
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49773
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49772
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49770
            Source: unknownNetwork traffic detected: HTTP traffic on port 49724 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49767 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49773 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49769
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49768
            Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49756 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49767
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49766
            Source: unknownNetwork traffic detected: HTTP traffic on port 49758 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49765
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49764
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49762
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49761
            Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49760
            Source: unknownNetwork traffic detected: HTTP traffic on port 49725 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49764 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49770 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49719 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49722 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49759
            Source: unknownNetwork traffic detected: HTTP traffic on port 49778 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49758
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49757
            Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49755 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49756
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49755
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49754
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49753
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49752
            Source: unknownNetwork traffic detected: HTTP traffic on port 49705 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49751
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
            Source: unknownNetwork traffic detected: HTTP traffic on port 49761 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49747 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49775 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49747
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49746
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49745
            Source: unknownHTTPS traffic detected: 20.190.159.71:443 -> 192.168.2.17:49703 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 20.190.159.71:443 -> 192.168.2.17:49705 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 13.85.23.86:443 -> 192.168.2.17:49711 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 2.19.104.72:443 -> 192.168.2.17:49712 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 2.19.104.72:443 -> 192.168.2.17:49713 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 13.85.23.86:443 -> 192.168.2.17:49787 version: TLS 1.2
            Source: classification engineClassification label: mal68.phis.winONE@21/247@20/63
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEFile created: C:\Users\user\AppData\Local\Microsoft\OneNote
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXEMutant created: \Sessions\1\BaseNamedObjects\OneNoteM:AppShared
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEFile created: C:\Users\user\AppData\Local\Temp\{8F65AAE7-671E-42FD-AD1B-C3FE2BC6B233} - OProcSessId.dat
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEFile read: C:\Program Files (x86)\desktop.ini
            Source: unknownProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\ONENOTE.EXE" "C:\Users\user\Desktop\Sign.one"
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE /tsr
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://ara1233mark.com/?rbmuwcdb
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2200 --field-trial-handle=1904,i,15573565381678590775,4567774448021983184,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE /tsr
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://ara1233mark.com/?rbmuwcdb
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2200 --field-trial-handle=1904,i,15573565381678590775,4567774448021983184,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXESection loaded: c2r32.dll
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXESection loaded: userenv.dll
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXESection loaded: msimg32.dll
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXESection loaded: vcruntime140.dll
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXESection loaded: msvcp140.dll
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXESection loaded: uxtheme.dll
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXESection loaded: msi.dll
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXESection loaded: srpapi.dll
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXESection loaded: kernel.appcore.dll
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXESection loaded: kernel.appcore.dll
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXESection loaded: msasn1.dll
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXESection loaded: windows.storage.dll
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXESection loaded: wldp.dll
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{104D4F7F-2292-42EE-A942-C820C720B38B}\InprocServer32
            Source: Window RecorderWindow detected: More than 3 window changes detected
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Common
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Send to OneNote.lnk
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXEProcess information set: NOOPENFILEERRORBOX
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information queried: ProcessInformation
            Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid
            ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
            Gather Victim Identity InformationAcquire Infrastructure1
            Drive-by Compromise
            Windows Management Instrumentation1
            DLL Side-Loading
            1
            Process Injection
            1
            Masquerading
            OS Credential Dumping1
            Process Discovery
            Remote ServicesData from Local System2
            Encrypted Channel
            Exfiltration Over Other Network MediumAbuse Accessibility Features
            CredentialsDomainsDefault AccountsScheduled Task/Job1
            Registry Run Keys / Startup Folder
            1
            DLL Side-Loading
            1
            Process Injection
            LSASS Memory1
            File and Directory Discovery
            Remote Desktop ProtocolData from Removable Media1
            Non-Application Layer Protocol
            Exfiltration Over BluetoothNetwork Denial of Service
            Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)1
            Registry Run Keys / Startup Folder
            1
            DLL Side-Loading
            Security Account Manager2
            System Information Discovery
            SMB/Windows Admin SharesData from Network Shared Drive2
            Application Layer Protocol
            Automated ExfiltrationData Encrypted for Impact

            This section contains all screenshots as thumbnails, including those not shown in the slideshow.


            windows-stand
            No Antivirus matches
            No Antivirus matches
            No Antivirus matches
            No Antivirus matches
            No Antivirus matches
            NameIPActiveMaliciousAntivirus DetectionReputation
            ooc-g2.tm-4.office.com
            40.99.150.2
            truefalse
              unknown
              challenges.cloudflare.com
              104.17.2.184
              truefalse
                unknown
                sni1gl.wpc.omegacdn.net
                152.199.21.175
                truefalse
                  unknown
                  www.google.com
                  216.58.212.132
                  truefalse
                    unknown
                    ara1233mark.com
                    141.11.88.237
                    truefalse
                      unknown
                      rbiip.com
                      141.11.88.237
                      truetrue
                        unknown
                        s-part-0032.t-0009.t-msedge.net
                        13.107.246.60
                        truefalse
                          unknown
                          r4.res.office365.com
                          unknown
                          unknownfalse
                            unknown
                            aadcdn.msftauth.net
                            unknown
                            unknownfalse
                              unknown
                              outlook.office365.com
                              unknown
                              unknownfalse
                                unknown
                                NameMaliciousAntivirus DetectionReputation
                                https://ara1233mark.com/?rbmuwcdb=512d552bfe569d0ede3144971cee43cc2eeed49e97097aff88e5cb8febef8519b5f8da93e9770a4a506eec9ad07e92fb8f25525040407d6a6437bc53f18d11d1false
                                  unknown
                                  https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv0/0/zbir7/0x4AAAAAAAe5DN2aGx7A8rqu/auto/fbE/normal/auto/false
                                    unknown
                                    https://outlook.office365.com/owa/prefetch.aspxfalse
                                      unknown
                                      • No. of IPs < 25%
                                      • 25% < No. of IPs < 50%
                                      • 50% < No. of IPs < 75%
                                      • 75% < No. of IPs
                                      IPDomainCountryFlagASNASN NameMalicious
                                      52.113.194.132
                                      unknownUnited States
                                      8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                      40.99.150.2
                                      ooc-g2.tm-4.office.comUnited States
                                      8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                      142.250.74.202
                                      unknownUnited States
                                      15169GOOGLEUSfalse
                                      216.58.212.132
                                      www.google.comUnited States
                                      15169GOOGLEUSfalse
                                      142.250.186.163
                                      unknownUnited States
                                      15169GOOGLEUSfalse
                                      52.178.17.2
                                      unknownUnited States
                                      8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                      40.126.31.71
                                      unknownUnited States
                                      8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                      104.17.3.184
                                      unknownUnited States
                                      13335CLOUDFLARENETUSfalse
                                      64.233.166.84
                                      unknownUnited States
                                      15169GOOGLEUSfalse
                                      239.255.255.250
                                      unknownReserved
                                      unknownunknownfalse
                                      142.250.185.142
                                      unknownUnited States
                                      15169GOOGLEUSfalse
                                      52.109.32.97
                                      unknownUnited States
                                      8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                      52.109.89.19
                                      unknownUnited States
                                      8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                      141.11.88.237
                                      ara1233mark.comUnited Kingdom
                                      3215FranceTelecom-OrangeFRtrue
                                      152.199.21.175
                                      sni1gl.wpc.omegacdn.netUnited States
                                      15133EDGECASTUSfalse
                                      104.17.2.184
                                      challenges.cloudflare.comUnited States
                                      13335CLOUDFLARENETUSfalse
                                      23.38.98.96
                                      unknownUnited States
                                      16625AKAMAI-ASUSfalse
                                      IP
                                      192.168.2.17
                                      192.168.2.16
                                      Joe Sandbox version:40.0.0 Tourmaline
                                      Analysis ID:1471857
                                      Start date and time:2024-07-11 23:43:42 +02:00
                                      Joe Sandbox product:CloudBasic
                                      Overall analysis duration:
                                      Hypervisor based Inspection enabled:false
                                      Report type:full
                                      Cookbook file name:defaultwindowsinteractivecookbook.jbs
                                      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                      Number of analysed new started processes analysed:18
                                      Number of new started drivers analysed:0
                                      Number of existing processes analysed:0
                                      Number of existing drivers analysed:0
                                      Number of injected processes analysed:0
                                      Technologies:
                                      • EGA enabled
                                      Analysis Mode:stream
                                      Analysis stop reason:Timeout
                                      Sample name:Sign.one
                                      Detection:MAL
                                      Classification:mal68.phis.winONE@21/247@20/63
                                      Cookbook Comments:
                                      • Found application associated with file extension: .one
                                      • Exclude process from analysis (whitelisted): dllhost.exe, TextInputHost.exe, svchost.exe
                                      • Excluded IPs from analysis (whitelisted): 52.109.32.97, 52.109.89.19, 52.113.194.132
                                      • Excluded domains from analysis (whitelisted): ecs.office.com, prod.configsvc1.live.com.akadns.net, weu-azsc-000.roaming.officeapps.live.com, ctldl.windowsupdate.com, prod.roaming1.live.com.akadns.net, eur.roaming1.live.com.akadns.net, s-0005-office.config.skype.com, ecs-office.s-0005.s-msedge.net, roaming.officeapps.live.com, osiprod-weu-buff-azsc-000.westeurope.cloudapp.azure.com, login.live.com, s-0005.s-msedge.net, config.officeapps.live.com, officeclient.microsoft.com, ecs.office.trafficmanager.net, ukw-azsc-config.officeapps.live.com, europe.configsvc1.live.com.akadns.net
                                      • Not all processes where analyzed, report is missing behavior information
                                      • Report size getting too big, too many NtQueryValueKey calls found.
                                      • VT rate limit hit for: Sign.one
                                      InputOutput
                                      URL: https://rbiip.com/?x11d8elg2=aHR0cHM6Ly9sb2dpbi5taWNyb3NvZnRvbmxpbmUuY29tL2NvbW1vbi9vYXV0aDIvYXV0aG9yaXplP2NsaWVudF9pZD0wMDAwMDAwMi0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDAmcmVkaXJlY3RfdXJpPWh0dHBzJTNhJTJmJTJmb3V0bG9vay5vZmZpY2UuY29tJTJmb3dhJTJmJnJlc291cmNlPT Model: Perplexity: mixtral-8x7b-instruct
                                      {"loginform": true,"urgency": false,"captcha": false,"reasons": ["The webpage contains a login form which explicitly requests sensitive information such as email addresses and passwords.","The text does not create a sense of urgency or interest.","The webpage does not contain a CAPTCHA or any other anti-robot detection mechanism."]}
                                      Title: 5cclfhw0t0 OCR: Outlook Microsoft Sign in to continue to Outlook Email, phone, or Skype No account? Create one! Can't access your account? Next Sign-in options Terms of use Privacy & 
                                      URL: https://rbiip.com Model: gpt-4o
                                      ```json{  "phishing_score": 9,  "brands": "Microsoft Outlook",  "phishing": true,  "suspicious_domain": true,  "has_prominent_loginform": true,  "has_captcha": false,  "setechniques": true,  "has_suspicious_link": false,  "legitmate_domain": "outlook.com",  "reasons": "The URL 'https://rbiip.com' does not match the legitimate domain 'outlook.com' associated with Microsoft Outlook. The page prominently displays a login form, which is a common tactic used in phishing attacks to harvest user credentials. The domain name 'rbiip.com' is suspicious and unrelated to Microsoft or Outlook, indicating a high likelihood of phishing. Additionally, the use of social engineering techniques is evident as the page mimics the legitimate Outlook login page to deceive users."}
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                      Category:dropped
                                      Size (bytes):174490
                                      Entropy (8bit):5.289607187770432
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:1B48F0364E9059245CDCEB050697DD29
                                      SHA1:EC7A1B96D1443AF3A95F16DC1FAF53C2ECDD2FD4
                                      SHA-256:3F63E74D82D99721601A1CE1B13E7F113A615074169C9E96B1CF16AB05413A2B
                                      SHA-512:D52C32B56ACF9BB941F35DD28A5EBDCEF4D859C3615DEC1D9C500187783C93A3AE1DADE0645C8C9D106C48554A85D9C74B6D953B7B7E2F0906AE1767CFF4C0AB
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:<?xml version="1.0" encoding="utf-8"?>..<o:OfficeConfig xmlns:o="urn:schemas-microsoft-com:office:office">.. <o:services o:GenerationTime="2024-07-11T21:44:10">.. Build: 16.0.17828.40125-->.. <o:default>.. <o:ticket o:headerName="Authorization" o:headerValue="{}" />.. </o:default>.. <o:service o:name="Research">.. <o:url>https://word-edit.officeapps.live.com/we/rrdiscovery.ashx</o:url>.. </o:service>.. <o:service o:name="ORedir">.. <o:url>https://o15.officeredir.microsoft.com/r</o:url>.. </o:service>.. <o:service o:name="ORedirSSL">.. <o:url>https://o15.officeredir.microsoft.com/r</o:url>.. </o:service>.. <o:service o:name="ClViewClientHelpId" o:authentication="1">.. <o:url>https://[MAX.BaseHost]/client/results</o:url>.. <o:ticket o:policy="MBI_SSL_SHORT" o:idprovider="1" o:target="[MAX.AuthHost]" o:headerValue="Passport1.4 from-PP='{}&amp;p='" />.. <o:ticket o:idprovider="3" o:headerValue="Bearer {}" o:resourceId="[
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:SQLite 3.x database, last written using SQLite version 3023002, writer version 2, read version 2, file counter 2, database pages 1, cookie 0, schema 0, largest root page 1, unknown 0 encoding, version-valid-for 2
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):0.09216609452072291
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:F138A66469C10D5761C6CBB36F2163C3
                                      SHA1:EEA136206474280549586923B7A4A3C6D5DB1E25
                                      SHA-256:C712D6C7A60F170A0C6C5EC768D962C58B1F59A2D417E98C7C528A037C427AB6
                                      SHA-512:9D25F943B6137DD2981EE75D57BAF3A9E0EE27EEA2DF19591D580F02EC8520D837B8E419A8B1EB7197614A3C6D8793C56EBC848C38295ADA23C31273DAA302D9
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:SQLite format 3......@ .......................................................................... .....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:SQLite Rollback Journal
                                      Category:dropped
                                      Size (bytes):4616
                                      Entropy (8bit):0.13640804182083316
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:1E0347600C0627958FAF1BD0797D2B4C
                                      SHA1:B83031A2C42D268201D8571055E57C2B66CEDB5D
                                      SHA-256:B103F3D371DE90CD7E7A2018FC00F3221250475D2306B0D56237F52C13E99967
                                      SHA-512:833FE76CC7E61871FAA3A13E29B850DA1D794D94DF30DFBD05ED1482109315502ABB50180F446AAEB8DAC904025B8669CCE468FFA419C7EAF9A018C51335C058
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:.... .c......a......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................SQLite format 3......@ .......................................................................... .................................................................................................................................................................................................................................................................................................................................................................................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):32768
                                      Entropy (8bit):0.04482848510499482
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:A9908D7A872F75C5FF1F779F6B05000C
                                      SHA1:A781960A260885B05955B4F8E708A9E7C763315B
                                      SHA-256:378C216D366E218E3E1A4ABF157631D664FC7A0BA2F990C50F5F85A25BA9E34F
                                      SHA-512:4F4BF59409B9BBE1A8EDC2C6F6941FDC6D676A469E7A21079AC98FDB45019876A83B1762C759FAB1A866D455C0A4F2E2E7186DCF7CF9E7C454B6CB7A5B5D27B6
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:..-........................ =.|..nF..7..*t.v9.Hq..-........................ =.|..nF..7..*t.v9.Hq........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:SQLite Write-Ahead Log, version 3007000
                                      Category:modified
                                      Size (bytes):45352
                                      Entropy (8bit):0.3938750968673551
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:3DC600B8AB54BE98133559DC38C9E9F4
                                      SHA1:0F8B6556C8E96CCC37843C0FC6AE8730AB0E8B70
                                      SHA-256:57FDEC971D697070D305A313DE43C1F5741FDAABE4B217AAA941B30454C1C1CB
                                      SHA-512:50BCA94035D048E5E6DF1CE1491757CDE1DFACC2B090F9F1D8337336EB87E412AF0DF713F29904B5A709C502A293F108630D9866060F3931882E332052F60527
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:7....-...........nF..7...-q'D...........nF..7.......6.SQLite format 3......@ .......................................................................... .............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):73728
                                      Entropy (8bit):3.7676145183037275
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:B37542F571608125BBB701102042A0C8
                                      SHA1:7A9A981689061F565162B7B3845CAA50C633ACC1
                                      SHA-256:453E067EAA89ED379751462F2A3391652E647ECF942F08F2FC5B8AF4EE0A0A29
                                      SHA-512:99A62CC9AD8B10513F16CD01F103FA968FEDAFFAE6941A9E69DFD342559FEC4D616483DB9FD38E2A4E4704E24646DDEB4FC6386D77FE96BAED6041D307D34622
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:^!..P$..,...r.....I..2.p..s:....P..........gG.x........X.......x.......x... ...8...........................................?...............................................................................................................<..........?.............................................................?....?.........................................(................x.l........?..........................?......................................................................................................................................................<.....................................................................?................................................................................................................................'................................................?............................?.................................E?.MxL...D......-}.....E?..N.................\..@Z...B....G~..$;....Y.[......<yX1$...2.xdF$............-}....MxL...D......-}
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:CD74ABACE8A00B17BD8107BC5982C21E
                                      SHA1:D53193CF8A43D766FBFA52976192F44D6B0F79B2
                                      SHA-256:B670BC07C9CB554511180DCF3F6A2C7818E8CE6E67B84784F0EA4D35EC61D516
                                      SHA-512:1B48A37FCF0F9FB9ED9B31A8F3E36596689BF1EEC6F41F5EFA3C728121944919CE7A81F0379A108D80AA051CFEF07DC296F9C0691FC8855983B2F29EC15C7FEF
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:C37C5511511A3B7ECAE48CC5B9107D59
                                      SHA1:8E3190E824A68D60E125CE90B595AEB5EFEEF15E
                                      SHA-256:5B0C5D594672E3B7D780D3CCA34564C79EFC0B0F37F28E0E6694A81E45618083
                                      SHA-512:45BFD6EBD0811BF2416E26DDA38381DDDC93BC4FBC0C6603302BD1A495938AFEF59DA64E740D0AD1B36A43C39D73B1411F5E77B1A862384A9DF56E4A9C7BEDCE
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>...........~.......................................................................................................................................................................................N.......N..A|G......>3........................N..A|G......>3N....................................................N...........................................................N..P..............................................................................5........m;.H....7.5N.........~zu..........3.n..8QB............N...^...........................................................................................................3.n..8QB....................................................................................................................................................................................................................................................................................................................................................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:3C4A7B04BC2806375A4F7CF96706665D
                                      SHA1:CDD1772F8E8891DF310CADC155ABAFF5D17ACE57
                                      SHA-256:FC92747E03E896B920890ED9BF20043C3DF12AE8C67D450422E9CA3E55861A8D
                                      SHA-512:BBBD5972B148BDFDA727E2E22B396527CB0BDB04B906C4A4E1B1A5ED43E3F3108D8874153E4E77E6513FA1F6D2544525AC9916F46BBCD46C6208ED72EA7EC628
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:x.......8..........@.................?..........................?.......................................................................................H.......t.......f...............0................+8......+8*V..O..>.+R.$.W]......W].^..... .-...e....s..E?..N....W].^..E.,.0.5zw.W]..+8*V..O..>.+R...+8.......+8...................................................................5......N..A|G......>3................+8............................................................X.........Q..................+8..W].3.4[.<G...HD7......h.... ...... H.68L..b....,.+8......+8*V..O..>.+R.$...............E?..N.e.......e..9...H./.....<G...HD7............W]......W]..................................................W]..C...W]`.1...W]..F....................................................4..~...1...(...(.......O.p.e.n. .S.e.c.t.i.o.n.s.......O.p.e.n. .S.e.c.t.i.o.n.s...........1.......O.p.e.n. .S.e.c.t.i.o.n.s..........W]......W].^..E.,.0.5zw...............E?..N.2.......................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:PNG image data, 1035 x 500, 8-bit/color RGBA, non-interlaced
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:1673BA0257F532D7A4D6FFCA319D0D80
                                      SHA1:0E542AF474CF50B3D2D9ACD7E0DBFB8854684E2E
                                      SHA-256:8C9BCBF69CB4F036A4C87B866F44A23F41609300751BB02332A717E770792EE5
                                      SHA-512:8A3A8C0D697BC75743FC98D5BE33CE9B4336498F1E5EDF919C8A8AAF835CC1017183E5EBF764CA2C80097B1F4E1EB491B14A6EDD3FCD3F3762C4B4263EB4EDD2
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:.PNG........IHDR.............[.....BiCCPICC Profile..H..W.XS...[..@h.......).....H/...$@(!....YTp-.X....(v@,(bgQl.....X.+oR@.}.{.}s.....sg....I.H.....#..G...'$&.I=.......h.7O......../.n.D.^..j.......?.....q*/....!..*.H...Q.M..I1.@K...x....q.....>.Ml4..V..T8.q:..W O/.C..~...<...5:..99.<.S ..6"......t....:....c.\dE._.'....?..KN.d.%.*...h.a.ne.J...}.....5!. ...!F)...8.=j..c......y..P.. ..f..)..4A .b.B..|v,../....(l6.s.....41....s.2.R_.$YqL....>[....f.&@L..@....*..yY1...q....!..$Z..9..|a..\.+H..F+.Ks..m......@~Fl.<?X+.#.......2.t.y............q1....|.h.X.".T.... )o..s^A.b,.....\.O..G.....39!..x.. ...?..... .d.A{_C.........t....fhD..G..1............A.....=H....Fd....P...%.Q.ao...d........U....!.;.L....y...Y.....`b ....qO<.^}au.....<.....:...7.]..S.E.....~."..?...........2....{...a.>..dY...Y........4.vdG2J.A.%[.<R.V.eXE....#.5u8....~.>...?[b....9..v.;.5.:.5bm.q).^]Od.k.[.,.,.#....'+.d.c.c...y_>.....X...bAzF>....|:[.u.Ewrtr.@.}....D...N.wn...x5......4.
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:PNG image data, 131 x 78, 8-bit/color RGBA, non-interlaced
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:D2647231ABEC666AC4153973FD9047C8
                                      SHA1:4D543CCDDB327F29973B1B42C6FC72B1D92DAB51
                                      SHA-256:EA0C3724E1F1E7588A30604C634E4938FBD4151CFD4E48397880B2BF236E47AC
                                      SHA-512:72406E88027F9B8B452C2F2B2DB41AE73380F4C486B576CC9D9A79FF9DE71139EBE91FA47FBD8714D603DCA6F51923156604AE5C05AD73128D4A888D512CA15F
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:.PNG........IHDR.......N............sRGB....... .IDATx^.}.x....,.z...$. l!!.a..EQ*.((....J[[..j........D.\J*..+{..@Y..a'..s.o....PD..U..<..7..w.9.s!.X.J.I..$.J.Y...p..'$p.......C..(gV........\.9......)..\3|6...O....p.j..y...q..b.~p0..,...M.....>...:..Zy.E.d.8<.?.B..n..........wv..U.....I.....z....B^2..~..C..@.;W.d..........}.v...".Z"........y...^.-.w...}.'.qk.E...{ulJ..E.="....0y.S...oT..........l_.7o.`...{...g.......%.2..".(V...:}.,!...l.....8...e.9.3.K.....o.....................wK...%..;&..........v...........@..d.8.N..QV...._.<S.wO...%.)s.....|m...'..$._..8...ww.!.).......o......R\..F..7....y._...........i....w|...h..?.FK.....C...a.....~~"..>}A.P........X.....W..T......x'..>...ny./6._.....f_.(.s.b...5....[....:e.'8W...V.I...w.fg.&..*......?y..[..Ny.....t.../(.....(...WF.t..(......0..MO.+%Z~.:l..}..3jy...P:=..(......4..}..t.]Yv.C).......(7.......~...T...&8.6ZXf1:-..??..|.n......Af..1......v.9....Q..nP0Z....C>cN..N.{`F...
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:PNG image data, 1024 x 495, 8-bit/color RGBA, non-interlaced
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:29A82AF68823DAE68B457FC868B69E75
                                      SHA1:8079D1F5555A3654E4DE8498AFA912FCE89BB4A9
                                      SHA-256:8BC02A5602CA1CCEEB66E0D664380163EA4CF19966007982BDBE7B757561EE57
                                      SHA-512:7A0C305D122E9ACD2DC8A261D1C4A28F1E47BAC819D50F16BAD927D16C193011A6DAF25065B142C16952A29A42AB6F49C2E8DCFF47052FDDE85DEE0EEB2AE263
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:.PNG........IHDR..............7.s....sRGB.........gAMA......a.....pHYs...%...%.IR$.....IDATx^..gt\...>...[.......2.2.R.JUjS5-.j.O......>.9g..Nu..9S..wJ...[z... ..............@&H.@......D....}#..oW=p..B.!..B.!V4.3.B.!..B.!.X... ..B.!..B..2..!..B.!..~...B.!..B.!.. ...B.!..B..... ..B.!..B..2..!..B.!..~...B.!..B.!.. ...B.!..B..... ..B.!..B..2..!..B.!..~...B.!..B.!.. ...B.!..B..... ..B.!..B..2..!..B.!..~...B.!..B.!.. ...B.!..B..... ..B.!..B..2..!..B.!..~...B.!..B.!.. ...B.!..B..... ..B.!..B....8.<.3LOOcjj....3.<..V..- .....(.........37...5...=....G...1......w>..B.!..B.....`tt....hoo.-...P....""".....8_1(..W.OLL`hh.}}}.6...1<<lkell....Z...............{......{O..c.\###v^.5.c.QQQv..,..B.!...A..9......q....v..E^HH..........t$''.........oA1N.N!N......z444....]]]........:.>.~||<.........<..."%%..q.5.x.....;Gkk..... ?.....W.z..@kG.!..B.1.d.....Z|......~`..Y...6....k......B...(.Gw.1(..~-...z.q.m|N.Na>00.0.`v...7.+.?........6.w...wo.M@...gq..e.w...4*......Gqq..C)%B.!..B.. ...
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:A0E6E60B64F8435A8FE7EE4E4870E982
                                      SHA1:EB054B4F01F683479E6CBE84CF9B7D9B679A1345
                                      SHA-256:7D6D79843C6359A1AF88444980EA3AD798CAF1370C94592AABA37CD1AF6B1835
                                      SHA-512:9CEEB4DD5F0D7B085E3102AB87263F19D7F6F814E0235D1FD1546A8695F4D377EEE7B9478AD82C8D0E6EF99321669AA40A31CBB7D04B04C8FFB8EFDD818A87CB
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:j..@...@<.......(.......................................................................................................................................j..@...@t.......(............................................KN.|.+.....{[......{[k....+..{:n...e.A.........@..e..j...j...0!.1%CT.j......1....$...E.q.........................................................................[[a.....[[a%j.^B.5..gaR.........I...M.....J..2... ...^............................{[.[[a.%}m......!..............T&.....T$...[[aT%q..%}mT.N...............".......l....T.:..............{[..c..,0...e...B4.$..........C@RQ.H..B......Y....................%}m.....%}m.|..@...?.P.............1....$...E.q.%}m.|..@...?.P..%}m.[[a%j.^B.5..gaR[[a...I...M.....J.........>..................1....$...E.q..{[k....+..{:n.N[[a%j.^B.5..gaR.!.......!.+....h1.r..P.........I...M.....J.......[[a.....j....c..,0...e...B4.$...........I...M.....0...............................0...........e....4..................T.i.t.l.e.......|{
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:E430E87846AE0F7C398B93C1041EC163
                                      SHA1:30902792C653FA3010B34A7342196E70D28D0E69
                                      SHA-256:C0206F5F3C4BAF1DB8B2AA4EDF9EB39005A04DC60BA60DD21A5224849E77336F
                                      SHA-512:A5C47A8CC2C8A12B2187A4AB332E96330C3FF38BD1722A0954B12D411FA11E0CDD46889D3CC9837E38C04076EDBEF76F134748EA8A1AB3C6DFEE14E7260D6856
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......t...v...h...................................................................................................................................2...>...P.......v................................I.......I.qk..B.....LZG.6.4...G.6/.....U......G.6/.....U......G.6..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'......................R.I.....N...^................Z*.S.O..Ha...............>...............................$....I.qk..B.....LZ.....................R.I..................R.I..........G.6.....G.6.....G.6.........................................G.6j....G.6T%;..G.6.....G.6..W..G.6H....G.6..+..G.6..S..G.6..........Z4...........................................4../4......p...............C.a.l.i.b.r.i..................G.6:G.6kG.6..z...y.. x.. ...........$...........7...7.....*...o.e.L.o.c.I.D...o.e.L.o.c.C.o.m.m.e.n.t.......0.0.0.3
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:9436BA36BA19A217635F9CCCD9787680
                                      SHA1:A086C796A3994D30FC59B57EB67DFA58C8D1FEFD
                                      SHA-256:3A4CA44FC443343A1D6452EB7651283E58B016A60ED7AEDF04D1E8CD15AF5A86
                                      SHA-512:5F86442A9CD2FDA5DE20CE3B545CBC4B867D2461DE850A5175BFCCEB2CF6A12278CB68952D2FF175A7E82AEF441C72359F5D105A727B510E32A07E3813AF93F2
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>...........v........ ...)..2...>...B.......v.......@....(...........................................................................................................................................I.......I.qk..B.....LZ.==.H....==f.S..0.../....==f.S..0.../....==..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'............._..s....'..bf0.t....N...^...................F..A.#.....[............................................"....I.qk..B.....LZ............_..s....'..bf0.t..................................==......==......==..........................................==j."...==T.....==......==..T...==......== .A...==......== .........==3.==:.==8.==..z...y.. x.. ........ ..$...$........D..........7...7.........*...o.e.L.o.c.I.D...o.e.L.o.c.C.o.m.m.e.n.t.......0.0.0.1.5........................Z4...........................................4../4......p.
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2004:03:04 13:19:29], progressive, precision 8, 221x792, components 3
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:3CD906D179F59DDFA112510C7E996351
                                      SHA1:48CDB3685606EDD79D5BCDF0D7267B8B1CCBD5A8
                                      SHA-256:1591FD26E7FFF5BE97431D0ED3D0ADE5CFC5FA74E3D7EC282FD242160CE68C1F
                                      SHA-512:2048CBA13AF532FF2BCC7B8B40541993234BD1A8AB6DE47B889AF3F3E4571F9C5A22996D0B1C16DD6603233F6066A1A2A97C16A6020BEDD0826B83BAD0075512
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....H.H......Exif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop 7.0.2004:03:04 13:19:29.....................................................................................(.....................&...................H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d...................................................................................................................................................$.."................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?.....)......[]t.\Z..g......A....&D.$LH._..X..Xl...`....cZ.X.........>......f.Z.X...]..~L.S..@..I$..I.IO.....x...s.g.[f.h{9..
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:F2C0D469F1FFAC7A84B09FB0059588E1
                                      SHA1:3B11275F2E2966AF913CE6612F7FD1582F825B95
                                      SHA-256:809E9DAB0C76D72B774965C180429BE31274B6A7DA1CB75967AD92FB37665760
                                      SHA-512:2A2B74D47E7E637518C94C4D46C13DF08BAE8D312DF3E711C678E4E64E0C54A80D518880940ECB90E09658BC800ACE513673D49BD07404A36D51BD7D54A6A34F
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>...6...z...v...N.... ..X,..2...>...........v.......@...H+...........................................................................................................................................I.......I.qk..B.....LZ....N.............8J.............8J........I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............q<.4.-p...r.../.....N...^.................A...M....&.@,............P....................................I.qk..B.....LZ............q<.4.-p...r.../.................................................................................................j.9.....T.................s.....H.........0.......`.&...............3...:...A...8.....z...y.. x.. ........ ..$...$...............7...7.........*...o.e.L.o.c.I.D...o.e.L.o.c.C.o.m.m.e.n.t.......0.0.0.1.1................Z4...........................................4../4......p.........
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:9700DE02720CDB5A45EDE51F1A4647EC
                                      SHA1:CF72A73E1181719B1CC45C2FE0A6B619081E115E
                                      SHA-256:7E6A7714A69688D9FFDF16AA942B66064A0C77FCD9B3E469F89730B4B9290C3E
                                      SHA-512:5438921467D62376472007B9EBF3C35C9D9FE3EDE04D99A990129332D53EBC8EE2555C0319A4F7C0DF63516F29CEDF2171D8B6DC34C9FCD075C2CA41EB728660
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d.........................................................................................!1..A...Qaq..".......2BR#...b%&6..'w.r.3f7W8.s5EUeF.g....CS$4.Vv..Tdt..G..(c..u.Hhx.......................!1.AQa..2.q....".s...3.4BRr.#......b.$c............?........uf.....t...;..[...W.h.....-.k.f..i.u..KQ..b.F...rM%/.8n.S..=9.....G$O;.f.}L..N..U._i.[.X...3.~....S.~..+t$...c.5......{..X/..#.G...}s....6......^....o~.$.\WA?...^*w[O.~..6..~....a....~..:..0.......{O...|.s.u._w.........i...........{K...._.?.../{.....A..8....<g.iu..<..................X......|]v....D..9.k.w.|-IF.Tv.-.&.........."'.4.b....z.._.Z.....G...u.xyt./_.q..m>..S.V.Xdc.bw.T.W......g..........}s.._..?....U]_.......`......>.|'.~xH....,...?........?.q....o../..R..;...Y.G....A"?......?.<..1...w..o.M.........tco.
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:136365046D56E785A3EE6BE1839F8DA2
                                      SHA1:A87BE1CEABEB5A811FF31D50469D29E17F0D2D2B
                                      SHA-256:9D9937B41097111FF7D8B7D7C87427448DA386C935745A279062645098CFC38C
                                      SHA-512:CB0D0D75A43F1841B882D3DC4BF44133980BE4CA2FE6303815FDB88E7AF727C747A6E107DBE97F4630BA4B6B27A80E7E5E04424836D854C53BCB8DF4AB18E67C
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:....>......."...v.......8 ..."......>.......r...v...>...@....!...........................................................................................................................................I.......I.qk..B.....LZ...........A.......s.1.~.>...;4%G[.Y1.~.....A.......sN....I.qk..B.....LZ.I............I.......I...................................................I.t.....I................................................................4..'...'..............%J...p..9.....9....N...^...............?...k.C.U.@.D.J............(...............................z....I.qk..B.....LZ.............%J...p..9.....9.........................................................................................1.~.8...1.~.>...;4%G[.Y...........A.......sN2................................I...............................1.~H....1.~.....1.~..d..1.~.....1.~ ....1.~$.7..1.~.....1.~ ........1.~!1.~..z...,4. ............................"......$...7...............T.u.e.s.d.a.y.,. .J.u.l.y. .2.8.,.
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:F38E794422E7F0FB4949D556DAF271AB
                                      SHA1:FA71F74FE9FC276F4B78BBEEDCACB1C52385FB8B
                                      SHA-256:B875EF6962B3A594668B180800C6DB4711D1639403E49BB3885DC88F91F7B3DF
                                      SHA-512:7783A1DB3FF2B39176676B0CB6F4E4367C3459E489C36939E8F4AA0379405E4716BB0D2458DE7E7E36163E812B49B7C9F4E080ED278C72B47BCA1E8DA920AD79
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>...........v........ .. "..2...>...d...<...v.......@....!...........................................................................................................................................I.......I.qk..B.....LZ....<...... ......MP.t..... ......MP.t.......I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'................f...>....t......N...^................+.ob;.A....2.,.............................................D....I.qk..B.....LZ...............f...>....t..................................................................................................j.......T.T...............|.......;.......h............. .W.....'...2.....z...,4. ...."......$>........4..p..7......S.u.m.m.a.r.y...........................3...8.....z...y.. x.. ...........$...........7...7.....*...o.e.L.o.c.I.D...o.e.L.o.c.C.o.m.m.e.n.t.......0.0.0.9................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:big endian ispell hash file (?), 8-bit, no capitalization, 26 flags and 19975 string characters
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:B94C215498E6077CE7A653D17E833FBF
                                      SHA1:80D14069E0D7F6CA07CE5F93E981CE7E662D1FCF
                                      SHA-256:27C25226A881FDA7A66333CF6825D19257A9F02D8DAF29D9F1DB7599E83E623F
                                      SHA-512:B986DC9A53A99D72CBA84FA3E5A7F4D5F1E881BD496557F0E78F0E5D60F4538C84B66D3F49A5E8B5968394FD665CDE6FBA8E2DCF1E238F993D0F3DE8CACD29BB
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:....N..@p...............(@..@!..@M..........N..@ ................K..@!...L..................................................................................N..@8................K..@!..`L..............v.......v...tf*D........0.......0..cK...4.P3..*...t........0n.Z..t..R.e.f.>.......R.h.w6....?..w...h.w..........0.......0...................................................v..T.......T._...#.T......'T.....K.T......7T....9.9T......<T!d...........0...........e....4.........................A..:4E.2..p1......(...`.i.....(...(...B.a.c.k.g.r.o.u.n.d. .-. .Y.e.l.l.o.w...j...P.a.g.e.L.o.c.I.D...L.o.c.V.e.r...P.a.g.e.V.e.r.C.o.m.m.e.n.t...P.a.g.e.O.v.e.r.i.d.e...P.a.g.e.N.a.m.e...2...0.0.0.1.9...1.....0...U.n.t.i.t.l.e.d. .p.a.g.e..............M.q.K...7./j5..j.......j...vI......@.2...............h...............v.......^<...#......|M....j...............0...........e....4........................yf.....F.Q.........(...pO;.....(.......S.t.a.t.e.m.e.n.t...j...P.a.g.e.L.o.c.I.D...L.o.c.V.e.r...P.
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:4E7A3BBD5070E2940E4DAC969DE1BC36
                                      SHA1:4876BDD4EE35005A9900AE38C7ED1DBE44700018
                                      SHA-256:DEC3882F65C3C6118E2B377D191AAD1773237723B900F2AEB0F598EBE6B4DB00
                                      SHA-512:28DF8B9EE65F790B38AB512021E96F15CED668100C1BB2E127FAE788EFB73A85A4406B09C2CD648F43BE988B5BD48DCC8FA2050545383C13B1CE78FC841333B8
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>....... ...v....................................................?....?.............................................................................2...>.......|...v...H............................I.......I.qk..B.....LZ.;......;.4...&e......;.4...&e......;..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'............. %../{..,1[..TAk....N...^................I....[I..F<..).........f........................................I.qk..B.....LZ............ %../{..,1[..TAk........ %../{..,1[..TAk..........;......;......;..........................................;j.....;T.]...;......;..B...;H.....;..B...;..>.).;..J...................;........4...4...4.."...............;..;..;..z...y.. x.. ...........$........4......7...7........................;........4...4...4..........;......;....#.;............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:47A877AA23D7FB74AF1B64EA5D61EC95
                                      SHA1:DC86CBF9EB6AA18EC64BD324274A0D05B9037539
                                      SHA-256:4B02400BFACE436991102F2A593FC56D27D5140336DBACF0EF3688F6CD4C53EB
                                      SHA-512:1C28D01B91C32D15C34346DEE584FDB2F77A5CEE7BF928BDC5CC0BC7382928F9C8C677053F08A87EB1D3D866DD8024060F8F50CCF4E5627140644E1BA9521082
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......&...v.......................................................................................................................................2...>...........v...N............................I.......I.qk..B.....LZ1.......1....F..B....1....F..B....1....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'...............n.<Z...E.....F....N...^...............y.I....H..v...l.........f........................................I.qk..B.....LZ..............n.<Z...E.....F..........n.<Z...E.....F.........1.......1.......1...........................................1..j....1..T.]..1.......1...B..1..H....1....B..1....>.)1....J...................;........4...4...4.."..............1...1...1....z...y.. x.. ...........$........4......7...7........................;........4...4...4.........1.......1......#1..............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:7B166B248DEC79415999D01233B95D16
                                      SHA1:6799E108D35C9D5BD778487C3C0BFB597D92B31E
                                      SHA-256:E764BDC445A2725715696FDD98DBDD8841EEE5E8E71A9A1B2E09D1CFCD3AC132
                                      SHA-512:2455677A08353FC4A41BA0B83CC3EE749A4A1F0FA7D68AA4BF7466AF58623AFF4947A859521AA58E068C4E832A33A90125EDEBB06D91AFF320E0680C7559017D
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......$...v.......................................................................................................................................2...>...........v...L............................I.......I.qk..B.....LZ..........'.~.....t.....'.~.....t......I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............O.}$.i..:`Quij......N...^.................\....F................f........................................I.qk..B.....LZ............O.}$.i..:`Quij..........O.}$.i..:`Quij......................................................................j......T.].............B....H........B......>.)....J...................;........4...4...4.."........................z...y.. x.. ...........$........4......7...7........................;........4...4...4......................#..............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:7733BCD409E87AEAE4381E98DF75866C
                                      SHA1:39693E7F33F1E6CAF176063A9A950B0E631B1639
                                      SHA-256:B21BE70DBDFE070B97574445170BE545E225542A38522611DF914A6E49B552EB
                                      SHA-512:DE5786F00DAAE4703754CA430654BDD10BC4AC15E3E46E476CD9730BAE2D3FAF5D865E1B409842EEDA1792ED7FD6BD0DEB8969A22BF390C34170A1E2AC2420AF
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......$...v.......................................................................................................................................2...>...........v...L............................I.......I.qk..B.....LZ..w.......w.(.....7c..\...w.(.....7c..\...w..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.....................*9.....*....N...^.................*K..GM.H.F.R........f........................................I.qk..B.....LZ....................*9.....*................*9.....*...........w.......w.......w...........................................wj......wT.]....w.......w..B....wH......w..B....w..>.)..w..J...................;........4...4...4.."................w...w...w..z...y.. x.. ...........$........4......7...7........................;........4...4...4...........w.......w....#..w............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:BB101E7F285971ACC6512FABA0B4866B
                                      SHA1:5A4B76E7AE38C0198EE060CECF28E29B7B7B758C
                                      SHA-256:9EAE4A51F9386B9F97AAFCA0F2ED49161036B55E829F3CD06527737FF128F31F
                                      SHA-512:D298E1DEC9DFDBB8248C51AD1F1AA6C53E39C327317A8D21AFE7AA91539D520BB04CF5F42D173A39ADBB3F4E26CB84082BC4B1C3EAEC026F0F4F3E499FAA1A08
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......$...v.......................................................................................................................................2...>...........v...L............................I.......I.qk..B.....LZ...........9..-..*.\.>#...9..-..*.\.>#.....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............:....9....8;.~)....N...^................O.T...J...t.cH.........f........................................I.qk..B.....LZ.............:....9....8;.~).........:....9....8;.~)........................................................................j.......T.]...............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4......7...7........................;........4...4...4........................#...............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:EB3A0300ABCACC0DA3D83A459CA9B77C
                                      SHA1:245525BFB4C038E947A0FE5DF2D2457336E48762
                                      SHA-256:1A1EBA837C45C85C96E3ABBB8691F1B37754E67E43313FE9B1D34AF35345EA0E
                                      SHA-512:78954D7F08BDC4E200911970E4D6207527EC15BE6839CA0F646997A1971CA3339181173791438D05A294CDC8428DE75B2728BD0D80AF87F56F0BC2F6E94C2EC2
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>......."...v.......................................................................................................................................2...>.......~...v...J............................I.......I.qk..B.....LZM{......M{...\..0.....=.M{...\..0.....=.M{...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............._..y.K....N3pXO....N...^.................D....O................f........................................I.qk..B.....LZ............._..y.K....N3pXO........._..y.K....N3pXO.........M{......M{......M{..........................................M{.j....M{.T.]..M{......M{..B..M{.H....M{...B..M{...>.)M{...J...................;........4...4...4.."..............M{..M{..M{...z...y.. x.. ...........$........4......7...7........................;........4...4...4.........M{......M{.....#M{.............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:2862ED8FB5E4D52515B1B7D4F3CA876C
                                      SHA1:849C5085BC9EBA956EF38813687EBEB717FBB40E
                                      SHA-256:9EDE81F3245FE9ED9FDAB8C06C9D9A29A44823C09201A100B5BE920D2C3EA6C3
                                      SHA-512:4810A0A317036C635226920A50755AA2B1ACAA07621FA0507DD5ACA11E4B548E6F0BA0F694FA59987221D18C587BB5758E3EAD92F6C6BA35C17FF5D2F861FD7A
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>......."...v.......................................................................................................................................2...>.......~...v...J............................I.......I.qk..B.....LZ.............(...MN..A.......(...MN..A.......I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'................."}..8....h......N...^................!...*.N.]...B.C........f........................................I.qk..B.....LZ................"}..8....h.............."}..8....h..........................................................................j.......T.]...............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4......7...7........................;........4...4...4........................#...............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:E3C07E1830FEE050EBFE429E2FE5C34A
                                      SHA1:A125DB73003E31DB6AE518D7EB8770FFD223DBC7
                                      SHA-256:A43897587C11079A8908A25D62A115130E2947360D65B6BCD076FC214743DB5A
                                      SHA-512:317850E3EBE0F2EC84BF1BE25DBE2F75CE07C194D220F42AD85635CD1435D877DAA505CC73D827B0AE58892A1DF2DD159E3054D0F04BAFBD0AAEB698374313CE
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>......."...v.......................................................................................................................................2...>.......~...v...J............................I.......I.qk..B.....LZ.................]h..2D..........]h..2D......I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............k]X.."...q........N...^......................D.pJJ.F. ........f........................................I.qk..B.....LZ............k]X.."...q............k]X.."...q............................................................................j.......T.]...............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4......7...7........................;........4...4...4........................#...............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:A0FAE1D441EDCAEF843BD85FF9305400
                                      SHA1:BA5E51D016A75DFD3043EDC40186B375853A3D5C
                                      SHA-256:D039D788D9146C94E2E346D8E58CDEF03A0A935EB979CE1E47825FA34ADDB049
                                      SHA-512:2FEFD6CEA397D853EEEB6E431CAB1C2C883FA36E84D45872E446D04DBDDD0CD0DDE61A4D570A67A55521215C520E30B808D90485F05EB7AEF5A50D06FA359D73
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>......."...v.......................................................................................................................................2...>.......~...v...J............................I.......I.qk..B.....LZr<......r<.....7.I.:.yr<.....7.I.:.yr<...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'................}....y.-.....N...^................2/ .*.O...............f........................................I.qk..B.....LZ...............}....y.-............}....y.-..........r<......r<......r<..........................................r<.j....r<.T.]..r<......r<...B..r<.H....r<...B..r<...>.)r<...J...................;........4...4...4.."..............r<..r<..r<...z...y.. x.. ...........$........4......7...7........................;........4...4...4.........r<......r<.....#r<.............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:E60464459A6FC830A49B494116D2F1EC
                                      SHA1:C0D8456390E0EF71C2B0A90FFFAF4BF600055EB8
                                      SHA-256:D8223285ED3CE110ABBACD32B184ED0C9F85DAEAABA933DEC1FDE03C2B1C5DF0
                                      SHA-512:7D47EA3140DEEC6A7DC59F7796BCA99FBF8F18A9FBF85CFD11BB992FE81326CDC7EE6057957E4D1525CB7960C7D76C2BF369440AADD139B9F57BA621D432B576
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>......."...v.......................................................................................................................................2...>.......~...v...J.......................................H.u...$...zz.I.......I.qk..B.....LZ....H.u...$...zz.....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.................<...8..U......N...^...............5VZ./..@... $.........f........................................I.qk..B.....LZ................<...8..U..............<...8..U..........................................................................j.......T.]...............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4......7...7........................;........4...4...4........................#...............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:4080F033C5A466F01F1FB6B640F3461B
                                      SHA1:E8C19228F99BBEAF293C1D4EAE75D09718A2DF08
                                      SHA-256:81D8081E875F536C8C5EE1614035B957937A6D0396AE8F736D6C7F0870D77425
                                      SHA-512:0B22FE6EC52F1B6FC7821FCFEDC3E9D57F07D3FE45128A492A0ECF1452D2E71E68B11BEEF7F79C1C645D6628FA68BEAA33A8E613EFEC72E13E6397B60BB619BD
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>......."...v.......................................................................................................................................2...>.......~...v...J............................I.......I.qk..B.....LZ$L......$L.1...........$L.1...........$L...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'................;..N..`.Z.I.W....N...^.................y.l..K.+.-(...........f........................................I.qk..B.....LZ...............;..N..`.Z.I.W...........;..N..`.Z.I.W.........$L......$L......$L..........................................$L.j....$L.T.]..$L......$L..B..$L.H....$L...B..$L...>.)$L...J...................;........4...4...4.."..............$L..$L..$L...z...y.. x.. ...........$........4......7...7........................;........4...4...4.........$L......$L.....#$L.............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:A9C9FC601D8DB94EF8FF68BC9FA9A243
                                      SHA1:F9F030584A90DE2571716DF4F6ECD9F9C834976B
                                      SHA-256:D63EE1ABCDB21D88A5A4AA8213D5C50284F5B10D168FF78D510D8FA29791A91E
                                      SHA-512:949CA125C58037E8FD0A452038CBBB98B41F6D63262E68DF4BEDF17A35040F276025CEE94CC1409B75CD4AD69DF1A32255F615E441C127D32D63A3B9D46CB309
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>......."...v.......................................................................................................................................2...>.......~...v...J............................I.......I.qk..B.....LZ..|.......|.2.4.0"].....|.2.4.0"].....|..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............`...b..Uer.|.&....N...^.................OPM.L.~..4{p.........f........................................I.qk..B.....LZ.............`...b..Uer.|.&.........`...b..Uer.|.&...........|.......|.......|...........................................|j......|T.]....|.......|..B....|H......|..B....|..>.)..|..J...................;........4...4...4.."................|...|...|..z...y.. x.. ...........$........4......7...7........................;........4...4...4...........|.......|....#..|............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:F0829E1BA9737AEED9884B4B6B5D8297
                                      SHA1:4A616A75E4945BDF575E0BB00D09DEB553A2075F
                                      SHA-256:1F339D660D8C939AC053787244B66A4BE8B9434288F2713C1799702767A54669
                                      SHA-512:C325E88FD7E6430265C0D886AD29253AD25659794374BAA82FB6FD897CB9ED2C6EC84258985C652D681A99BC652A250DEE9124872C89BBB07274DA27AC466FD7
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......&...v.......................................................................................................................................2...>...........v...N............................I.......I.qk..B.....LZrcI.....rcI..g..0^..:...rcI..g..0^..:...rcI..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............J.U..9v./V..&..0....N...^...............+....bhB..u..y.........f........................................I.qk..B.....LZ............J.U..9v./V..&..0........J.U..9v./V..&..0.........rcI.....rcI.....rcI.........................................rcIj....rcIT.]..rcI.....rcI..B..rcIH....rcI..B..rcI..>.)rcI..J...................;........4...4...4.."..............rcI.rcI.rcI..z...y.. x.. ...........$........4......7...7........................;........4...4...4.........rcI.....rcI....#rcI............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:4C358215204EE0D252EE06DB377F46B3
                                      SHA1:B515FF6A30463CC87057496CEB417908D2657CA8
                                      SHA-256:E0630DC2D2EA223205D6F9541E77582A8150E08DF9CD402F0F12FB6C7507826B
                                      SHA-512:21A7EE9D1B033EFA83E5E59B9A215D6E92526FB110F98D26FB92C08A6501CF89F3FE628A571606A822D7A3FD1572AD9181EEFBD21F6469720938E42A42631A85
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......&...v.......................................................................................................................................2...>...........v...N............................I.......I.qk..B.....LZ..........)...1.G......)...1.G.......I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............U.......[.l.]3+....N...^...............v...T.A...N............f........................................I.qk..B.....LZ............U.......[.l.]3+........U.......[.l.]3+....................................................................j......T.].............B....H........B......>.)....J...................;........4...4...4.."........................z...y.. x.. ...........$........4......7...7........................;........4...4...4......................#..............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:FEC181E6FC5B7AB8CFAD9966BDD40552
                                      SHA1:E5FC1D065821AC640ABF34EA266DFECAFC72FD94
                                      SHA-256:C3DC0D4A430CD5132C674C08E935DDFF38B05202B8BBB14AA24CCB8F33837450
                                      SHA-512:6B88F1BE575E36B1C171B4D9A096F2DC27630CFDE27FDFE6E79933166FAC2B2A5674F7216D761B1BD68E22560345E3D21363E3F0F0742EE583D962FF0D4D38AA
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......&...v.......................................................................................................................................2...>...........v...N............................I.......I.qk..B.....LZ.$.......$..X&D..........$..X&D..........$...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............k...9.....)...S....N...^...............E....}.K.h...(........f........................................I.qk..B.....LZ............k...9.....)...S........k...9.....)...S..........$.......$.......$...........................................$.j.....$.T.]...$.......$...B...$.H.....$...B...$...>.).$...J...................;........4...4...4.."...............$...$...$...z...y.. x.. ...........$........4......7...7........................;........4...4...4..........$.......$.....#.$.............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:76634DF7E5F92C1B08E3D16B5330481A
                                      SHA1:982A12C78C2C3F59FA9D8343C2F6D8D6FA9A17C3
                                      SHA-256:B46030340594C8E98C7CCB21424CAD2E9C5AC9C6FC8487BF07DF77B66BB5EC77
                                      SHA-512:160482637261D55B9F88E7C3BB4EC9D2445ABC55B4B61433299CC66D6BB1E5932BA0B58A73B02EBCE62E9243160634DBA3563765E8564EA0EEF7D713A8110E12
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......0...v...$.................................................?....?............................................................................2...>...........v...X............................I.......I.qk..B.....LZ.*.......*...._..K.R&.tu.*...._..K.R&.tu.*...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............3.......+'P.^'....N...^.................3....A..v..0o.........f........................................I.qk..B.....LZ.............3.......+'P.^'.........3.......+'P.^'..........*.......*.......*...........................................*.j.....*.T.]...*.......*...B...*.H.....*...B...*...>.).*...J...................;........4...4...4.."...............*...*...*...z...y.. x.. ...........$........4......7...7........................;........4...4...4..........*.......*.....#.*.............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:46D9208789BB1D424CC1CB136C039D96
                                      SHA1:5D2C964300E7DF2EC3D7A4C569869FE8055142BF
                                      SHA-256:B24640831813A1FDFB8BB35234CD0FD200FB859880E8359F3AF6BB20B709FBE9
                                      SHA-512:9DC50AE62FAF82581C4FE0497F9A3A764F43CCFFBCB214A2779EF816FEB23155F73D27D5E192FAF3CCF067022FCC64C253FBA1734DB06F9943E665BCE72D66CB
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......0...v...$.................................................?....?............................................................................2...>...........v...X............................I.......I.qk..B.....LZ'T......'T.8.&..0Q...PIs'T.8.&..0Q...PIs'T...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.....................6..{p......N...^...............<y...S.J...a1..!........f........................................I.qk..B.....LZ....................6..{p..................6..{p...........'T......'T......'T..........................................'T.j....'T.T.]..'T......'T..B..'T.H....'T...B..'T...>.)'T...J...................;........4...4...4.."..............'T..'T..'T...z...y.. x.. ...........$........4......7...7........................;........4...4...4.........'T......'T.....#'T.............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:155A67FAB98E241F363AF24CC1FB89EC
                                      SHA1:F711F09DB1E17B264DE9AB186ECADC2B9C873BBF
                                      SHA-256:E326FE75ECE36524D2F30911EC24C0D3A7CD56DDED65619EA55A03F84A22CB87
                                      SHA-512:7FB1EBAF38625458133328D1A127B7AE562E16C2FAD0A59FE787926FBD44692913BFC596289331D362C2D729CDE7FAEB85244B2B857913356AD5B84E62CF495D
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......*...v.......................................................................................................................................2...>...........v...R............................I.......I.qk..B.....LZ...........(0.L..N..9.d...(0.L..N..9.d.....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'................u+dV..T.gy..6....N...^..............."k|.t.zC.t.2.SUb........f........................................I.qk..B.....LZ...............u+dV..T.gy..6...........u+dV..T.gy..6........................................................................j.......T.]..............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4......7...7........................;........4...4...4........................#...............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:96536AE40C1D932DF8D0B3D159FC90CC
                                      SHA1:C1536575962925D8340E1A97E520D2A685072F19
                                      SHA-256:0F29B6EAE43720873DCE0C49CAAF8B74EA57F6558B9C0BA4EBB494DC994E5652
                                      SHA-512:F8BDEA2455B8D76E897CEEC81F93EA30AD68DC9D82CB24A78C660855EA7142852251687DFA74768F72F45819BB4AEA62BF4B1CC0C894F2B016254813D42ADB86
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......*...v.......................................................................................................................................2...>...........v...R............................I.......I.qk..B.....LZA......A.t....%.......A.t....%.......A...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............i~...&..&..n..[.....N...^.................;L...B...,.b..........f........................................I.qk..B.....LZ............i~...&..&..n..[.........i~...&..&..n..[..........A......A......A..........................................A.j....A.T.]..A......A...B..A.H....A...B..A...>.)A...J...................;........4...4...4.."..............A..A..A...z...y.. x.. ...........$........4......7...7........................;........4...4...4.........A......A.....#A.............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:B0565A13E3E604F7669DBFBE622B915A
                                      SHA1:AB4D3D665ED551CAF1D44EBC06062379B1082CF7
                                      SHA-256:59D2D6541CCD92CB9B836AF60D6CEAA32A0F4A3AE67859A468E6D4353C054D69
                                      SHA-512:8A1B028CDFACE1F3AA8156309855753E456247DCCC571B87B9589947DD5692BCA449B2B09ECCEC75157518173FA937A550402111DAB4CF454946F30E174142F4
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......*...v.......................................................................................................................................2...>...........v...R............................I.......I.qk..B.....LZ.............5..............5..............I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............x.1*..u..]5.e.W^....N...^................U..l.O.K.V?PS^........f........................................I.qk..B.....LZ............x.1*..u..]5.e.W^........x.1*..u..]5.e.W^........................................................................j.......T.]...............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4......7...7........................;........4...4...4........................#...............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:FECA50DF9F694B6A6B7188C82E670911
                                      SHA1:1FDDF0BE7490093339BC7E179B1F2F996EE9EE79
                                      SHA-256:4FB8216B2916DE0F2D63CFB4E85454D3AEA586C1FF267BCA931FCDD9F07B2CD1
                                      SHA-512:EFC5A9292306B4A7FC96F3E0A89C30C621FF933879352398BFEA6AB72E6AB64F57CCBA5E9C3FF35E3B1AEFC83DF693AC05D2F84907440B410501F1EDA764068A
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......*...v.......................................................................................................................................2...>...........v...R............................I.......I.qk..B.....LZ..i.......i7..a.8.~..X.@..i7..a.8.~..X.@..i..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............8..+..7.(1.{z.Sc....N...^.................".Cg.M......Z........f........................................I.qk..B.....LZ............8..+..7.(1.{z.Sc........8..+..7.(1.{z.Sc...........i.......i.......i...........................................ij......iT.]....i.......i..B....iH......i..B....i..>.)..i..J...................;........4...4...4.."................i...i...i..z...y.. x.. ...........$........4......7...7........................;........4...4...4...........i.......i....#..i............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:342325EBC1C9D4794B97464E6A19E3A2
                                      SHA1:B4F9095074DCA7C3D735298E0F82BAE2620926E2
                                      SHA-256:518CFF0740C05A2C30D54BE644294ADE979A64EA6CD7D07E585E92B6AFD7E458
                                      SHA-512:C62924CB3B6E6D804C7FCD99A58EA1B9831CC0950804E8CD22D9E13680BE61969DA7FA88C06BB3417226A5E4A1BC012601E9FA468FBBFA191301BE8335F877EB
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......*...v.......................................................................................................................................2...>...........v...R............................I.......I.qk..B.....LZ.8.......8.s.6{.1...=..F.8.s.6{.1...=..F.8...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............:.......!:.8.......N...^.................t...}F..P...gF........f........................................I.qk..B.....LZ............:.......!:.8...........:.......!:.8.............8.......8.......8...........................................8.j.....8.T.]...8.......8...B...8.H.....8...B...8...>.).8...J...................;........4...4...4.."...............8...8...8...z...y.. x.. ...........$........4......7...7........................;........4...4...4..........8.......8.....#.8.............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:1A31B21BD1E8888C9F3B29434D611B41
                                      SHA1:BB6038F4105AB233D7ED7F820DF47EFD9434313E
                                      SHA-256:A6476CA5D0E34014CE457F6ED71AB7D6DB08D2821B7CC20025E2E275187CB282
                                      SHA-512:82F2236AD3847F993957F9139B942DFC12E30B41C04E522EDF7700ACDB52F33B74F7266EA02799FA1DD1336F6699111264B6085D91BBDBAE8EC8203EBCA11514
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......*...v.......................................................................................................................................2...>...........v...R............................I.......I.qk..B.....LZk.......k...|...*YD|1...k...|...*YD|1...k....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..................h..=jbH..bB....N...^...................z.SO..m.>w.a........f........................................I.qk..B.....LZ.................h..=jbH..bB.............h..=jbH..bB.........k.......k.......k...........................................k..j....k..T.]..k.......k....B..k..H....k....B..k....>.)k....J...................;........4...4...4.."..............k...k...k....z...y.. x.. ...........$........4......7...7........................;........4...4...4.........k.......k......#k..............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:A9720F5177FCD4E9D560CAEFC1B6E067
                                      SHA1:6E418D9D1C74C96D91BF6F861AF0B924B46BFD7E
                                      SHA-256:DC3177C9FEEF542474B1FA06328D63BA4C42095A46353FE7D9D995FA5B51AD33
                                      SHA-512:C8614ACC5482DC88FE8342840F2CE4BED684AE37E0A240D54E9D151B8DA7737470C38916F696458C70815E3C70AE8C5279728904D95CDB274C48E8880F4BF40E
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......*...v.......................................................................................................................................2...>...........v...R............................I.......I.qk..B.....LZv.y.....v.y.'...9B....>.v.y.'...9B....>.v.y..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............&....U...|.B.?.....N...^.................q..u.H.9iI............f........................................I.qk..B.....LZ............&....U...|.B.?.........&....U...|.B.?..........v.y.....v.y.....v.y.........................................v.yj....v.yT.]..v.y.....v.y..B..v.yH....v.y..B..v.y..>.)v.y..J...................;........4...4...4.."..............v.y.v.y.v.y..z...y.. x.. ...........$........4......7...7........................;........4...4...4.........v.y.....v.y....#v.y............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:B5770179CA6069FD7789AC2F23EF059A
                                      SHA1:999A93104FE5A0E816775D763F9D1DB25D27E9EA
                                      SHA-256:E36C34EF2B20CB6A84B021B87987A3A0523640C6960D8321CCD7FEA51DA2F5C9
                                      SHA-512:DEF15221A1D8FAEA1A3CC34BEB86938D85EF4B55FB8072E6C0AFA60D3AEA6A9DF51586347269FF71BD42886DA549B7C237A4CEABB2A0D8CF18F2DF7B9BF0CE36
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......,...v... ...................................................................................................................................2...>...........v...T............................I.......I.qk..B.....LZ..`.......`.x.=.:*..j.'K..`.x.=.:*..j.'K..`..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............6w-.Iu..41.....c....N...^...............yB.....C.[...!'.........f........................................I.qk..B.....LZ............6w-.Iu..41.....c........6w-.Iu..41.....c...........`.......`.......`...........................................`j......`T.]....`.......`..B....`H......`..B....`..>.)..`..J...................;........4...4...4.."................`...`...`..z...y.. x.. ...........$........4......7...7........................;........4...4...4...........`.......`....#..`............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:78BD3BA706811E572DB94924A5376D46
                                      SHA1:93A28D8A5B9CBB4EA63F55C13387A1F049837295
                                      SHA-256:63C7C4D7A842894DAF9EB38BE81A5917199E13EF078395016631C622E147C05D
                                      SHA-512:94D9CB6F5F3858D773572B790D29B78A7F299853626D311F2D0E8D3B590BE350E9B4DDAD9C17F55D0EF1A6809DAADD08F4643243711D77F703B82655A64EA83B
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......,...v... ...................................................................................................................................2...>...........v...T...........................D.......D..YV$...(..rXv..I.......I.qk..B.....LZD..YV$...(..rXv.D....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............L..q.S&.%...ev......N...^....................VTI.....Zu........f........................................I.qk..B.....LZ............L..q.S&.%...ev..........L..q.S&.%...ev...........D.......D.......D...........................................D..j....D..T.]..D.......D....B..D..H....D....B..D....>.)D....J...................;........4...4...4.."..............D...D...D....z...y.. x.. ...........$........4......7...7........................;........4...4...4.........D.......D......#D..............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:4C01054BBCFA41D7241B488119C4F392
                                      SHA1:67C3081F66BBBF2A0017B76243083AD550F3A856
                                      SHA-256:94F32BF4A931AD4E93BCA046B7936417E9A9B9177CBBD26243A97043C4B892A5
                                      SHA-512:0EF8F647BA85DD0DD65D31DD36A60A51E93D297F5B94A830D2E04FE77DAA043FD0286B89A9DF4FE3363D7A9D2AC715A0F53F7CD8FCC9B070D09429FF8E0D8C09
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>...........v..."...................................................................................................................................2...>...........v...V............................I.......I.qk..B.....LZ.7.......7..4..$.l..j5..7..4..$.l..j5..7...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'...............yU...2hf.}.......N...^................L...YK....w^..........f........................................I.qk..B.....LZ..............yU...2hf.}.............yU...2hf.}.............7.......7.......7...........................................7.j.....7.T.]...7.......7..B...7.H.....7...B...7...>.).7...J...................;........4...4...4.."...............7...7...7...z...y.. x.. ...........$........4......7...7........................;........4...4...4..........7.......7.....#.7.............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:0845DA124F29C383BD0B1BBAFD86341B
                                      SHA1:2B020B398861C13E52FA86ACA3D394FBBB204202
                                      SHA-256:9802016288C94A3D678432EDEB80F4B64617F2ADC9F9A3667BDE7ABAE4D0512A
                                      SHA-512:5D8D57FFD586B002C15A3BB7BE621C358B6C3714647EEE6A01AA5753ABC9BF43AFFB1C72A1207D0D5E39674A483E7BF1753144ADFCE5EAA4B122C6DB4486DF1F
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......*...v.......................................................................................................................................2...>...........v...R............................I.......I.qk..B.....LZ..&.......&Y.....<6d...7..&Y.....<6d...7..&..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............QA(.r..?...ILp9....N...^..................,A....s.........f........................................I.qk..B.....LZ.............QA(.r..?...ILp9.........QA(.r..?...ILp9...........&.......&.......&...........................................&j......&T.]....&.......&..B....&H......&..B....&..>.)..&..J...................;........4...4...4.."................&...&...&..z...y.. x.. ...........$........4......7...7........................;........4...4...4...........&.......&....#..&............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:67C3B6A8992DB67433B5D97FF37BC0FE
                                      SHA1:25951EBFDD929286697FBEC522D22C98C2E6BE4D
                                      SHA-256:66B3FEE3E8CA2559E13EE410175B96C0051E117B53860D2A153E9BBF8134F267
                                      SHA-512:2EEFCA133B23296396D3DFA22A550D5CB5B4BE674D9A47C32F76AF1E0BFAB4F3AC7CD378BC5C8E7952FB5677B9C85332FFB917CBF5AAA9F732E07B247B559A11
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......*...v.......................................................................................................................................2...>...........v...R............................I.......I.qk..B.....LZZ@......Z@..{...3w.+.UAiZ@..{...3w.+.UAiZ@...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............6.\.h. !w...j\....N...^................?..O..T...i.........f........................................I.qk..B.....LZ.............6.\.h. !w...j\.........6.\.h. !w...j\.........Z@......Z@......Z@..........................................Z@.j....Z@.T.]..Z@......Z@...B..Z@.H....Z@...B..Z@...>.)Z@...J...................;........4...4...4.."..............Z@..Z@..Z@...z...y.. x.. ...........$........4......7...7........................;........4...4...4.........Z@......Z@.....#Z@.............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:57BDE9912A9E85C6DAC8D82849A4A003
                                      SHA1:85B8A064ECEDF60CDCE37790D478E931595CB326
                                      SHA-256:1571A6E8C566329348263AB43E35C30B99E4941C4D1782BEAB6450D3238B84D3
                                      SHA-512:BAB7EF18543EDD110E82281A74D0D112A939526AE7F8B717A7A7C43EE57ECF3F1A989F2241EED29945B0BBE4FBB6868BA343350EB51EEDD39B50F80CEAB90F53
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......*...v.......................................................................................................................................2...>...........v...R............................I.......I.qk..B.....LZ.G......G=.#.7.......G=.#.7.......G..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............e4.`.......u3R.....N...^.................2j..F.....a.d........f........................................I.qk..B.....LZ.............e4.`.......u3R..........e4.`.......u3R...........G......G......G..........................................Gj.....GT.]...G......G..B...GH.....G..B...G..>.).G..J...................;........4...4...4.."...............G..G..G..z...y.. x.. ...........$........4......7...7........................;........4...4...4..........G......G....#.G............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:9C600E0C9AF3A0E76D7BAD239764859C
                                      SHA1:420ADBD4466F360099295F22A99DD2508193108A
                                      SHA-256:0C05153E3C5219F0A6D472ED28584BF7E5AA5454C97DE7A7474C38ACEF281B9A
                                      SHA-512:C42D1873D670065DD114D17A5A7EB6E8D3BF33740EE533812503AAB731677502DFEC133D5FE977675DEB04393DA08BC8B1001C88914B38DCC1A8D159C82FDF5C
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......*...v.......................................................................................................................................2...>...........v...R............................I.......I.qk..B.....LZ.l......lPC....w...y_Y.lPC....w...y_Y.l..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............B.Sp..L.,Eg..:......N...^...............H.f..S.@....et.Z........f........................................I.qk..B.....LZ............B.Sp..L.,Eg..:..........B.Sp..L.,Eg..:............l......l......l..........................................lj.....lT.]...l......l..B...lH.....l..B...l..>.).l..J...................;........4...4...4.."...............l..l..l..z...y.. x.. ...........$........4......7...7........................;........4...4...4..........l......l....#.l............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:3A7F5E7CFAE8C352223526E29007BE65
                                      SHA1:4AAC0BDA9E01C162B4C6E24DF096C92E8607B318
                                      SHA-256:238E9447D59D7C25B3BABB29E2CD814D35F2371C87EF25E51E936FDEE946F0CA
                                      SHA-512:0E25B5031ABAC40D9508A04D1400AA15534FF2A4271AC7AC8A232538F361311A4D98E2F00676D1072EB419FF1048CB61F4382BF406CA7CFAF54152DC82BEA182
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......,...v... ...................................................................................................................................2...>...........v...T..........................................;.=].....I.......I.qk..B.....LZ.......;.=]........I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'...............l.3....d~!..[....N...^...............<.Y+.3MM....@..E........f........................................I.qk..B.....LZ..............l.3....d~!..[..........l.3....d~!..[........................................................................j.......T.]...............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4......7...7........................;........4...4...4........................#...............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:885B11392F0365C944BB9E644EDA3F97
                                      SHA1:DEB0FA742C227F9B8A345A7CD2B484DF022B122E
                                      SHA-256:D45860CC65854AAF85C9D9C02C3C7121D71558AB92DB7B7F861747EF3C697CE4
                                      SHA-512:1659561F83AD50BBF32D295C7CC3BF025F868C7631353DD37182DE02E802EF1769434D5ACADB94217E4250461E676C771AB7AB9D9B60598F3C272D2379487B4A
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......(...v.......................................................................................................................................2...>...........v...P............................I.......I.qk..B.....LZe.......e..{.@..*.P.4.}Se..{.@..*.P.4.}Se....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'...............l.]i....:.......N...^................A.x..XJ......U.........f........................................I.qk..B.....LZ..............l.]i....:.............l.]i....:............e.......e.......e...........................................e..j....e..T.]..e.......e...B..e..H....e....B..e....>.)e....J...................;........4...4...4.."..............e...e...e....z...y.. x.. ...........$........4......7...7........................;........4...4...4.........e.......e......#e..............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:B6F52CB5DBB74350C6216D5CA0BA52EB
                                      SHA1:0F49A92691BCB02B4D93D1AEABA34C191BA72643
                                      SHA-256:F169C3466ADFFB4FF88274CA8426399E9E2DEF1A6BC672B066E2D32DD06B75CF
                                      SHA-512:A661BE56DED69628A14A2801DAD05F24AB969A784FD03FD926437EC3D0FB5C1C764D35178037860D063B8D02D2389DCE45D05A81A3F48CA5C20FCCA57F3A1BEC
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:L...L...............................................................................................?...................................................L...L...............,...........................(n......(n.&WC...|.2...K.............x.D.NW...+.._.....7.....|._......NF..Z.........H..J'M../(U..F..H............H.......H..................................................bUx.....bUx.{.9L.......-H.......H..J'M../(U..F..2...........^.......0................]M.. l.bUx.........S...........T./...]MT.r... lT....bUxT)...H.......H...."..H....j.....T)O....... l..........c..,0...e...B4.$...........GP..A..}.....J........................L.08.....U....S..{...;.......S........x.D.NW...+........>...............H..J'M../(U..F.....S....5.x.8..bUx.{.9L..................0...........e....4.............."...P.r.o.j.e.c.t. .O.v.e.r.v.i.e.w.......B.^....F...r.QH.....(...........(..."...P.r.o.j.e.c.t. .O.v.e.r.v.i.e.w...j...P.a.g.e.L.o.c.I.D...L.o.c.V.e.r...P.a.g.e.V.e.r.C.o.m.m.e.n.t...P.a.g.e.O.v.e.
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:CD85952DF66804B461093F155DDC5696
                                      SHA1:3CDC21C5BE023ED4171EB2C584A1FF5CE7D6D8DE
                                      SHA-256:40E73D878C9E7A5D166167AE6C11E03EB3CD595CE7F702529A1C4B4E7CD9945C
                                      SHA-512:7089252F511A97640AF3AEDEC3A56C9557CE2611C5C4330782EE95EA71521C9BB50349FA4BEFD2880A4AB237284206F3AE2A3A256DD0E868B5AC57BBAD865B47
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:....>...........v........@..( ..`J..........>...t...8...v........H..( ..PI..................................................................................>...........v........I..( ...I...............I.......I.qk..B.....LZ.............W./JYh..N......W./JYh..N......6/.!..7.S8.k.P.6..I.qk..B.....LZ.I............I.......I...................................................I.t.....I................................................................4..'...'................:.+...8..{..H....N...^.................>....G.-9.z.5.............J...............................4....I.qk..B.....LZ...............:.+...8..{..H..............................................................................................6(.6...6(.z...6 .....6$.....6 .....6(.5...6 .....6$...........3...8.....z...y.. x.. ...........$........!..7!..7.....*...o.e.L.o.c.I.D...o.e.L.o.c.C.o.m.m.e.n.t.......0.0.0.3..............Z4...........................................4../4......p...............C.a.l.i.b.r.i.....
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:3A75B04A22D2272D79C0C9C620A0EE02
                                      SHA1:7DC9E3018BBB9F47142438BEB9CD5610FFD4EA7B
                                      SHA-256:B16CA3FE6635961CAF03475B6BC6C500FA69142551303968602B613D1AE0CFE1
                                      SHA-512:F4593F4E5A5F2041F5CAA5258D697E0346F86FB5A54DF05C3F734526D5572374261C33447B99DD17F939C6E77484D5D68E95BE9FA3854CD9712A3D70C0CDD98C
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>...........v.......................................................................................................................................2...>.......Z...v...&............................I.......I.qk..B.....LZ.l.)....l.WfF...+.Q3.l.WfF...+.Q3.l..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............Wb.. ..#p..EH3A....N...^...............P./.^.G..--..f..................................................I.qk..B.....LZ............Wb.. ..#p..EH3A........Wb.. ..#p..EH3A..........l......l......l..........................................lj.h...lT)....l......l..L...lH.]...l......l..H...l..}.......Z4...........................................4../4......p...............C.a.l.i.b.r.i...................l..l..l..z...y.. x.. ...........$........4...!..7!..7................l:.lF.lG.l..z...y.. x.. ...........$..
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:50DAD9EA3077E07A0080DE4049521DF0
                                      SHA1:14096E24C6E185938494B86FA88BD4E5CCAD852A
                                      SHA-256:306498894CFFA62E3647D6C33A978C9649222C93447F4F354BE07ED27FBCC10E
                                      SHA-512:9271A3CEA1CB9B463783C62C56A2531E34D4C8537089EB5440BDE33514C80B98372D2131735379F8A774777AC081A091A85FD45357FFAE46AC8937D8EC443F49
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>...........v.......................................................................................................................................2...>.......@...v................................I.......I.qk..B.....LZ.k..9....k...>...,..>._..k...>...,..>._..k...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..................L.#....?.m....N...^................5..).B.)SM?...............................................r....I.qk..B.....LZ.................L.#....?.m.............L.#....?.m..........k.......k.......k...........................................k.j.....k.T.H...k.......k...\...k.H.....k...3...k...O...k...........Z4...........................................4../4......p...............C.a.l.i.b.r.i...................k...k...k...z...y.. x.. ...........$........4...!..7!..7................k.:.k.F.k...z...y.. x.. ...........$......
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:202A024F76B17735A9CE6B83464E1ABD
                                      SHA1:E4CE2030FAF4368E64D1EB1C79CF9BB9BB36C622
                                      SHA-256:14F8C2F7C6BFBFAC5CCEF98A6AC27D05C626586771FA25D8E2860A71FFE04048
                                      SHA-512:CE069116D4D6D4BC7C2DE7A4FBA899BCF9F83D1EE286E15F5EE45B768AF4CB2940EAFA5437ADAFA33C3978D1813987848FB400992D5CF21860562D5A20A32CC0
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>...........v.......0 .../.......-.....:..g-.Q.........-.....:..g-.Q.....I.qk..B.....LZ................................2...>.......B...v........-..............v........-..8....................I.......I.qk..B.....LZ.L..T....L...Ld.*<v...B:.L...Ld.*<v...B:.L...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............-.....:..g-.Q....N...^.................L...F...(..x..........................-.....:..g-.Q..........L...F...(..x..............-.....:..g-.Q..................................L.......L.......L...........................................L.j.e...L.T.....L.......L.......L...a...L.......L.......L. .H.......z.......R...................!..7......}.....W.i.n.g.d.i.n.g.s. .3.......................Z4...........................................4../4......p...............C.a.l.i.b.r.i...................L...z... ..$..............
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:FFA5EC40DC9A0FD10EB9E6355142D6A6
                                      SHA1:3D3D6A7E086B3C610C08F1F3E3F883604F06F2A4
                                      SHA-256:D74C3973C8D1F7C77274691AFB1AA934940674341D7EEE563BE75E563281BDFD
                                      SHA-512:6FAF2A24D06E6008F3579C7CEC90C2887462BDF83FAD7372FBB74B8DE90340B580E9836F309B68A9794597A598F7DCDA661C9A58DA6D8187C69083B7A17C9CD9
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d.........................................................................................!.1.....AQ..aq.g..8...."r....2.FG..#.E..7.Rb..Cc..D.v.B..3s..$d.%5Uu..&6fW'w........................!....1Aa...d..5e.6.q...Q..."2b.c..r3DE..BRs4U.#C.S.T............?...u.&0...cV.T.I...1..=4....Ce_.g.q.=F.M:>)...k..pm..h..=........S....)Ja8x...b.).=5.q..0......k.M.....1?-.G.b&.5..Ep.8t...'...R)..ta.F$bXO]tW.b.6#.t.XWN..ZW......].....G....x&&f..'L.....7...\...'.8...~`.sa...............................................X........qo...SMk...'.V...i..hb.}&?/.k.:>l.^....>Y...<}...&.jY.Gn.MKejyV......D......gf.0....t.nw..XQ...H.B.....=8.UkR.....Hm..w..]...k...#Z...F../.gjWvf.....w.aZ].2..5..^...VZv..._.7..a.|...:.B...,f...............~....m.;_.....-.e.y.w.[m.].bu.b.f+.E++\.....Y..7
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:7D7D75B4A392116570F3A9CED3157F53
                                      SHA1:13ADF725E6FCFBFBE66C1AAD02B3D1D9A1EE8C96
                                      SHA-256:66FC1979AB58463B2C14C485673079FE28D5E5FF7EBE3DC70675FA2B125A32FB
                                      SHA-512:0EF4A1CD3DFD9EEB37A4C7B07E863CB77D7CF1126671E03605196A5C160D64E1D00E882D7CC0A10241847C1DA6E21AE1F3EFBBF894F6CE09939272ACCD0F4F01
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>...x.......v........ ..`!..2...>...........v.......@................................................................................................................................................I.......I.qk..B.....LZ%*..9...%*...4O.=J.2..$]%*...4O.=J.2..$]%*...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............,.+1....%%g.Gs......N...^...............lj....wC.V...8.U.................................................I.qk..B.....LZ............,.+1....%%g.Gs...................................%*......%*......%*..........................................%*.j....%*.T.Q..%*......%*..n..%*.H....%*...9..%*...V..%*...........Z4...........................................4../4......p...............C.a.l.i.b.r.i..................%*..%*..%*...z...y.. x.. ...........$........4...!..7!..7..............'%*.%%*.%*...z...,4. ...........$>........4
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:616F3B5B111248E7C7619F656DFC9F94
                                      SHA1:03ECCDEAF86E10B3CE5C3763519784FFAE15306F
                                      SHA-256:D3D8600C700356278FEB549D74732AD3CBE4B74AB4593F16DE7554432B117CA5
                                      SHA-512:95922E9BD631538DD6CDEA27A0CF9D0E3C0595921973A9F8A16BB54E58193BF915FC86A611B3D68B9E04479082E10A03032B9F08531EA321332E98F3E0EBE238
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:....>.......>...v.......0 ..h+......>...........v...Z...@...X*...........................................................................................................................................I.......I.qk..B.....LZ,.......,..0E.3.(.......,..0E.3.(.......,....I.qk..B.....LZ.I........9C.R..:..h..............I.......I...................................................I.t.....I................................................................4..'...'.............7.`D.A3A...g.............................1.|.'N.....&....N...^........................................I.qk..B.....LZ..............1.|.'N.....&.................................,.......,.......,................................................|.....(.......(.z..,..j.N..,..T)...,.......,....b..,.. .......',..8,....z...,4. ...."......$>........4.."..7......A.g.e.n.d.a.:.........................Z4...........................................4../4......p...............C.a.l.i.b.r.i..................,...,...,....z...y.. x.. ..
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:496BC620560BEB4C45E6C2ACE3E94DFD
                                      SHA1:D7E447B6E55206DECAF4CE9A3189BFD784F75ACD
                                      SHA-256:3A934F7EEE47A4AC22BA2105608AB6F0DA74012AEBA7B6D02C4C318A747C72E0
                                      SHA-512:1B11012CCEE037D6E3FBAE70BD4587C200E85E9B329839B01073B597752DBC12A6C93BF8696B8A4AFB09E050DDAB15E349A743C8A38412A091C258A89D1C4B9F
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......,...v....... .. +..2...>.......|...v...H...@....*..............................................................................................................................................G......`+.....n.K`..I.......I.qk..B.....LZ...`+.....n.K`.....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..................z..r...0......N...^.................2.m$$F................V...x....................................I.qk..B.....LZ.................z..r...0..................................................................................................j.A.....T.................r............. .7............. .........Z4...........................................4../4......p...............C.a.l.i.b.r.i...............................z...y.. x.. ...........$........4...!..7!..7..................;.........z...y.. x.. ...........$......
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:7CDCE7EEBF795998DA6CAC11D363291C
                                      SHA1:183B4CC25B50A80D3EC7CCE4BF445BCFBAA6F224
                                      SHA-256:DE35AF949D4F83E97EE22F817AFE2531CC4B59FF9EE6026DCA7ECEBC5CF2737F
                                      SHA-512:560FB15A9C12758D11BB40B742A6EAD755F15AD10D6C5DEBA67F7BC8A2AE67C860831914CBCBCDED9E6B2D1D5F26A636B9BCEF178151F70B4D027316F94F27E1
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d........................................................................................!.1..A....Qa".q..2.....&...B%6.'..R#3.$E.r457bS.DUFV.Wg(.......................1...3.Q..2Rr....s.4.!Aq.S.aC5B$%............?...n.Liq.}.{#....3/gg.1.M +..~3...q..+=..:.g.i1;P)7.....q..n.s"p...wx........v.t.f;..L/..~....y.r[.r.....n.n3..6i..g..}../........3..x.L.i?We..l.......~..<.;..6..o.....N.t.o6.l..~.......<...m.V...Q.7k.u./wq.t..;.I...}..{...>.L..3m..a....yd......6~.f..~Y..}+..<.[w..'-..?.v.7...v.u..4.......1];..u.MO.......s..p..ms.'.O-o...O......m.k.e....)t....i>..E|....,iOyD|.{......g.n...cu....=..........h.\.Q:?g/?.I.3._...t...d.n.0.%y....S.Q....S.&K.w..&wY<....%.g.v.....$y..#,i;.=...t...I6..yO..o.d..w\k...~......)..rK.......].u....N....e.s..kU.u..'}
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:55B9E5564395CC54EE3218B9EEE02A05
                                      SHA1:0E217488F3B5E3C08A09BF1B5B4B2198D69B479A
                                      SHA-256:C64749FF6858865F485A3AC7738108D5BA2CCD1525C8E52773B8D44859A610AF
                                      SHA-512:00A506F819438295CCE51FF117285AFC0475CDF4C9C598272688AE46E4EEDEAF668A52C646CCDE9EBD5D8B6287BD9E27DA092B148A5EEE41B5621EDDF79F5D60
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:........2&.......%..J&..(...@ ...@..@`..H................%.......%..f&......@ ...@..@`...........................................................................%.......%.........@ ...@..@`..h...................T...9.....j.=.......=.....H...3r[s...%k$.....(x.1....^.TW."N...|..\..^.T.....u...5..BK................[[......[[..................................................=..T.....A.T./..n&.T.....@.T"...n..T.L..[[...-..[[.X....[[...............0...........e....4........................u.^s.Q.@.).~b.......(...@kO.....(..."...P.l.a.i.n. .a.n.d. .S.i.m.p.l.e...j...P.a.g.e.L.o.c.I.D...L.o.c.V.e.r...P.a.g.e.V.e.r.C.o.m.m.e.n.t...P.a.g.e.O.v.e.r.i.d.e...P.a.g.e.N.a.m.e...2...0.0.0.5.2...1.....0...U.n.t.i.t.l.e.d. .p.a.g.e...........#.......#..c.G.0.C....$.......$.(.j..\....t.2.......p...............................=....A..[[....$..@*..........oh......^.T..c..,0...e...B4.$........{p.....G...^...?@kO...................,=U.....,=U...f.._u..6....X.......X.e.q.?...|.l...a.........].......s.
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:EFB06C398485FF0C01F32EBE2F444BF5
                                      SHA1:2C91D7FB5942AE53A840807ADBC231B9B0C8E626
                                      SHA-256:379EC04865057853B5F72AFD4491BB70F0C8285885ECD712FB9DC101958C8323
                                      SHA-512:D873B89AB396203AE7D6CB4665EB0028E299D9995AD1155DCB32BFAF1C2FC92C99CE619C9A598BDB50CF6C00D84F2639C246CEFC47216163CF354915D386A47B
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......R...v...F...................................................................................................................................2...>...........v...z............................I.......I.qk..B.....LZG9......G9.J.....H.7..}.G9.J.....H.7..}.G9...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............M.L.....O....1o....N...^...............wfQc.c-D.Y".K.i+........f........................................I.qk..B.....LZ............M.L.....O....1o........M.L.....O....1o.........G9......G9......G9..........................................G9.j....G9.T.]..G9......G9...B..G9.H....G9...B..G9...>.)G9...J...................;........4...4...4.."..............G9..G9..G9...z...y.. x.. ...........$........4...(..7(..7........................;........4...4...4.........G9......G9.....#G9.............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 814x105, components 3
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:4BCCCDBB4273ECEBE216C84930A8D0B2
                                      SHA1:FFBF617787E27BC94D9BAF89F2FE34A2BD42794B
                                      SHA-256:474F9A8C25D5E21192315397EA995B1E11E2C1608157C6E0277688091BFD136A
                                      SHA-512:DAD73A8C0E293B88685C0C71EF15E0DC95EE39B7FC9F849DE5D634173FD9FA0AF0AA96742D9E94BE03556AA4A817D5001C95A6736EAD5D5DF03661876785EB74
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....H.H.....C....................................................................C.......................................................................i..............................................E.....................U....V...f..ASTc.......de.1Qq...!Rb....Ca."r.................................B....................b....Ra.....!Qc.....AS.1U.."C...2Bq...$#3%&.............?......3.....~......:..g..s"......:..g..s"..ic..Vk.f.. :..f..h.....Vk.f.. :..f..h.....Vk.f.. :..f..h.....Vk.f.. :..f..h.....Vk.f.. ..0...Q_..X..V5E~..c..X...@u...cTW...0...Q_..;.m.....@w...Q.+....*.4W...lUFh....v..._..wn...dW....y._..v..E~...*...@wn...dW....y._...v..U..@wn...d..{`;.|U.2g...*.3...:.0?ViN.z.@w...4.M.:m..`~..i7...q...I....J.`l...W..n..PQTiB...6....+..sj.*."...6....+..WA...x..A........(.N6`..AD.q.....'S...t.Q:.l.......f.]..N..0.. .u8..A........_W..Y...}.C...~....&.E~....&.E~....&.E~....&.E~....&.E~....&.E~....&.E~....&.E~....&.E~....&.E~....&.E~.v..?U..^.r..}..Bep
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:939ADF8E21983556FD35E98CFF7B8CFF
                                      SHA1:DB428F0E20575AAF39DA8E891E32C5CAFE54F872
                                      SHA-256:BDB6C09F30230197969D56EB75318A09E63F90AAADB394C42B81875F8C00C8AF
                                      SHA-512:047AF26C015904AD570E7FE364CF0837951FA3CE5C5A9777AEEC349B9451C5D5C5FF2F15713060B53B83F67CA584A998E856DB13EA171088868FFA3777EC9D0A
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......R...v...F...................................................................................................................................2...>...........v...z............................I.......I.qk..B.....LZ7&......7&..8$N..!..3..7&..8$N..!..3..7&...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............r..w=.|.9x...B......N...^..............."..X.^.D...`.f..........f........................................I.qk..B.....LZ............r..w=.|.9x...B..........r..w=.|.9x...B...........7&......7&......7&..........................................7&.j....7&.T.]..7&......7&..B..7&.H....7&...B..7&...>.)7&...J...................;........4...4...4.."..............7&..7&..7&...z...y.. x.. ...........$........4...(..7(..7........................;........4...4...4.........7&......7&.....#7&.............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:6F7B0AC6BB7C7D9B2E6B89C627C0F6CE
                                      SHA1:87BD2F691080F3BAB49BDADD27EF4EC50EC71F29
                                      SHA-256:33CDAD3F81F9EF8E63254CD4C9E15E6A5D92F90242933BF05D0782963FE8CCD9
                                      SHA-512:872D61287E8495D85E7182132E92EB61AD7C6CED05B1AAAD590BC0165322176EC029500F9563AD725CEC8E85CDAE9A35F9DA1CC2A0DBFEDD73A37976D744412A
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......R...v...F...................................................................................................................................2...>...........v...z............................I.......I.qk..B.....LZ..P.......P.)...4=..?.s..P.)...4=..?.s..P..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............(..{q./.>a.........N...^.....................O..g..\.#........f........................................I.qk..B.....LZ............(..{q./.>a.............(..{q./.>a................P.......P.......P...........................................Pj......PT.]....P.......P..B....PH......P..B....P..>.)..P..J...................;........4...4...4.."................P...P...P..z...y.. x.. ...........$........4...(..7(..7........................;........4...4...4...........P.......P....#..P............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:30952E54EB85B949BEA313343C953959
                                      SHA1:A69B1FE2C93B0432E9DAE5AF3EFB2157C1BC2C8F
                                      SHA-256:6D0074218FB33F7245FCCEF3243C6013383EDFB070BD702FF4822C88D5F9612E
                                      SHA-512:B1153B992CC35B6CB065B7F013E40CDC7FD52AF77700D16F96426E02CE269A866B792BB5FBBF2B0B0E60E394485F1E4AD22F7E5E0594CEC34D6294F07547D1FA
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......p...v...d.....................................................?....?........................................................................2...>...L.......v................................I.......I.qk..B.....LZ.G.......G.y9.%..n.#.....G.y9.%..n.#.....G...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.................#Z..7.l........N...^................p.w.7L@..V..1.^........Z................................... ....I.qk..B.....LZ................#Z..7.l................#Z..7.l..............G.......G.......G...........................................G.j.....G.T%c...G.......G...G...G...H...G...>...G.......G. .3...................;........4...4...4.."...............G...G...G...z...y.. x.. ...........$........4...(..7(..7........................;........4...4...4..........G.......G.....#.G.............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:E5DC8EBE157353CB7197D082FD77916F
                                      SHA1:EBDEAFAE4DB0365C8C46E402B31B87AB0D33F2DB
                                      SHA-256:B3BAC398BBC39DAED1E0C98C94AD433EDC388D7104066FDE9FFF7A3BFCE3D0EF
                                      SHA-512:1DAB532B42D8EC12ACCB3F0A3977F93ED5D9DF2B3E47C6B6D622EFBE2EF3EB8ABE49AC5F5B5BD98AC5FB2C469512081FC049E7852A926B33E9E1FE9997C4EF40
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>...........v.......................................................................................................................................2...>...........v................................I.......I.qk..B.....LZ.~.......~...>..7...J=..~...>..7...J=..~...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'...............K..My.%.g.*......N...^...............~.\.f.F.rZ..W1*............................................^....I.qk..B.....LZ..............K..My.%.g.*............K..My.%.g.*............~.......~.......~...........................................~.j.....~.T.l...~.......~..Q...~...Q...~...>...~.......~. .3...................;........4...4...4.."...............~...~...~...z...y.. x.. ...........$........4...(..7(..7........................;........4...4...4..........~.......~.....#.~.............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 95x498, components 3
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:D9BD80D40B458EDB2A318F639561579A
                                      SHA1:83BA01519F3C7C1525C2EA4C2D9B40F28B2F2E5E
                                      SHA-256:509A6945FACFB3DDC7BE6EE8B82797AD0C72DB5755486EE878125A959CC09B59
                                      SHA-512:C368499667028180A922DD015980C29865AEF4A890C83E87AE29F6A27DC323DD729E6FB1C34A2168A148E6A7A972F65A5FC8ACE6981AF1D4E7057D99681CB366
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....H.H.....C....................................... ! ..''**''555556666666666...C......................&.....&,$ $,(+&&&+(//,,//666666666666666........_.........................................:.......................r.!12BQ...3Aaq.."CRb.....#4$c.S.....................................................1A............?..p..-.....u0$.......l......)..o.FTd..DG....... .t*e..jO..Z.U......r..j.O.,..VD./.....V5D.&......A..Zi....E.N....*..........#..M<|.2.Y.../QO.x.cTM4......+.F;V.x.de*....]e..O.x.c\Y........r..j.O.,..T...hw..k.^.[B..J.sEl.w.x.m.5%zzt0..T.......b..<\.3Q..W</..!.xh6..Z..\.+M.o.Y..1............#.........|.a.l.KR>..U......e....@...\.1Z...Y...[....F.6.t.#..Z,.x.Q..[`.X......#........W</..TM..-H...V....Tf..........r..j.x.df.f.....#..l.KR>..U......e....@...\.1Z...Y..Y.us....D.)....Uh....FkYm.m`P...W .V.g..FjVj.\..1Q6.t.#..Z,.x.Q..[`.X......#........W</..TM..-H...V....Tf..........r..j.x.df.f.....#..l.KR>..U......e....@...\.1Z...Y..Y.us....D.)....
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:0DE3A30BDAB61FF8B9A3DE5D79E14880
                                      SHA1:D55F088C69947905F2B87032D5AF588B910BBEEE
                                      SHA-256:BC41CD3F79619E2E3B4020A46182A3B5F04B4BDFD0057143A5E2C0814336FAF5
                                      SHA-512:383BB8DEB9E397396A0EC73C79C65B3D390220266DD201909B0C383077EC7107E96B4518D0F83B52FFE38B116280A42FF3309B73E255F21B9B5669226056F498
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......P...v...D...................................................?....?..........................................................................2...>...,.......v...x............................I.......I.qk..B.....LZd.......d....... ...7.Fd....... ...7.Fd....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............v....OE....;..yX....N...^..................E..tK..S$r\..........f........................................I.qk..B.....LZ............v....OE....;..yX........v....OE....;..yX.........d.......d.......d...........................................d..j....d..T.]..d.......d....B..d..H....d....B..d....>.)d....J...................;........4...4...4.."..............d...d...d....z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4.........d.......d......#d..............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:PNG image data, 813 x 99, 8-bit/color RGBA, non-interlaced
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:EA45266A770EEA27A24A5BB3BE688B14
                                      SHA1:9F0B23B3C8EBA4FC3C521E875EF876FBE018F3C8
                                      SHA-256:EDAD0F03E6FF99FEF9EF8E8B834CE74F26CD23C5F8C067F5CEE66F304181E64D
                                      SHA-512:D4EE36BDA897BBD643A699A0332DD00DE9CDCC6F46D861789BAD259A4BF87868AE3B4CFAAB6DFAF29941C7055B77A95D76BAA86A4A0DB2BF3BAF7E3317F03EB9
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:.PNG........IHDR...-...c............sBIT....|.d.....pHYs...........~.....tEXtSoftware.Macromedia Fireworks 8.h.x....tEXtCreation Time.05/15/06.8.p....prVWx..[Oh\E...y3kv........`.%m.R..6.1.4).o..Ki...D.......P!.].=..K...C[....f.}o7VPJIg...{3.|....d.....i..=.4.u0...n y......@j..Q..f)..mQ...4-SJ..9.d.?..5\-....:b.W..i...c.5..{..pj#.....B1C/.I.......].Su.k?.2..:.9Q...5.U...UZ...e..U.c],..2.}...1..)W./..Epr.Zt.....K.=..{......e..."...v..B.4.#....A.V1.".V}t..[..2f..Y..V9.".6.......(..gbm.P.....Y%2.c.z.:Q.2.<tYF.....u.@..KJ.;u.q:.].....$.....V....Hqk..DW.l.e.j.Z.YP?:'R..*.<........6...m@..r..j2..HK"|..L.Nc..D..y.9..B4$.......`.3.m1LE....7(OU\+./.O...%6T..w......h....).I.&n...*......#..W.41...5.#.`..I...<.?.|..*+Q.....#i........$,..n...`.s....[..E. T.w..j.,&-.r..;a....#.>(.P......f...MU\3*..;B....)..5....z..(....-...a.....}y.l..E...z>......&..g.$.....*T...N....E:./.>..#...^..E.0..%......(..@..W.X.NDM.<~.]A.>..fW.O.y.'...Z...h..).F..
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:6AE841F804F15DF8DA1C7A3E4DADF50A
                                      SHA1:60995B5C65A5194DEFC22A592461BD335E2819A6
                                      SHA-256:B1A90C511354A205E7FAD3B0BCEFD6E310121243337BCD5AB76F5C23D4CB7A26
                                      SHA-512:A7BA71505DA1BE2F798DD699E5560E8569FBB83119B876F6DFE7F9A56F428F4B827D3F6A835622193297643BF6E8AC26EA6F5E0A1FCE87118F07EDD3096A2362
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......P...v...D...................................................?....?..........................................................................2...>...,.......v...x............................I.......I.qk..B.....LZ.E*......E*.z>S.9Te?m....E*.z>S.9Te?m....E*..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............2c......-.?.l..R....N...^...............NZ...K.q..KBt.........f........................................I.qk..B.....LZ............2c......-.?.l..R........2c......-.?.l..R..........E*......E*......E*..........................................E*j.....E*T.]...E*......E*..B...E*H.....E*..B...E*..>.).E*..J...................;........4...4...4.."...............E*..E*..E*..z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4..........E*......E*....#.E*............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 780x107, components 3
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:7C7D9922101488124D2E4666709198AC
                                      SHA1:00CC44A1B84D4D94A0ACE8834491EB5F65D04619
                                      SHA-256:20016E5FA1A32DCE5AF4E92872597E36432185A7BB2E61C91F362BD68484529B
                                      SHA-512:882944B2CF040485899128E03B7499C540D481E45FE8017DBF4FE0330157B2D8ABB7334DDB31C112BA0EFE3722A554883917C54155A7F60044D2D7F3D848260F
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.............C................................... $.' ",#..(7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222222222222222222222222......k....".......................................2...........................c.....TUb...Sa...QRqr..............................!.....................Q...R..!..............?...$.)m.1...%%bV.J..H....-.%a[...I"WJ..:.X.:TT.$.......N.-NR.E..-NR.E...9..E....$.k.....B.I,I)..J...kr..+)..I,Yj..YbI..+,J..e..Z..V.e.$V..TV.X..V.YQZ.EQ..U%PY[.[.R.EP............................| F.. ...j*...!m.!j.I%.j.$...YeEYYEEUE..eY[.hEEUeEil.....%..el...V..TUYA.U.UTTUT.Z..UQQUQE...V.,...UlE.U[.lEP.P.@......................................R1...AR1m.....#..$:.T.p..IJ.t.....A..AH.,5..]F!a.XJFaa. ..a.!*.aa. X.e.......bB.b..,HX[,!..,,.c0.,..U..X..(,,...B(.,..4..B.`..".a..-......"...........................>D..IKEb...t.....)u.....)K.%+L\.J]i)*b.JR.IIL\i)u....T............T.....qs.it.iJ...])ZJb.....X....U.A...V1..B.R1....X...,.c...,%X...,%#0...,H
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:6F6249E4688AAFB73C2AB51BCC305E20
                                      SHA1:FEA5118747874BA9339DB187256364841041D568
                                      SHA-256:4C321037234DAA12338C2020DD55C8418B9B8F6E2E6C57B60541E0AB4D36C256
                                      SHA-512:315466AE725D917B8DFAA7E5C42D6107480A9DDFBFE5AB03B690A3989A7F48FB47C7D023FBDED01B383D811E8A36D334E581B1C1F707CD79A87A874AC63A8F85
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......T...v...H...................................................................................................................................2...>...0.......v...|............................I.......I.qk..B.....LZ..`.......`-A.'..S.?..s..`-A.'..S.?..s..`..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............J.e.....#..OA$.....N...^...............>.8.`M.@.W.F..3.........f........................................I.qk..B.....LZ............J.e.....#..OA$.........J.e.....#..OA$............`.......`.......`...........................................`j......`T.]....`.......`..B....`H......`..B....`..>.)..`..J...................;........4...4...4.."................`...`...`..z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4...........`.......`....#..`............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:CB73C648516EFA8E8CE2A1BE0D367186
                                      SHA1:555BE873EB8D85123D03D6344C521A8BF6F328D2
                                      SHA-256:3DD5AF973A2CD7CD1A3A4F00F680CCA72473E6C5ACCCE03AB9D400AC7D4956F1
                                      SHA-512:E368DA12275733731A4CC2AD87357B5EFD58EEEDEEB79641D8F9ED0D41F1115F561438052281332666060B2734AD05CAF192576D2F28B54625CBD1277AA6D8EE
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......R...v...F...................................................................................................................................2...>...........v...z............................I.......I.qk..B.....LZQ.3.....Q.3j....>T.....Q.3j....>T.....Q.3..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............f+...7..jF........N...^...................*.$E.../#..}........f........................................I.qk..B.....LZ.............f+...7..jF.............f+...7..jF.............Q.3.....Q.3.....Q.3.........................................Q.3j....Q.3T.]..Q.3.....Q.3..B..Q.3H....Q.3..B..Q.3..>.)Q.3..J...................;........4...4...4.."..............Q.3.Q.3.Q.3..z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4.........Q.3.....Q.3....#Q.3............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 276x139, components 3
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:5D6C1F361BC04403555BE945E28E53FC
                                      SHA1:00C254F7B3BC0289590C2BBDBB39C8EC2E2B2821
                                      SHA-256:131D637CDC5D0B094FB9FAD17F4D2A1ACE0D03613588155AACAA2D1CB4E16DA9
                                      SHA-512:34D2C0929FCC3CC10D0A2121BD55BFA9A07062C2A7B8F101071164C946895DBCB2777641E79DE4193D57A3F0778DD4F1351FAF333B7E4B4DBE31A32DD69C51F9
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.............C................................... $.' ",#..(7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222222222222222222222222...........".......................................<........................!1..AQaq"...2B...#Rb..r..$3CS.cs..................................................!1A............?.............u....p.p($.Y...9,j...V.*..S86yh.G.#m.5..9...6Y.."C.R:.[..-.7U3c:..].;.....f.?%..<T...&F.Lh.N...m]..x.D.g<B.....k..S........>j.K....#U..Z....<e.:..8....o..xq.[..4v..U..y...k... k....A#..A...pn.jJ.I.7:..{.b..ns.t,...8.Td.I....m.I.5Z.).-.. ]..X.Do%.....?..4jV.`llt.E...5...u.|..\F.=.F.r<...5dV....xc.%..&...4,...f...3..H.<......eQ...P.J....7...lLc..?..-.fR..7.#.6.......}:.]'.ny..........e;u.Y..$0...i..-....f..9(....}..T,.Inb...+=Cca7....WULA1@.s...4uY5.N.f.c..].ks.....3v..~..k..m)...f gNE`S......#.....Z..6.uc.m...#k.s.f*.l.$6..?..xC.Cm.`...N2..&H...._.&.E...[....f.Z./...!.a{K..#.V.5..v.B....1...9..B.&....%s.
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:3B34AF3F40BA7F592DD4E4005E47521A
                                      SHA1:1501177F034E8FABDB8A644FDEA12066D0214D2F
                                      SHA-256:CC40A8412D705B6D31E7F91D50CD44D6DFD401131019049BB7694AC5C912CC2C
                                      SHA-512:9479387995E8F6C82A85B4BC8418F7F512A0F6246F1D84AD5DF116F9128D45A0BBB4FC9B1CB68DA838A50F506CB960AEB7D42748ECCB6DCC4494024F1965C878
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......V...v...J...................................................................................................................................2...>...2.......v...~............................I.......I.qk..B.....LZ...........o.I..<D..:.A4...o.I..<D..:.A4.....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............o..w...&$..........N...^.................JSF.I..y.:.@e........f........................................I.qk..B.....LZ............o..w...&$..............o..w...&$..............................................................................j.......T.]...............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4........................#...............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:40F264E18183DD1DC29810D13214188E
                                      SHA1:6374701A1CBC03931E963E1262960DD724E05CFF
                                      SHA-256:4457D50A6F951CD687DD875188F19FAA59CAD474BFB309505DEB90D1603E482C
                                      SHA-512:D56C1FB6EBDF1FF93247ABB657F2583DDA1D7629A908B153028C38A057184892A3E1BE93BE4A8C00B0645428002A626EFDEE84700DAA31A8456EA12F8FE7C51F
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......T...v...H...................................................................................................................................2...>...0.......v...|............................I.......I.qk..B.....LZ..c.......cv(h..5O=..U..cv(h..5O=..U..c..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'...............-2 w...Sx..,....N...^...............r?....|J.U.A..6........f........................................I.qk..B.....LZ..............-2 w...Sx..,..........-2 w...Sx..,...........c.......c.......c...........................................cj......cT.]....c.......c..B....cH......c..B....c..>.)..c..J...................;........4...4...4.."................c...c...c..z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4...........c.......c....#..c............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 262x277, components 3
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:8A5444524F467A45A5A10245F89C855A
                                      SHA1:ACE68D567B02B68275E0345C86DB1139C0EC1386
                                      SHA-256:7D2B01F17354D9237A6AB99D5B9AFDF0E1CC43687125848B0C2DEDFB44CE3843
                                      SHA-512:8151B447B60D110C32EC1EF286B941FFC09B99140F41BBACF5A1650A385FF4D13C0DDB2878E9A470FC7CFCC95A1AB6E44F6DE72562B0FFE093DC8A3C3C7FCC14
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.............C................................... $.' ",#..(7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222222222222222222222222...........".......................................2........................!1AQ.a."2q.B..#R...3C................................ .......................!1.AQBq............?........)&vD.)3Hn*..X+....r...tmL.k..(.E...R. .Z..&...,fJ...!...6..S\t3.=...g&..Bqe.)_U.....1......-..fl.................J...u.i.mU..K..v.w.0O..E.h..D~K.(..9.,8..E.}.............i.\.....t."v..q..C............<..|3.........................*Q..../c.....f.}8....D..|k..Z......0..~..c..e..m(...|.c..'.5.5............==bx.5x.8...T;....=.--.pc...I;.V.m..,(....}...NH.ho....Q..U.E$.~...w.t>.S\....'f.{.+.g._.t....;>.....P...........-..G.h..2...J.% !.E97Ir.D..N....j...oE._...._...".?.......#".S.........Q.Tc.I..*I..k.......=$.........sk1Jp.\K.....F.3.Q..q..J....N..[l.&....OR4bB|..2ul....J...B.$&H..9#j.f.n./........?R~....B.I.@..........m
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:2520CF11B1287D1D6FAD5C098CF3E141
                                      SHA1:F6819675D7386D2C93A44EE9B79717DECEA07120
                                      SHA-256:86A9F571729C1E25FB524EE69BCAA408B8CC3F5A0C8CA6C96F80E21FBE6C8B8E
                                      SHA-512:F9B05AAA3EE39E3094AD80E9D1BF6CA21ACFF5A361669C4E8724EF1EBBF4A82C02F46BF4C12187737BE1835776D3B6A3C1E8C7AB65784FB3598F4756FBDB7B54
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......R...v...F...................................................................................................................................2...>...........v...z............................I.......I.qk..B.....LZ..Z.......Z..L......x...Z..L......x...Z..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............a&...g}.!S.....B....N...^.................!n...J.4.N&|..........f........................................I.qk..B.....LZ............a&...g}.!S.....B........a&...g}.!S.....B...........Z.......Z.......Z...........................................Zj......ZT.]....Z.......Z..B....ZH......Z..B....Z..>.)..Z..J...................;........4...4...4.."................Z...Z...Z..z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4...........Z.......Z....#..Z............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 70x626, components 3
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:EE9E2DF458733B61333E8A82F7A2613D
                                      SHA1:A86704C969F51B86D6A05ED51C6C60214ED9FA89
                                      SHA-256:BE4F0E6C89FCE91B9EBD2623567F7DFC259E0E3C77C9158742B8F64B724DF673
                                      SHA-512:BFB5D6DD6B66EE21E946E90D1E482384CD10244308562DDA814189602681DADDE5752B80519E5B8515F115A71BD6BB4317A59BE65B8B5E3474AED119F8303569
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.............C................................... $.' ",#..(7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222222222222222222222222......r.F.."........................................H............................!Qaq.."12.....#3ARbr...$B...cd...&CSu.....................................+.......................12..aAQ.!#q.."................?...#...3.Za......rV.5&...../"..i.t...j..W........d.FL.V.2K....]t.f.d.NK..:.....f...... ......2.[...#..D...ZK....p.z.E.N..T..L.-....1....2.\.6FIr2..zS\U#..........fB\t..5J..~q...D....A.......!....MY..../.HY..../e.M.Y.n.~..,....'..Pc...l...d2..m.f.it$..qx-z*...._..].cOO....n..&.....FIA.....2J2..d:<qc..6.I.G.N....f.K..Dx.-.......`....2.FZ."K7.r}..<.P.Z.da.Y.....8..s....G.....b.e..g .S.......FL.Z,&..q.MG.J+..x\..m...qN=.....)..`...&Y...S....u6{.z.g.....@......FL.ZL&.Iv.w..8....U..v...*.q.B.v_./A..#.#.g.j........*J;...u...W.Ao...%....#$.....M..^\{W.SO...s,.N.....c).,.B.Gv...."k..z."..S]H.
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:0F93C140484B8B0132D219E4F2DC8F3D
                                      SHA1:3D23EF21720B986107FFD20B9C8942125F48190D
                                      SHA-256:B703710270684B7729C1616E6627A7ED747826D2FC38A4EB6D3504E8B74A81CD
                                      SHA-512:14116E5AE17929F17EA23AF6BCE618FFD83A703DFFC93B21403D5103D8A67517B3D3EDCDAE7E6DDE3F60E1764B14D39C3AC07A9F0E187CFEB3F3E63E4EC4852A
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......R...v...F...................................................................................................................................2...>...........v...z............................I.......I.qk..B.....LZU|......U|..al..#g.~.V..U|..al..#g.~.V..U|...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............h..~..#.....\gf.....N...^...............s.ccs..J...............f........................................I.qk..B.....LZ............h..~..#.....\gf.........h..~..#.....\gf..........U|......U|......U|..........................................U|.j....U|.T.]..U|......U|...B..U|.H....U|...B..U|...>.)U|...J...................;........4...4...4.."..............U|..U|..U|...z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4.........U|......U|.....#U|.............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:PNG image data, 177 x 123, 8-bit/color RGBA, non-interlaced
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:8B48DA9F89264D14B83FF9969F869577
                                      SHA1:E1BD58E2D80FEEF56DC514F3F0B3AB9669F22F95
                                      SHA-256:62AD3C277E54F03F1ADB44062407346F789E63859B7AFABFD64BE6AF5E9F66EC
                                      SHA-512:03B783EC968DF3F648504D068D64DD1AE110E28110FE5B3401C9D04F44897DBE0CBB5680D42CA4C665FA94A6CED4B559106EB3C06C9BF2C5B14951ECBFFAC8AE
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:.PNG........IHDR.......{.....;Za.....sBIT....|.d.....pHYs...........~.....tEXtSoftware.Macromedia Fireworks 8.h.x....tEXtCreation Time.05/15/06.8.p....prVWx..Y=.+I....t.y...,^vv....;. "|. .i7.....$.2g..']pH@p..]b....H.H.......d'@ B...U.xm..3{3k?..5n.._}U...3......~..>...g.....f..t...t:...p>..Si..d:..k:.Lf..t6.K.i....d<...x.8\.8.+lc...)i.$.r.....x.t.BG.R.cm.c...p.:&.6.4..K.......^...~b].0....oBYv..u.'.=.K.Q.g)6.....4.!.M......4.=....G.%.Sr........nxC.F..t.U........1...J.t..eQ....".... |...81.$D.!.>...........$...^.vY..EY8tb..'.P.g#O....S*..0'.V....x.W..........k.......s.C.S...J%.iVb..].........3....j.}*.z....+.s..@..K.....\x.C..e.Qq.....;N.....;....,....^.*..$F..{G...8.#....8'..&....8..5.....3(P._....S......|".....u.cr....+a-....&V..x...iI-<|a.{E.c.X.......?..&.C....'........(.x....>...M.?.9..#X......l...0...Z.F..<.z.0}Q..Z1..........?h..`E$K.2o.A*c^.......*..D..uL=.}.#*0.. M!.A.C......|_..(.Y........!E... .O...`;....M+..x.u~g...q>...N."D^..K..x..D.`.!.
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:12D37A2095958A562B9538181BF7A882
                                      SHA1:E11C50434183FB9FC328EBE3B567ED0BA4809C1E
                                      SHA-256:EE8695B1DAEBCC5B15D96A2BA864B8C45E4E2F1B192AF7BBF6434567480B77E9
                                      SHA-512:C5983EA52004BBA4F2F9FDD18899930C3876AFC449034F03FB4367A74DAAFA077323E8CDFDB8FB9807039823A2B13E36D94675424316EC044281F2DCA0475CF3
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......V...v...J...................................................................................................................................2...>...2.......v...~............................I.......I.qk..B.....LZ6.......6...s#M.<.Lg...46...s#M.<.Lg...46....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............}1Kv..L.&...........N...^................1..U.N...t-..t........f........................................I.qk..B.....LZ............}1Kv..L.&...............}1Kv..L.&................6.......6.......6...........................................6..j....6..T.]..6.......6...B..6..H....6....B..6....>.)6....J...................;........4...4...4.."..............6...6...6....z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4.........6.......6......#6..............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:8B1871EEF20FCD71FE0AEC794ACA3B41
                                      SHA1:734C8F951C80A6520AF736B83C52D01855A538D1
                                      SHA-256:83DC423479130C022F10C45C64F8CA19172FEE8189AC369EC1E8C29971832221
                                      SHA-512:028887D05F0D91600B9D1171589679A9E9A09AEF96787BE30A35F653DD542759B2E70D1766277B55B1C0EC9C02825A46F7DA1E58974FBC52AF7B89503A53FD6D
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......n...v...b...................................................................................................................................2...>...J.......v................................I.......I.qk..B.....LZ.kG......kG,.?..#....N..kG,.?..#....N..kG..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'................U.....:.>.......N...^...............-Ve~..@.I..G.N.........Z........................................I.qk..B.....LZ...............U.....:.>..............U.....:.>.............kG......kG......kG..........................................kGj.....kGT$c...kG......kG..G...kG..H...kG..>...kG......kG .3...................;........4...4...4.."...............kG..kG..kG..z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4..........kG......kG....#.kG............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:09F9298B6372A5FA0EC435BC108C3831
                                      SHA1:45E6AB464C0CC7433A1F7640F9926E725AFA4B33
                                      SHA-256:1C73C53A526AF2EE9EEE7F1D67EADD1063DA562C731DEC4B41D6D8B7F521A880
                                      SHA-512:9EE8525F4099E3AFC7D171982E15AA4B46C78DF5E2FE673FBF50EC667891BFA0C14D694852619B76AEAA97130B9A18C554A0026616B4AE96DBC4D59F30EEF2DF
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......N...v...B...................................................................................................................................2...>...*.......v...v............................I.......I.qk..B.....LZF0......F0...&.. .V^..2?F0...&.. .V^..2?F0...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............7...+..&.....1....N...^................G ).BsF..qm............f........................................I.qk..B.....LZ............7...+..&.....1........7...+..&.....1.........F0......F0......F0..........................................F0.j....F0.T.]..F0......F0...B..F0.H....F0...B..F0...>.)F0...J...................;........4...4...4.."..............F0..F0..F0...z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4.........F0......F0.....#F0.............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:15:20], progressive, precision 8, 604x784, components 3
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:CC087700C07D674D69AFDFDA0FA9825C
                                      SHA1:F11113DF69DACDB255C6CBCFB29C1D1CCE40B346
                                      SHA-256:A7FA7F092EFF43030A56342C39A765F8D5CC48C7DB815DDFC8C1E5EC40117FAE
                                      SHA-512:843202D975EFA91E73287052A893584B6E5AE601F91612B56539AA2F73D1AD3F997FCAD1E711E0F483A2E91D46D9643D0B026B43F4E94116A5D2FB6551536034
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....H.H......Exif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop CS Windows.2004:03:12 11:15:20.............................\.......................................................&.(.........................................H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d...................................................................................................................................................{.."................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?.......J...\O.,......../$..........OE.m.o......T....Z..l.g.-....m.?...Y....3......"....].j.X.k.S.k.....4..R....{....?F.
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:1C67DCCACEC263AB6009D46588B60D1A
                                      SHA1:4CF68D70059FBB3D84598A01F62887F79971B50E
                                      SHA-256:995219F7B62EFC6BCEE296151259D40160302CB635054697DDE75020DCC478ED
                                      SHA-512:9B500A503EE133E505F4FC3FC7B9F266A649C03744BA344FE2A2527680A959D38CC7537AB5B875B734458FABCDF05900CEE4F289CA2C5BFEFAEB8E714E1C60F9
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......P...v...D...................................................?....?..........................................................................2...>...,.......v...x............................I.......I.qk..B.....LZe.......e......#.W.U!..e......#.W.U!..e....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.......................;........N...^................t.{.G.K..rT.:%~........f........................................I.qk..B.....LZ......................;......................;.............e.......e.......e...........................................e..j....e..T.]..e.......e....B..e..H....e....B..e....>.)e....J...................;........4...4...4.."..............e...e...e....z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4.........e.......e......#e..............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:13:06], progressive, precision 8, 570x779, components 3
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:737E96E41D79D3BDACE7AB4F8CBF6274
                                      SHA1:E6202A41A4F86B27D9EBCAEF7670B16C0ED67CF2
                                      SHA-256:7966F3D8A2D61ECB49A35E163781858E052C0B122A18A1238AFE27B57E2850E8
                                      SHA-512:D398C8521DB2FB3F8456FE792CF37472F3B851DD7298DB20E2DB79144F8E846D051878E77E5EF5D00E6840EDB90C6E2D97935BC1023A15FC45038CCE731E9895
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....H.H.....iExif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop CS Windows.2004:03:12 11:13:06.............................:.......................................................&.(.................................3.......H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d...................................................................................................................................................u.."................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?...W..I:..*....a....Aa ...w.T.M.v.........3x.......8Y....$.."-..m.I.0~sxB[@..=...:..\.Y?....@O.L;9i..U....?.5">+9.s\Z..vN
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:9BD416D05379C0F7C7A825F0BC5FA9E4
                                      SHA1:716FD07F1EC5CEAA65E0791AD36BDFC40F48400A
                                      SHA-256:B8EC5ECA13E290193966226D0F5E4CE248A2B91C9990B3DB9D59774D733776A9
                                      SHA-512:61AD79A321DEA144F997C8A92A75BBA8D5F74A1389EA1ECA76A53CA663B2DC18F7A113CF6740B902C9245F7D79A6C215392FCA022C6624EB2C7E09DE72D07DB9
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......P...v...D...................................................?....?..........................................................................2...>...,.......v...x............................I.......I.qk..B.....LZ...........%?......."v....%?......."v......I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............U...}.....U.@z....N...^................?....5O......mp........f........................................I.qk..B.....LZ.............U...}.....U.@z.........U...}.....U.@z........................................................................j.......T.]...............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4........................#...............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:CB84C108A76C2AFFCAC2551A3C1EAD56
                                      SHA1:8BB7C2A12B056C1ED12EBBAE5BC9F60CCE880FFE
                                      SHA-256:139BB0E79F89C3DDEF79B1716A5FBAB4C07DF5785FB3CDF6B4EEDDBF6C078452
                                      SHA-512:6EF85144E9A7ACD0FF2E52A5FF42093153EFB69127B1C8549EEBC49B6CC196A46B65EE39A2CAD0206F6A41476D8B5B35D29EAC9942B8F84972B32E14CAFEED27
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d....................................................................................!.1A.Qa..q...........".2..BRbr#.T.3C....S$.cs.D..4%5......................!1A..Qaq."2..BR....3...b#.r.C4.............?.......m.q..'O.....r......_.1....8h....?.....O]~..k......GO...''._...!....o........''..g..H?k.......1...?.....z......>...+0..................GO...''._.........}.O.Z|.L?...........?.........[~t.......}......NO.....v.......J.......?..g..H?k......GO,m..r}o.z.....}......dC.9?..g..H_..........?.....O]~...m...C?.z..f....W.=u.B..m..C.-?.a.....3._.?.......o....np.M....g..H_............9?..g..H...../..kO...''._...!~...o.....0.M....g..H.........../......O]~.~...o.......7..+.... ..l?.}........&....3._./....?.........W.=u.C..m..C.+?..o.W.=u.A.^.O....:......_.........}..t
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:F306153613046702657200732DDD4D1D
                                      SHA1:B5299F71D2F494E18898D91B9A119820F56A7998
                                      SHA-256:D8AF770E99FAD54C35E6A753DB3392352338DA82D13D30D17030892907BF36C4
                                      SHA-512:CDB83AA5011F7831315ABF6E496CF32645D7DFCD96F986C28F07510F2A8E95F07AE3AA9F89581C711CF2063C7CD9324F4AD66774AFD5C746CAE1283A98A0452A
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......P...v...D...................................................?....?..........................................................................2...>...,.......v...x............................I.......I.qk..B.....LZ|N\.....|N\J\.3.?.g.}..|N\J\.3.?.g.}..|N\..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.................i...5N/.g.......N...^...................vU.N.R.....o........f........................................I.qk..B.....LZ................i...5N/.g...............i...5N/.g............|N\.....|N\.....|N\.........................................|N\j....|N\T.]..|N\.....|N\..B..|N\H....|N\..B..|N\..>.)|N\..J...................;........4...4...4.."..............|N\.|N\.|N\..z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4.........|N\.....|N\....#|N\............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:PNG image data, 40 x 623, 8-bit colormap, non-interlaced
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:07DB3F43DE7C1392C67802E74707DAA6
                                      SHA1:C173ADB1999065C5E1E6DBEF934B4D4D7AF0CC23
                                      SHA-256:51E05999A1C9F17DF28CB474E57DD8E64BDAB824874A532C20A23766A01F8967
                                      SHA-512:E509255519D4E521E82332FF418DD5A6BBBC8476399A0D9C3D81542C1CABA535B2D79E5BC90F73F9EE8468643302137671934ABD600FC696F16161C91FEAC111
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:.PNG........IHDR...(...o.....>.c.....PLTE................................................................................................................................................................................................a.o.....bKGD....H....cmPPJCmp0712....H.s.....IDATx^.Y.. ..........}%.../].`<..y....V...m.....<....)..;Ki..'9...2.:.c...t..V..d.t;-y.Z.=K>B.."{Lj.~G..|..ENC.!Sw,....";.p..g....E.B..S.-...k..P."..E......l[./D.-.....Q+.G<>.+..b...#..y(...{a.M..J...<....v.W..F.qm.`.....(.mk.nX....l.Px8.0\Z....7G...$*.....&..Z.VJ.~......J.2|...2H..../...=.)q....ZT" .,%..h.p....Z$.!........r...Hh.f. ....P .d..1d....2.3h....;.A.... ....d..g4...A..^.....2.ew..."h...y/..j.h..B.......%.2.%..{r...+dG.=9h....P1...A...c...^h.]Q0.8x....q .!3....ZW"Z.!3...G.vC.GG..".&..X!3.|xB..V.P!.+zS..NX!3.....Nh.y(.Z.1.h..B...Z+....l8Xcu.B...K...@U..@Q...mB...x...&L C....mB.....@kC...Y.,.... ..e\F.B..........y..e\..:$(....Z.a...yn...f..z.~Q.{o...].ln.r....^.@.{..c.7..{...
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:3BDB611742877C0AF2773A28FF60EF70
                                      SHA1:E10684E897F7D944B8B65A11B2D5C9FA97EDA3DC
                                      SHA-256:BAC74E66750B2D43C3611D95BBE12251DD2A698166C2CD6C50D93E12F73D7A0E
                                      SHA-512:A8A51882B8E16214412052B2B49CDD6D99A05B6E595FA927F8A78204059D15587E272590849252C43B15232AFD0E55A63B2DA61B63E7C0D2A88FF8A2FBE9E83D
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......R...v...F...................................................................................................................................2...>...........v...z............................I.......I.qk..B.....LZ..1.......1.:....#:.'..+..1.:....#:.'..+..1..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............$(c/...<.'.........N...^...............^.VOP.XB.9m..G+?........f........................................I.qk..B.....LZ.............$(c/...<.'..............$(c/...<.'................1.......1.......1...........................................1j......1T.]....1.......1..B....1H......1..B....1..>.)..1..J...................;........4...4...4.."................1...1...1..z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4...........1.......1....#..1............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:B1DDD365D87605F96D72042CB56572F6
                                      SHA1:ADF71DAD1A62B8A58A657C2EDBDD665A19EB846B
                                      SHA-256:06E09DE80C3F32254DA4FE6B2CBAD7C05EF144DD54B8C65745E195BBF7317A2E
                                      SHA-512:9C686092CC9524F34EA6CEC9AAE936A6225BCC54DE38DE1786EBA8F532959A80FF885E8664A09E4C318D7CA4B278E807D3D1F135BE55F30979B844FF5EC9699A
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d........................................................................................!1....AQ.aq.....".3.5...2B#s.$%..Rr.CS4&6...bE'7.c.DTtU...d.eu...VFfv.Gw.....Wg......................!...1AQaq........"2..4..Rbr#3$...B.s5Cc.S%.D............?..^.f....R*.N{.{f.....O.r.V.;U..~...U.(..>M._.yI.{8,..^.t...s`...j.O..U5t.&&..h.G.6Da.;.....J.......E..QD...C...}..N...tR.....~..].J:.V$.*.r......]...W......4.[.)6..Y_.....4...........m._'HR.a......]U=.....n...0.W..]..K..){.+...w...f...<|..1/.|.....b..-..y....]U#Ctn.7m.._.|..2I;|....tM....q.q.}.N)....'...9&...nR...R..}.........m._.LZ}u.../K....9.~..?.{....V.#..dx.Zk.:=..:.j].....E#....E~w%....J..[S..[......gr...vb.r]..<..ut..i...[P.w....:..Gkn>......#..m...9km`......t).up.....w....VOR.{&.nQI..}...wD.7Ey#n....MO.
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:5E486B27516FCBDD0294127B34D13AF2
                                      SHA1:2E10B21D6A86484EC8B2B83DD05B29A1150CE867
                                      SHA-256:A201D496AF9E12CADA1EFEEE3CE25328AC9D18EB39CA9F521EC28CC153216ADE
                                      SHA-512:9450572197881E14B13B3656F2AD2BA6050C87858AC52CDB48971E8498A146F4BF141834D56396E7A93D16B0A50CA6803EEFDCD3A604813433BAF401CEA38E98
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>...........v...~...................................................................................................................................2...>...f.......v................................I.......I.qk..B.....LZ...........a.......a.c.Q...a.......a.c.Q.....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............aBf3$M..'..z.c.$....N...^...............h...L.7J."s.|k._........f...................................:....I.qk..B.....LZ............aBf3$M..'..z.c.$........aBf3$M..'..z.c.$........................................................................j.......T.]..............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4........................#...............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:10:32], progressive, precision 8, 594x773, components 3
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:C594A4AA7234EF91E6C2714CFE1410F1
                                      SHA1:C0F720D4CE3196852814D0B7347F0CAA0C6FD526
                                      SHA-256:10C833E47BE1C8496F949A6B059C2D79212A4DD66BDE62116EA337FA4FE0B654
                                      SHA-512:7313F6545A334F9E2DE5430B2DB5C419C4C8A40E075338DAFCD74970BCC6309786946E5DFB57531612BF4C6269495655706D920FD99922FDACFF9796710DA9C0
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....H.H......Exif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop CS Windows.2004:03:12 11:10:32.............................R.......................................................&.(.........................................H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d...................................................................................................................................................{.."................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?...v&.F;-v;}FH..Z...N..)Y.......h;C....G.0W..ww...MI..Z+..\.........c..4.1.~.Yo.Y6.&. q...............l.A#.~s?yYg..7ky...r
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:1A62E777F49DE36E3B1FB7C4768DA27C
                                      SHA1:5DA19A621578DB59ECC1756C98A5AD0736A31FDA
                                      SHA-256:8A172D4298B4816CE3D7D2C6C1025A5013902567B3C9107E41116EED24D21F4C
                                      SHA-512:2E2D9EA3602B56D0C548461906CBC51AC91B60E7838F68248F30B22ADB64645F979F5873FF094D5A4DA36A3903D8F22DE7EF12F876B8B52EF324625AF397BBE6
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......P...v...D...................................................?....?..........................................................................2...>...,.......v...x............................I.......I.qk..B.....LZE;......E;.x).....I7..znE;.x).....I7..znE;...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'................X/.'.=.../.....N...^...............Ne.zM.O...d.<C.........f........................................I.qk..B.....LZ...............X/.'.=.../............X/.'.=.../..........E;......E;......E;..........................................E;.j....E;.T.]..E;......E;..B..E;.H....E;...B..E;...>.)E;...J...................;........4...4...4.."..............E;..E;..E;...z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4.........E;......E;.....#E;.............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:12:29], progressive, precision 8, 598x766, components 3
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:EC7811912ACA47F6AEB912469761D70D
                                      SHA1:C759BC2D908705D599B03BDB366C951B11F99A4E
                                      SHA-256:FBB4573E3BEE1B337077691BEBAE15D6FAC52432405D31396D526D7694A8283D
                                      SHA-512:881828150993A8C56E36CDA2051D89C1F6E0322643902C9506392C163E8734A2933A46486F40E5BC8C8D0164E180605E52620EF22FE14540AEA787A38B22E98E
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....H.H.....7Exif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop CS Windows.2004:03:12 11:12:29.............................V.......................................................&.(.........................................H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d...................................................................................................................................................}.."................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?.....H.yM..? .Z.. .^.x..p.8.A...K.... .\{..)..y....t..=.^y)..v.@.W>. .h.. ..p.:.\)(.$....$.I).....!....E..Z.....&.5.).
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:31AE32F4AFBD29B2EF7B35316C94DE69
                                      SHA1:B13D096CF3F0716B312D0EECE9F23BD584AC93E8
                                      SHA-256:F986EF6F5091E6E1C85B44DB471E008946F3B53E5169AB0A845EA5DF5DEB7D9E
                                      SHA-512:03127521CE042B43F1403B608F4169C721D71717BF833A539ACE9B8B9EC5A3CBF3509522B0E32984393A0D4A092D3721EBADB1E6480181A5ECD9C47B89F8A60B
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......N...v...B...................................................................................................................................2...>...*.......v...v............................I.......I.qk..B.....LZ................".>.|P.#........".>.|P.#.....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.................["...x.V|.6....N...^................."ho..D....}..........f........................................I.qk..B.....LZ................["...x.V|.6............["...x.V|.6........................................................................j.......T.]...............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4........................#...............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:3F0B5C5FA685B79304662F1FE4172670
                                      SHA1:CE01876DBF29ECBD23E6A981BEDAC5B0A5A84492
                                      SHA-256:639438DFD3A1F3786EDC07E621426FF0D66A2A07381E7D0C1A7A5B90B5AA96B6
                                      SHA-512:57C21C030303C1228D36B90DB74C9535B3A6D3F5BF85E5605C478E8FE85273E1172B1A62D79D4C0D454DB8E5495A7300B7FE3980DAD4108681619BEC1C634410
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......N...v...B...................................................................................................................................2...>...*.......v...v............................I.......I.qk..B.....LZ.7.......7.%;0..?4GG.:0Z.7.%;0..?4GG.:0Z.7...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..................?.......XV....N...^................wD%..K.&H....m........f........................................I.qk..B.....LZ.................?.......XV.............?.......XV..........7.......7.......7...........................................7.j.....7.T.]...7.......7...B...7.H.....7...B...7...>.).7...J...................;........4...4...4.."...............7...7...7...z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4..........7.......7.....#.7.............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:7A450E086AD14BA7D89BA5DB3D3AE6C7
                                      SHA1:E7AEAFCFCE476390E18C19456BDF6529D863D518
                                      SHA-256:BDD997068701ED3A00A224EB694B003C01AC69B857FE7B4147D6C34875B1632B
                                      SHA-512:9B6D50A6CDB6081DA107A2CDDB1BD2811A5764994C8E3F67D56CA81084BE0D068C27435154E867199F38688EA65E8DE02A56DCAC47D0F5E55F0FBB6598814938
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d.............................................................................................!1..A..Qa"..q..2.......B#...R%.r...$&b...3Ss.4dU6F.cE..'GC..t..5eufW......................!.1..AQ.aq..".....2BR......r.#3.d...b..Ccs.t......$4T...SD%5Ue&Vf............?..M.7(..).:.a.q.......>..[:O...afQ.uCO..U.....go.l..p..YqVklQ.{i.w&.]Z.\+JQw._.n.'.h..,.bj..X.].k&.Q.>gU..f...1|....[...jQ.%Zb.......t..........*..V..j.6....Vj..i.....?...IY.P.....$.j........[l.....S.4.J9.U\.......7I..[..=*N5....xW..../...=?n....uG.D..S.>...8..3........n.S....]k.*...4.>.R.o..{..l.H.#.^....<amG.m&.......,....wDY.W.m.X....We.IR.Nu...y..Z.l.._S.mr.m...y.]m.R.MT...6.5.5}.K..#%..k].7.Y.q]...%.r.7.R^jR..z.K.T[t.a..d.)glW.r.v,.`....O..^..o:.Uc.\..D....f..D......yt.Q...Y.....
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:5F5A9AFE78BF52DF23DACCA4FC5ADDF9
                                      SHA1:D60A2BCD34E8341612799F50D5117CB18F4D68C4
                                      SHA-256:34FE33E189C52FFFDA1CF0BC06D2ABDD8727867E1F9833357EF0A84CE079B371
                                      SHA-512:58D362E51A66EF8186DCE29DC50B9BCD745EC526E2A1A0044D6F72BC84F52A7ACDC6C191FB973657F0C54E7CBFC6411B10890458464AD3773D3609D83A798233
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......n...v...b...................................................................................................................................2...>...J.......v................................I.......I.qk..B.....LZ.34......34...0.-.k....34...0.-.k....34..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.................../.Q.R/.~....N...^..................z..A.s.y.(Qk........f........................................I.qk..B.....LZ................../.Q.R/.~............../.Q.R/.~..........34......34......34..........................................34j.....34T.]...34......34..B...34H.....34..B...34..>.).34..J...................;........4...4...4.."...............34..34..34..z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4..........34......34....#.34............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:9A4FE7C0723DA492B522591B04DE0833
                                      SHA1:79A8A842F7286F0CA78D9ECB550C2970D595A757
                                      SHA-256:DCD22495C72BE5754EF37A1CEAAB313C18C9908BC56393B0B921FC8CF5ED7766
                                      SHA-512:21A0464CEF541AB9B2C74BCE3A0F4C2ECE2F47217CAFEBAAEE79D0CE82D6B76FA3C397C37B61DC95E2605C2B5B46CBF4EE96F50E6CDB0551AE703EF4F19AF2EB
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......R...v...F...................................................................................................................................2...>...........v...z............................I.......I.qk..B.....LZ.b......b... .,~.?P.a..b... .,~.?P.a..b..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'........................DB-......N...^................s...3.@....5."N........f........................................I.qk..B.....LZ.......................DB-.....................DB-............b......b......b..........................................bj.....bT.]...b......b..B...bH.....b..B...b..>.).b..J...................;........4...4...4.."...............b..b..b..z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4..........b......b....#.b............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:PNG image data, 40 x 617, 8-bit colormap, non-interlaced
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:3E675D61F588462FB452342B14BCF9C0
                                      SHA1:86B62019BC3C5BE48B654256B5D10293FC8C842A
                                      SHA-256:639EADAD468B6B32B9124B1F4395A8DA3027FF7258D102173BA070AE2ED541AE
                                      SHA-512:E6EA855B642ED36FA82F8E469A826DC57EB0C36E307045FF8D166F67AF9242C87840833BE31FBE4706DC54100E999D6A3D3A78D0633A3114735818874AD34758
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:.PNG........IHDR...(...i..........`PLTE...................................................................................................bKGD....H....cmPPJCmp0712....H.s....qIDATx^...0.Cg.;......@j..2c.=~KP.[H~..@..8...?U.g.n.a=.=.).....3..u^(.....L....5..........8.}..T.f.n.a=.=.).....3..u^(.....L..r....s..8.....W]....,..9..G?.a..`c.z...E.p...)Y.P.....#....@9.7].....,..9..G?.a..`c.z...E.p...)Y.P...`b....0.b.+~{.Pu...1..<..0._.l.@O.y.(...V3%..J....s... .(g.+.qyWu...1..<..0._.l.@O.y.(...V3%...%R.L.Q..x..R.<t.o......7.............:/.E..j.da@i..`b..Z......u.>.?...7.............:/.E..j.da@.Dj..9.W....s. .....:.......L...">w..7... .....:..."...L..."..a....D..Ya.l....E.{.@&.|.._...7..D..Ya.l.....{.@&.|....0.J.."z.0s..s....=g ..>........"z.0s..s....=g ..>..l..1...y..g......IEND.B`.
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:C3BA3A1643B1EC968C0F9487B2454A61
                                      SHA1:1E31FB785B410703FFC0FD2A1D8CE4D4166319B6
                                      SHA-256:2FE2A6C85996E386D49B2E187A1125209E64DA5451C94D768EEEC7D1E7DC2C40
                                      SHA-512:75B4172588BAB655B507E858EEE3F5D0EDB8E137E9634DA9841B067B5F84837F6027877B4B254270D0FBAFB1181692270AFA8C397E1096359F93174CA158A6C9
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......N...v...B...................................................................................................................................2...>...*.......v...v............................I.......I.qk..B.....LZ.+.......+.1.i...v..:2.+.1.i...v..:2.+...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............j.1....3..w......N...^................A.8j..L.u./.No.........f........................................I.qk..B.....LZ............j.1....3..w..........j.1....3..w............+.......+.......+...........................................+.j.....+.T.]...+.......+..B...+.H.....+...B...+...>.).+...J...................;........4...4...4.."...............+...+...+...z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4..........+.......+.....#.+.............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:PNG image data, 50 x 600, 8-bit colormap, non-interlaced
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:2494381A1ACDC83843B912CFCDE5643B
                                      SHA1:98F9D1CC140076D1AE5A9EA19F47658FD5DF0D66
                                      SHA-256:5EEBE803E434A845D19BC600DF3C75E98BB69BD0DE473CEEC410D1B3A9154E28
                                      SHA-512:0E64CC3723DC41D94910F7ADFB6A0DFB5049350FD15A873695614E4A89ABD78B166BA4E9C8CB95E275FB56981539DECD2A7F28FBC25E80DD5E2DEA8077CC9489
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:.PNG........IHDR...2...X.......E.....PLTE...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................B..(....bKGD....H....cmPPJCmp0712....H.s.....IDATx^.].\TU.?3"...(..L........q.Q...H.*j......W..Xd.ie.f..%.XT...em..m.m.vkik...>.}..}|..{'.U..~......}....s.............,CVu.x.:C..5...;.
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:F621A83C1DA306EA05D0DF5B236B152A
                                      SHA1:9EDDC3A7CFAF9141AA42D334CE640B52E5F09746
                                      SHA-256:D1AB6AB09390E03531E34AEFB8A96ED7EE5CD47592D2ECE3B6378213D9A6C67E
                                      SHA-512:108822C15E4BE7028F7883AD8252073476BA60144C1F7B36C1242C4427C0DE9A4EA84104FD7DE25DB4DACCA48CA6412F25C1E7210E1E03D150CEFC91B3109DB6
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......P...v...D...................................................?....?..........................................................................2...>...,.......v...x............................I.......I.qk..B.....LZ..3.......3.w...9...@....3.w...9...@....3..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'...............A*.{...tL..`.....N...^...................t.J..rA.C..........f........................................I.qk..B.....LZ..............A*.{...tL..`...........A*.{...tL..`............3.......3.......3...........................................3j......3T.]....3.......3..B....3H......3..B....3..>.)..3..J...................;........4...4...4.."................3...3...3..z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4...........3.......3....#..3............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:4A2472AC2A9434E35701362D1C56EDDF
                                      SHA1:16FA2EA2D2808D75445896E03B67A93000EEDDD8
                                      SHA-256:505F731CB7707EFAB2EB06685B392DC7E59265A40B55AAE43E5DC15C0A86CBA4
                                      SHA-512:5E28D8FB2AC62ED270968072A30013334461F7CAE96058AF9EAA6E10912989DC47112D2133892BF61F7A516B77C6FF71BA2A000B750A9F95C787E538B09595C2
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d.............................................................................................!1..AQaq".....2B....R#..b3...r...C$...X.....Sc...9.%'.(Hs4Dgw..T..5GW.x.)......................!.1..AQa"2.q.......B..#c........b6.Rr.3s$.&..S...C4.%5............?.........(......(......(......(......(......(......(......(.G/.GE&...)..P.x..B.({i2Y;.z?G...Yfc.)H..^....#.....}3..Sc^.H..+...M.a.P.....GS.....H_.3..<....1f........1.<.\..nn-..s.s.\9Y....=.......S.0.......N..cA..Io..r.3..........ay.....K.....,.;9..Q......xO.Fa.2..>........{4k.....|....?U....3.8..._/3....#.. t.y......yY.......e.<........#.....B.....Z.%.Y..S.ye.W4...l.......X...%.@y}>....l.yi..D..W......L..._D.Q....)...E....n.%...*..K.4#.8`..I....h..h.o..I......-...hB...3..u.(5..........n...,.@....a.t.9.....@.s.>.&...@
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:A2226385060D0594C98E33745AE98CC3
                                      SHA1:7603FADA21A39CAA2364EB43BCEC75F469CE06E9
                                      SHA-256:09D96C695B3F9D4A858FA5B0C7CC4EE193A5CFC840AB54FABF42CE2016CE5DE7
                                      SHA-512:E75675DC48F73E79301DA61DBF0FB4B6BCBECBFAE3979357E8D342AE3AAD177AD776691797366CE815A636E53D5102E9B484E5F3A796110A6603CA58BBD10B6D
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......N...v...B...................................................................................................................................2...>...*.......v...v............................I.......I.qk..B.....LZ...........`.{p..V......`.{p..V........I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............8+......9..F.......N...^...............Z?..<..B...MK...........f........................................I.qk..B.....LZ............8+......9..F...........8+......9..F...........................................................................j.......T.]...............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4........................#...............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:PNG image data, 77 x 627, 8-bit colormap, non-interlaced
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:FA38AFA965141EA3F17863EE8DCCDE61
                                      SHA1:2B4611E651AF7549C1AA73932B1136B561A7602F
                                      SHA-256:E1CB1A0EC9BE62D5445C73AA84DF38234002A7E164EE830C9DF24997802CB5D2
                                      SHA-512:A372674F5CA343321BA9C413D346070709F7685706C9C6C3DC7F61846B59253A5E6FE800DBA10AE870FD3887439B2AA106FBBB51751E92A163938A4393C43E28
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:.PNG........IHDR...M...s.....}8nv....PLTE.................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................z`.....tRNS...................................................................................................................................................................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:A4C4AFF87C0165466FD91E0FDA578B36
                                      SHA1:2937870274A9A5C158432681691007E2BDAC848C
                                      SHA-256:4E4407C7C3A47D92B696ACC63535CF8BCA76756F267BE38121EF98C1B214F8D1
                                      SHA-512:44BBF2E0685F4DA6CA9E8A76407F7F135A852D22DAB2AE32D3C30D0986272BDE5815A57FE2BA92A5423F7C1819D9AFC7B993D022581CDEE2A3DAFAD2D3CBF5DA
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......h...v...\...................................................................................................................................2...>...D.......v...............................6.......6...}.K..*..8"F..I.......I.qk..B.....LZ6...}.K..*..8"F.6....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'....................!'..O\.w....N...^.................oiN.F......8!........f........................................I.qk..B.....LZ...................!'..O\.w...............!'..O\.w.........6.......6.......6...........................................6..j....6..T.]..6.......6....B..6..H....6....B..6....>.)6....J...................;........4...4...4.."..............6...6...6....z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4.........6.......6......#6..............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:C75FAE8C22E1C47E71D8D14FF4AD82FD
                                      SHA1:67771BC139F7627BE7858F5B47A8EE08ACC117E3
                                      SHA-256:BED882D21A13B4B3B7573E61F4C69D5F278BB0E080EEE1D6538037ABE2E8432A
                                      SHA-512:5164A06325D05C0BBE75B8B6BDA067FE7D73BB0D22893983F32A7D3BF45506F3E750BB677DB1765C8A58F4B5BD9C89CA9E662D46CCB92954C82B505D3DE51EF3
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......h...v...\...................................................................................................................................2...>...D.......v................................I.......I.qk..B.....LZ..C.......C.^.4.0....`"c..C.^.4.0....`"c..C..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............<.^.....K...q.....N...^.................3.v.~I..b.0.P.........f........................................I.qk..B.....LZ............<.^.....K...q.........<.^.....K...q............C.......C.......C...........................................Cj......CT.]....C.......C..B....CH......C..B....C..>.)..C..J...................;........4...4...4.."................C...C...C..z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4...........C.......C....#..C............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:FAA0DAB1A838A10D9B82E9517436B1EE
                                      SHA1:02AA94F2EAB96B79DF17B4309FBC44383E210DDC
                                      SHA-256:14ACA1A78C54A6B731941ED5F6217A55BC4CC4D413D48A4836D4BE5B9636BAD3
                                      SHA-512:0471196EF8DC55B46CDA95D5FD29D533F0227C9412FBADE711D03EEA3DCDC17AF470154D1ACFABDE4DC491F2C072880DDAEB84C6FE07767162D192A1EF22ECD0
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......p...v...d.....................................................?....?........................................................................2...>...L.......v................................I.......I.qk..B.....LZ............)...6Z.d1.0.....)...6Z.d1.0......I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.................|..3TM(..IH....N...^...............X..9..WC.R.............f................................... ....I.qk..B.....LZ................|..3TM(..IH............|..3TM(..IH........................................................................j.......T.]..............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4...*..7*..7........................;........4...4...4........................#...............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:18C2F30AE738C232245866C3021E636F
                                      SHA1:D9543ED1A9E02A2CC49B47B13C2CD37A552E4A34
                                      SHA-256:767C6D9DC7A8C61189FB6B2805F48AEE75EABB7FB70B1FA147F2FBE23C632F8A
                                      SHA-512:759640A662FA6A102C23C1B12ABCEC06D2815502F3D5BD1045B9606F55107A00AD35D71969ACAFD80F38F218955B3B0F7C8A52B16AFDD011A24C5D7A90C98F2D
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......P...v...D...................................................?....?..........................................................................2...>...,.......v...x............................I.......I.qk..B.....LZ.........x].i."8...SK..x].i."8...SK....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............I..k......Q........N...^.................nvrfD.C....)k........f........................................I.qk..B.....LZ............I..k......Q............I..k......Q........................................................................j......T.].............B....H........B......>.)....J...................;........4...4...4.."........................z...y.. x.. ...........$........4...*..7*..7........................;........4...4...4......................#..............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:88FFA9CDD060B67A01360AFD8B212245
                                      SHA1:E119E61AC0F5FCD2E06ED20DC3BE03319F0C464F
                                      SHA-256:DA58B9DAE1523CF8A8BCBB3C657837582ED815F30C99350407A3E7E493415BBA
                                      SHA-512:5CA6ED65AD9C7E7643D4F215BC9ACA9A6C1EC8C954B1D1113F0484277297540E5B5919CF54478E419295876530D3797632026F7CBF56FA31699D074E7E88A81B
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......t...v...h...................................................................................................................................2...>...P.......v................................I.......I.qk..B.....LZO!......O!..*.......|.&nO!..*.......|.&nO!...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............BI./~P..<..pj..H....N...^....................#J.......e........f...................................$....I.qk..B.....LZ............BI./~P..<..pj..H........BI./~P..<..pj..H.........O!......O!......O!..........................................O!.j....O!.T.]..O!......O!...B..O!.H....O!...B..O!...>.)O!...J...................;........4...4...4.."..............O!..O!..O!...z...y.. x.. ...........$........4...*..7*..7........................;........4...4...4.........O!......O!.....#O!.............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:PNG image data, 176 x 513, 8-bit colormap, non-interlaced
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:8E9AB9C28B155A66BC5C0DA5E2A4EFB5
                                      SHA1:972E61F162D48F1CEE21963ECBB2FE439105DB55
                                      SHA-256:B243A24FA13BC8523450E22F408F9EFF15301C938F8CA52A57018B58CE6785DE
                                      SHA-512:12062D69E676B3B34AFCEF25AC17B40294282D5BAB6C0110680293D7CC96EC17EBCFE104C284E64A30EE3C483E319E9C37C03F6EE82C79632180E45C7A684E8C
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:.PNG........IHDR..............`....`PLTE............................................................................................... .......bKGD....H....cmPPJCmp0712....H.s...*YIDATx^.]...,.N.8.i......0..e..y.......8.6....Fo.........=...F..._..........O..{..............3.|.L.|.............>.....v..n.1J...k...."....7........J._.5LQ`..k...._Z.W.x:..k...g..._.....u<.Q{...1...q6.cs...l............30.g...< W...a.5..>O....9}..c..........s|I.).>.fo4.<q......>...c.:.u..co.#.7,.O..G./.K.|..q.p...(.(....iH.......m..+.7...../..{W.l....b....?.`^.q.9L&.>.hN2`1..m...]$.0J....rBy......{.._...G....;.r.Q..;..,...9..F...t;.+..2.Ub......V...8.k..5.........'[..s.H..).......%j._.&.....BN..V..q...T...#..........0.E&.o7....$..m..8g.f._$..k.8...5......HgQ...L..\.........)B.I.r.(..8.a..$N.9.=..o..Q..(.e.a..O.....c.= .......$0..X.S,..(p......$..l.c.I...=."......g....^..#~,&.a9iK..ZNE`...pFJ.@Wd?.<..Bt.E.......e...i.%d...}.!..B......9.........B}.....5...;..hL.D.....4z.....|.)
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:EEE941C8A59192F6AD3BAE0CEB2EB5CC
                                      SHA1:FB2D8CCFA9A692B83058C6381C317F02A9A98D94
                                      SHA-256:523A764415CA8A91673237A459B11692C3E59CAC3BF0FBC87DDAA2932407E953
                                      SHA-512:085D69E060FC12FD56A7EDCC663B713420F860F19C8D47601A5B9FA8535D6EFF8909E61BDEE52474EA45D9E0CE008F70B9437AF1297E2F81571351CFF6A76602
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......R...v...F...................................................................................................................................2...>...........v...z............................I.......I.qk..B.....LZ.f.......f.}$9..?W.....K.f.}$9..?W.....K.f...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............C......_.e8......N...^...............:.....TA..1..yu.........f........................................I.qk..B.....LZ............C......_.e8..........C......_.e8............f.......f.......f...........................................f.j.....f.T.]...f.......f..B...f.H.....f...B...f...>.).f...J...................;........4...4...4.."...............f...f...f...z...y.. x.. ...........$........4...*..7*..7........................;........4...4...4..........f.......f.....#.f.............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:PNG image data, 40 x 650, 8-bit colormap, non-interlaced
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:DD876AA103BEC3AC83C769D768AD39FB
                                      SHA1:1833603AA9B6A7E53F9AD8A336F96CCE33088234
                                      SHA-256:1262DD23AD54E935CFA10FEB1BE56648E43BEF1116696CA71D87E6E033B1CA7D
                                      SHA-512:946DB2277213104A3B29EC4388578B05027B974A3093B4CCAD8847397AA51AE308BC6A199E5705E1F901D6E4B1BA34D8DECFD6E5B6685184A307D749D7CFAEDD
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:.PNG........IHDR...(.........xk....`PLTE.........................................................................................>.S.....bKGD....H....cmPPJCmp0712....H.s.....IDATx^.)..1..7w....6.*.H`T6.ha.k.............b!....Ba..C..P.4K..@.....h.E..X....PX+.P.-.....@@"...o.O4....xZ<...B...B..,A..y.s<......b!....Ba..C..0_p. .......=..,...i. ...=.j..N...........{4+...xZ<...B....|.....$.K<.vyE..X....PX+.P.-.:... .'p......\,...i. ...=.j........K.....%J..S+.....q..k.H.@DD.s...:..J.K.DDL.\.@`,.DD.:.(]..N....KD....A M.....F..S+.....1.sq........\.t..;..../...~k...4.DD.:..]..N....KD........@DD.s...:..J.K..[...Q....V......IEND.B`.
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:5EE63D0E0DC5E09B36070398F25AE638
                                      SHA1:CDD2A67D4D275AD4A3D0A1A83ABB78B351480387
                                      SHA-256:D8EEEDB6A226793A5D4341E7DA9C1B92FF5D9536545FF74E88BD19D89E8B33F1
                                      SHA-512:916056A8E69D723A74D7258932F6F73981AF4F52B45C1C8849AA0EC4906B2E1B912CBA0B0B6866506D6BCBAF02558E0710A03B3C065273011CA041477CAEA001
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......T...v...H...................................................................................................................................2...>...0.......v...|............................I.......I.qk..B.....LZ.~.......~. .=`.1.....YG.~. .=`.1.....YG.~...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'...............N..]k..e...8.n....N...^...............?&.....M.0u.'..........f........................................I.qk..B.....LZ..............N..]k..e...8.n..........N..]k..e...8.n..........~.......~.......~...........................................~.j.....~.T.]...~.......~..B...~.H.....~...B...~...>.).~...J...................;........4...4...4.."...............~...~...~...z...y.. x.. ...........$........4...*..7*..7........................;........4...4...4..........~.......~.....#.~.............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:C7CD481CD999704307BF5A28DE246CB3
                                      SHA1:FFBED7D327E4DF876CE6DC5BCB14AFC51AE1FBD8
                                      SHA-256:748BA570EAC6E736D5A0DDA41EBE1E1F3D8FC2F2E225BE1EBD3C1F117D31418B
                                      SHA-512:0D8A336F11F23FEFCBE220FFE3578FEC0FED0C8632334B3116EF1846EAA15F2F3951DFADB0B76A7A50A2869BB6A172CD1F3ADBC7B8776ED28765999EB9CAC366
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......N...v...B...................................................................................................................................2...>...*.......v...v............................I.......I.qk..B.....LZ.B^......B^m.....|.......B^m.....|.......B^..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............)..5...5...>.....N...^................e?R...G..@...."........f........................................I.qk..B.....LZ.............)..5...5...>..........)..5...5...>...........B^......B^......B^..........................................B^j.....B^T.]...B^......B^..B...B^H.....B^..B...B^..>.).B^..J...................;........4...4...4.."...............B^..B^..B^..z...y.. x.. ...........$........4...*..7*..7........................;........4...4...4..........B^......B^....#.B^............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2004:03:04 13:18:09], progressive, precision 8, 164x641, components 3
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:E62F2908FA5F7189ED8EEBD413928DEE
                                      SHA1:CA249B4A70924B73BDA52972E9C735AEC35A0C5D
                                      SHA-256:20ABE389C885E42B6EBE9E902976229BB6FD63C8C34CB61AA70B8B746209F90A
                                      SHA-512:EE8D1821A918BE8714F431895E7223D08036E88A4FDB9A5485EFF246640EE969A69A8AA4E2E9DDC35BA75FB6D4E95092A286E90B477BD6998C313639C2C31F25
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....H.H......Exif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop 7.0.2004:03:04 13:18:09......................................................................................(.....................&...................H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d...................................................................................................................................................!.."................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?..P.v..+..n(a..Q..S\6....Y....D......} w#.b..]l.5.RU..k...... ]$.$.........f........?.z@2uU...7....?..|.Q..I.&.. ......"T4)wdH.
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:4EB9FA650A3E1D9A99322D243AD384A8
                                      SHA1:275CC4FCCDA66F8B44AE5BC0CEA0BDC96259C1C4
                                      SHA-256:77E01A6BE4A612D5B573F3653E80AEB7CC6896D9459D8AF368D65AE2A1946299
                                      SHA-512:6319887077C8D4E403423E739B3F3A766184B7440F5D71A0638EDD0FC1E81615F31D72EB9513C25DB20EEE864EDE5E9556CDA2162D79F6694CAA010EA42B55A4
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......r...v...f...................................................................................................................................2...>...N.......v................................I.......I.qk..B.....LZ.J.......J.{...3...L...J.{...3...L...J...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'...............34D....{*..?h.....N...^...............\6....5D.m..5..........f..................................."....I.qk..B.....LZ..............34D....{*..?h...........34D....{*..?h...........J.......J.......J...........................................J.j.....J.T.]...J.......J...B...J.H.....J...B...J...>.).J...J...................;........4...4...4.."...............J...J...J...z...y.. x.. ...........$........4...*..7*..7........................;........4...4...4..........J.......J.....#.J.............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:PNG image data, 50 x 556, 8-bit colormap, non-interlaced
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:B7F74C18002A81A578A4EE60C407A8D3
                                      SHA1:70A7D4BB1B3ADF4397D168AD0D81B286F88EBDE0
                                      SHA-256:95F59A0433050180D4C0E8858B83363D51BEA6752A8B7CA516A8677854D8F5B6
                                      SHA-512:13186A7CDCE80BCA9D2238666D6D7A989FA1887EABFA5D8A9A63EEC304DFD4BE8EFF652205FA56E1D1CEE7D3680AF8C70A952AF73AB3C246400E8D4EBECBDBA9
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:.PNG........IHDR...2...,........A....PLTE...................................................................................................................................................................................$.y.....bKGD....H....cmPPJCmp0712....H.s.....IDATx^...0.D_.......cck.....%a...X.a0Y...-..!.G...[....(.r.H.$...1 .zq.4V.e|a.6.X..4..kl.%....=w....6..TN.....{.4..T/.z...../.....3..!~..t.#b..^.....E!.SFb ...-.....^...,..C.!.b...i._c...s.X.w.. lsQH..H.gKc@@...i. ....m...;Ci....@G.; V{..lO..\.R9e$..{.....P...E.+.2.0D.B,..P...56.?......K.6..TN....^z.4..T/.z...../.....3..!~..t.]b........E!.SFb ...-.....^...,..C.!.b...i._c..Y.O...?.9k2.M.?5 .n.P...,...d._..%M?....6....,.1..R.4.a.R.+..U.Q..P...vd..T........j .]@....."..lJ../.90.4...Y. ...9.%...{......Hc%.....i..%M?aG..H....o.q.......4.......X.d9.r..CI.O.5.Ri0?.s\b....w...>/k..4V.)Y....P...vd..T........j .]@....."..lJ../.90..2..MP..l..?....K.X.....IEND.B`.
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:7BED7FC56FF5953CC1EC03C0733B5375
                                      SHA1:40A922A238D58E00AAB1345D4257D665B90BE9A6
                                      SHA-256:7108E68B4CEC82440D232D6F96A0D0564826BBF163477626340B42531D24A218
                                      SHA-512:EDD70CACB76B26081F9F2E3F7758C4729EB94C1634B901DB7CF13EB63A64F39FC0D3F1ED1303793D19FA3BD49F4F1038ADFB9BE9ACEB783F3A98B1B6147CA9FB
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......R...v...F...................................................................................................................................2...>...........v...z............................I.......I.qk..B.....LZ.^.......^..V...8.=~.:.^..V...8.=~.:.^...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............7 :.)......ju.....N...^...............Y.#.z.=L.a.Q..c........f........................................I.qk..B.....LZ.............7 :.)......ju..........7 :.)......ju...........^.......^.......^...........................................^.j.....^.T.]...^.......^..B...^.H.....^...B...^...>.).^...J...................;........4...4...4.."...............^...^...^...z...y.. x.. ...........$........4...*..7*..7........................;........4...4...4..........^.......^.....#.^.............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:1528D1BE32BC9A9BF01A0CDC613B4826
                                      SHA1:1FD86C3AED08342E777969A4D69DD60A0378B5EC
                                      SHA-256:05DAFC2AAEA5EE503A3887367DEBDE612A5BDC5D9B528B4436767401FE6318ED
                                      SHA-512:E9AFABFC225533F8314680CFDC393AB058962EB4E4781ECDD2BD844A5DEA7077376C456F080D87F2A8BD6A57E33B2A080918245364792C8C94F16BD569AEAAA1
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......N...v...B...................................................................................................................................2...>...*.......v...v......................................k..<.....KR.I.......I.qk..B.....LZ....k..<.....KR....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............<.....^.4.OCzi4.....N...^...................-UC....6?..........f........................................I.qk..B.....LZ............<.....^.4.OCzi4.........<.....^.4.OCzi4.....................................................................j......T.].............B....H........B......>.)....J...................;........4...4...4.."........................z...y.. x.. ...........$........4...*..7*..7........................;........4...4...4......................#..............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:PNG image data, 171 x 552, 8-bit colormap, non-interlaced
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:E1B57A8851177DD25DC05B50B904656A
                                      SHA1:96D2E31A325322F2720722973814D2CAED23D546
                                      SHA-256:2035407A0540E1C4F7934DB08BA4ADD750FCB9A62863DDD9553E7871C81A99E3
                                      SHA-512:BC7DC1201884E6DAFDC1F9D8E32656BFAEE0BB4905835E09B65299FE2D7C064B27EAA10B531F9BECF970C986E89A5FD8A0B83F508BBA34EB4E38B3F7F5FC623A
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:.PNG........IHDR.......(.....!..t....PLTE.......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................4.....bKGD....H....cmPPJCmp0712....H.s...#.IDATx^.w`......$..B....... ....fz5..6`l\.8...Nsz{.//y./....{.7}g.....e.....~.......s...f.....%c...6....O.PJ...Y.oi...9..'j.2..6.-
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:11464116E5BBD47AA2C4488559190103
                                      SHA1:E06156B1FCDBFB55E000A7ADFC929383872A9F69
                                      SHA-256:681858B87049BDA8588399D64EF86F4F562002DCEFA90F703928A2552F56C746
                                      SHA-512:C6B597B122FE7A8209B1924A9DF6F90AADB4D625B1975149D192B32E5AFE75AC93491006D9E083DEEE8ECBEA6EB47DBD793FDB26AEE6B58685BCC0FBAB15995E
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......N...v...B...................................................................................................................................2...>...*.......v...v............................I.......I.qk..B.....LZ7=......7=.6.pV.*.E...g.7=.6.pV.*.E...g.7=...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............7..{F.+ri.........N...^...............E......N..R*M.\n........f........................................I.qk..B.....LZ.............7..{F.+ri..............7..{F.+ri..............7=......7=......7=..........................................7=.j....7=.T.]..7=......7=...B..7=.H....7=...B..7=...>.)7=...J...................;........4...4...4.."..............7=..7=..7=...z...y.. x.. ...........$........4...*..7*..7........................;........4...4...4.........7=......7=.....#7=.............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:A3F03376987F13C6F6C27F71F7AA536C
                                      SHA1:CA30F6C1982EF14CAA401144B940DAE40C58F21E
                                      SHA-256:0CE5EC848FF38097B175AB645ED4F0582901EDA6B405FEC3F394047D562815D2
                                      SHA-512:441F94D1A6D5AE56B7D6D7D3E00B4CE482FE88F9BB918605B70855593CEF3BADA75067EEB9763746EA85482B265E88E2ECCC4C3DE4A7DE3EAE4892B8E65ED590
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......L...v...@...................................................................................................................................2...>...(.......v...t............................I.......I.qk..B.....LZ..s.......s........G.>w...s........G.>w...s..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'...............K.................N...^.................`.,.L.Y....f.........f........................................I.qk..B.....LZ..............K.......................K........................s.......s.......s...........................................sj......sT.]....s.......s..B....sH......s..B....s..>.)..s..J...................;........4...4...4.."................s...s...s..z...y.. x.. ...........$........4...*..7*..7........................;........4...4...4...........s.......s....#..s............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2004:03:04 13:26:15], progressive, precision 8, 216x792, components 3
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:864EEA0336F8628AE4A1ED46D4406807
                                      SHA1:CFCD7A751DFDBE52A20C03EE0C60FDFFA7A45B93
                                      SHA-256:7CE10D1EA660D2F9CF8B704F3FAB2966A4CE2627D9858D32C75D857095012098
                                      SHA-512:0CAA0C54C14571C279A75F0D5922F78A17803CF6EE1724D66819F7F5944C0F5B25CB586BB686A52808CDF2F8FEB3E4864052A914884054EF7DE44124A8CA951E
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....H.H......Exif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop 7.0.2004:03:04 13:26:15.....................................................................................(.....................&...........s.......H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d...................................................................................................................................................#.."................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?....NC+n....<.=.7..&.8A56..@^.Q..\\...E.>..".&G.......J .'....$.I)........0.../..mv...D....<v0=..ugc+..l.o...=.c.......x.&D..{`8...v
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:09BBD1E6F0DDA427B44F26BC1CDEA4E4
                                      SHA1:109103DA97B1E9B53BB262F66630A59B0A46940E
                                      SHA-256:901DEA7E089ACA6F5B52E29F9A477E2607231455E62177AFAAA3202C352CD2A9
                                      SHA-512:CDE7B75F50631412C5A20600FBD632B124339F0D5085445071686F7BC3475A7ADE7F6FBD1866BFBA203E16850DD3AED8E8F81A03695A746F6461A6FE8C68CE67
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......N...v...B...................................................................................................................................2...>...*.......v...v............................I.......I.qk..B.....LZE.R.....E.R..X........%E.R..X........%E.R..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.................!`..9..!x......N...^.................g>.7zG...<..zx........f........................................I.qk..B.....LZ................!`..9..!x..............!`..9..!x...........E.R.....E.R.....E.R.........................................E.Rj....E.RT.]..E.R.....E.R..B..E.RH....E.R..B..E.R..>.)E.R..J...................;........4...4...4.."..............E.R.E.R.E.R..z...y.. x.. ...........$........4...*..7*..7........................;........4...4...4.........E.R.....E.R....#E.R............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:1FE4F41DFAD97477674AB27CE8E722D1
                                      SHA1:41189AA95078225685277291D7CBAFEABDDBA760
                                      SHA-256:8C5B6F076AF2D5C263BCD97D0ECFA8540DEEAC32714FB5DA963477E53EF0D55C
                                      SHA-512:75E1455BF2F079BE860BDD442D51ED757BDDA95F771B0F8C0CCB5DF227A475EFD4F7E80CC103EC62006D073A55937D5E8000C969C51365C465F69022330FB58F
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>...........v.......................................................................................................................................2...>...j.......v................................I.......I.qk..B.....LZ...........&c....?..Z:R...&c....?..Z:R.....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............<.}Z.oN..U..c'.....N...^.................N..=.@....."W`........&...................................>....I.qk..B.....LZ............<.}Z.oN..U..c'.........<.}Z.oN..U..c'.........................................................................j.......T.a..............D.....H.........N.......?.#....9...................;........4...4...4.."...........................z...y.. x.. ...........$........4...*..7*..7...........Op.b..F.$..i.................;........4...4...4........................#...............................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:PNG image data, 189 x 305, 8-bit/color RGBA, non-interlaced
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:2628353534C5AD86CBFE57B6616D46DD
                                      SHA1:244B7E39D6CEF5B07FCDE80554D31F7DA240BB0D
                                      SHA-256:69BDB000AC7E030B0B28E6CE78F19547D235355B3B841146951AD1294429FA51
                                      SHA-512:2529F97BE62DE038445D1C86EE2C01404FB1A2D83A5D16C7B5F4E21723C17EC86FA180DFE10342536CFD7D334EA3AF1FFE151B77F2FBFFFE8E7B2A0C2A3ACD59
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:.PNG........IHDR.......1.....).'....sRGB.........pHYs..........+....1.IDATx^.}.w\.n...A.H...E.J...l.......p...\{.w...e.-K.%..d.9..DN...^}..p.L...._$.t...n.=U..ID..]~(.?.)J...-.../.......0V..........'.)1X..c..D..2..A'f."...Ru..R=b..\....\.n.0...7.~".'..s!bd.|..p.u....-w'.....R.........i]..r....A.........r#...W..f{O.2~C.O........{.....3..W.}e:...~.....4.......t.Mv_....}*f..I...x11....d..6.@..O.......f.e..K.....L]..gohj&D..+.....#...#.J...n/]...8~.....zx.'.LI6..W....p...................V.F.. ...y.[.kl<?.^....N..$..7j.biU....c.51{S{.....q....c...<..x..............zG.F*.........U.w..fE.....DU.......WG7.5uC...7.....j..7yM...~jU..;J..a|LoG..x..<^.Z ...Z.....ip....._.4......f.rg..[...z....x1k.....z...K.l...;6.\..Y.#.WT.p.@{W....>.+..*..W....'v.nV...YA[.q!\.\...9..3.[|....7...HO......2<.....w.,].T^eN..XB.....M3...I.k...e..8...lZ.R...T.%......|N.w..9..!..O.-p..NA.eD_.d..nW2!...N...z>..;....=t#....H,.N.|. ......EC..............1.\
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:Windows Enhanced Metafile (EMF) image data version 0x10000
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:DD4CA4BC0A73FCB71BEBAA3C29CB8F66
                                      SHA1:1A7085771D7941540EC94A1BD24D7CC8EA556D4B
                                      SHA-256:0401451E1D1D7DFDC29AD1B2B68A6C8AC0B706E9868BF22FAB26A01CD48620CE
                                      SHA-512:5B7D386C46EC75E21DE94DBCA922FB9A6E5358DEB3D60FEEE7B197D739F15D11050825D9323502EDFAF60720F1074DE896B23E71C44D07C9C7E943C31FDC078A
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:....l...r...1...*...^...bX.......^...... EMF........h...................`...E...........................(...F...,... ...EMF+.@..................,...,...F...\...P...EMF+"@...........@..........$@..........0@.............?!@...........@..........F...(.......GDIC....s...2...+...^.......F...(.......GDIC....s...2.......N.......F...........EMF+*@..$..........?...........?.........@........................(E..HB.'E..HB.0'EI.`B.0'EU5.B.0'E..B.'EU5.B..(EU5.B.(EU5.B..(E..B..(EU5.B..(EI.`B.(E..HB..(E..HB.................@..............!.......b...........$...$......>...........>............'......................%.......................;.......U...P........................T...S...S...S...S8..Si..Ti.@Ti.qT8.qT..qT..@T...T..<.......>.......r...1.......N...............%...........$...$......A...........A............"...........F...........EMF+.@..........F...........GDIC....F...(.......GDIC........2.......N.......F...........EMF+*@..$..........?...........?.........@.......................}*E
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:359091753FEE4A5FA73FC02B96FE2E69
                                      SHA1:864E471312A3F98A0BC577BA8774CA1FC66AEE4A
                                      SHA-256:01660178C7217584CD77083DAF3C70D344059199681C842A7ABB73692FC1CB5A
                                      SHA-512:04A50AC64A154FFE3D294DA8DDE3D84D1C5384BE712ABFEC22883E684A4034837D0436C7369B3A4619DF89C964F511D86FACF485AE18DA981BFC674559389372
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......P...v...D...................................................?....?..........................................................................2...>...,.......v...x............................I.......I.qk..B.....LZ.............>..$$.iX.......>..$$.iX.......I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............,.NiY>.....Y.(......N...^..................@.G<@...*.^........f........................................I.qk..B.....LZ............,.NiY>.....Y.(..........,.NiY>.....Y.(..........................................................................j.......T.]..............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4...*..7*..7........................;........4...4...4........................#...............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:CD30BED05D870059DEA153363FAE5F01
                                      SHA1:C8DD98B1075CFF9EFECCE161BB4CD5C7E78A92D6
                                      SHA-256:1E77F72892C03561B0B89F30CE45FE44126ECFC36ECDE2618984C0B52DD5AF06
                                      SHA-512:82EFED740C7B49E3E8483429C1F2E63D0F5385168E2D38F137A51F29F76585684F663AE857C2B8CDAD51E5BEA1A1B78694A62A5E4F242ABBA4F0443F8A47D344
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......h...v...\...................................................................................................................................2...>...D.......v...............................}3......}3.g............I.......I.qk..B.....LZ}3.g...........}3...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............<;......(V...~......N...^...............a5x...K.M............f........................................I.qk..B.....LZ............<;......(V...~..........<;......(V...~...........}3......}3......}3..........................................}3.j....}3.T.]..}3......}3...B..}3.H....}3...B..}3...>.)}3...J...................;........4...4...4.."..............}3..}3..}3...z...y.. x.. ...........$........4...+..7+..7........................;........4...4...4.........}3......}3.....#}3.............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:F8CCFC24DEB1D991EBE085E1B2D7D9BF
                                      SHA1:AF76C22A765434AEDA134924C517C84107F4FED5
                                      SHA-256:7354001527AB554C44E7D6981B86DD933B7DC2E0D3DC8512AD3EECD843245C52
                                      SHA-512:818BC3690B01B30BC571E4CF45EC8D1AFCAECBAB003532644381F1CF730A5B3486862D08F7579B2D3D89167AD7DF35028881245C9550B0DA23D1F81A720A9704
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d........................................................................................!...1A.Qaq.........."2Rr.#.t6..B..3S$4..v.b..Cs.%5..8..cUV.(.DEe.&Ff...T.d.......................!.1A..Qaq...s4....2r..S"BR.3....b#C$.....c............?..D.."}:......&&...?3..W.q*.......]...m.Y.k1......K).J...uV.b.../.0.E.H..4..W_T.[t.V.w.9.x.qe.L..o.oL.....d.\.....6.|.o...}..H{Yn..E...6Y3.l.e..D.:,.n.%...t...m.........,+,..|..n.....6.*...f........6.../$../Vi..H...e.f.F.zn.).n.E..2sTn.i...Yb?6+H&...Bf..*....z.o.^7[..u.:o....t.s=.....(.s.....f.g....q9o.u1L.N...smzE..[>...+\O....j.<....j.c.W.............U..+.F/.'..W...T./W...>i01./....j.s."..Q...{...a._~OW...Rp.)*.e..W..Q4)<..'..W...q...'..U..z..g......U}...O....w....0F:.N..V.3W.|..'z0.]...j..U[v..g$D.Lc[.e...UW.m0+
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:F1740A0CADFF1A0C0DB00C2D5FCF05C0
                                      SHA1:B28F1938E1EB40E349A7DDD5EEC3D6A751D5F31E
                                      SHA-256:D2AC7785FD8D45EA8E77D711E959D51F0B77A26DFF596F06FDD7BAAF0A5DBB96
                                      SHA-512:71994EC5B26F319720444DE8E0D063F4D7E66D4D4170B270C1846942B5C5F3C05F9F59305C15AF0AE01816DC7AA25460B3F306C8EBEF602ADD624636A5E2E09A
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......P...v...D...................................................?....?..........................................................................2...>...,.......v...x............................I.......I.qk..B.....LZX.......X.....a.........X.....a.........X....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............t4...9......|:*....N...^..................x.9.L.o...7.A........f........................................I.qk..B.....LZ............t4...9......|:*........t4...9......|:*.........X.......X.......X...........................................X..j....X..T.]..X.......X....B..X..H....X....B..X....>.)X....J...................;........4...4...4.."..............X...X...X....z...y.. x.. ...........$........4...+..7+..7........................;........4...4...4.........X.......X......#X..............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:7A039772A7D9FB7AF4E6B7B27CB7A37C
                                      SHA1:09E40AE9E05D53283634772911B6C6790BE28F46
                                      SHA-256:66008A635C1E0F9D04E4DB292E7D2C0C38F2480613209791CCF6C6598C61FB4E
                                      SHA-512:177AEED289AA9ADBD0F9835A95A1D67C43DFA65B032B36E7EB894A7C073E9E84F43861302385A1D88A92814B30AC2BD0CCE0C133054C07293BBFFE9DD17B5634
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......N...v...B...................................................................................................................................2...>...*.......v...v............................I.......I.qk..B.....LZ,"L.....,"L|.0....U..YI.,"L|.0....U..YI.,"L..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............S.O.&*....^..c....N...^...............k..f.m.L..e..E?........f........................................I.qk..B.....LZ............S.O.&*....^..c........S.O.&*....^..c.........,"L.....,"L.....,"L.........................................,"Lj....,"LT.]..,"L.....,"L..B..,"LH....,"L..B..,"L..>.),"L..J...................;........4...4...4.."..............,"L.,"L.,"L..z...y.. x.. ...........$........4...+..7+..7........................;........4...4...4.........,"L.....,"L....#,"L............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:04FB78EFE7B6AD043094DDC8EBF42874
                                      SHA1:5762962574A25698803252894AC1CD183F2FFF74
                                      SHA-256:D37434B96BCED60B3E20B28E1B167C93CD9D1ECEF5E2294B6457BB00E1B3A7BF
                                      SHA-512:1DFA664E96A2AC13B7C3B19F7EA5366C94C60A890CC15B9D31A9CF6FE0EBFD357BC474C0BA9324CC51476F252C10279AD7CDFAFC3D3B4C92546D5DD657774FA5
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......n...v...b...................................................................................................................................2...>...J.......v................................I.......I.qk..B.....LZ.A.......A..r;...C.p....A..r;...C.p....A...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'...................P..B..W.......N...^.................B..v.I...s:.s.........f........................................I.qk..B.....LZ..................P..B..W.................P..B..W.............A.......A.......A...........................................A.j.....A.T.]...A.......A...B...A.H.....A...B...A...>.).A...J...................;........4...4...4.."...............A...A...A...z...y.. x.. ...........$........4...+..7+..7........................;........4...4...4..........A.......A.....#.A.............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:08:07], baseline, precision 8, 595x450, components 3
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:DCDD543A4E0BA2C1909BA095D46FFBCB
                                      SHA1:B86C89537138FE07255354202D3EAD0B53B3C54D
                                      SHA-256:28F334B77068F71F5F92A95695433B950610204A0E5580CE567DB8FAD4993ECB
                                      SHA-512:5408C3259B7F3288A4BEB04342799AD5FE3A6F0EC7E92353B29B7E7E538DFA9903B39637226919E0421BC422635D25F5F8069DC7441864DC03E1B909BF5C2C84
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....H.H.....fExif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop CS Windows.2004:03:12 11:08:07.............................S.......................................................&.(.................................0.......H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d.................................................................................................................................................y...."................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?......;R~+'....xh..~.n-}.......Te................^B..IU_....._...S......h.......!....9...A}6V=J......C..c.....Ug.Wh......
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:932D9660ADC4B746E085063C7C95CAE5
                                      SHA1:435D02EFDB6466DDD0BA3F8369DACC10B7FF3C7A
                                      SHA-256:4A99CA9AE96E9E7683CAEBB2AE48BD684BC5C540815885F1A5F45537DC4627F3
                                      SHA-512:23CC08CD7082A6A0C245C048565AF680E1FD7EA30BC443791F2ABEA33E07DE1C4C6CD1FB0BA40CF88BF9F48D8AE794BABFA24F7E4EBD18E50D530ADE57299000
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......T...v...H...................................................................................................................................2...>...0.......v...|............................I.......I.qk..B.....LZ6-......6-.&X>..?s.(.~M6-.&X>..?s.(.~M6-...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............^$..Wp..&...\N&.....N...^...............(.!d.dZO...X..8........H........................................I.qk..B.....LZ............^$..Wp..&...\N&.........^$..Wp..&...\N&..........6-......6-......6-..........................................6-.j....6-.T.^..6-......6-..B..6-...C..6-...>..6-...|..6-. .3...................;........4...4...4.."..............6-..6-..6-...z...y.. x.. ...........$........4...+..7+..7........................;........4...4...4.........6-......6-.....#6-.............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:361C2417F0C64BD4F379D622BDAA3F5E
                                      SHA1:0EE9FC3FB96B6FDCF6EC1741E0C5EC5FDBD562B4
                                      SHA-256:8A639E1C4ECB6ECFF26AEE8B0F5A244184E9462545FC677064768AC977D20195
                                      SHA-512:DB11EB37322ACC163D82DD1EAB0E60ACBF7B1680C3C547DA312579E255BAD2B4AD1D044B18BE9C926ADE43DDB5CAC4792838E18975075435B36EE12DED072BA8
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......R...v...F...................................................................................................................................2...>...........v...z............................I.......I.qk..B.....LZ.EA......EA......rx..e..EA......rx..e..EA..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............m=.6.. ....c.....N...^...............O...1h.M..^5.k0.........f........................................I.qk..B.....LZ.............m=.6.. ....c..........m=.6.. ....c...........EA......EA......EA..........................................EAj.....EAT.]...EA......EA..B...EAH.....EA..B...EA..>.).EA..J...................;........4...4...4.."...............EA..EA..EA..z...y.. x.. ...........$........4...+..7+..7........................;........4...4...4..........EA......EA....#.EA............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:955D04158794A5211DA91CDA2B67694D
                                      SHA1:1DDC96F3E40D950B38125B34363936EBB3F2A6F1
                                      SHA-256:010B036141E9DC4FCC40DCB7316662E3EFE9F2E4419BB288B19B74E6FA9A864B
                                      SHA-512:428B8018DFC9DC1369BF1BAFD567C7B30A9A074C0079BD0E803BD5BD8E0C1FA116098ED9F89616DFD8B8C5BE32BC806184F2022012302BD5D339CD3ED8084252
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......T...v...H...................................................................................................................................2...>...0.......v...|............................I.......I.qk..B.....LZ..C.......C..#...R..p.<..C..#...R..p.<..C..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'...................\...e...1.....N...^...............6......J..............f........................................I.qk..B.....LZ..................\...e...1...............\...e...1............C.......C.......C...........................................Cj......CT.]....C.......C..B....CH......C..B....C..>.)..C..J...................;........4...4...4.."................C...C...C..z...y.. x.. ...........$........4...,..7,..7........................;........4...4...4...........C.......C....#..C............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:CCE7446E93C66C4712D0133615416E4E
                                      SHA1:0A45488EAEF3E82A20C1F22870C61BEB91E6E207
                                      SHA-256:E8242B5BF39BB5DD53CAA602DBF33F49A243BC42575AE1BC1354FA410000C34E
                                      SHA-512:3B20DFED88B21DCEFF07F6B3E222CEEEA5C0FBD53C462C415E999E6C581A82B542DF1727A1D810691996ACC07B105E1EFF63807A75DEF58343B32BA10BB24704
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......R...v...F...................................................................................................................................2...>...........v...z............................I.......I.qk..B.....LZ"......"....A.6r...d,."....A.6r...d,."...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............K...x.&..H....(&....N...^...............R.s...!F...._}.........f........................................I.qk..B.....LZ............K...x.&..H....(&........K...x.&..H....(&........."......"......"..........................................".j....".T.].."......"...B..".H...."...B.."...>.)"...J...................;........4...4...4..".............."..".."...z...y.. x.. ...........$........4...,..7,..7........................;........4...4...4........."......".....#".............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2004:03:04 13:44:07], progressive, precision 8, 611x163, components 3
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:9C205C8D770516C5AA70D31B2CA00AF3
                                      SHA1:9A1002F0CF7F92F1BE2BB25BAD61CEBFAC282482
                                      SHA-256:E111F96490755C7D71E87C88ACAEA38AFE55BB865B1A14A83C5BD239648D5E2C
                                      SHA-512:A3E105208B32831265428572B0937DD3C17B793D8611B2DA8D4939F1BEC6050999D375E3F6B87D53AD49DFA0EAE737B0141D37597AA42116C310761973D4A134
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....H.H......Exif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop 7.0.2004:03:04 13:44:07............................c.........................................................(.....................&...........n.......H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d................................................................................................................................................."...."................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?..o...4.gP.~.c...K{...V.=...].<.........vS.........s....(.t......X......kk7....~-...yF}^c.Z.\.G./.?t...>....:.>......./.ib..).
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:9826D5B90640EE341E3736A8D3910BB2
                                      SHA1:CAF7FBBABEF7A35C41E982F3B9F401A2EF758096
                                      SHA-256:4622B743C87CEDE5901C4B3D1E38F0266931E8FBD0E3088DFA405A58BDCD6318
                                      SHA-512:AAC0CC7F3BE6A3CC0522312FEFD197360C926F8DB87FE941A128125F108D1A8EA26BEFA62DD7D5A84EEFF76BE6C072C24ED617BA5B71DD18AF0240460331EED2
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......l...v...`...................................................................................................................................2...>...H.......v................................I.......I.qk..B.....LZ...........XL"q.3..&.......XL"q.3..&.........I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'............._U8..AH.. ..:.......N...^.................s.Z.|I..-.dX..........f........................................I.qk..B.....LZ............_U8..AH.. ..:..........._U8..AH.. ..:...........................................................................j.......T.]..............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4...,..7,..7........................;........4...4...4........................#...............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:DE430D9094437372F3D0D9EF8CBEA6B5
                                      SHA1:94AECD177005860A2E70CAE3170C0AC6BEF47721
                                      SHA-256:D05530EAE37016C35F61D4B55C08B860CA00A9A700D4C934322D074DCDF8CDBC
                                      SHA-512:7C92E8F5B1281BFB7DE9042F274FC7EA9A0D04571B4A899E75905C381443B71ACB13BE21FC28B0E139E827689B206021E5CB40428E1C6F3279EA2707E49FB820
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......N...v...B...................................................................................................................................2...>...*.......v...v............................I.......I.qk..B.....LZ.u.......u.6....,..W.....u.6....,..W.....u...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'...............M.....6W-k..u....N...^...............Lp...f.F....Y.........f........................................I.qk..B.....LZ..............M.....6W-k..u..........M.....6W-k..u..........u.......u.......u...........................................u.j.....u.T.]...u.......u...B...u.H.....u...B...u...>.).u...J...................;........4...4...4.."...............u...u...u...z...y.. x.. ...........$........4...,..7,..7........................;........4...4...4..........u.......u.....#.u.............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:D58C51D2CF586A5E14A9EC8529C3B0A8
                                      SHA1:F4811A353797C29B1E3F5A61B125C46E1534D587
                                      SHA-256:F927C7825851974A2149868146970706523A49165133CEE6027A43E8C9ABDF27
                                      SHA-512:34B963173AFBDF07432F4B983D29F10376E4771FE666E9D50B1A81DA0B9F6001FD86B4A08B9711386DE153BF6E03C8E932E2D181C8EAF94EFF34D20FCA7570E0
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d................................................................................................!1AQ.aq....".....2B...Rbr#.s.4...3$.5u.6v..CSc...DT..f..t..&F........................!1..A.Qaq....."2....B.s....Rbr..#4...35...CSc.$...DTdt..%..............?....O<......X.O.Fg..{.W&u.u.T~.|r;g!.._X..N.p.4.........................................................yK..xd...6..|%....\j..e.=...Y..f..I.|-....e...$R.j.......~.W#....{.....V.k.|F..z^..:.~..f......"x.....L..K..r../.;..[..l...;.U...W...X.........8.....y?..B...m.......j..Q.g3..G.K....GL.o..n7a..Y..[.'.........x........\......~...f...0\Wc.n?k.|.....1.ww;..2..?...r4uF.MXdB6..W..mG2NJ.E........u...2.q...Z..=(l)jU.X...U.\X.......O<......X.O.Fg..{.W&u.u.T~.|r;g!.._X..N.p.4.......................................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:4131D817243D0C108D8EAC7504140C75
                                      SHA1:7DB01802DC49D2329EAE721DC7A5EF1BBA8BE6AD
                                      SHA-256:A28F88528EE5A554DFE045ED90948B98E9CDDEB90E81BC0BD0FC778085E38194
                                      SHA-512:3B710A238A5D5C66405E0C634437E88773722D05853F58958AC650CAB867C3A02B351851461217BDEEB97C8A4CAC1E316CAE5D5446B0683F0E49B4C146C75763
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......R...v...F...................................................................................................................................2...>...........v...z............................I.......I.qk..B.....LZFA......FA.P8.w.9..X].3.FA.P8.w.9..X].3.FA...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............O.8j....E.K..q.....N...^...............M^....^A."..9>).........f........................................I.qk..B.....LZ.............O.8j....E.K..q..........O.8j....E.K..q..........FA......FA......FA..........................................FA.j....FA.T.]..FA......FA...B..FA.H....FA...B..FA...>.)FA...J...................;........4...4...4.."..............FA..FA..FA...z...y.. x.. ...........$........4...,..7,..7........................;........4...4...4.........FA......FA.....#FA.............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:PNG image data, 39 x 579, 8-bit colormap, non-interlaced
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:E96BE30D892A5412CF262FEE652921CA
                                      SHA1:8190A0BFE21D04BC6F3A406E91B87CA69C03A2DE
                                      SHA-256:0E31DA4DFCFF4A36C64C1CE940362D2309769F36369E4C43C317D5F2FA15658E
                                      SHA-512:D647F51ABBD013226A6ADD0D551D058C633F867F9AF5A9E099B85D6E291D220F7B85958B07381CD4C7C4F72356DBAFE2A86932AE398E28C56CDDF0744E92EE24
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:.PNG........IHDR...'...C........b...`PLTE..................................................................................................bKGD....H....cmPPJCmp0712....H.s....9IDATx^..I..@.C..<..?mo.#C((.J}...~..B...b.I.i.\<.e.....(p.I.EO...q.x.......dRz....K..b0.:.<c.o..0.x\:...F....I&..ap....."P@....DO...q)p*..@Y.CL2)=......1.........4....._.G..^`..lDO...q...X....SL..z....K..#.L#..I6..ap.Ls.,....7&..ap.p..lI...,GO...q.....k.n1..4......3=.f.x.$..4.....o....x.$+..0.x\.,&6...............IEND.B`.
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:2AED46C3A28B25FEE38F875AE8204C84
                                      SHA1:DC8685BD1AD95CFA1AD464922536FFC2FEAF7E7E
                                      SHA-256:23E99BF6E91E0248F4BAB2319CB8F3A4827428055A6AA13B09F5819908BF632D
                                      SHA-512:B101485697C57F30F913BBD00809803703D77B4E11450B3ACB7D8FFA722B7E7B81BA2FB859D087F8648FE4FA55318F1F8CDDA304216EF1B5809457EFB4F359A7
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......T...v...H...................................................................................................................................2...>...0.......v...|......................................n.)..&j..2....I.......I.qk..B.....LZ...n.)..&j..2........I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'...............'..#.1..P..e.....N...^................".....A.n...q..........f........................................I.qk..B.....LZ..............'..#.1..P..e...........'..#.1..P..e.........................................................................j.......T.]...............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4...,..7,..7........................;........4...4...4........................#...............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:PNG image data, 30 x 700, 8-bit colormap, non-interlaced
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:0BA36A74DFBF411FAB348404CCEC3348
                                      SHA1:4C619790E517416E178161028987DF1CD3B871CC
                                      SHA-256:2E7AAF26BEC32148B96442E8FFF1BD2CEF2D72630969F23B9A2ABEDB6CFEC93B
                                      SHA-512:90AF53DB7C413E2ADB970AC345F73E4ED8AF626E179C929E6560118F7A9E98DC7C5FF02B2B3F6C98D397E0FE2D85F3427C6928C328872149E176FA8A99E91F54
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:.PNG........IHDR...............\....PLTE.......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................D......bKGD....H....cmPPJCmp0712....H.s.....IDATx^.WSTA........b.0gPPP0..E.9b@L(.c.N.U>..@......;...}..B.(....$......5..XS...I....).!....D^.uE...\..5........F."o..-...m.n. .^.....q= .
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:6BF0734327A1369691551DF028149C55
                                      SHA1:2199974004B7633A478666E71460F285D2BBDF7B
                                      SHA-256:6C55FEE8B9F3AF6ED7ED3158F7CD81775C4573E1113C7E821442FF2FBB1A2B3C
                                      SHA-512:873B53441E71E8C6BEAE61DEF4378737D24976920719DEFC988C62A7556C54EF18DE958912E9FDAF1EFB7FAACA75F8356B567A7F63473B90DC2D757980F41D9B
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......N...v...B...................................................................................................................................2...>...*.......v...v............................I.......I.qk..B.....LZ9......9.GD....%-.M...9.GD....%-.M...9...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............B..<..M....,>.;E....N...^................i..E..I..:.............f........................................I.qk..B.....LZ............B..<..M....,>.;E........B..<..M....,>.;E.........9......9......9..........................................9.j....9.T.]..9......9..B..9.H....9...B..9...>.)9...J...................;........4...4...4.."..............9..9..9...z...y.. x.. ...........$........4...,..7,..7........................;........4...4...4.........9......9.....#9.............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:FCAFBEC74305EE25DD98FE806E29C44C
                                      SHA1:2D8CA6D4516D0CEC8CC95DD1751783645AA02917
                                      SHA-256:4E4E6CF3FCA540A198A2BD926C101A1B254E1D7A78299A4D38D975011BCFB6A6
                                      SHA-512:C45FDB17E34FAB1396293EC10FD8DE90E620A7350CFCD2CE54965ACA8E7803372BFE1436527A7CFF88FA6E37BB42779AF62B26AB74BB40170731364D39A9B556
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......N...v...B...................................................................................................................................2...>...*.......v...v............................I.......I.qk..B.....LZ.........{Pa....E).S....{Pa....E).S......I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............H.DEh)..6yM...l.....N...^................N#..QA..BW.Q .........f........................................I.qk..B.....LZ............H.DEh)..6yM...l.........H.DEh)..6yM...l.....................................................................j......T.].............B....H........B......>.)....J...................;........4...4...4.."........................z...y.. x.. ...........$........4...,..7,..7........................;........4...4...4......................#..............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:4C605CA5D313D04C5713BF861F81F869
                                      SHA1:4EE84CBCFEC539D0560D4A2353715EE3E42271C7
                                      SHA-256:276F2C3106E916FD5A29722EDD47C351BFE640C28092F041C8DAD1CA29F0DB15
                                      SHA-512:71CD9326B9ADA381D06D568698F47BD4499DEC48728BC57C3F0097ED97E2396E346D98B6831543BE40F65261B7DFFED2BAC2A7E9958AC561A478954BFD60B6E6
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......R...v...F...................................................................................................................................2...>...........v...z............................I.......I.qk..B.....LZ..[.......[pC.K....]x.*5..[pC.K....]x.*5..[..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............`.........{.o.....N...^...............%"?...<C.1...)F.........f........................................I.qk..B.....LZ.............`.........{.o..........`.........{.o............[.......[.......[...........................................[j......[T.]....[.......[..B....[H......[..B....[..>.)..[..J...................;........4...4...4.."................[...[...[..z...y.. x.. ...........$........4...,..7,..7........................;........4...4...4...........[.......[....#..[............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:8594D1B4D422D7C3F3973DC15E288871
                                      SHA1:DCB80C0F0F459BF660E4946FD1AE3A2E32C156F5
                                      SHA-256:5A5EFD01BE38A321C8BA821A280767B0D88B095B29F598C050CBB083733757B9
                                      SHA-512:F0E3608D709BEA32E2B4ADF9C587A241EF68A064D02EDE37900DDB1901BB06FCD8CF782444E1CCF6CA2E951EAD95E27C5564F4775CCA9E25263F8FE7DD91D716
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......l...v...`...................................................................................................................................2...>...H.......v................................I.......I.qk..B.....LZ...........3.O...7m..|....3.O...7m..|......I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'................G.q~..&>........N...^................v.....D.R?.5.6C........f........................................I.qk..B.....LZ...............G.q~..&>...............G.q~..&>............................................................................j.......T.]...............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4...,..7,..7........................;........4...4...4........................#...............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:43270B5638DD26172896576FDDE326B9
                                      SHA1:A568384E41B96D001584DFC1C17556FAEE61CC72
                                      SHA-256:1CE26B0D2D2E051ED06344C3378CE05331F2BA1A520A5B76943C7B08E173E5E9
                                      SHA-512:9ECB96C826151336A2FB35C6F60A1D6D8A6CA7210A3F7CEE01747A728FF462CDC5894223553976CCAAD242F85008B44239E0F3C9D6F17EE674B3ACBDE10E0437
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......N...v...B...................................................................................................................................2...>...*.......v...v............................I.......I.qk..B.....LZj!......j!.S....&....7..j!.S....&....7..j!...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............o.`.........*}G.....N...^...............Jk.{..K..)..$.4........f........................................I.qk..B.....LZ............o.`.........*}G.........o.`.........*}G..........j!......j!......j!..........................................j!.j....j!.T.]..j!......j!...B..j!.H....j!...B..j!...>.)j!...J...................;........4...4...4.."..............j!..j!..j!...z...y.. x.. ...........$........4...,..7,..7........................;........4...4...4.........j!......j!.....#j!.............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:FEE4785DF76E93A9DC2F4501CBAEAE12
                                      SHA1:8FB4527BDE05EF208FCDB168098A07707C27501F
                                      SHA-256:F091DED5E283AF6848670A3172E7C43C6099875D39B3FC69C2BDBA914F609602
                                      SHA-512:7E99D33151A0D3873D6A819C98EA8E62D928C087B7BA2080F11C7BCF746AD60A44D4FF6EE3D2D2E8DFA4BF1FC6285ED56BB83F91C2FC6FC4FDFF2000105F10B1
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d...........................................................................................1.!Aq...Qa."...2..BR#...br......6v.7..3.CSc...$4.s..&dt%u.f.......................!1.AQ..aq........"2.B#....Rb3..t.5u.67.8.r..$....C4.cs.Sd%.DEUe&.............?............w.....c.....i.A.....3...7.......7..P......%.........?Th..l./?.;.....$}..=5Oa...F.c.A/...D.D..]..y..3e.5\%.fo2.X.*]q.5Ee.}..i..md.T....#...-...Mu...9...-+..~w5O.);..G..'.;..).....A_...M.vV..y.q......,<.3.(...._K:..XM.......w.......9..T.......?b..a-%.c;.}..>....|.,lZKCEB.t...fw|.Sw^..Y..:.J.................t._P..v..j.1.R8.R....G..W*H<(Xi........i..xcu...WM.dqM>'W..g....M.q.....+.....b'..~....>..T.~Jc....fj.X.x..9...N.w.6:..>.......&.(h..u...t._...)_k#7Za...cZ....P...Y..;.V.,..xo.....f........Y...\6...M'L._
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:468FDEC4D6FA18334424530D7B6C616B
                                      SHA1:754C2CC63C14CFAA66E205F747F0ABBDD0E47260
                                      SHA-256:B9C2ABBCDE65EFE3B43BF94F935A6D09150271E70575D876B58CF94A315BA390
                                      SHA-512:0E7C83CC61CA55233AA77EF7C2CA1642699F3AC69836FA0A1C19C09ED0A40E5C69C094A780016E995245E090E83CB723379836BE54B0DF9FCB63F73206FC6977
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>...........v.......................................................................................................................................2...>...t.......v................................I.......I.qk..B.....LZ.>U......>U,...5T..33..>U,...5T..33..>U..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............6(..Q..8.U........N...^.................."J..A....,..7........f...................................H....I.qk..B.....LZ.............6(..Q..8.U.............6(..Q..8.U..............>U......>U......>U..........................................>Uj.....>UT.]...>U......>U..B...>UH.....>U..B...>U..>.).>U..J...................;........4...4...4.."...............>U..>U..>U..z...y.. x.. ...........$........4...,..7,..7........................;........4...4...4..........>U......>U....#.>U............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:65FA5A2F165723F5F233107F8E020190
                                      SHA1:7717B85F8DBCA56F6B8C6119068ECAB3B4C6818A
                                      SHA-256:6A33D0A3907838557F7EEE502F0891D4A1D261E7326776385C2686C8FAA75CEB
                                      SHA-512:C2074B96B6F0C69B9886E494F7FAF47E4DB219128F53508CDDE2E06D29B4D8E689792932A331DD9A3504C12CD42D794DFD87B8269CC0F5D596081455FD0E6F34
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......N...v...B...................................................................................................................................2...>...*.......v...v............................I.......I.qk..B.....LZ..T.......T....4.9...u..T....4.9...u..T..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............y.]<.[.4n..(.......N...^................D.E.Q.M.@.1..:.........f........................................I.qk..B.....LZ............y.]<.[.4n..(...........y.]<.[.4n..(..............T.......T.......T...........................................Tj......TT.]....T.......T..B....TH......T..B....T..>.)..T..J...................;........4...4...4.."................T...T...T..z...y.. x.. ...........$........4...,..7,..7........................;........4...4...4...........T.......T....#..T............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:PNG image data, 88 x 574, 8-bit colormap, non-interlaced
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:1BDAD9B3B6DE549162F9567697389E1C
                                      SHA1:5D9C09159F07A3A9BDCC6C4B9BD9CB72D0184E6F
                                      SHA-256:0908A4CFA23F93011176D47F45843E9CA2973030421996E8E27484781F54B0EC
                                      SHA-512:475040779AC247BB5C3E11862FB55FBDDFA12D759EE86A33E11BC1F3B656D6CD0F9B25146C0113E43E1D8001D8867D3BC3BF7E6FE21F3A0016CB1F8B70B7A15A
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:.PNG........IHDR...X...>......y=h....PLTE..................................t........iw..............................................._n|...Tds...ky......................................................p~.....................................................dr.................v.............................................n{.......ap}..........x.....z...................u......................|..Vfu............r.....w........................................~...................Zjx...................................Yiw............w..|....................Xgv{.....y...........................jx..............\lz.........}..z.....t..[ky........u..y.....gu................................{..........}.....u....................~...........y....r.....bKGD....H....cmPPJCmp0712....H.s...JfIDATx^...\.W./.}....Sy...(..4....D.-.....H...% .$"D.Qr.......`..;...6...N......s...^...L.....Y{.GQU`..~...j....{...-Ax.K..&.....F..I\i..
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:CEC4997A1F24101E3A1C63799588A9A0
                                      SHA1:5C11314AB5ABF32C4750C3BF67EE846DE23E3EED
                                      SHA-256:03AE283AF172F72A53F55EF2440FBE6B96B7B13101AE16050FC528923CBFADE5
                                      SHA-512:0962C5BAC12E1EBBE79CA1BAA0882174C9A0CBBB9F64D8D5C78BD7D9362A45E2912187FA588AA3397C6D64797D94C4588649E8FA45A6B923955A7C1A4BC1A0B7
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>...........v.......................................................................................................................................2...>.......H...v................................I.......I.qk..B.....LZQ.......Q..3.j0.1......Q..3.j0.1......Q....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'...............D..J.......x.....N...^...............n2K...SD.......}........f........................................I.qk..B.....LZ..............D..J.......x...........D..J.......x..........Q.......Q.......Q...........................................Q..j....Q..T.]..Q.......Q....B..Q..H....Q....B..Q....>.)Q....J...................;........4...4...4.."..............Q...Q...Q....z...y.. x.. ...........$........4...,..7,..7........................;........4...4...4.........Q.......Q......#Q..............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:4E131DBFEC5C2462273CA7B35675B9D9
                                      SHA1:CA037F444D819A118AC37D7AA3782B9BF94C1616
                                      SHA-256:2A4A3530D652E227DDD5ADC096A95F6034718F7C380B07DB622022D768815059
                                      SHA-512:C333ECEB1439D0238BF44FB7896E62DBA4C645B70413AA0F99C1F10E8DCD20C2EEE5C83F2E9DDE9A2494C85A6D8D13CFFFC4160E2F598E17867015F5244D656A
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d.............................................................................................!.1AQ.aq...".....2Rr..Bb..#34.....CSs.$5c.t....%.Dd.6.T..u.U....E.7w........................!.1A.Qaq......2."r.3....BRb.#4......CsSc...$.5..%.DT.t67d..Uu...'............?..c.......p..z..i.....z......kj........F>f......3N...M....RM.&..-.~.Q..'.....q.a..w...-~......g.{..&.......V.n.D....>FS!n.....@..)...W..q..Wr{..J.gf.{.M$.P@m.,..9..&m.D...w.._...-.O........s.....h.k~......(.K...V..l.-...+.9.k......*......#.p#.O..9M..mF...C.......7+.AI....4vw.;..H......e..Q.u[.eUK.....z.....[.Kt...s..Lf.4..l{.....sh.............=..;..iqkj.m.a...NH......v..H..$..q.y......c...U[Mcf.......+...S-...^....4..T..YtL.x.v.;.....<...Ik|B.$.s8......3.+.8.l.. h.:....%B..W..I.QRS..,*x.
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:2F56B5A6A901C238937177DAC6C8C453
                                      SHA1:0036DE5BD12981C23271398A6D23B42E1FA1C96B
                                      SHA-256:3BF1C37DB498089A4C652B6E205DA84D2B8D7E2A819FE1899FF03D1DB7566646
                                      SHA-512:439737CBD1DDE7218C490B4FB20D0FA1C8635A2BE6286A6700C84FAEFE1E50BA3E274EC07E355B65CE6147B0BC6BBBB55F06C84E6DB93958DBEECD52A6280A94
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......T...v...H...................................................................................................................................2...>...0.......v...|............................I.......I.qk..B.....LZa.2.....a.2j.....Fk.0...a.2j.....Fk.0...a.2..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'................Oy....9.g......N...^..................=}`EJ.)...B.........f........................................I.qk..B.....LZ...............Oy....9.g.............Oy....9.g...........a.2.....a.2.....a.2.........................................a.2j....a.2T.]..a.2.....a.2..B..a.2H....a.2..B..a.2..>.)a.2..J...................;........4...4...4.."..............a.2.a.2.a.2..z...y.. x.. ...........$........4...,..7,..7........................;........4...4...4.........a.2.....a.2....#a.2............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:8D804A60E86627383BED6280ED62F1CF
                                      SHA1:E23FF14B10AD0762DD67FBA3CD6EFC85647C0384
                                      SHA-256:494547E566FB7A63DD429EB0699FE41AA8998F8EA2F758D813FE3D56C3075719
                                      SHA-512:0FB19F3D00159F2748C3A54E952E551B9FEA6910D67A54DECA8D099992E50383EADB92768FF1F75CFFAE82A7A157B1E0F77A2F0BE7EC64FD2324304FDCA46577
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d...............................................................................................!"#.123..AQB$..aq.RCS...b..c4%..rs..D&....5E6'..TdUte...u.....FV...7.......................!"..1A2B..QaqR.#.br3.........C%...$5.....c4U..Eeu&SsD.6T..................?.....O.C.....^..R<A.g...[....3.....r.0.....nX.S....}...[.?Z.....A.?..~~I..rY|N.o...9......!...o7r../-.y...'5.3.U.s".-.0.1......SS...&.Q.j.*.$m.e..:x....`}...EP.?.7..~G(so.......O.....z.N..<....~^a.e...........p9.?<._..|......~.<@.D.9..G..?.?z.y?z.C.U.w..[.,..A.+........s......g...G.^....pz.xY.....d8.y.X...P..O(A.O..~:._.......<...o..4s..^.^b..x......_a.....|{c...:..X.....}.._...[?..NK.c...}.<......H.G....+x.Z..|....n...o....`.nk.#.%x......-|...|7......N!=././..w.8x.".8....'x........w...,>....j[w8a..}..lS..?.
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:85F762872E21FAB1936C509897919B57
                                      SHA1:1784C31F5A634302DCE640BE49CF47FC4792CF29
                                      SHA-256:B9ED56C784AE7729E453A5872F650BFFC7B26415AEA2D406749EC80FE62C0BB8
                                      SHA-512:6FA14985A540759CD46D19C09C4FF62C400388BAC2533D7D8A7F41B96FDA89946B9221B31B04ACF6ABE85F4C2AEA5A1F49DBA3AED4F22E5CE4F31918953D22CE
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......N...v...B...................................................................................................................................2...>...*.......v...v............................I.......I.qk..B.....LZ..a.......aG.T..7..".....aG.T..7..".....a..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'...............h......al...*.....N...^.................B.=.1@...W=u..........f........................................I.qk..B.....LZ..............h......al...*...........h......al...*............a.......a.......a...........................................aj......aT.]....a.......a..B....aH......a..B....a..>.)..a..J...................;........4...4...4.."................a...a...a..z...y.. x.. ...........$........4...,..7,..7........................;........4...4...4...........a.......a....#..a............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:EFE95B00A4FF683BE42E1AB1E853F624
                                      SHA1:9A1B51B14373452741574C80372DD735106633AB
                                      SHA-256:EAAA1B85CCB9810ABC6109ACFD6F017922B09143C3B272E383531A986A95ED30
                                      SHA-512:98527651B9D8634ABD660EBBD1B5A5B15016B6774A3F6B73FECC928AFCF670C110962B2F47790F65F3E9FD30F432810473B19176E587BC89C9E56272B0AB0EB6
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:........$...........t......................................?....................................................................................................\..................................................w.kHC..9q..Ii.B.....i.B.1...).0.x.[.X.U.]....i.....X....Go..Z./.#!5..^..G.i.B.1...).0.x.[i.B.......................................................................T&d......w....X........4.............$..XO.T.9.....T(P................4..(.....x.(.......G.......Go..Z./.#!5..^.X.......X.U.]....i....2...v.......4...................i.B..X..............................XO......i.B..c..,0...e...B4.$........[.-...I.......9.........................w.kHC..9q..I.......M.#.G....9......XO.1..O...A|\0.XO......>.................Go..Z./.#!5..^i.B.1...).0.x.[..........................Y0...b...71.XO......XO.1..O...A|\0...............X...c..,0...e...B4.$..............E........................................0...........e....4..................T.o. .D.o. .L.i.s.t........s.)..O@
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:79D90E1E817154A222737C22F746710D
                                      SHA1:923205AECDFD8FC6DDF845F75C44B97AF56E6045
                                      SHA-256:1B8A51DCE4F43A9D69A374AA453F44AE2D1500EB51E537238F311AEC32227185
                                      SHA-512:788053C1935844C64E978CA7A6B2C673FE40625AE1376209D66580E3EC1155D4989D40D3227B4CB1149F70F25DAEB73E7729D19A5F51DA685BD6ABBD2B4784DA
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>...........v.......X .. "..2...>...d...<...v.......@....!...........................................................................................................................................I.......I.qk..B.....LZ.Bd.;....Bd..#$.....&..a.Bd..#$.....&..a.Bd..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............W.B.&.....D.x....N...^...............? ..r..O..:.............h...L...............................D....I.qk..B.....LZ............W.B.&.....D.x..................................Bd......Bd......Bd..........................................Bdj.....BdT&n...Bd......Bd......BdH.....Bd..K...Bd......Bd$.........Bd-.BdJ.Bd..z...y.. x.. ...........$........2..72..7.....*...o.e.L.o.c.I.D...o.e.L.o.c.C.o.m.m.e.n.t.......0.0.0.5............(.Bd#.Bd8.Bd..z...,4. .......$>........4...4.@..7.....................D..n4..o4..p4...4. .F
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:AA5BD62432F5FB47E9E15569543BFA98
                                      SHA1:18EF091B46C508B9E3F242F1FB3F4DBF90D280BC
                                      SHA-256:01F9750FFE1F436B37C619295A0777CD4FAA63ABD5D9F2BC80755A561C490208
                                      SHA-512:647D8F7FD502BA4BB6CCCA5AA0440ADC71E3B628FF04ED4ED4A3C91C3F7E4EC94195253F35F9C787E05B76BB367932544CCC803301E72FF08D10FE47C67A1BB2
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:N...>.......L...d... .... ...9..N...>...........d...h...@...@;...........................................................................................................................................I.......I.qk..B.....LZ.|.......|....e....|9.F..|....e....|9.F..|..J............QJ....I.qk..B.....LZ.I...........J.......J.......J...........................................J..j....J..T.7..J....~..J.......J..H....J.......J......&J..........'J..2J....z...,4. ...."......$>........4..`..7......L.o.w. .P.r.i.o.r.i.t.y......................J..:J...J....z...y.. x.. ...........$........2..72..7.....*...o.e.L.o.c.I.D...o.e.L.o.c.C.o.m.m.e.n.t.......0.0.0.2.3............|...z... ..$........................................2..7.........1.h...?.......?...?....rA\.-?>...o.u.t.l.i.n.e.L.o.c.I.D...o.u.t.l.i.n.e.L.o.c.C.o.m.m.e.n.t.......0.0.0.4........?ff.A......'J..%J...J....z...,4. .......$>........4.@.4..`..7.....................D..n4..o4..p4...4. ..1.......J..*....J......%J..#...'J..&...9J......
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:35D42F48078806988C4A2F69C829CFC9
                                      SHA1:B9ACE2495BD999DF21CB66E48FF7F28DF66698B5
                                      SHA-256:AE2D9959235BC987FCB5EC765C5ABB60B7B60298B7D3B572D90D8C466399F809
                                      SHA-512:F25339E9FD7ABFAF80C04FCE5FF62EA6650BFB60156B3299C677838A83A1F55984807A334D72D22A52D1E3337FF80005E185F83833272499C175F8F64921AD91
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>...........v........ ...-..2...>...B.......v.......@....,...........................................................................................................................................I.......I.qk..B.....LZ0.z.P...0.z.y.].&......=0.z.y.].&......=0.z..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'................S}M_...."........N...^................'V....L....8..p.............................'V....L....8..p.........'V....L....8..p...........S}M_....".....................................0.z.....0.z.....0.z.........................................0.zj.^..0.zT'...0.z.....0.z.....0.z..-..0.z.....0.z.....0.z .L......0.z30.zI0.z..z...y.. x.. ...........$........2..72..7.....*...o.e.L.o.c.I.D...o.e.L.o.c.C.o.m.m.e.n.t.......0.0.0.6.............0.z30.z90.z..z...y.. x.. ...........$........2..72..7.....*...o.e.L.o.c.I.D...o.e.L.o.c.C.o
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:2EE369ABB7936F8C28FF0ABDD224EA05
                                      SHA1:FE9D304A7B49E31EAE439369ABC548E265149636
                                      SHA-256:FB12D59B8BE911247BBAFDD416852E8B74B028005A141CB4DBBBA109B4B6ED2C
                                      SHA-512:5CF396CA472C32AE988600176114106CB1619404DD899A3867A5AB43DC90583B771EF69B14EF50E56A21F038BF51D8463C6ADD2DE9D4CB523F6290E24A4DECB3
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d............................................................................................!1..AQa....q........"2..R..Bbr..#S....3$.....C.4v..(X.DtEUV.....cs..Td.5uf'Wgw8Hh........................!1Q.Aa....q.2...."R...r..3.t..U...B#S.4ub..C$d.5Ee&'7c.D%sT..............?.....?...k,lk^...M".Yo5.Qp.&s}b.m.:...W.x}.*.a......N1..d-n.-..^..b..TZ.W..."....F....^......ve5...^...2.:i...........~u2pK.z./&..u..L[I....Y....@y{|>..MN=:....Q[..H....a........|%..4fV....).....^.9b.f...F...p.=.W...aZ.........Z.t.n.....z3..[..lVh..\.N-.._.sK.y.._e.G.jig.a.7^....u...*.p.5.a.].........u/u..D.yl.XA..f.z..~.x.....N.....b=.uv.2.t.'.N.-.H..n.v.a.A[.Z.....T2...._...:....h..l.E..sm..a.3I...RE...fWb.Ek.0.#.)..Y#T...........u{....U....s.].7_H.2.`O6...P......}..4LR....]4.mid...
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:91160002A76920D0B1DF2DF4E6D82C6F
                                      SHA1:F556AB18C0651F18551C1E08506B22B4EA470CF8
                                      SHA-256:1EA1AF73AF4CDB66217EE64D861FAFC79FA28462D1ACC2A9DC47ACCD5EF1E216
                                      SHA-512:ECB90AF7748D18780C1345E1E3D6F48DCDA46758EEA7F5206BD8B52D9B8157C999516D93030DB498C7BD9FAE82CDA2218EC72BEDC9B6C3263EFA03CBED01813B
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:..........................................................................................................................................................................................................3.......3E.....- M.M.$..@.......@.}.GL...a.v..u....T$........u........O..,.c;.>........@.}.GL...a.v....@............@.......@...................................................@..k....@`....s....8..s....Q..s....[..s....b..s....o....................4..~...1...(...(.......C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.M.i.c.r.o.s.o.f.t. .O.f.f.i.c.e.\.r.o.o.t.\.T.e.m.p.l.a.t.e.s.\.1.0.3.3.\.O.N.E.N.O.T.E.\.1.6.\.S.t.a.t.i.o.n.e.r.y.......S.t.a.t.i.o.n.e.r.y.........1.......S.t.a.t.i.o.n.e.r.y............s....1... ..$....S.t.a.t.i.o.n.e.r.y.........H.......H)G...&.?..=@0u.......u....T$........2.................................@...H.u................................u....c..,.......................u....c..,0..............T...B.Y....Jh...............s...s....1... ..$....S.t.a.t.i.o.n.e.r.y...
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:Matlab v4 mat-file (little endian) 8, rows 975182774, columns 0
                                      Category:modified
                                      Size (bytes):72
                                      Entropy (8bit):2.296631615393777
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:21F4433D8A5F1D7014150A56EBF8D000
                                      SHA1:93033472CFAA78A79778BF7ECCCE88BA6905F84A
                                      SHA-256:3EBA8921C1364150B370BABDF0B9326E7223C851632F0501529F69CA922F6FB9
                                      SHA-512:A4F08A2BD39B7E52BF5C4F33C7A68240EFD5524C2F92B0DAE2011025A388510F533EA54A07B659EEEC5BC6EAE7D96EE851483D8F50C11A64A0B0696197A41E5F
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:...... :........X...8..................................@N2.. ...........
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):0.04401584019170665
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:CD74ABACE8A00B17BD8107BC5982C21E
                                      SHA1:D53193CF8A43D766FBFA52976192F44D6B0F79B2
                                      SHA-256:B670BC07C9CB554511180DCF3F6A2C7818E8CE6E67B84784F0EA4D35EC61D516
                                      SHA-512:1B48A37FCF0F9FB9ED9B31A8F3E36596689BF1EEC6F41F5EFA3C728121944919CE7A81F0379A108D80AA051CFEF07DC296F9C0691FC8855983B2F29EC15C7FEF
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):0.4851423704818626
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:C37C5511511A3B7ECAE48CC5B9107D59
                                      SHA1:8E3190E824A68D60E125CE90B595AEB5EFEEF15E
                                      SHA-256:5B0C5D594672E3B7D780D3CCA34564C79EFC0B0F37F28E0E6694A81E45618083
                                      SHA-512:45BFD6EBD0811BF2416E26DDA38381DDDC93BC4FBC0C6603302BD1A495938AFEF59DA64E740D0AD1B36A43C39D73B1411F5E77B1A862384A9DF56E4A9C7BEDCE
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>...........~.......................................................................................................................................................................................N.......N..A|G......>3........................N..A|G......>3N....................................................N...........................................................N..P..............................................................................5........m;.H....7.5N.........~zu..........3.n..8QB............N...^...........................................................................................................3.n..8QB....................................................................................................................................................................................................................................................................................................................................................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):2.362052497344421
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:86104450B5BF7D262F4DC7BAC025AA8E
                                      SHA1:8315E7E4DFEC8515FABDE5DCBB166B00E9C2820D
                                      SHA-256:710BBD2BA71917D628ED042B5674FF5B2FC627123A8A82176379245078FAFC17
                                      SHA-512:CA9D933594D949334B9AAA5D1A537E56FA2769CC1B23430DFB60C8EF2AA629CFF17C12E0BC55791EE90941E08CB99D1918D7328406F37056AEF3A7D33F28972B
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......................................................................................................................................................................0...2...>...z..........................3.9mC.Q.?{j.F...............E?..N........E?..N......3.9mC.Q.?{j.F..............................................................................................T.3......"....Y. ......&................................................4..e...0...(.......(....9..............."nC.|L...p......................4.....(...(..............e...0...i... ..$.9...........].C...I.gh.........S.i.g.n........................z...e...0...B4.$c..,{D.S.9..............F..O....p............................4..e...0.......(.......(....9..............."nC.|L...p.*...I.n.v.o.i.c.e. .1.8.7.2.7. .P.O.9.1.8.2.............b4...........4..e...0.......(.......(....9..............."nC.|L...p.*...I.n.v.o.i.c.e. .1.8.7.2.7. .P.O.9.1.8.2...........E?..N.K...N...^.......................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.489152811173856
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:3C4A7B04BC2806375A4F7CF96706665D
                                      SHA1:CDD1772F8E8891DF310CADC155ABAFF5D17ACE57
                                      SHA-256:FC92747E03E896B920890ED9BF20043C3DF12AE8C67D450422E9CA3E55861A8D
                                      SHA-512:BBBD5972B148BDFDA727E2E22B396527CB0BDB04B906C4A4E1B1A5ED43E3F3108D8874153E4E77E6513FA1F6D2544525AC9916F46BBCD46C6208ED72EA7EC628
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:x.......8..........@.................?..........................?.......................................................................................H.......t.......f...............0................+8......+8*V..O..>.+R.$.W]......W].^..... .-...e....s..E?..N....W].^..E.,.0.5zw.W]..+8*V..O..>.+R...+8.......+8...................................................................5......N..A|G......>3................+8............................................................X.........Q..................+8..W].3.4[.<G...HD7......h.... ...... H.68L..b....,.+8......+8*V..O..>.+R.$...............E?..N.e.......e..9...H./.....<G...HD7............W]......W]..................................................W]..C...W]`.1...W]..F....................................................4..~...1...(...(.......O.p.e.n. .S.e.c.t.i.o.n.s.......O.p.e.n. .S.e.c.t.i.o.n.s...........1.......O.p.e.n. .S.e.c.t.i.o.n.s..........W]......W].^..E.,.0.5zw...............E?..N.2.......................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):32768
                                      Entropy (8bit):4.003705110140657
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:3E331B7235B74A18016F0B2ADA4BFF79
                                      SHA1:B54A026A0335B11DC4AD53DCAA0F5520E56C50C5
                                      SHA-256:D86ED78F54BED1EE7F50C41A976C6B9991136B45FB6A65D6445CE53A17B28F21
                                      SHA-512:2997BDACC2DD902C0FADCDE8E4BC553A0F3ED44961499A8336C3A14B8D2824CB16124633E919F13BF883F5728807FFA1497F64AE4C256264743B8D4A917CD1C9
                                      Malicious:false
                                      Reputation:unknown
                                      Preview::..@J......@.......@...@8 ...%.........4...........4../4......Z4...4......u..............C.a.l.i.b.r.i.......h.2.......p................~..@....^......@........PS...........................................................................................................................................%...&.................'......)................................................D....-..i..$.........j.............I........>......#..... .. ..$....................z...x.. y.. ...$.zD.SzD.S.....l................................I.qk..B.....LZ...............4...........4../4......Z4...4......u..............C.a.l.i.b.r.i.......h.2.......p............ .. ..$....................z...x.. y.. ...$.zD.SzD.S......... .. ...........................z...x.. y.. ...$.zD.S{D.S....................4...........4../4......Z4.....YYY.............C.a.l.i.b.r.i.......b.l.o.c.k.q.u.o.t.e...................4...........4../4......Z4...4......u..............C.a.l.i.b.r.i.......h.6.......p...........4
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:PNG image data, 1035 x 500, 8-bit/color RGBA, non-interlaced
                                      Category:dropped
                                      Size (bytes):78304
                                      Entropy (8bit):7.906676726312999
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:1673BA0257F532D7A4D6FFCA319D0D80
                                      SHA1:0E542AF474CF50B3D2D9ACD7E0DBFB8854684E2E
                                      SHA-256:8C9BCBF69CB4F036A4C87B866F44A23F41609300751BB02332A717E770792EE5
                                      SHA-512:8A3A8C0D697BC75743FC98D5BE33CE9B4336498F1E5EDF919C8A8AAF835CC1017183E5EBF764CA2C80097B1F4E1EB491B14A6EDD3FCD3F3762C4B4263EB4EDD2
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:.PNG........IHDR.............[.....BiCCPICC Profile..H..W.XS...[..@h.......).....H/...$@(!....YTp-.X....(v@,(bgQl.....X.+oR@.}.{.}s.....sg....I.H.....#..G...'$&.I=.......h.7O......../.n.D.^..j.......?.....q*/....!..*.H...Q.M..I1.@K...x....q.....>.Ml4..V..T8.q:..W O/.C..~...<...5:..99.<.S ..6"......t....:....c.\dE._.'....?..KN.d.%.*...h.a.ne.J...}.....5!. ...!F)...8.=j..c......y..P.. ..f..)..4A .b.B..|v,../....(l6.s.....41....s.2.R_.$YqL....>[....f.&@L..@....*..yY1...q....!..$Z..9..|a..\.+H..F+.Ks..m......@~Fl.<?X+.#.......2.t.y............q1....|.h.X.".T.... )o..s^A.b,.....\.O..G.....39!..x.. ...?..... .d.A{_C.........t....fhD..G..1............A.....=H....Fd....P...%.Q.ao...d........U....!.;.L....y...Y.....`b ....qO<.^}au.....<.....:...7.]..S.E.....~."..?...........2....{...a.>..dY...Y........4.vdG2J.A.%[.<R.V.eXE....#.5u8....~.>...?[b....9..v.;.5.:.5bm.q).^]Od.k.[.,.,.#....'+.d.c.c...y_>.....X...bAzF>....|:[.u.Ewrtr.@.}....D...N.wn...x5......4.
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:PNG image data, 131 x 78, 8-bit/color RGBA, non-interlaced
                                      Category:dropped
                                      Size (bytes):13307
                                      Entropy (8bit):7.973741249254137
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:D2647231ABEC666AC4153973FD9047C8
                                      SHA1:4D543CCDDB327F29973B1B42C6FC72B1D92DAB51
                                      SHA-256:EA0C3724E1F1E7588A30604C634E4938FBD4151CFD4E48397880B2BF236E47AC
                                      SHA-512:72406E88027F9B8B452C2F2B2DB41AE73380F4C486B576CC9D9A79FF9DE71139EBE91FA47FBD8714D603DCA6F51923156604AE5C05AD73128D4A888D512CA15F
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:.PNG........IHDR.......N............sRGB....... .IDATx^.}.x....,.z...$. l!!.a..EQ*.((....J[[..j........D.\J*..+{..@Y..a'..s.o....PD..U..<..7..w.9.s!.X.J.I..$.J.Y...p..'$p.......C..(gV........\.9......)..\3|6...O....p.j..y...q..b.~p0..,...M.....>...:..Zy.E.d.8<.?.B..n..........wv..U.....I.....z....B^2..~..C..@.;W.d..........}.v...".Z"........y...^.-.w...}.'.qk.E...{ulJ..E.="....0y.S...oT..........l_.7o.`...{...g.......%.2..".(V...:}.,!...l.....8...e.9.3.K.....o.....................wK...%..;&..........v...........@..d.8.N..QV...._.<S.wO...%.)s.....|m...'..$._..8...ww.!.).......o......R\..F..7....y._...........i....w|...h..?.FK.....C...a.....~~"..>}A.P........X.....W..T......x'..>...ny./6._.....f_.(.s.b...5....[....:e.'8W...V.I...w.fg.&..*......?y..[..Ny.....t.../(.....(...WF.t..(......0..MO.+%Z~.:l..}..3jy...P:=..(......4..}..t.]Yv.C).......(7.......~...T...&8.6ZXf1:-..??..|.n......Af..1......v.9....Q..nP0Z....C>cN..N.{`F...
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:PNG image data, 1024 x 495, 8-bit/color RGBA, non-interlaced
                                      Category:dropped
                                      Size (bytes):70699
                                      Entropy (8bit):7.923158875243697
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:29A82AF68823DAE68B457FC868B69E75
                                      SHA1:8079D1F5555A3654E4DE8498AFA912FCE89BB4A9
                                      SHA-256:8BC02A5602CA1CCEEB66E0D664380163EA4CF19966007982BDBE7B757561EE57
                                      SHA-512:7A0C305D122E9ACD2DC8A261D1C4A28F1E47BAC819D50F16BAD927D16C193011A6DAF25065B142C16952A29A42AB6F49C2E8DCFF47052FDDE85DEE0EEB2AE263
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:.PNG........IHDR..............7.s....sRGB.........gAMA......a.....pHYs...%...%.IR$.....IDATx^..gt\...>...[.......2.2.R.JUjS5-.j.O......>.9g..Nu..9S..wJ...[z... ..............@&H.@......D....}#..oW=p..B.!..B.!V4.3.B.!..B.!.X... ..B.!..B..2..!..B.!..~...B.!..B.!.. ...B.!..B..... ..B.!..B..2..!..B.!..~...B.!..B.!.. ...B.!..B..... ..B.!..B..2..!..B.!..~...B.!..B.!.. ...B.!..B..... ..B.!..B..2..!..B.!..~...B.!..B.!.. ...B.!..B..... ..B.!..B..2..!..B.!..~...B.!..B.!.. ...B.!..B..... ..B.!..B....8.<.3LOOcjj....3.<..V..- .....(.........37...5...=....G...1......w>..B.!..B.....`tt....hoo.-...P....""".....8_1(..W.OLL`hh.}}}.6...1<<lkell....Z...............{......{O..c.\###v^.5.c.QQQv..,..B.!...A..9......q....v..E^HH..........t$''.........oA1N.N!N......z444....]]]........:.>.~||<.........<..."%%..q.5.x.....;Gkk..... ?.....W.z..@kG.!..B.1.d.....Z|......~`..Y...6....k......B...(.Gw.1(..~-...z.q.m|N.Na>00.0.`v...7.+.?........6.w...wo.M@...gq..e.w...4*......Gqq..C)%B.!..B.. ...
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.679176734617307
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:A0E6E60B64F8435A8FE7EE4E4870E982
                                      SHA1:EB054B4F01F683479E6CBE84CF9B7D9B679A1345
                                      SHA-256:7D6D79843C6359A1AF88444980EA3AD798CAF1370C94592AABA37CD1AF6B1835
                                      SHA-512:9CEEB4DD5F0D7B085E3102AB87263F19D7F6F814E0235D1FD1546A8695F4D377EEE7B9478AD82C8D0E6EF99321669AA40A31CBB7D04B04C8FFB8EFDD818A87CB
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:j..@...@<.......(.......................................................................................................................................j..@...@t.......(............................................KN.|.+.....{[......{[k....+..{:n...e.A.........@..e..j...j...0!.1%CT.j......1....$...E.q.........................................................................[[a.....[[a%j.^B.5..gaR.........I...M.....J..2... ...^............................{[.[[a.%}m......!..............T&.....T$...[[aT%q..%}mT.N...............".......l....T.:..............{[..c..,0...e...B4.$..........C@RQ.H..B......Y....................%}m.....%}m.|..@...?.P.............1....$...E.q.%}m.|..@...?.P..%}m.[[a%j.^B.5..gaR[[a...I...M.....J.........>..................1....$...E.q..{[k....+..{:n.N[[a%j.^B.5..gaR.!.......!.+....h1.r..P.........I...M.....J.......[[a.....j....c..,0...e...B4.$...........I...M.....0...............................0...........e....4..................T.i.t.l.e.......|{
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):8192
                                      Entropy (8bit):4.752870415548909
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:E430E87846AE0F7C398B93C1041EC163
                                      SHA1:30902792C653FA3010B34A7342196E70D28D0E69
                                      SHA-256:C0206F5F3C4BAF1DB8B2AA4EDF9EB39005A04DC60BA60DD21A5224849E77336F
                                      SHA-512:A5C47A8CC2C8A12B2187A4AB332E96330C3FF38BD1722A0954B12D411FA11E0CDD46889D3CC9837E38C04076EDBEF76F134748EA8A1AB3C6DFEE14E7260D6856
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......t...v...h...................................................................................................................................2...>...P.......v................................I.......I.qk..B.....LZG.6.4...G.6/.....U......G.6/.....U......G.6..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'......................R.I.....N...^................Z*.S.O..Ha...............>...............................$....I.qk..B.....LZ.....................R.I..................R.I..........G.6.....G.6.....G.6.........................................G.6j....G.6T%;..G.6.....G.6..W..G.6H....G.6..+..G.6..S..G.6..........Z4...........................................4../4......p...............C.a.l.i.b.r.i..................G.6:G.6kG.6..z...y.. x.. ...........$...........7...7.....*...o.e.L.o.c.I.D...o.e.L.o.c.C.o.m.m.e.n.t.......0.0.0.3
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):12288
                                      Entropy (8bit):4.395345515663568
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:9436BA36BA19A217635F9CCCD9787680
                                      SHA1:A086C796A3994D30FC59B57EB67DFA58C8D1FEFD
                                      SHA-256:3A4CA44FC443343A1D6452EB7651283E58B016A60ED7AEDF04D1E8CD15AF5A86
                                      SHA-512:5F86442A9CD2FDA5DE20CE3B545CBC4B867D2461DE850A5175BFCCEB2CF6A12278CB68952D2FF175A7E82AEF441C72359F5D105A727B510E32A07E3813AF93F2
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>...........v........ ...)..2...>...B.......v.......@....(...........................................................................................................................................I.......I.qk..B.....LZ.==.H....==f.S..0.../....==f.S..0.../....==..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'............._..s....'..bf0.t....N...^...................F..A.#.....[............................................"....I.qk..B.....LZ............_..s....'..bf0.t..................................==......==......==..........................................==j."...==T.....==......==..T...==......== .A...==......== .........==3.==:.==8.==..z...y.. x.. ........ ..$...$........D..........7...7.........*...o.e.L.o.c.I.D...o.e.L.o.c.C.o.m.m.e.n.t.......0.0.0.1.5........................Z4...........................................4../4......p.
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2004:03:04 13:19:29], progressive, precision 8, 221x792, components 3
                                      Category:dropped
                                      Size (bytes):24268
                                      Entropy (8bit):6.946124661664625
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:3CD906D179F59DDFA112510C7E996351
                                      SHA1:48CDB3685606EDD79D5BCDF0D7267B8B1CCBD5A8
                                      SHA-256:1591FD26E7FFF5BE97431D0ED3D0ADE5CFC5FA74E3D7EC282FD242160CE68C1F
                                      SHA-512:2048CBA13AF532FF2BCC7B8B40541993234BD1A8AB6DE47B889AF3F3E4571F9C5A22996D0B1C16DD6603233F6066A1A2A97C16A6020BEDD0826B83BAD0075512
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....H.H......Exif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop 7.0.2004:03:04 13:19:29.....................................................................................(.....................&...................H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d...................................................................................................................................................$.."................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?.....)......[]t.\Z..g......A....&D.$LH._..X..Xl...`....cZ.X.........>......f.Z.X...]..~L.S..@..I$..I.IO.....x...s.g.[f.h{9..
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):12288
                                      Entropy (8bit):4.664432216003761
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:F2C0D469F1FFAC7A84B09FB0059588E1
                                      SHA1:3B11275F2E2966AF913CE6612F7FD1582F825B95
                                      SHA-256:809E9DAB0C76D72B774965C180429BE31274B6A7DA1CB75967AD92FB37665760
                                      SHA-512:2A2B74D47E7E637518C94C4D46C13DF08BAE8D312DF3E711C678E4E64E0C54A80D518880940ECB90E09658BC800ACE513673D49BD07404A36D51BD7D54A6A34F
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>...6...z...v...N.... ..X,..2...>...........v.......@...H+...........................................................................................................................................I.......I.qk..B.....LZ....N.............8J.............8J........I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............q<.4.-p...r.../.....N...^.................A...M....&.@,............P....................................I.qk..B.....LZ............q<.4.-p...r.../.................................................................................................j.9.....T.................s.....H.........0.......`.&...............3...:...A...8.....z...y.. x.. ........ ..$...$...............7...7.........*...o.e.L.o.c.I.D...o.e.L.o.c.C.o.m.m.e.n.t.......0.0.0.1.1................Z4...........................................4../4......p.........
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                      Category:dropped
                                      Size (bytes):39010
                                      Entropy (8bit):7.362726513389497
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:9700DE02720CDB5A45EDE51F1A4647EC
                                      SHA1:CF72A73E1181719B1CC45C2FE0A6B619081E115E
                                      SHA-256:7E6A7714A69688D9FFDF16AA942B66064A0C77FCD9B3E469F89730B4B9290C3E
                                      SHA-512:5438921467D62376472007B9EBF3C35C9D9FE3EDE04D99A990129332D53EBC8EE2555C0319A4F7C0DF63516F29CEDF2171D8B6DC34C9FCD075C2CA41EB728660
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d.........................................................................................!1..A...Qaq..".......2BR#...b%&6..'w.r.3f7W8.s5EUeF.g....CS$4.Vv..Tdt..G..(c..u.Hhx.......................!1.AQa..2.q....".s...3.4BRr.#......b.$c............?........uf.....t...;..[...W.h.....-.k.f..i.u..KQ..b.F...rM%/.8n.S..=9.....G$O;.f.}L..N..U._i.[.X...3.~....S.~..+t$...c.5......{..X/..#.G...}s....6......^....o~.$.\WA?...^*w[O.~..6..~....a....~..:..0.......{O...|.s.u._w.........i...........{K...._.?.../{.....A..8....<g.iu..<..................X......|]v....D..9.k.w.|-IF.Tv.-.&.........."'.4.b....z.._.Z.....G...u.xyt./_.q..m>..S.V.Xdc.bw.T.W......g..........}s.._..?....U]_.......`......>.|'.~xH....,...?........?.q....o../..R..;...Y.G....A"?......?.<..1...w..o.M.........tco.
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):12288
                                      Entropy (8bit):3.9209856003397374
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:136365046D56E785A3EE6BE1839F8DA2
                                      SHA1:A87BE1CEABEB5A811FF31D50469D29E17F0D2D2B
                                      SHA-256:9D9937B41097111FF7D8B7D7C87427448DA386C935745A279062645098CFC38C
                                      SHA-512:CB0D0D75A43F1841B882D3DC4BF44133980BE4CA2FE6303815FDB88E7AF727C747A6E107DBE97F4630BA4B6B27A80E7E5E04424836D854C53BCB8DF4AB18E67C
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:....>......."...v.......8 ..."......>.......r...v...>...@....!...........................................................................................................................................I.......I.qk..B.....LZ...........A.......s.1.~.>...;4%G[.Y1.~.....A.......sN....I.qk..B.....LZ.I............I.......I...................................................I.t.....I................................................................4..'...'..............%J...p..9.....9....N...^...............?...k.C.U.@.D.J............(...............................z....I.qk..B.....LZ.............%J...p..9.....9.........................................................................................1.~.8...1.~.>...;4%G[.Y...........A.......sN2................................I...............................1.~H....1.~.....1.~..d..1.~.....1.~ ....1.~$.7..1.~.....1.~ ........1.~!1.~..z...,4. ............................"......$...7...............T.u.e.s.d.a.y.,. .J.u.l.y. .2.8.,.
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):12288
                                      Entropy (8bit):3.869784946538798
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:F38E794422E7F0FB4949D556DAF271AB
                                      SHA1:FA71F74FE9FC276F4B78BBEEDCACB1C52385FB8B
                                      SHA-256:B875EF6962B3A594668B180800C6DB4711D1639403E49BB3885DC88F91F7B3DF
                                      SHA-512:7783A1DB3FF2B39176676B0CB6F4E4367C3459E489C36939E8F4AA0379405E4716BB0D2458DE7E7E36163E812B49B7C9F4E080ED278C72B47BCA1E8DA920AD79
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>...........v........ .. "..2...>...d...<...v.......@....!...........................................................................................................................................I.......I.qk..B.....LZ....<...... ......MP.t..... ......MP.t.......I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'................f...>....t......N...^................+.ob;.A....2.,.............................................D....I.qk..B.....LZ...............f...>....t..................................................................................................j.......T.T...............|.......;.......h............. .W.....'...2.....z...,4. ...."......$>........4..p..7......S.u.m.m.a.r.y...........................3...8.....z...y.. x.. ...........$...........7...7.....*...o.e.L.o.c.I.D...o.e.L.o.c.C.o.m.m.e.n.t.......0.0.0.9................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:big endian ispell hash file (?), 8-bit, no capitalization, 26 flags and 19975 string characters
                                      Category:dropped
                                      Size (bytes):20480
                                      Entropy (8bit):5.370241049071708
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:B94C215498E6077CE7A653D17E833FBF
                                      SHA1:80D14069E0D7F6CA07CE5F93E981CE7E662D1FCF
                                      SHA-256:27C25226A881FDA7A66333CF6825D19257A9F02D8DAF29D9F1DB7599E83E623F
                                      SHA-512:B986DC9A53A99D72CBA84FA3E5A7F4D5F1E881BD496557F0E78F0E5D60F4538C84B66D3F49A5E8B5968394FD665CDE6FBA8E2DCF1E238F993D0F3DE8CACD29BB
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:....N..@p...............(@..@!..@M..........N..@ ................K..@!...L..................................................................................N..@8................K..@!..`L..............v.......v...tf*D........0.......0..cK...4.P3..*...t........0n.Z..t..R.e.f.>.......R.h.w6....?..w...h.w..........0.......0...................................................v..T.......T._...#.T......'T.....K.T......7T....9.9T......<T!d...........0...........e....4.........................A..:4E.2..p1......(...`.i.....(...(...B.a.c.k.g.r.o.u.n.d. .-. .Y.e.l.l.o.w...j...P.a.g.e.L.o.c.I.D...L.o.c.V.e.r...P.a.g.e.V.e.r.C.o.m.m.e.n.t...P.a.g.e.O.v.e.r.i.d.e...P.a.g.e.N.a.m.e...2...0.0.0.1.9...1.....0...U.n.t.i.t.l.e.d. .p.a.g.e..............M.q.K...7./j5..j.......j...vI......@.2...............h...............v.......^<...#......|M....j...............0...........e....4........................yf.....F.Q.........(...pO;.....(.......S.t.a.t.e.m.e.n.t...j...P.a.g.e.L.o.c.I.D...L.o.c.V.e.r...P.
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.097558612300757
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:4E7A3BBD5070E2940E4DAC969DE1BC36
                                      SHA1:4876BDD4EE35005A9900AE38C7ED1DBE44700018
                                      SHA-256:DEC3882F65C3C6118E2B377D191AAD1773237723B900F2AEB0F598EBE6B4DB00
                                      SHA-512:28DF8B9EE65F790B38AB512021E96F15CED668100C1BB2E127FAE788EFB73A85A4406B09C2CD648F43BE988B5BD48DCC8FA2050545383C13B1CE78FC841333B8
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>....... ...v....................................................?....?.............................................................................2...>.......|...v...H............................I.......I.qk..B.....LZ.;......;.4...&e......;.4...&e......;..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'............. %../{..,1[..TAk....N...^................I....[I..F<..).........f........................................I.qk..B.....LZ............ %../{..,1[..TAk........ %../{..,1[..TAk..........;......;......;..........................................;j.....;T.]...;......;..B...;H.....;..B...;..>.).;..J...................;........4...4...4.."...............;..;..;..z...y.. x.. ...........$........4......7...7........................;........4...4...4..........;......;....#.;............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.062439684366303
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:47A877AA23D7FB74AF1B64EA5D61EC95
                                      SHA1:DC86CBF9EB6AA18EC64BD324274A0D05B9037539
                                      SHA-256:4B02400BFACE436991102F2A593FC56D27D5140336DBACF0EF3688F6CD4C53EB
                                      SHA-512:1C28D01B91C32D15C34346DEE584FDB2F77A5CEE7BF928BDC5CC0BC7382928F9C8C677053F08A87EB1D3D866DD8024060F8F50CCF4E5627140644E1BA9521082
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......&...v.......................................................................................................................................2...>...........v...N............................I.......I.qk..B.....LZ1.......1....F..B....1....F..B....1....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'...............n.<Z...E.....F....N...^...............y.I....H..v...l.........f........................................I.qk..B.....LZ..............n.<Z...E.....F..........n.<Z...E.....F.........1.......1.......1...........................................1..j....1..T.]..1.......1...B..1..H....1....B..1....>.)1....J...................;........4...4...4.."..............1...1...1....z...y.. x.. ...........$........4......7...7........................;........4...4...4.........1.......1......#1..............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.032864814060123
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:7B166B248DEC79415999D01233B95D16
                                      SHA1:6799E108D35C9D5BD778487C3C0BFB597D92B31E
                                      SHA-256:E764BDC445A2725715696FDD98DBDD8841EEE5E8E71A9A1B2E09D1CFCD3AC132
                                      SHA-512:2455677A08353FC4A41BA0B83CC3EE749A4A1F0FA7D68AA4BF7466AF58623AFF4947A859521AA58E068C4E832A33A90125EDEBB06D91AFF320E0680C7559017D
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......$...v.......................................................................................................................................2...>...........v...L............................I.......I.qk..B.....LZ..........'.~.....t.....'.~.....t......I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............O.}$.i..:`Quij......N...^.................\....F................f........................................I.qk..B.....LZ............O.}$.i..:`Quij..........O.}$.i..:`Quij......................................................................j......T.].............B....H........B......>.)....J...................;........4...4...4.."........................z...y.. x.. ...........$........4......7...7........................;........4...4...4......................#..............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.107900709807377
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:7733BCD409E87AEAE4381E98DF75866C
                                      SHA1:39693E7F33F1E6CAF176063A9A950B0E631B1639
                                      SHA-256:B21BE70DBDFE070B97574445170BE545E225542A38522611DF914A6E49B552EB
                                      SHA-512:DE5786F00DAAE4703754CA430654BDD10BC4AC15E3E46E476CD9730BAE2D3FAF5D865E1B409842EEDA1792ED7FD6BD0DEB8969A22BF390C34170A1E2AC2420AF
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......$...v.......................................................................................................................................2...>...........v...L............................I.......I.qk..B.....LZ..w.......w.(.....7c..\...w.(.....7c..\...w..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.....................*9.....*....N...^.................*K..GM.H.F.R........f........................................I.qk..B.....LZ....................*9.....*................*9.....*...........w.......w.......w...........................................wj......wT.]....w.......w..B....wH......w..B....w..>.)..w..J...................;........4...4...4.."................w...w...w..z...y.. x.. ...........$........4......7...7........................;........4...4...4...........w.......w....#..w............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.048998901257052
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:BB101E7F285971ACC6512FABA0B4866B
                                      SHA1:5A4B76E7AE38C0198EE060CECF28E29B7B7B758C
                                      SHA-256:9EAE4A51F9386B9F97AAFCA0F2ED49161036B55E829F3CD06527737FF128F31F
                                      SHA-512:D298E1DEC9DFDBB8248C51AD1F1AA6C53E39C327317A8D21AFE7AA91539D520BB04CF5F42D173A39ADBB3F4E26CB84082BC4B1C3EAEC026F0F4F3E499FAA1A08
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......$...v.......................................................................................................................................2...>...........v...L............................I.......I.qk..B.....LZ...........9..-..*.\.>#...9..-..*.\.>#.....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............:....9....8;.~)....N...^................O.T...J...t.cH.........f........................................I.qk..B.....LZ.............:....9....8;.~).........:....9....8;.~)........................................................................j.......T.]...............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4......7...7........................;........4...4...4........................#...............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.0684806174876895
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:EB3A0300ABCACC0DA3D83A459CA9B77C
                                      SHA1:245525BFB4C038E947A0FE5DF2D2457336E48762
                                      SHA-256:1A1EBA837C45C85C96E3ABBB8691F1B37754E67E43313FE9B1D34AF35345EA0E
                                      SHA-512:78954D7F08BDC4E200911970E4D6207527EC15BE6839CA0F646997A1971CA3339181173791438D05A294CDC8428DE75B2728BD0D80AF87F56F0BC2F6E94C2EC2
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>......."...v.......................................................................................................................................2...>.......~...v...J............................I.......I.qk..B.....LZM{......M{...\..0.....=.M{...\..0.....=.M{...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............._..y.K....N3pXO....N...^.................D....O................f........................................I.qk..B.....LZ............._..y.K....N3pXO........._..y.K....N3pXO.........M{......M{......M{..........................................M{.j....M{.T.]..M{......M{..B..M{.H....M{...B..M{...>.)M{...J...................;........4...4...4.."..............M{..M{..M{...z...y.. x.. ...........$........4......7...7........................;........4...4...4.........M{......M{.....#M{.............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.020307049879541
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:2862ED8FB5E4D52515B1B7D4F3CA876C
                                      SHA1:849C5085BC9EBA956EF38813687EBEB717FBB40E
                                      SHA-256:9EDE81F3245FE9ED9FDAB8C06C9D9A29A44823C09201A100B5BE920D2C3EA6C3
                                      SHA-512:4810A0A317036C635226920A50755AA2B1ACAA07621FA0507DD5ACA11E4B548E6F0BA0F694FA59987221D18C587BB5758E3EAD92F6C6BA35C17FF5D2F861FD7A
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>......."...v.......................................................................................................................................2...>.......~...v...J............................I.......I.qk..B.....LZ.............(...MN..A.......(...MN..A.......I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'................."}..8....h......N...^................!...*.N.]...B.C........f........................................I.qk..B.....LZ................"}..8....h.............."}..8....h..........................................................................j.......T.]...............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4......7...7........................;........4...4...4........................#...............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.060540604072043
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:E3C07E1830FEE050EBFE429E2FE5C34A
                                      SHA1:A125DB73003E31DB6AE518D7EB8770FFD223DBC7
                                      SHA-256:A43897587C11079A8908A25D62A115130E2947360D65B6BCD076FC214743DB5A
                                      SHA-512:317850E3EBE0F2EC84BF1BE25DBE2F75CE07C194D220F42AD85635CD1435D877DAA505CC73D827B0AE58892A1DF2DD159E3054D0F04BAFBD0AAEB698374313CE
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>......."...v.......................................................................................................................................2...>.......~...v...J............................I.......I.qk..B.....LZ.................]h..2D..........]h..2D......I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............k]X.."...q........N...^......................D.pJJ.F. ........f........................................I.qk..B.....LZ............k]X.."...q............k]X.."...q............................................................................j.......T.]...............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4......7...7........................;........4...4...4........................#...............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.0969174477220385
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:A0FAE1D441EDCAEF843BD85FF9305400
                                      SHA1:BA5E51D016A75DFD3043EDC40186B375853A3D5C
                                      SHA-256:D039D788D9146C94E2E346D8E58CDEF03A0A935EB979CE1E47825FA34ADDB049
                                      SHA-512:2FEFD6CEA397D853EEEB6E431CAB1C2C883FA36E84D45872E446D04DBDDD0CD0DDE61A4D570A67A55521215C520E30B808D90485F05EB7AEF5A50D06FA359D73
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>......."...v.......................................................................................................................................2...>.......~...v...J............................I.......I.qk..B.....LZr<......r<.....7.I.:.yr<.....7.I.:.yr<...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'................}....y.-.....N...^................2/ .*.O...............f........................................I.qk..B.....LZ...............}....y.-............}....y.-..........r<......r<......r<..........................................r<.j....r<.T.]..r<......r<...B..r<.H....r<...B..r<...>.)r<...J...................;........4...4...4.."..............r<..r<..r<...z...y.. x.. ...........$........4......7...7........................;........4...4...4.........r<......r<.....#r<.............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.023888617121352
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:E60464459A6FC830A49B494116D2F1EC
                                      SHA1:C0D8456390E0EF71C2B0A90FFFAF4BF600055EB8
                                      SHA-256:D8223285ED3CE110ABBACD32B184ED0C9F85DAEAABA933DEC1FDE03C2B1C5DF0
                                      SHA-512:7D47EA3140DEEC6A7DC59F7796BCA99FBF8F18A9FBF85CFD11BB992FE81326CDC7EE6057957E4D1525CB7960C7D76C2BF369440AADD139B9F57BA621D432B576
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>......."...v.......................................................................................................................................2...>.......~...v...J.......................................H.u...$...zz.I.......I.qk..B.....LZ....H.u...$...zz.....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.................<...8..U......N...^...............5VZ./..@... $.........f........................................I.qk..B.....LZ................<...8..U..............<...8..U..........................................................................j.......T.]...............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4......7...7........................;........4...4...4........................#...............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.082153358169915
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:4080F033C5A466F01F1FB6B640F3461B
                                      SHA1:E8C19228F99BBEAF293C1D4EAE75D09718A2DF08
                                      SHA-256:81D8081E875F536C8C5EE1614035B957937A6D0396AE8F736D6C7F0870D77425
                                      SHA-512:0B22FE6EC52F1B6FC7821FCFEDC3E9D57F07D3FE45128A492A0ECF1452D2E71E68B11BEEF7F79C1C645D6628FA68BEAA33A8E613EFEC72E13E6397B60BB619BD
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>......."...v.......................................................................................................................................2...>.......~...v...J............................I.......I.qk..B.....LZ$L......$L.1...........$L.1...........$L...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'................;..N..`.Z.I.W....N...^.................y.l..K.+.-(...........f........................................I.qk..B.....LZ...............;..N..`.Z.I.W...........;..N..`.Z.I.W.........$L......$L......$L..........................................$L.j....$L.T.]..$L......$L..B..$L.H....$L...B..$L...>.)$L...J...................;........4...4...4.."..............$L..$L..$L...z...y.. x.. ...........$........4......7...7........................;........4...4...4.........$L......$L.....#$L.............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.072742220511062
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:A9C9FC601D8DB94EF8FF68BC9FA9A243
                                      SHA1:F9F030584A90DE2571716DF4F6ECD9F9C834976B
                                      SHA-256:D63EE1ABCDB21D88A5A4AA8213D5C50284F5B10D168FF78D510D8FA29791A91E
                                      SHA-512:949CA125C58037E8FD0A452038CBBB98B41F6D63262E68DF4BEDF17A35040F276025CEE94CC1409B75CD4AD69DF1A32255F615E441C127D32D63A3B9D46CB309
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>......."...v.......................................................................................................................................2...>.......~...v...J............................I.......I.qk..B.....LZ..|.......|.2.4.0"].....|.2.4.0"].....|..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............`...b..Uer.|.&....N...^.................OPM.L.~..4{p.........f........................................I.qk..B.....LZ.............`...b..Uer.|.&.........`...b..Uer.|.&...........|.......|.......|...........................................|j......|T.]....|.......|..B....|H......|..B....|..>.)..|..J...................;........4...4...4.."................|...|...|..z...y.. x.. ...........$........4......7...7........................;........4...4...4...........|.......|....#..|............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.09880837548636
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:F0829E1BA9737AEED9884B4B6B5D8297
                                      SHA1:4A616A75E4945BDF575E0BB00D09DEB553A2075F
                                      SHA-256:1F339D660D8C939AC053787244B66A4BE8B9434288F2713C1799702767A54669
                                      SHA-512:C325E88FD7E6430265C0D886AD29253AD25659794374BAA82FB6FD897CB9ED2C6EC84258985C652D681A99BC652A250DEE9124872C89BBB07274DA27AC466FD7
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......&...v.......................................................................................................................................2...>...........v...N............................I.......I.qk..B.....LZrcI.....rcI..g..0^..:...rcI..g..0^..:...rcI..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............J.U..9v./V..&..0....N...^...............+....bhB..u..y.........f........................................I.qk..B.....LZ............J.U..9v./V..&..0........J.U..9v./V..&..0.........rcI.....rcI.....rcI.........................................rcIj....rcIT.]..rcI.....rcI..B..rcIH....rcI..B..rcI..>.)rcI..J...................;........4...4...4.."..............rcI.rcI.rcI..z...y.. x.. ...........$........4......7...7........................;........4...4...4.........rcI.....rcI....#rcI............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.077249815181259
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:4C358215204EE0D252EE06DB377F46B3
                                      SHA1:B515FF6A30463CC87057496CEB417908D2657CA8
                                      SHA-256:E0630DC2D2EA223205D6F9541E77582A8150E08DF9CD402F0F12FB6C7507826B
                                      SHA-512:21A7EE9D1B033EFA83E5E59B9A215D6E92526FB110F98D26FB92C08A6501CF89F3FE628A571606A822D7A3FD1572AD9181EEFBD21F6469720938E42A42631A85
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......&...v.......................................................................................................................................2...>...........v...N............................I.......I.qk..B.....LZ..........)...1.G......)...1.G.......I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............U.......[.l.]3+....N...^...............v...T.A...N............f........................................I.qk..B.....LZ............U.......[.l.]3+........U.......[.l.]3+....................................................................j......T.].............B....H........B......>.)....J...................;........4...4...4.."........................z...y.. x.. ...........$........4......7...7........................;........4...4...4......................#..............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.105849343811707
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:FEC181E6FC5B7AB8CFAD9966BDD40552
                                      SHA1:E5FC1D065821AC640ABF34EA266DFECAFC72FD94
                                      SHA-256:C3DC0D4A430CD5132C674C08E935DDFF38B05202B8BBB14AA24CCB8F33837450
                                      SHA-512:6B88F1BE575E36B1C171B4D9A096F2DC27630CFDE27FDFE6E79933166FAC2B2A5674F7216D761B1BD68E22560345E3D21363E3F0F0742EE583D962FF0D4D38AA
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......&...v.......................................................................................................................................2...>...........v...N............................I.......I.qk..B.....LZ.$.......$..X&D..........$..X&D..........$...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............k...9.....)...S....N...^...............E....}.K.h...(........f........................................I.qk..B.....LZ............k...9.....)...S........k...9.....)...S..........$.......$.......$...........................................$.j.....$.T.]...$.......$...B...$.H.....$...B...$...>.).$...J...................;........4...4...4.."...............$...$...$...z...y.. x.. ...........$........4......7...7........................;........4...4...4..........$.......$.....#.$.............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.144982870249891
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:76634DF7E5F92C1B08E3D16B5330481A
                                      SHA1:982A12C78C2C3F59FA9D8343C2F6D8D6FA9A17C3
                                      SHA-256:B46030340594C8E98C7CCB21424CAD2E9C5AC9C6FC8487BF07DF77B66BB5EC77
                                      SHA-512:160482637261D55B9F88E7C3BB4EC9D2445ABC55B4B61433299CC66D6BB1E5932BA0B58A73B02EBCE62E9243160634DBA3563765E8564EA0EEF7D713A8110E12
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......0...v...$.................................................?....?............................................................................2...>...........v...X............................I.......I.qk..B.....LZ.*.......*...._..K.R&.tu.*...._..K.R&.tu.*...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............3.......+'P.^'....N...^.................3....A..v..0o.........f........................................I.qk..B.....LZ.............3.......+'P.^'.........3.......+'P.^'..........*.......*.......*...........................................*.j.....*.T.]...*.......*...B...*.H.....*...B...*...>.).*...J...................;........4...4...4.."...............*...*...*...z...y.. x.. ...........$........4......7...7........................;........4...4...4..........*.......*.....#.*.............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.151148735903206
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:46D9208789BB1D424CC1CB136C039D96
                                      SHA1:5D2C964300E7DF2EC3D7A4C569869FE8055142BF
                                      SHA-256:B24640831813A1FDFB8BB35234CD0FD200FB859880E8359F3AF6BB20B709FBE9
                                      SHA-512:9DC50AE62FAF82581C4FE0497F9A3A764F43CCFFBCB214A2779EF816FEB23155F73D27D5E192FAF3CCF067022FCC64C253FBA1734DB06F9943E665BCE72D66CB
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......0...v...$.................................................?....?............................................................................2...>...........v...X............................I.......I.qk..B.....LZ'T......'T.8.&..0Q...PIs'T.8.&..0Q...PIs'T...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.....................6..{p......N...^...............<y...S.J...a1..!........f........................................I.qk..B.....LZ....................6..{p..................6..{p...........'T......'T......'T..........................................'T.j....'T.T.]..'T......'T..B..'T.H....'T...B..'T...>.)'T...J...................;........4...4...4.."..............'T..'T..'T...z...y.. x.. ...........$........4......7...7........................;........4...4...4.........'T......'T.....#'T.............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.142052372821501
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:155A67FAB98E241F363AF24CC1FB89EC
                                      SHA1:F711F09DB1E17B264DE9AB186ECADC2B9C873BBF
                                      SHA-256:E326FE75ECE36524D2F30911EC24C0D3A7CD56DDED65619EA55A03F84A22CB87
                                      SHA-512:7FB1EBAF38625458133328D1A127B7AE562E16C2FAD0A59FE787926FBD44692913BFC596289331D362C2D729CDE7FAEB85244B2B857913356AD5B84E62CF495D
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......*...v.......................................................................................................................................2...>...........v...R............................I.......I.qk..B.....LZ...........(0.L..N..9.d...(0.L..N..9.d.....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'................u+dV..T.gy..6....N...^..............."k|.t.zC.t.2.SUb........f........................................I.qk..B.....LZ...............u+dV..T.gy..6...........u+dV..T.gy..6........................................................................j.......T.]..............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4......7...7........................;........4...4...4........................#...............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.133079222907534
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:96536AE40C1D932DF8D0B3D159FC90CC
                                      SHA1:C1536575962925D8340E1A97E520D2A685072F19
                                      SHA-256:0F29B6EAE43720873DCE0C49CAAF8B74EA57F6558B9C0BA4EBB494DC994E5652
                                      SHA-512:F8BDEA2455B8D76E897CEEC81F93EA30AD68DC9D82CB24A78C660855EA7142852251687DFA74768F72F45819BB4AEA62BF4B1CC0C894F2B016254813D42ADB86
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......*...v.......................................................................................................................................2...>...........v...R............................I.......I.qk..B.....LZA......A.t....%.......A.t....%.......A...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............i~...&..&..n..[.....N...^.................;L...B...,.b..........f........................................I.qk..B.....LZ............i~...&..&..n..[.........i~...&..&..n..[..........A......A......A..........................................A.j....A.T.]..A......A...B..A.H....A...B..A...>.)A...J...................;........4...4...4.."..............A..A..A...z...y.. x.. ...........$........4......7...7........................;........4...4...4.........A......A.....#A.............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.114845204487224
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:B0565A13E3E604F7669DBFBE622B915A
                                      SHA1:AB4D3D665ED551CAF1D44EBC06062379B1082CF7
                                      SHA-256:59D2D6541CCD92CB9B836AF60D6CEAA32A0F4A3AE67859A468E6D4353C054D69
                                      SHA-512:8A1B028CDFACE1F3AA8156309855753E456247DCCC571B87B9589947DD5692BCA449B2B09ECCEC75157518173FA937A550402111DAB4CF454946F30E174142F4
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......*...v.......................................................................................................................................2...>...........v...R............................I.......I.qk..B.....LZ.............5..............5..............I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............x.1*..u..]5.e.W^....N...^................U..l.O.K.V?PS^........f........................................I.qk..B.....LZ............x.1*..u..]5.e.W^........x.1*..u..]5.e.W^........................................................................j.......T.]...............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4......7...7........................;........4...4...4........................#...............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.101467114529366
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:FECA50DF9F694B6A6B7188C82E670911
                                      SHA1:1FDDF0BE7490093339BC7E179B1F2F996EE9EE79
                                      SHA-256:4FB8216B2916DE0F2D63CFB4E85454D3AEA586C1FF267BCA931FCDD9F07B2CD1
                                      SHA-512:EFC5A9292306B4A7FC96F3E0A89C30C621FF933879352398BFEA6AB72E6AB64F57CCBA5E9C3FF35E3B1AEFC83DF693AC05D2F84907440B410501F1EDA764068A
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......*...v.......................................................................................................................................2...>...........v...R............................I.......I.qk..B.....LZ..i.......i7..a.8.~..X.@..i7..a.8.~..X.@..i..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............8..+..7.(1.{z.Sc....N...^.................".Cg.M......Z........f........................................I.qk..B.....LZ............8..+..7.(1.{z.Sc........8..+..7.(1.{z.Sc...........i.......i.......i...........................................ij......iT.]....i.......i..B....iH......i..B....i..>.)..i..J...................;........4...4...4.."................i...i...i..z...y.. x.. ...........$........4......7...7........................;........4...4...4...........i.......i....#..i............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.123680452848708
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:342325EBC1C9D4794B97464E6A19E3A2
                                      SHA1:B4F9095074DCA7C3D735298E0F82BAE2620926E2
                                      SHA-256:518CFF0740C05A2C30D54BE644294ADE979A64EA6CD7D07E585E92B6AFD7E458
                                      SHA-512:C62924CB3B6E6D804C7FCD99A58EA1B9831CC0950804E8CD22D9E13680BE61969DA7FA88C06BB3417226A5E4A1BC012601E9FA468FBBFA191301BE8335F877EB
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......*...v.......................................................................................................................................2...>...........v...R............................I.......I.qk..B.....LZ.8.......8.s.6{.1...=..F.8.s.6{.1...=..F.8...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............:.......!:.8.......N...^.................t...}F..P...gF........f........................................I.qk..B.....LZ............:.......!:.8...........:.......!:.8.............8.......8.......8...........................................8.j.....8.T.]...8.......8...B...8.H.....8...B...8...>.).8...J...................;........4...4...4.."...............8...8...8...z...y.. x.. ...........$........4......7...7........................;........4...4...4..........8.......8.....#.8.............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.133400552302487
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:1A31B21BD1E8888C9F3B29434D611B41
                                      SHA1:BB6038F4105AB233D7ED7F820DF47EFD9434313E
                                      SHA-256:A6476CA5D0E34014CE457F6ED71AB7D6DB08D2821B7CC20025E2E275187CB282
                                      SHA-512:82F2236AD3847F993957F9139B942DFC12E30B41C04E522EDF7700ACDB52F33B74F7266EA02799FA1DD1336F6699111264B6085D91BBDBAE8EC8203EBCA11514
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......*...v.......................................................................................................................................2...>...........v...R............................I.......I.qk..B.....LZk.......k...|...*YD|1...k...|...*YD|1...k....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..................h..=jbH..bB....N...^...................z.SO..m.>w.a........f........................................I.qk..B.....LZ.................h..=jbH..bB.............h..=jbH..bB.........k.......k.......k...........................................k..j....k..T.]..k.......k....B..k..H....k....B..k....>.)k....J...................;........4...4...4.."..............k...k...k....z...y.. x.. ...........$........4......7...7........................;........4...4...4.........k.......k......#k..............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.109444421228003
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:A9720F5177FCD4E9D560CAEFC1B6E067
                                      SHA1:6E418D9D1C74C96D91BF6F861AF0B924B46BFD7E
                                      SHA-256:DC3177C9FEEF542474B1FA06328D63BA4C42095A46353FE7D9D995FA5B51AD33
                                      SHA-512:C8614ACC5482DC88FE8342840F2CE4BED684AE37E0A240D54E9D151B8DA7737470C38916F696458C70815E3C70AE8C5279728904D95CDB274C48E8880F4BF40E
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......*...v.......................................................................................................................................2...>...........v...R............................I.......I.qk..B.....LZv.y.....v.y.'...9B....>.v.y.'...9B....>.v.y..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............&....U...|.B.?.....N...^.................q..u.H.9iI............f........................................I.qk..B.....LZ............&....U...|.B.?.........&....U...|.B.?..........v.y.....v.y.....v.y.........................................v.yj....v.yT.]..v.y.....v.y..B..v.yH....v.y..B..v.y..>.)v.y..J...................;........4...4...4.."..............v.y.v.y.v.y..z...y.. x.. ...........$........4......7...7........................;........4...4...4.........v.y.....v.y....#v.y............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.107725782138221
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:B5770179CA6069FD7789AC2F23EF059A
                                      SHA1:999A93104FE5A0E816775D763F9D1DB25D27E9EA
                                      SHA-256:E36C34EF2B20CB6A84B021B87987A3A0523640C6960D8321CCD7FEA51DA2F5C9
                                      SHA-512:DEF15221A1D8FAEA1A3CC34BEB86938D85EF4B55FB8072E6C0AFA60D3AEA6A9DF51586347269FF71BD42886DA549B7C237A4CEABB2A0D8CF18F2DF7B9BF0CE36
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......,...v... ...................................................................................................................................2...>...........v...T............................I.......I.qk..B.....LZ..`.......`.x.=.:*..j.'K..`.x.=.:*..j.'K..`..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............6w-.Iu..41.....c....N...^...............yB.....C.[...!'.........f........................................I.qk..B.....LZ............6w-.Iu..41.....c........6w-.Iu..41.....c...........`.......`.......`...........................................`j......`T.]....`.......`..B....`H......`..B....`..>.)..`..J...................;........4...4...4.."................`...`...`..z...y.. x.. ...........$........4......7...7........................;........4...4...4...........`.......`....#..`............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.118238112871495
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:78BD3BA706811E572DB94924A5376D46
                                      SHA1:93A28D8A5B9CBB4EA63F55C13387A1F049837295
                                      SHA-256:63C7C4D7A842894DAF9EB38BE81A5917199E13EF078395016631C622E147C05D
                                      SHA-512:94D9CB6F5F3858D773572B790D29B78A7F299853626D311F2D0E8D3B590BE350E9B4DDAD9C17F55D0EF1A6809DAADD08F4643243711D77F703B82655A64EA83B
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......,...v... ...................................................................................................................................2...>...........v...T...........................D.......D..YV$...(..rXv..I.......I.qk..B.....LZD..YV$...(..rXv.D....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............L..q.S&.%...ev......N...^....................VTI.....Zu........f........................................I.qk..B.....LZ............L..q.S&.%...ev..........L..q.S&.%...ev...........D.......D.......D...........................................D..j....D..T.]..D.......D....B..D..H....D....B..D....>.)D....J...................;........4...4...4.."..............D...D...D....z...y.. x.. ...........$........4......7...7........................;........4...4...4.........D.......D......#D..............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.15850911108072
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:4C01054BBCFA41D7241B488119C4F392
                                      SHA1:67C3081F66BBBF2A0017B76243083AD550F3A856
                                      SHA-256:94F32BF4A931AD4E93BCA046B7936417E9A9B9177CBBD26243A97043C4B892A5
                                      SHA-512:0EF8F647BA85DD0DD65D31DD36A60A51E93D297F5B94A830D2E04FE77DAA043FD0286B89A9DF4FE3363D7A9D2AC715A0F53F7CD8FCC9B070D09429FF8E0D8C09
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>...........v..."...................................................................................................................................2...>...........v...V............................I.......I.qk..B.....LZ.7.......7..4..$.l..j5..7..4..$.l..j5..7...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'...............yU...2hf.}.......N...^................L...YK....w^..........f........................................I.qk..B.....LZ..............yU...2hf.}.............yU...2hf.}.............7.......7.......7...........................................7.j.....7.T.]...7.......7..B...7.H.....7...B...7...>.).7...J...................;........4...4...4.."...............7...7...7...z...y.. x.. ...........$........4......7...7........................;........4...4...4..........7.......7.....#.7.............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.1101395790819195
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:0845DA124F29C383BD0B1BBAFD86341B
                                      SHA1:2B020B398861C13E52FA86ACA3D394FBBB204202
                                      SHA-256:9802016288C94A3D678432EDEB80F4B64617F2ADC9F9A3667BDE7ABAE4D0512A
                                      SHA-512:5D8D57FFD586B002C15A3BB7BE621C358B6C3714647EEE6A01AA5753ABC9BF43AFFB1C72A1207D0D5E39674A483E7BF1753144ADFCE5EAA4B122C6DB4486DF1F
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......*...v.......................................................................................................................................2...>...........v...R............................I.......I.qk..B.....LZ..&.......&Y.....<6d...7..&Y.....<6d...7..&..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............QA(.r..?...ILp9....N...^..................,A....s.........f........................................I.qk..B.....LZ.............QA(.r..?...ILp9.........QA(.r..?...ILp9...........&.......&.......&...........................................&j......&T.]....&.......&..B....&H......&..B....&..>.)..&..J...................;........4...4...4.."................&...&...&..z...y.. x.. ...........$........4......7...7........................;........4...4...4...........&.......&....#..&............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.16058557714119
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:67C3B6A8992DB67433B5D97FF37BC0FE
                                      SHA1:25951EBFDD929286697FBEC522D22C98C2E6BE4D
                                      SHA-256:66B3FEE3E8CA2559E13EE410175B96C0051E117B53860D2A153E9BBF8134F267
                                      SHA-512:2EEFCA133B23296396D3DFA22A550D5CB5B4BE674D9A47C32F76AF1E0BFAB4F3AC7CD378BC5C8E7952FB5677B9C85332FFB917CBF5AAA9F732E07B247B559A11
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......*...v.......................................................................................................................................2...>...........v...R............................I.......I.qk..B.....LZZ@......Z@..{...3w.+.UAiZ@..{...3w.+.UAiZ@...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............6.\.h. !w...j\....N...^................?..O..T...i.........f........................................I.qk..B.....LZ.............6.\.h. !w...j\.........6.\.h. !w...j\.........Z@......Z@......Z@..........................................Z@.j....Z@.T.]..Z@......Z@...B..Z@.H....Z@...B..Z@...>.)Z@...J...................;........4...4...4.."..............Z@..Z@..Z@...z...y.. x.. ...........$........4......7...7........................;........4...4...4.........Z@......Z@.....#Z@.............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.148837479585983
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:57BDE9912A9E85C6DAC8D82849A4A003
                                      SHA1:85B8A064ECEDF60CDCE37790D478E931595CB326
                                      SHA-256:1571A6E8C566329348263AB43E35C30B99E4941C4D1782BEAB6450D3238B84D3
                                      SHA-512:BAB7EF18543EDD110E82281A74D0D112A939526AE7F8B717A7A7C43EE57ECF3F1A989F2241EED29945B0BBE4FBB6868BA343350EB51EEDD39B50F80CEAB90F53
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......*...v.......................................................................................................................................2...>...........v...R............................I.......I.qk..B.....LZ.G......G=.#.7.......G=.#.7.......G..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............e4.`.......u3R.....N...^.................2j..F.....a.d........f........................................I.qk..B.....LZ.............e4.`.......u3R..........e4.`.......u3R...........G......G......G..........................................Gj.....GT.]...G......G..B...GH.....G..B...G..>.).G..J...................;........4...4...4.."...............G..G..G..z...y.. x.. ...........$........4......7...7........................;........4...4...4..........G......G....#.G............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.11439811267283
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:9C600E0C9AF3A0E76D7BAD239764859C
                                      SHA1:420ADBD4466F360099295F22A99DD2508193108A
                                      SHA-256:0C05153E3C5219F0A6D472ED28584BF7E5AA5454C97DE7A7474C38ACEF281B9A
                                      SHA-512:C42D1873D670065DD114D17A5A7EB6E8D3BF33740EE533812503AAB731677502DFEC133D5FE977675DEB04393DA08BC8B1001C88914B38DCC1A8D159C82FDF5C
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......*...v.......................................................................................................................................2...>...........v...R............................I.......I.qk..B.....LZ.l......lPC....w...y_Y.lPC....w...y_Y.l..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............B.Sp..L.,Eg..:......N...^...............H.f..S.@....et.Z........f........................................I.qk..B.....LZ............B.Sp..L.,Eg..:..........B.Sp..L.,Eg..:............l......l......l..........................................lj.....lT.]...l......l..B...lH.....l..B...l..>.).l..J...................;........4...4...4.."...............l..l..l..z...y.. x.. ...........$........4......7...7........................;........4...4...4..........l......l....#.l............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.155981783856092
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:3A7F5E7CFAE8C352223526E29007BE65
                                      SHA1:4AAC0BDA9E01C162B4C6E24DF096C92E8607B318
                                      SHA-256:238E9447D59D7C25B3BABB29E2CD814D35F2371C87EF25E51E936FDEE946F0CA
                                      SHA-512:0E25B5031ABAC40D9508A04D1400AA15534FF2A4271AC7AC8A232538F361311A4D98E2F00676D1072EB419FF1048CB61F4382BF406CA7CFAF54152DC82BEA182
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......,...v... ...................................................................................................................................2...>...........v...T..........................................;.=].....I.......I.qk..B.....LZ.......;.=]........I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'...............l.3....d~!..[....N...^...............<.Y+.3MM....@..E........f........................................I.qk..B.....LZ..............l.3....d~!..[..........l.3....d~!..[........................................................................j.......T.]...............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4......7...7........................;........4...4...4........................#...............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.099387347343143
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:885B11392F0365C944BB9E644EDA3F97
                                      SHA1:DEB0FA742C227F9B8A345A7CD2B484DF022B122E
                                      SHA-256:D45860CC65854AAF85C9D9C02C3C7121D71558AB92DB7B7F861747EF3C697CE4
                                      SHA-512:1659561F83AD50BBF32D295C7CC3BF025F868C7631353DD37182DE02E802EF1769434D5ACADB94217E4250461E676C771AB7AB9D9B60598F3C272D2379487B4A
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......(...v.......................................................................................................................................2...>...........v...P............................I.......I.qk..B.....LZe.......e..{.@..*.P.4.}Se..{.@..*.P.4.}Se....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'...............l.]i....:.......N...^................A.x..XJ......U.........f........................................I.qk..B.....LZ..............l.]i....:.............l.]i....:............e.......e.......e...........................................e..j....e..T.]..e.......e...B..e..H....e....B..e....>.)e....J...................;........4...4...4.."..............e...e...e....z...y.. x.. ...........$........4......7...7........................;........4...4...4.........e.......e......#e..............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):8192
                                      Entropy (8bit):3.5767159341405454
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:B6F52CB5DBB74350C6216D5CA0BA52EB
                                      SHA1:0F49A92691BCB02B4D93D1AEABA34C191BA72643
                                      SHA-256:F169C3466ADFFB4FF88274CA8426399E9E2DEF1A6BC672B066E2D32DD06B75CF
                                      SHA-512:A661BE56DED69628A14A2801DAD05F24AB969A784FD03FD926437EC3D0FB5C1C764D35178037860D063B8D02D2389DCE45D05A81A3F48CA5C20FCCA57F3A1BEC
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:L...L...............................................................................................?...................................................L...L...............,...........................(n......(n.&WC...|.2...K.............x.D.NW...+.._.....7.....|._......NF..Z.........H..J'M../(U..F..H............H.......H..................................................bUx.....bUx.{.9L.......-H.......H..J'M../(U..F..2...........^.......0................]M.. l.bUx.........S...........T./...]MT.r... lT....bUxT)...H.......H...."..H....j.....T)O....... l..........c..,0...e...B4.$...........GP..A..}.....J........................L.08.....U....S..{...;.......S........x.D.NW...+........>...............H..J'M../(U..F.....S....5.x.8..bUx.{.9L..................0...........e....4.............."...P.r.o.j.e.c.t. .O.v.e.r.v.i.e.w.......B.^....F...r.QH.....(...........(..."...P.r.o.j.e.c.t. .O.v.e.r.v.i.e.w...j...P.a.g.e.L.o.c.I.D...L.o.c.V.e.r...P.a.g.e.V.e.r.C.o.m.m.e.n.t...P.a.g.e.O.v.e.
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):20480
                                      Entropy (8bit):4.635915532612272
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:CD85952DF66804B461093F155DDC5696
                                      SHA1:3CDC21C5BE023ED4171EB2C584A1FF5CE7D6D8DE
                                      SHA-256:40E73D878C9E7A5D166167AE6C11E03EB3CD595CE7F702529A1C4B4E7CD9945C
                                      SHA-512:7089252F511A97640AF3AEDEC3A56C9557CE2611C5C4330782EE95EA71521C9BB50349FA4BEFD2880A4AB237284206F3AE2A3A256DD0E868B5AC57BBAD865B47
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:....>...........v........@..( ..`J..........>...t...8...v........H..( ..PI..................................................................................>...........v........I..( ...I...............I.......I.qk..B.....LZ.............W./JYh..N......W./JYh..N......6/.!..7.S8.k.P.6..I.qk..B.....LZ.I............I.......I...................................................I.t.....I................................................................4..'...'................:.+...8..{..H....N...^.................>....G.-9.z.5.............J...............................4....I.qk..B.....LZ...............:.+...8..{..H..............................................................................................6(.6...6(.z...6 .....6$.....6 .....6(.5...6 .....6$...........3...8.....z...y.. x.. ...........$........!..7!..7.....*...o.e.L.o.c.I.D...o.e.L.o.c.C.o.m.m.e.n.t.......0.0.0.3..............Z4...........................................4../4......p...............C.a.l.i.b.r.i.....
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):8192
                                      Entropy (8bit):3.986562648114251
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:3A75B04A22D2272D79C0C9C620A0EE02
                                      SHA1:7DC9E3018BBB9F47142438BEB9CD5610FFD4EA7B
                                      SHA-256:B16CA3FE6635961CAF03475B6BC6C500FA69142551303968602B613D1AE0CFE1
                                      SHA-512:F4593F4E5A5F2041F5CAA5258D697E0346F86FB5A54DF05C3F734526D5572374261C33447B99DD17F939C6E77484D5D68E95BE9FA3854CD9712A3D70C0CDD98C
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>...........v.......................................................................................................................................2...>.......Z...v...&............................I.......I.qk..B.....LZ.l.)....l.WfF...+.Q3.l.WfF...+.Q3.l..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............Wb.. ..#p..EH3A....N...^...............P./.^.G..--..f..................................................I.qk..B.....LZ............Wb.. ..#p..EH3A........Wb.. ..#p..EH3A..........l......l......l..........................................lj.h...lT)....l......l..L...lH.]...l......l..H...l..}.......Z4...........................................4../4......p...............C.a.l.i.b.r.i...................l..l..l..z...y.. x.. ...........$........4...!..7!..7................l:.lF.lG.l..z...y.. x.. ...........$..
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):12288
                                      Entropy (8bit):3.534000681840407
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:50DAD9EA3077E07A0080DE4049521DF0
                                      SHA1:14096E24C6E185938494B86FA88BD4E5CCAD852A
                                      SHA-256:306498894CFFA62E3647D6C33A978C9649222C93447F4F354BE07ED27FBCC10E
                                      SHA-512:9271A3CEA1CB9B463783C62C56A2531E34D4C8537089EB5440BDE33514C80B98372D2131735379F8A774777AC081A091A85FD45357FFAE46AC8937D8EC443F49
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>...........v.......................................................................................................................................2...>.......@...v................................I.......I.qk..B.....LZ.k..9....k...>...,..>._..k...>...,..>._..k...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..................L.#....?.m....N...^................5..).B.)SM?...............................................r....I.qk..B.....LZ.................L.#....?.m.............L.#....?.m..........k.......k.......k...........................................k.j.....k.T.H...k.......k...\...k.H.....k...3...k...O...k...........Z4...........................................4../4......p...............C.a.l.i.b.r.i...................k...k...k...z...y.. x.. ...........$........4...!..7!..7................k.:.k.F.k...z...y.. x.. ...........$......
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):20480
                                      Entropy (8bit):3.2008352255065673
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:202A024F76B17735A9CE6B83464E1ABD
                                      SHA1:E4CE2030FAF4368E64D1EB1C79CF9BB9BB36C622
                                      SHA-256:14F8C2F7C6BFBFAC5CCEF98A6AC27D05C626586771FA25D8E2860A71FFE04048
                                      SHA-512:CE069116D4D6D4BC7C2DE7A4FBA899BCF9F83D1EE286E15F5EE45B768AF4CB2940EAFA5437ADAFA33C3978D1813987848FB400992D5CF21860562D5A20A32CC0
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>...........v.......0 .../.......-.....:..g-.Q.........-.....:..g-.Q.....I.qk..B.....LZ................................2...>.......B...v........-..............v........-..8....................I.......I.qk..B.....LZ.L..T....L...Ld.*<v...B:.L...Ld.*<v...B:.L...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............-.....:..g-.Q....N...^.................L...F...(..x..........................-.....:..g-.Q..........L...F...(..x..............-.....:..g-.Q..................................L.......L.......L...........................................L.j.e...L.T.....L.......L.......L...a...L.......L.......L. .H.......z.......R...................!..7......}.....W.i.n.g.d.i.n.g.s. .3.......................Z4...........................................4../4......p...............C.a.l.i.b.r.i...................L...z... ..$..............
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                      Category:dropped
                                      Size (bytes):15740
                                      Entropy (8bit):6.0674556182683945
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:FFA5EC40DC9A0FD10EB9E6355142D6A6
                                      SHA1:3D3D6A7E086B3C610C08F1F3E3F883604F06F2A4
                                      SHA-256:D74C3973C8D1F7C77274691AFB1AA934940674341D7EEE563BE75E563281BDFD
                                      SHA-512:6FAF2A24D06E6008F3579C7CEC90C2887462BDF83FAD7372FBB74B8DE90340B580E9836F309B68A9794597A598F7DCDA661C9A58DA6D8187C69083B7A17C9CD9
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d.........................................................................................!.1.....AQ..aq.g..8...."r....2.FG..#.E..7.Rb..Cc..D.v.B..3s..$d.%5Uu..&6fW'w........................!....1Aa...d..5e.6.q...Q..."2b.c..r3DE..BRs4U.#C.S.T............?...u.&0...cV.T.I...1..=4....Ce_.g.q.=F.M:>)...k..pm..h..=........S....)Ja8x...b.).=5.q..0......k.M.....1?-.G.b&.5..Ep.8t...'...R)..ta.F$bXO]tW.b.6#.t.XWN..ZW......].....G....x&&f..'L.....7...\...'.8...~`.sa...............................................X........qo...SMk...'.V...i..hb.}&?/.k.:>l.^....>Y...<}...&.jY.Gn.MKejyV......D......gf.0....t.nw..XQ...H.B.....=8.UkR.....Hm..w..]...k...#Z...F../.gjWvf.....w.aZ].2..5..^...VZv..._.7..a.|...:.B...,f...............~....m.;_.....-.e.y.w.[m.].bu.b.f+.E++\.....Y..7
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):12288
                                      Entropy (8bit):3.7650668687093813
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:7D7D75B4A392116570F3A9CED3157F53
                                      SHA1:13ADF725E6FCFBFBE66C1AAD02B3D1D9A1EE8C96
                                      SHA-256:66FC1979AB58463B2C14C485673079FE28D5E5FF7EBE3DC70675FA2B125A32FB
                                      SHA-512:0EF4A1CD3DFD9EEB37A4C7B07E863CB77D7CF1126671E03605196A5C160D64E1D00E882D7CC0A10241847C1DA6E21AE1F3EFBBF894F6CE09939272ACCD0F4F01
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>...x.......v........ ..`!..2...>...........v.......@................................................................................................................................................I.......I.qk..B.....LZ%*..9...%*...4O.=J.2..$]%*...4O.=J.2..$]%*...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............,.+1....%%g.Gs......N...^...............lj....wC.V...8.U.................................................I.qk..B.....LZ............,.+1....%%g.Gs...................................%*......%*......%*..........................................%*.j....%*.T.Q..%*......%*..n..%*.H....%*...9..%*...V..%*...........Z4...........................................4../4......p...............C.a.l.i.b.r.i..................%*..%*..%*...z...y.. x.. ...........$........4...!..7!..7..............'%*.%%*.%*...z...,4. ...........$>........4
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):12288
                                      Entropy (8bit):4.64885268536462
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:616F3B5B111248E7C7619F656DFC9F94
                                      SHA1:03ECCDEAF86E10B3CE5C3763519784FFAE15306F
                                      SHA-256:D3D8600C700356278FEB549D74732AD3CBE4B74AB4593F16DE7554432B117CA5
                                      SHA-512:95922E9BD631538DD6CDEA27A0CF9D0E3C0595921973A9F8A16BB54E58193BF915FC86A611B3D68B9E04479082E10A03032B9F08531EA321332E98F3E0EBE238
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:....>.......>...v.......0 ..h+......>...........v...Z...@...X*...........................................................................................................................................I.......I.qk..B.....LZ,.......,..0E.3.(.......,..0E.3.(.......,....I.qk..B.....LZ.I........9C.R..:..h..............I.......I...................................................I.t.....I................................................................4..'...'.............7.`D.A3A...g.............................1.|.'N.....&....N...^........................................I.qk..B.....LZ..............1.|.'N.....&.................................,.......,.......,................................................|.....(.......(.z..,..j.N..,..T)...,.......,....b..,.. .......',..8,....z...,4. ...."......$>........4.."..7......A.g.e.n.d.a.:.........................Z4...........................................4../4......p...............C.a.l.i.b.r.i..................,...,...,....z...y.. x.. ..
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):12288
                                      Entropy (8bit):4.570031545241318
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:496BC620560BEB4C45E6C2ACE3E94DFD
                                      SHA1:D7E447B6E55206DECAF4CE9A3189BFD784F75ACD
                                      SHA-256:3A934F7EEE47A4AC22BA2105608AB6F0DA74012AEBA7B6D02C4C318A747C72E0
                                      SHA-512:1B11012CCEE037D6E3FBAE70BD4587C200E85E9B329839B01073B597752DBC12A6C93BF8696B8A4AFB09E050DDAB15E349A743C8A38412A091C258A89D1C4B9F
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......,...v....... .. +..2...>.......|...v...H...@....*..............................................................................................................................................G......`+.....n.K`..I.......I.qk..B.....LZ...`+.....n.K`.....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..................z..r...0......N...^.................2.m$$F................V...x....................................I.qk..B.....LZ.................z..r...0..................................................................................................j.A.....T.................r............. .7............. .........Z4...........................................4../4......p...............C.a.l.i.b.r.i...............................z...y.. x.. ...........$........4...!..7!..7..................;.........z...y.. x.. ...........$......
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                      Category:dropped
                                      Size (bytes):14177
                                      Entropy (8bit):5.705782002886174
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:7CDCE7EEBF795998DA6CAC11D363291C
                                      SHA1:183B4CC25B50A80D3EC7CCE4BF445BCFBAA6F224
                                      SHA-256:DE35AF949D4F83E97EE22F817AFE2531CC4B59FF9EE6026DCA7ECEBC5CF2737F
                                      SHA-512:560FB15A9C12758D11BB40B742A6EAD755F15AD10D6C5DEBA67F7BC8A2AE67C860831914CBCBCDED9E6B2D1D5F26A636B9BCEF178151F70B4D027316F94F27E1
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d........................................................................................!.1..A....Qa".q..2.....&...B%6.'..R#3.$E.r457bS.DUFV.Wg(.......................1...3.Q..2Rr....s.4.!Aq.S.aC5B$%............?...n.Liq.}.{#....3/gg.1.M +..~3...q..+=..:.g.i1;P)7.....q..n.s"p...wx........v.t.f;..L/..~....y.r[.r.....n.n3..6i..g..}../........3..x.L.i?We..l.......~..<.;..6..o.....N.t.o6.l..~.......<...m.V...Q.7k.u./wq.t..;.I...}..{...>.L..3m..a....yd......6~.f..~Y..}+..<.[w..'-..?.v.7...v.u..4.......1];..u.MO.......s..p..ms.'.O-o...O......m.k.e....)t....i>..E|....,iOyD|.{......g.n...cu....=..........h.\.Q:?g/?.I.3._...t...d.n.0.%y....S.Q....S.&K.w..&wY<....%.g.v.....$y..#,i;.=...t...I6..yO..o.d..w\k...~......)..rK.......].u....N....e.s..kU.u..'}
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):49152
                                      Entropy (8bit):4.641052299178808
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:55B9E5564395CC54EE3218B9EEE02A05
                                      SHA1:0E217488F3B5E3C08A09BF1B5B4B2198D69B479A
                                      SHA-256:C64749FF6858865F485A3AC7738108D5BA2CCD1525C8E52773B8D44859A610AF
                                      SHA-512:00A506F819438295CCE51FF117285AFC0475CDF4C9C598272688AE46E4EEDEAF668A52C646CCDE9EBD5D8B6287BD9E27DA092B148A5EEE41B5621EDDF79F5D60
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:........2&.......%..J&..(...@ ...@..@`..H................%.......%..f&......@ ...@..@`...........................................................................%.......%.........@ ...@..@`..h...................T...9.....j.=.......=.....H...3r[s...%k$.....(x.1....^.TW."N...|..\..^.T.....u...5..BK................[[......[[..................................................=..T.....A.T./..n&.T.....@.T"...n..T.L..[[...-..[[.X....[[...............0...........e....4........................u.^s.Q.@.).~b.......(...@kO.....(..."...P.l.a.i.n. .a.n.d. .S.i.m.p.l.e...j...P.a.g.e.L.o.c.I.D...L.o.c.V.e.r...P.a.g.e.V.e.r.C.o.m.m.e.n.t...P.a.g.e.O.v.e.r.i.d.e...P.a.g.e.N.a.m.e...2...0.0.0.5.2...1.....0...U.n.t.i.t.l.e.d. .p.a.g.e...........#.......#..c.G.0.C....$.......$.(.j..\....t.2.......p...............................=....A..[[....$..@*..........oh......^.T..c..,0...e...B4.$........{p.....G...^...?@kO...................,=U.....,=U...f.._u..6....X.......X.e.q.?...|.l...a.........].......s.
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.390945414322767
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:EFB06C398485FF0C01F32EBE2F444BF5
                                      SHA1:2C91D7FB5942AE53A840807ADBC231B9B0C8E626
                                      SHA-256:379EC04865057853B5F72AFD4491BB70F0C8285885ECD712FB9DC101958C8323
                                      SHA-512:D873B89AB396203AE7D6CB4665EB0028E299D9995AD1155DCB32BFAF1C2FC92C99CE619C9A598BDB50CF6C00D84F2639C246CEFC47216163CF354915D386A47B
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......R...v...F...................................................................................................................................2...>...........v...z............................I.......I.qk..B.....LZG9......G9.J.....H.7..}.G9.J.....H.7..}.G9...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............M.L.....O....1o....N...^...............wfQc.c-D.Y".K.i+........f........................................I.qk..B.....LZ............M.L.....O....1o........M.L.....O....1o.........G9......G9......G9..........................................G9.j....G9.T.]..G9......G9...B..G9.H....G9...B..G9...>.)G9...J...................;........4...4...4.."..............G9..G9..G9...z...y.. x.. ...........$........4...(..7(..7........................;........4...4...4.........G9......G9.....#G9.............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 814x105, components 3
                                      Category:dropped
                                      Size (bytes):12654
                                      Entropy (8bit):7.745439197485533
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:4BCCCDBB4273ECEBE216C84930A8D0B2
                                      SHA1:FFBF617787E27BC94D9BAF89F2FE34A2BD42794B
                                      SHA-256:474F9A8C25D5E21192315397EA995B1E11E2C1608157C6E0277688091BFD136A
                                      SHA-512:DAD73A8C0E293B88685C0C71EF15E0DC95EE39B7FC9F849DE5D634173FD9FA0AF0AA96742D9E94BE03556AA4A817D5001C95A6736EAD5D5DF03661876785EB74
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....H.H.....C....................................................................C.......................................................................i..............................................E.....................U....V...f..ASTc.......de.1Qq...!Rb....Ca."r.................................B....................b....Ra.....!Qc.....AS.1U.."C...2Bq...$#3%&.............?......3.....~......:..g..s"......:..g..s"..ic..Vk.f.. :..f..h.....Vk.f.. :..f..h.....Vk.f.. :..f..h.....Vk.f.. :..f..h.....Vk.f.. ..0...Q_..X..V5E~..c..X...@u...cTW...0...Q_..;.m.....@w...Q.+....*.4W...lUFh....v..._..wn...dW....y._..v..E~...*...@wn...dW....y._...v..U..@wn...d..{`;.|U.2g...*.3...:.0?ViN.z.@w...4.M.:m..`~..i7...q...I....J.`l...W..n..PQTiB...6....+..sj.*."...6....+..WA...x..A........(.N6`..AD.q.....'S...t.Q:.l.......f.]..N..0.. .u8..A........_W..Y...}.C...~....&.E~....&.E~....&.E~....&.E~....&.E~....&.E~....&.E~....&.E~....&.E~....&.E~....&.E~.v..?U..^.r..}..Bep
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.372656603132851
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:939ADF8E21983556FD35E98CFF7B8CFF
                                      SHA1:DB428F0E20575AAF39DA8E891E32C5CAFE54F872
                                      SHA-256:BDB6C09F30230197969D56EB75318A09E63F90AAADB394C42B81875F8C00C8AF
                                      SHA-512:047AF26C015904AD570E7FE364CF0837951FA3CE5C5A9777AEEC349B9451C5D5C5FF2F15713060B53B83F67CA584A998E856DB13EA171088868FFA3777EC9D0A
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......R...v...F...................................................................................................................................2...>...........v...z............................I.......I.qk..B.....LZ7&......7&..8$N..!..3..7&..8$N..!..3..7&...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............r..w=.|.9x...B......N...^..............."..X.^.D...`.f..........f........................................I.qk..B.....LZ............r..w=.|.9x...B..........r..w=.|.9x...B...........7&......7&......7&..........................................7&.j....7&.T.]..7&......7&..B..7&.H....7&...B..7&...>.)7&...J...................;........4...4...4.."..............7&..7&..7&...z...y.. x.. ...........$........4...(..7(..7........................;........4...4...4.........7&......7&.....#7&.............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.3613472708779835
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:6F7B0AC6BB7C7D9B2E6B89C627C0F6CE
                                      SHA1:87BD2F691080F3BAB49BDADD27EF4EC50EC71F29
                                      SHA-256:33CDAD3F81F9EF8E63254CD4C9E15E6A5D92F90242933BF05D0782963FE8CCD9
                                      SHA-512:872D61287E8495D85E7182132E92EB61AD7C6CED05B1AAAD590BC0165322176EC029500F9563AD725CEC8E85CDAE9A35F9DA1CC2A0DBFEDD73A37976D744412A
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......R...v...F...................................................................................................................................2...>...........v...z............................I.......I.qk..B.....LZ..P.......P.)...4=..?.s..P.)...4=..?.s..P..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............(..{q./.>a.........N...^.....................O..g..\.#........f........................................I.qk..B.....LZ............(..{q./.>a.............(..{q./.>a................P.......P.......P...........................................Pj......PT.]....P.......P..B....PH......P..B....P..>.)..P..J...................;........4...4...4.."................P...P...P..z...y.. x.. ...........$........4...(..7(..7........................;........4...4...4...........P.......P....#..P............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.467456013828808
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:30952E54EB85B949BEA313343C953959
                                      SHA1:A69B1FE2C93B0432E9DAE5AF3EFB2157C1BC2C8F
                                      SHA-256:6D0074218FB33F7245FCCEF3243C6013383EDFB070BD702FF4822C88D5F9612E
                                      SHA-512:B1153B992CC35B6CB065B7F013E40CDC7FD52AF77700D16F96426E02CE269A866B792BB5FBBF2B0B0E60E394485F1E4AD22F7E5E0594CEC34D6294F07547D1FA
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......p...v...d.....................................................?....?........................................................................2...>...L.......v................................I.......I.qk..B.....LZ.G.......G.y9.%..n.#.....G.y9.%..n.#.....G...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.................#Z..7.l........N...^................p.w.7L@..V..1.^........Z................................... ....I.qk..B.....LZ................#Z..7.l................#Z..7.l..............G.......G.......G...........................................G.j.....G.T%c...G.......G...G...G...H...G...>...G.......G. .3...................;........4...4...4.."...............G...G...G...z...y.. x.. ...........$........4...(..7(..7........................;........4...4...4..........G.......G.....#.G.............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):8192
                                      Entropy (8bit):2.7350889791718567
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:E5DC8EBE157353CB7197D082FD77916F
                                      SHA1:EBDEAFAE4DB0365C8C46E402B31B87AB0D33F2DB
                                      SHA-256:B3BAC398BBC39DAED1E0C98C94AD433EDC388D7104066FDE9FFF7A3BFCE3D0EF
                                      SHA-512:1DAB532B42D8EC12ACCB3F0A3977F93ED5D9DF2B3E47C6B6D622EFBE2EF3EB8ABE49AC5F5B5BD98AC5FB2C469512081FC049E7852A926B33E9E1FE9997C4EF40
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>...........v.......................................................................................................................................2...>...........v................................I.......I.qk..B.....LZ.~.......~...>..7...J=..~...>..7...J=..~...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'...............K..My.%.g.*......N...^...............~.\.f.F.rZ..W1*............................................^....I.qk..B.....LZ..............K..My.%.g.*............K..My.%.g.*............~.......~.......~...........................................~.j.....~.T.l...~.......~..Q...~...Q...~...>...~.......~. .3...................;........4...4...4.."...............~...~...~...z...y.. x.. ...........$........4...(..7(..7........................;........4...4...4..........~.......~.....#.~.............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 95x498, components 3
                                      Category:dropped
                                      Size (bytes):3009
                                      Entropy (8bit):7.493528353751471
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:D9BD80D40B458EDB2A318F639561579A
                                      SHA1:83BA01519F3C7C1525C2EA4C2D9B40F28B2F2E5E
                                      SHA-256:509A6945FACFB3DDC7BE6EE8B82797AD0C72DB5755486EE878125A959CC09B59
                                      SHA-512:C368499667028180A922DD015980C29865AEF4A890C83E87AE29F6A27DC323DD729E6FB1C34A2168A148E6A7A972F65A5FC8ACE6981AF1D4E7057D99681CB366
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....H.H.....C....................................... ! ..''**''555556666666666...C......................&.....&,$ $,(+&&&+(//,,//666666666666666........_.........................................:.......................r.!12BQ...3Aaq.."CRb.....#4$c.S.....................................................1A............?..p..-.....u0$.......l......)..o.FTd..DG....... .t*e..jO..Z.U......r..j.O.,..VD./.....V5D.&......A..Zi....E.N....*..........#..M<|.2.Y.../QO.x.cTM4......+.F;V.x.de*....]e..O.x.c\Y........r..j.O.,..T...hw..k.^.[B..J.sEl.w.x.m.5%zzt0..T.......b..<\.3Q..W</..!.xh6..Z..\.+M.o.Y..1............#.........|.a.l.KR>..U......e....@...\.1Z...Y...[....F.6.t.#..Z,.x.Q..[`.X......#........W</..TM..-H...V....Tf..........r..j.x.df.f.....#..l.KR>..U......e....@...\.1Z...Y..Y.us....D.)....Uh....FkYm.m`P...W .V.g..FjVj.\..1Q6.t.#..Z,.x.Q..[`.X......#........W</..TM..-H...V....Tf..........r..j.x.df.f.....#..l.KR>..U......e....@...\.1Z...Y..Y.us....D.)....
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.3153534507963665
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:0DE3A30BDAB61FF8B9A3DE5D79E14880
                                      SHA1:D55F088C69947905F2B87032D5AF588B910BBEEE
                                      SHA-256:BC41CD3F79619E2E3B4020A46182A3B5F04B4BDFD0057143A5E2C0814336FAF5
                                      SHA-512:383BB8DEB9E397396A0EC73C79C65B3D390220266DD201909B0C383077EC7107E96B4518D0F83B52FFE38B116280A42FF3309B73E255F21B9B5669226056F498
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......P...v...D...................................................?....?..........................................................................2...>...,.......v...x............................I.......I.qk..B.....LZd.......d....... ...7.Fd....... ...7.Fd....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............v....OE....;..yX....N...^..................E..tK..S$r\..........f........................................I.qk..B.....LZ............v....OE....;..yX........v....OE....;..yX.........d.......d.......d...........................................d..j....d..T.]..d.......d....B..d..H....d....B..d....>.)d....J...................;........4...4...4.."..............d...d...d....z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4.........d.......d......#d..............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:PNG image data, 813 x 99, 8-bit/color RGBA, non-interlaced
                                      Category:dropped
                                      Size (bytes):99293
                                      Entropy (8bit):7.9690121496708555
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:EA45266A770EEA27A24A5BB3BE688B14
                                      SHA1:9F0B23B3C8EBA4FC3C521E875EF876FBE018F3C8
                                      SHA-256:EDAD0F03E6FF99FEF9EF8E8B834CE74F26CD23C5F8C067F5CEE66F304181E64D
                                      SHA-512:D4EE36BDA897BBD643A699A0332DD00DE9CDCC6F46D861789BAD259A4BF87868AE3B4CFAAB6DFAF29941C7055B77A95D76BAA86A4A0DB2BF3BAF7E3317F03EB9
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:.PNG........IHDR...-...c............sBIT....|.d.....pHYs...........~.....tEXtSoftware.Macromedia Fireworks 8.h.x....tEXtCreation Time.05/15/06.8.p....prVWx..[Oh\E...y3kv........`.%m.R..6.1.4).o..Ki...D.......P!.].=..K...C[....f.}o7VPJIg...{3.|....d.....i..=.4.u0...n y......@j..Q..f)..mQ...4-SJ..9.d.?..5\-....:b.W..i...c.5..{..pj#.....B1C/.I.......].Su.k?.2..:.9Q...5.U...UZ...e..U.c],..2.}...1..)W./..Epr.Zt.....K.=..{......e..."...v..B.4.#....A.V1.".V}t..[..2f..Y..V9.".6.......(..gbm.P.....Y%2.c.z.:Q.2.<tYF.....u.@..KJ.;u.q:.].....$.....V....Hqk..DW.l.e.j.Z.YP?:'R..*.<........6...m@..r..j2..HK"|..L.Nc..D..y.9..B4$.......`.3.m1LE....7(OU\+./.O...%6T..w......h....).I.&n...*......#..W.41...5.#.`..I...<.?.|..*+Q.....#i........$,..n...`.s....[..E. T.w..j.,&-.r..;a....#.>(.P......f...MU\3*..;B....)..5....z..(....-...a.....}y.l..E...z>......&..g.$.....*T...N....E:./.>..#...^..E.0..%......(..@..W.X.NDM.<~.]A.>..fW.O.y.'...Z...h..).F..
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.357125163361352
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:6AE841F804F15DF8DA1C7A3E4DADF50A
                                      SHA1:60995B5C65A5194DEFC22A592461BD335E2819A6
                                      SHA-256:B1A90C511354A205E7FAD3B0BCEFD6E310121243337BCD5AB76F5C23D4CB7A26
                                      SHA-512:A7BA71505DA1BE2F798DD699E5560E8569FBB83119B876F6DFE7F9A56F428F4B827D3F6A835622193297643BF6E8AC26EA6F5E0A1FCE87118F07EDD3096A2362
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......P...v...D...................................................?....?..........................................................................2...>...,.......v...x............................I.......I.qk..B.....LZ.E*......E*.z>S.9Te?m....E*.z>S.9Te?m....E*..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............2c......-.?.l..R....N...^...............NZ...K.q..KBt.........f........................................I.qk..B.....LZ............2c......-.?.l..R........2c......-.?.l..R..........E*......E*......E*..........................................E*j.....E*T.]...E*......E*..B...E*H.....E*..B...E*..>.).E*..J...................;........4...4...4.."...............E*..E*..E*..z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4..........E*......E*....#.E*............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 780x107, components 3
                                      Category:dropped
                                      Size (bytes):2898
                                      Entropy (8bit):7.551512280854713
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:7C7D9922101488124D2E4666709198AC
                                      SHA1:00CC44A1B84D4D94A0ACE8834491EB5F65D04619
                                      SHA-256:20016E5FA1A32DCE5AF4E92872597E36432185A7BB2E61C91F362BD68484529B
                                      SHA-512:882944B2CF040485899128E03B7499C540D481E45FE8017DBF4FE0330157B2D8ABB7334DDB31C112BA0EFE3722A554883917C54155A7F60044D2D7F3D848260F
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.............C................................... $.' ",#..(7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222222222222222222222222......k....".......................................2...........................c.....TUb...Sa...QRqr..............................!.....................Q...R..!..............?...$.)m.1...%%bV.J..H....-.%a[...I"WJ..:.X.:TT.$.......N.-NR.E..-NR.E...9..E....$.k.....B.I,I)..J...kr..+)..I,Yj..YbI..+,J..e..Z..V.e.$V..TV.X..V.YQZ.EQ..U%PY[.[.R.EP............................| F.. ...j*...!m.!j.I%.j.$...YeEYYEEUE..eY[.hEEUeEil.....%..el...V..TUYA.U.UTTUT.Z..UQQUQE...V.,...UlE.U[.lEP.P.@......................................R1...AR1m.....#..$:.T.p..IJ.t.....A..AH.,5..]F!a.XJFaa. ..a.!*.aa. X.e.......bB.b..,HX[,!..,,.c0.,..U..X..(,,...B(.,..4..B.`..".a..-......"...........................>D..IKEb...t.....)u.....)K.%+L\.J]i)*b.JR.IIL\i)u....T............T.....qs.it.iJ...])ZJb.....X....U.A...V1..B.R1....X...,.c...,%X...,%#0...,H
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.307298852813859
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:6F6249E4688AAFB73C2AB51BCC305E20
                                      SHA1:FEA5118747874BA9339DB187256364841041D568
                                      SHA-256:4C321037234DAA12338C2020DD55C8418B9B8F6E2E6C57B60541E0AB4D36C256
                                      SHA-512:315466AE725D917B8DFAA7E5C42D6107480A9DDFBFE5AB03B690A3989A7F48FB47C7D023FBDED01B383D811E8A36D334E581B1C1F707CD79A87A874AC63A8F85
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......T...v...H...................................................................................................................................2...>...0.......v...|............................I.......I.qk..B.....LZ..`.......`-A.'..S.?..s..`-A.'..S.?..s..`..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............J.e.....#..OA$.....N...^...............>.8.`M.@.W.F..3.........f........................................I.qk..B.....LZ............J.e.....#..OA$.........J.e.....#..OA$............`.......`.......`...........................................`j......`T.]....`.......`..B....`H......`..B....`..>.)..`..J...................;........4...4...4.."................`...`...`..z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4...........`.......`....#..`............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.338953773378363
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:CB73C648516EFA8E8CE2A1BE0D367186
                                      SHA1:555BE873EB8D85123D03D6344C521A8BF6F328D2
                                      SHA-256:3DD5AF973A2CD7CD1A3A4F00F680CCA72473E6C5ACCCE03AB9D400AC7D4956F1
                                      SHA-512:E368DA12275733731A4CC2AD87357B5EFD58EEEDEEB79641D8F9ED0D41F1115F561438052281332666060B2734AD05CAF192576D2F28B54625CBD1277AA6D8EE
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......R...v...F...................................................................................................................................2...>...........v...z............................I.......I.qk..B.....LZQ.3.....Q.3j....>T.....Q.3j....>T.....Q.3..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............f+...7..jF........N...^...................*.$E.../#..}........f........................................I.qk..B.....LZ.............f+...7..jF.............f+...7..jF.............Q.3.....Q.3.....Q.3.........................................Q.3j....Q.3T.]..Q.3.....Q.3..B..Q.3H....Q.3..B..Q.3..>.)Q.3..J...................;........4...4...4.."..............Q.3.Q.3.Q.3..z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4.........Q.3.....Q.3....#Q.3............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 276x139, components 3
                                      Category:dropped
                                      Size (bytes):4819
                                      Entropy (8bit):7.874649683222419
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:5D6C1F361BC04403555BE945E28E53FC
                                      SHA1:00C254F7B3BC0289590C2BBDBB39C8EC2E2B2821
                                      SHA-256:131D637CDC5D0B094FB9FAD17F4D2A1ACE0D03613588155AACAA2D1CB4E16DA9
                                      SHA-512:34D2C0929FCC3CC10D0A2121BD55BFA9A07062C2A7B8F101071164C946895DBCB2777641E79DE4193D57A3F0778DD4F1351FAF333B7E4B4DBE31A32DD69C51F9
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.............C................................... $.' ",#..(7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222222222222222222222222...........".......................................<........................!1..AQaq"...2B...#Rb..r..$3CS.cs..................................................!1A............?.............u....p.p($.Y...9,j...V.*..S86yh.G.#m.5..9...6Y.."C.R:.[..-.7U3c:..].;.....f.?%..<T...&F.Lh.N...m]..x.D.g<B.....k..S........>j.K....#U..Z....<e.:..8....o..xq.[..4v..U..y...k... k....A#..A...pn.jJ.I.7:..{.b..ns.t,...8.Td.I....m.I.5Z.).-.. ]..X.Do%.....?..4jV.`llt.E...5...u.|..\F.=.F.r<...5dV....xc.%..&...4,...f...3..H.<......eQ...P.J....7...lLc..?..-.fR..7.#.6.......}:.]'.ny..........e;u.Y..$0...i..-....f..9(....}..T,.Inb...+=Cca7....WULA1@.s...4uY5.N.f.c..].ks.....3v..~..k..m)...f gNE`S......#.....Z..6.uc.m...#k.s.f*.l.$6..?..xC.Cm.`...N2..&H...._.&.E...[....f.Z./...!.a{K..#.V.5..v.B....1...9..B.&....%s.
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.363176937552885
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:3B34AF3F40BA7F592DD4E4005E47521A
                                      SHA1:1501177F034E8FABDB8A644FDEA12066D0214D2F
                                      SHA-256:CC40A8412D705B6D31E7F91D50CD44D6DFD401131019049BB7694AC5C912CC2C
                                      SHA-512:9479387995E8F6C82A85B4BC8418F7F512A0F6246F1D84AD5DF116F9128D45A0BBB4FC9B1CB68DA838A50F506CB960AEB7D42748ECCB6DCC4494024F1965C878
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......V...v...J...................................................................................................................................2...>...2.......v...~............................I.......I.qk..B.....LZ...........o.I..<D..:.A4...o.I..<D..:.A4.....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............o..w...&$..........N...^.................JSF.I..y.:.@e........f........................................I.qk..B.....LZ............o..w...&$..............o..w...&$..............................................................................j.......T.]...............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4........................#...............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.36122380616081
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:40F264E18183DD1DC29810D13214188E
                                      SHA1:6374701A1CBC03931E963E1262960DD724E05CFF
                                      SHA-256:4457D50A6F951CD687DD875188F19FAA59CAD474BFB309505DEB90D1603E482C
                                      SHA-512:D56C1FB6EBDF1FF93247ABB657F2583DDA1D7629A908B153028C38A057184892A3E1BE93BE4A8C00B0645428002A626EFDEE84700DAA31A8456EA12F8FE7C51F
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......T...v...H...................................................................................................................................2...>...0.......v...|............................I.......I.qk..B.....LZ..c.......cv(h..5O=..U..cv(h..5O=..U..c..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'...............-2 w...Sx..,....N...^...............r?....|J.U.A..6........f........................................I.qk..B.....LZ..............-2 w...Sx..,..........-2 w...Sx..,...........c.......c.......c...........................................cj......cT.]....c.......c..B....cH......c..B....c..>.)..c..J...................;........4...4...4.."................c...c...c..z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4...........c.......c....#..c............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 262x277, components 3
                                      Category:dropped
                                      Size (bytes):3555
                                      Entropy (8bit):7.686253071499049
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:8A5444524F467A45A5A10245F89C855A
                                      SHA1:ACE68D567B02B68275E0345C86DB1139C0EC1386
                                      SHA-256:7D2B01F17354D9237A6AB99D5B9AFDF0E1CC43687125848B0C2DEDFB44CE3843
                                      SHA-512:8151B447B60D110C32EC1EF286B941FFC09B99140F41BBACF5A1650A385FF4D13C0DDB2878E9A470FC7CFCC95A1AB6E44F6DE72562B0FFE093DC8A3C3C7FCC14
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.............C................................... $.' ",#..(7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222222222222222222222222...........".......................................2........................!1AQ.a."2q.B..#R...3C................................ .......................!1.AQBq............?........)&vD.)3Hn*..X+....r...tmL.k..(.E...R. .Z..&...,fJ...!...6..S\t3.=...g&..Bqe.)_U.....1......-..fl.................J...u.i.mU..K..v.w.0O..E.h..D~K.(..9.,8..E.}.............i.\.....t."v..q..C............<..|3.........................*Q..../c.....f.}8....D..|k..Z......0..~..c..e..m(...|.c..'.5.5............==bx.5x.8...T;....=.--.pc...I;.V.m..,(....}...NH.ho....Q..U.E$.~...w.t>.S\....'f.{.+.g._.t....;>.....P...........-..G.h..2...J.% !.E97Ir.D..N....j...oE._...._...".?.......#".S.........Q.Tc.I..*I..k.......=$.........sk1Jp.\K.....F.3.Q..q..J....N..[l.&....OR4bB|..2ul....J...B.$&H..9#j.f.n./........?R~....B.I.@..........m
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.347593491943084
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:2520CF11B1287D1D6FAD5C098CF3E141
                                      SHA1:F6819675D7386D2C93A44EE9B79717DECEA07120
                                      SHA-256:86A9F571729C1E25FB524EE69BCAA408B8CC3F5A0C8CA6C96F80E21FBE6C8B8E
                                      SHA-512:F9B05AAA3EE39E3094AD80E9D1BF6CA21ACFF5A361669C4E8724EF1EBBF4A82C02F46BF4C12187737BE1835776D3B6A3C1E8C7AB65784FB3598F4756FBDB7B54
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......R...v...F...................................................................................................................................2...>...........v...z............................I.......I.qk..B.....LZ..Z.......Z..L......x...Z..L......x...Z..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............a&...g}.!S.....B....N...^.................!n...J.4.N&|..........f........................................I.qk..B.....LZ............a&...g}.!S.....B........a&...g}.!S.....B...........Z.......Z.......Z...........................................Zj......ZT.]....Z.......Z..B....ZH......Z..B....Z..>.)..Z..J...................;........4...4...4.."................Z...Z...Z..z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4...........Z.......Z....#..Z............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 70x626, components 3
                                      Category:dropped
                                      Size (bytes):3428
                                      Entropy (8bit):7.766473352510893
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:EE9E2DF458733B61333E8A82F7A2613D
                                      SHA1:A86704C969F51B86D6A05ED51C6C60214ED9FA89
                                      SHA-256:BE4F0E6C89FCE91B9EBD2623567F7DFC259E0E3C77C9158742B8F64B724DF673
                                      SHA-512:BFB5D6DD6B66EE21E946E90D1E482384CD10244308562DDA814189602681DADDE5752B80519E5B8515F115A71BD6BB4317A59BE65B8B5E3474AED119F8303569
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.............C................................... $.' ",#..(7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222222222222222222222222......r.F.."........................................H............................!Qaq.."12.....#3ARbr...$B...cd...&CSu.....................................+.......................12..aAQ.!#q.."................?...#...3.Za......rV.5&...../"..i.t...j..W........d.FL.V.2K....]t.f.d.NK..:.....f...... ......2.[...#..D...ZK....p.z.E.N..T..L.-....1....2.\.6FIr2..zS\U#..........fB\t..5J..~q...D....A.......!....MY..../.HY..../e.M.Y.n.~..,....'..Pc...l...d2..m.f.it$..qx-z*...._..].cOO....n..&.....FIA.....2J2..d:<qc..6.I.G.N....f.K..Dx.-.......`....2.FZ."K7.r}..<.P.Z.da.Y.....8..s....G.....b.e..g .S.......FL.Z,&..q.MG.J+..x\..m...qN=.....)..`...&Y...S....u6{.z.g.....@......FL.ZL&.Iv.w..8....U..v...*.q.B.v_./A..#.#.g.j........*J;...u...W.Ao...%....#$.....M..^\{W.SO...s,.N.....c).,.B.Gv...."k..z."..S]H.
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.3421724628674205
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:0F93C140484B8B0132D219E4F2DC8F3D
                                      SHA1:3D23EF21720B986107FFD20B9C8942125F48190D
                                      SHA-256:B703710270684B7729C1616E6627A7ED747826D2FC38A4EB6D3504E8B74A81CD
                                      SHA-512:14116E5AE17929F17EA23AF6BCE618FFD83A703DFFC93B21403D5103D8A67517B3D3EDCDAE7E6DDE3F60E1764B14D39C3AC07A9F0E187CFEB3F3E63E4EC4852A
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......R...v...F...................................................................................................................................2...>...........v...z............................I.......I.qk..B.....LZU|......U|..al..#g.~.V..U|..al..#g.~.V..U|...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............h..~..#.....\gf.....N...^...............s.ccs..J...............f........................................I.qk..B.....LZ............h..~..#.....\gf.........h..~..#.....\gf..........U|......U|......U|..........................................U|.j....U|.T.]..U|......U|...B..U|.H....U|...B..U|...>.)U|...J...................;........4...4...4.."..............U|..U|..U|...z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4.........U|......U|.....#U|.............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:PNG image data, 177 x 123, 8-bit/color RGBA, non-interlaced
                                      Category:dropped
                                      Size (bytes):65589
                                      Entropy (8bit):7.960181939300061
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:8B48DA9F89264D14B83FF9969F869577
                                      SHA1:E1BD58E2D80FEEF56DC514F3F0B3AB9669F22F95
                                      SHA-256:62AD3C277E54F03F1ADB44062407346F789E63859B7AFABFD64BE6AF5E9F66EC
                                      SHA-512:03B783EC968DF3F648504D068D64DD1AE110E28110FE5B3401C9D04F44897DBE0CBB5680D42CA4C665FA94A6CED4B559106EB3C06C9BF2C5B14951ECBFFAC8AE
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:.PNG........IHDR.......{.....;Za.....sBIT....|.d.....pHYs...........~.....tEXtSoftware.Macromedia Fireworks 8.h.x....tEXtCreation Time.05/15/06.8.p....prVWx..Y=.+I....t.y...,^vv....;. "|. .i7.....$.2g..']pH@p..]b....H.H.......d'@ B...U.xm..3{3k?..5n.._}U...3......~..>...g.....f..t...t:...p>..Si..d:..k:.Lf..t6.K.i....d<...x.8\.8.+lc...)i.$.r.....x.t.BG.R.cm.c...p.:&.6.4..K.......^...~b].0....oBYv..u.'.=.K.Q.g)6.....4.!.M......4.=....G.%.Sr........nxC.F..t.U........1...J.t..eQ....".... |...81.$D.!.>...........$...^.vY..EY8tb..'.P.g#O....S*..0'.V....x.W..........k.......s.C.S...J%.iVb..].........3....j.}*.z....+.s..@..K.....\x.C..e.Qq.....;N.....;....,....^.*..$F..{G...8.#....8'..&....8..5.....3(P._....S......|".....u.cr....+a-....&V..x...iI-<|a.{E.c.X.......?..&.C....'........(.x....>...M.?.9..#X......l...0...Z.F..<.z.0}Q..Z1..........?h..`E$K.2o.A*c^.......*..D..uL=.}.#*0.. M!.A.C......|_..(.Y........!E... .O...`;....M+..x.u~g...q>...N."D^..K..x..D.`.!.
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.374106122544257
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:12D37A2095958A562B9538181BF7A882
                                      SHA1:E11C50434183FB9FC328EBE3B567ED0BA4809C1E
                                      SHA-256:EE8695B1DAEBCC5B15D96A2BA864B8C45E4E2F1B192AF7BBF6434567480B77E9
                                      SHA-512:C5983EA52004BBA4F2F9FDD18899930C3876AFC449034F03FB4367A74DAAFA077323E8CDFDB8FB9807039823A2B13E36D94675424316EC044281F2DCA0475CF3
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......V...v...J...................................................................................................................................2...>...2.......v...~............................I.......I.qk..B.....LZ6.......6...s#M.<.Lg...46...s#M.<.Lg...46....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............}1Kv..L.&...........N...^................1..U.N...t-..t........f........................................I.qk..B.....LZ............}1Kv..L.&...............}1Kv..L.&................6.......6.......6...........................................6..j....6..T.]..6.......6...B..6..H....6....B..6....>.)6....J...................;........4...4...4.."..............6...6...6....z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4.........6.......6......#6..............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.467430511456225
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:8B1871EEF20FCD71FE0AEC794ACA3B41
                                      SHA1:734C8F951C80A6520AF736B83C52D01855A538D1
                                      SHA-256:83DC423479130C022F10C45C64F8CA19172FEE8189AC369EC1E8C29971832221
                                      SHA-512:028887D05F0D91600B9D1171589679A9E9A09AEF96787BE30A35F653DD542759B2E70D1766277B55B1C0EC9C02825A46F7DA1E58974FBC52AF7B89503A53FD6D
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......n...v...b...................................................................................................................................2...>...J.......v................................I.......I.qk..B.....LZ.kG......kG,.?..#....N..kG,.?..#....N..kG..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'................U.....:.>.......N...^...............-Ve~..@.I..G.N.........Z........................................I.qk..B.....LZ...............U.....:.>..............U.....:.>.............kG......kG......kG..........................................kGj.....kGT$c...kG......kG..G...kG..H...kG..>...kG......kG .3...................;........4...4...4.."...............kG..kG..kG..z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4..........kG......kG....#.kG............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.326562292942234
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:09F9298B6372A5FA0EC435BC108C3831
                                      SHA1:45E6AB464C0CC7433A1F7640F9926E725AFA4B33
                                      SHA-256:1C73C53A526AF2EE9EEE7F1D67EADD1063DA562C731DEC4B41D6D8B7F521A880
                                      SHA-512:9EE8525F4099E3AFC7D171982E15AA4B46C78DF5E2FE673FBF50EC667891BFA0C14D694852619B76AEAA97130B9A18C554A0026616B4AE96DBC4D59F30EEF2DF
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......N...v...B...................................................................................................................................2...>...*.......v...v............................I.......I.qk..B.....LZF0......F0...&.. .V^..2?F0...&.. .V^..2?F0...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............7...+..&.....1....N...^................G ).BsF..qm............f........................................I.qk..B.....LZ............7...+..&.....1........7...+..&.....1.........F0......F0......F0..........................................F0.j....F0.T.]..F0......F0...B..F0.H....F0...B..F0...>.)F0...J...................;........4...4...4.."..............F0..F0..F0...z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4.........F0......F0.....#F0.............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:15:20], progressive, precision 8, 604x784, components 3
                                      Category:dropped
                                      Size (bytes):140755
                                      Entropy (8bit):7.9013245181576695
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:CC087700C07D674D69AFDFDA0FA9825C
                                      SHA1:F11113DF69DACDB255C6CBCFB29C1D1CCE40B346
                                      SHA-256:A7FA7F092EFF43030A56342C39A765F8D5CC48C7DB815DDFC8C1E5EC40117FAE
                                      SHA-512:843202D975EFA91E73287052A893584B6E5AE601F91612B56539AA2F73D1AD3F997FCAD1E711E0F483A2E91D46D9643D0B026B43F4E94116A5D2FB6551536034
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....H.H......Exif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop CS Windows.2004:03:12 11:15:20.............................\.......................................................&.(.........................................H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d...................................................................................................................................................{.."................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?.......J...\O.,......../$..........OE.m.o......T....Z..l.g.-....m.?...Y....3......"....].j.X.k.S.k.....4..R....{....?F.
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.3200554447174495
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:1C67DCCACEC263AB6009D46588B60D1A
                                      SHA1:4CF68D70059FBB3D84598A01F62887F79971B50E
                                      SHA-256:995219F7B62EFC6BCEE296151259D40160302CB635054697DDE75020DCC478ED
                                      SHA-512:9B500A503EE133E505F4FC3FC7B9F266A649C03744BA344FE2A2527680A959D38CC7537AB5B875B734458FABCDF05900CEE4F289CA2C5BFEFAEB8E714E1C60F9
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......P...v...D...................................................?....?..........................................................................2...>...,.......v...x............................I.......I.qk..B.....LZe.......e......#.W.U!..e......#.W.U!..e....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.......................;........N...^................t.{.G.K..rT.:%~........f........................................I.qk..B.....LZ......................;......................;.............e.......e.......e...........................................e..j....e..T.]..e.......e....B..e..H....e....B..e....>.)e....J...................;........4...4...4.."..............e...e...e....z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4.........e.......e......#e..............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:13:06], progressive, precision 8, 570x779, components 3
                                      Category:dropped
                                      Size (bytes):129887
                                      Entropy (8bit):7.8877849553452695
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:737E96E41D79D3BDACE7AB4F8CBF6274
                                      SHA1:E6202A41A4F86B27D9EBCAEF7670B16C0ED67CF2
                                      SHA-256:7966F3D8A2D61ECB49A35E163781858E052C0B122A18A1238AFE27B57E2850E8
                                      SHA-512:D398C8521DB2FB3F8456FE792CF37472F3B851DD7298DB20E2DB79144F8E846D051878E77E5EF5D00E6840EDB90C6E2D97935BC1023A15FC45038CCE731E9895
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....H.H.....iExif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop CS Windows.2004:03:12 11:13:06.............................:.......................................................&.(.................................3.......H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d...................................................................................................................................................u.."................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?...W..I:..*....a....Aa ...w.T.M.v.........3x.......8Y....$.."-..m.I.0~sxB[@..=...:..\.Y?....@O.L;9i..U....?.5">+9.s\Z..vN
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.351440208857727
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:9BD416D05379C0F7C7A825F0BC5FA9E4
                                      SHA1:716FD07F1EC5CEAA65E0791AD36BDFC40F48400A
                                      SHA-256:B8EC5ECA13E290193966226D0F5E4CE248A2B91C9990B3DB9D59774D733776A9
                                      SHA-512:61AD79A321DEA144F997C8A92A75BBA8D5F74A1389EA1ECA76A53CA663B2DC18F7A113CF6740B902C9245F7D79A6C215392FCA022C6624EB2C7E09DE72D07DB9
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......P...v...D...................................................?....?..........................................................................2...>...,.......v...x............................I.......I.qk..B.....LZ...........%?......."v....%?......."v......I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............U...}.....U.@z....N...^................?....5O......mp........f........................................I.qk..B.....LZ.............U...}.....U.@z.........U...}.....U.@z........................................................................j.......T.]...............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4........................#...............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                      Category:dropped
                                      Size (bytes):84941
                                      Entropy (8bit):7.966881945560921
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:CB84C108A76C2AFFCAC2551A3C1EAD56
                                      SHA1:8BB7C2A12B056C1ED12EBBAE5BC9F60CCE880FFE
                                      SHA-256:139BB0E79F89C3DDEF79B1716A5FBAB4C07DF5785FB3CDF6B4EEDDBF6C078452
                                      SHA-512:6EF85144E9A7ACD0FF2E52A5FF42093153EFB69127B1C8549EEBC49B6CC196A46B65EE39A2CAD0206F6A41476D8B5B35D29EAC9942B8F84972B32E14CAFEED27
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d....................................................................................!.1A.Qa..q...........".2..BRbr#.T.3C....S$.cs.D..4%5......................!1A..Qaq."2..BR....3...b#.r.C4.............?.......m.q..'O.....r......_.1....8h....?.....O]~..k......GO...''._...!....o........''..g..H?k.......1...?.....z......>...+0..................GO...''._.........}.O.Z|.L?...........?.........[~t.......}......NO.....v.......J.......?..g..H?k......GO,m..r}o.z.....}......dC.9?..g..H_..........?.....O]~...m...C?.z..f....W.=u.B..m..C.-?.a.....3._.?.......o....np.M....g..H_............9?..g..H...../..kO...''._...!~...o.....0.M....g..H.........../......O]~.~...o.......7..+.... ..l?.}........&....3._./....?.........W.=u.C..m..C.+?..o.W.=u.A.^.O....:......_.........}..t
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.328531443557379
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:F306153613046702657200732DDD4D1D
                                      SHA1:B5299F71D2F494E18898D91B9A119820F56A7998
                                      SHA-256:D8AF770E99FAD54C35E6A753DB3392352338DA82D13D30D17030892907BF36C4
                                      SHA-512:CDB83AA5011F7831315ABF6E496CF32645D7DFCD96F986C28F07510F2A8E95F07AE3AA9F89581C711CF2063C7CD9324F4AD66774AFD5C746CAE1283A98A0452A
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......P...v...D...................................................?....?..........................................................................2...>...,.......v...x............................I.......I.qk..B.....LZ|N\.....|N\J\.3.?.g.}..|N\J\.3.?.g.}..|N\..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.................i...5N/.g.......N...^...................vU.N.R.....o........f........................................I.qk..B.....LZ................i...5N/.g...............i...5N/.g............|N\.....|N\.....|N\.........................................|N\j....|N\T.]..|N\.....|N\..B..|N\H....|N\..B..|N\..>.)|N\..J...................;........4...4...4.."..............|N\.|N\.|N\..z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4.........|N\.....|N\....#|N\............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:PNG image data, 40 x 623, 8-bit colormap, non-interlaced
                                      Category:dropped
                                      Size (bytes):1569
                                      Entropy (8bit):7.583832946136897
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:07DB3F43DE7C1392C67802E74707DAA6
                                      SHA1:C173ADB1999065C5E1E6DBEF934B4D4D7AF0CC23
                                      SHA-256:51E05999A1C9F17DF28CB474E57DD8E64BDAB824874A532C20A23766A01F8967
                                      SHA-512:E509255519D4E521E82332FF418DD5A6BBBC8476399A0D9C3D81542C1CABA535B2D79E5BC90F73F9EE8468643302137671934ABD600FC696F16161C91FEAC111
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:.PNG........IHDR...(...o.....>.c.....PLTE................................................................................................................................................................................................a.o.....bKGD....H....cmPPJCmp0712....H.s.....IDATx^.Y.. ..........}%.../].`<..y....V...m.....<....)..;Ki..'9...2.:.c...t..V..d.t;-y.Z.=K>B.."{Lj.~G..|..ENC.!Sw,....";.p..g....E.B..S.-...k..P."..E......l[./D.-.....Q+.G<>.+..b...#..y(...{a.M..J...<....v.W..F.qm.`.....(.mk.nX....l.Px8.0\Z....7G...$*.....&..Z.VJ.~......J.2|...2H..../...=.)q....ZT" .,%..h.p....Z$.!........r...Hh.f. ....P .d..1d....2.3h....;.A.... ....d..g4...A..^.....2.ew..."h...y/..j.h..B.......%.2.%..{r...+dG.=9h....P1...A...c...^h.]Q0.8x....q .!3....ZW"Z.!3...G.vC.GG..".&..X!3.|xB..V.P!.+zS..NX!3.....Nh.y(.Z.1.h..B...Z+....l8Xcu.B...K...@U..@Q...mB...x...&L C....mB.....@kC...Y.,.... ..e\F.B..........y..e\..:$(....Z.a...yn...f..z.~Q.{o...].ln.r....^.@.{..c.7..{...
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.336766244052283
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:3BDB611742877C0AF2773A28FF60EF70
                                      SHA1:E10684E897F7D944B8B65A11B2D5C9FA97EDA3DC
                                      SHA-256:BAC74E66750B2D43C3611D95BBE12251DD2A698166C2CD6C50D93E12F73D7A0E
                                      SHA-512:A8A51882B8E16214412052B2B49CDD6D99A05B6E595FA927F8A78204059D15587E272590849252C43B15232AFD0E55A63B2DA61B63E7C0D2A88FF8A2FBE9E83D
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......R...v...F...................................................................................................................................2...>...........v...z............................I.......I.qk..B.....LZ..1.......1.:....#:.'..+..1.:....#:.'..+..1..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............$(c/...<.'.........N...^...............^.VOP.XB.9m..G+?........f........................................I.qk..B.....LZ.............$(c/...<.'..............$(c/...<.'................1.......1.......1...........................................1j......1T.]....1.......1..B....1H......1..B....1..>.)..1..J...................;........4...4...4.."................1...1...1..z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4...........1.......1....#..1............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                      Category:dropped
                                      Size (bytes):40035
                                      Entropy (8bit):7.360144465307449
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:B1DDD365D87605F96D72042CB56572F6
                                      SHA1:ADF71DAD1A62B8A58A657C2EDBDD665A19EB846B
                                      SHA-256:06E09DE80C3F32254DA4FE6B2CBAD7C05EF144DD54B8C65745E195BBF7317A2E
                                      SHA-512:9C686092CC9524F34EA6CEC9AAE936A6225BCC54DE38DE1786EBA8F532959A80FF885E8664A09E4C318D7CA4B278E807D3D1F135BE55F30979B844FF5EC9699A
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d........................................................................................!1....AQ.aq.....".3.5...2B#s.$%..Rr.CS4&6...bE'7.c.DTtU...d.eu...VFfv.Gw.....Wg......................!...1AQaq........"2..4..Rbr#3$...B.s5Cc.S%.D............?..^.f....R*.N{.{f.....O.r.V.;U..~...U.(..>M._.yI.{8,..^.t...s`...j.O..U5t.&&..h.G.6Da.;.....J.......E..QD...C...}..N...tR.....~..].J:.V$.*.r......]...W......4.[.)6..Y_.....4...........m._'HR.a......]U=.....n...0.W..]..K..){.+...w...f...<|..1/.|.....b..-..y....]U#Ctn.7m.._.|..2I;|....tM....q.q.}.N)....'...9&...nR...R..}.........m._.LZ}u.../K....9.~..?.{....V.#..dx.Zk.:=..:.j].....E#....E~w%....J..[S..[......gr...vb.r]..<..ut..i...[P.w....:..Gkn>......#..m...9km`......t).up.....w....VOR.{&.nQI..}...wD.7Ey#n....MO.
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.608779443890171
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:5E486B27516FCBDD0294127B34D13AF2
                                      SHA1:2E10B21D6A86484EC8B2B83DD05B29A1150CE867
                                      SHA-256:A201D496AF9E12CADA1EFEEE3CE25328AC9D18EB39CA9F521EC28CC153216ADE
                                      SHA-512:9450572197881E14B13B3656F2AD2BA6050C87858AC52CDB48971E8498A146F4BF141834D56396E7A93D16B0A50CA6803EEFDCD3A604813433BAF401CEA38E98
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>...........v...~...................................................................................................................................2...>...f.......v................................I.......I.qk..B.....LZ...........a.......a.c.Q...a.......a.c.Q.....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............aBf3$M..'..z.c.$....N...^...............h...L.7J."s.|k._........f...................................:....I.qk..B.....LZ............aBf3$M..'..z.c.$........aBf3$M..'..z.c.$........................................................................j.......T.]..............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4........................#...............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:10:32], progressive, precision 8, 594x773, components 3
                                      Category:dropped
                                      Size (bytes):242903
                                      Entropy (8bit):7.944495275553473
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:C594A4AA7234EF91E6C2714CFE1410F1
                                      SHA1:C0F720D4CE3196852814D0B7347F0CAA0C6FD526
                                      SHA-256:10C833E47BE1C8496F949A6B059C2D79212A4DD66BDE62116EA337FA4FE0B654
                                      SHA-512:7313F6545A334F9E2DE5430B2DB5C419C4C8A40E075338DAFCD74970BCC6309786946E5DFB57531612BF4C6269495655706D920FD99922FDACFF9796710DA9C0
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....H.H......Exif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop CS Windows.2004:03:12 11:10:32.............................R.......................................................&.(.........................................H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d...................................................................................................................................................{.."................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?...v&.F;-v;}FH..Z...N..)Y.......h;C....G.0W..ww...MI..Z+..\.........c..4.1.~.Yo.Y6.&. q...............l.A#.~s?yYg..7ky...r
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.331018687895441
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:1A62E777F49DE36E3B1FB7C4768DA27C
                                      SHA1:5DA19A621578DB59ECC1756C98A5AD0736A31FDA
                                      SHA-256:8A172D4298B4816CE3D7D2C6C1025A5013902567B3C9107E41116EED24D21F4C
                                      SHA-512:2E2D9EA3602B56D0C548461906CBC51AC91B60E7838F68248F30B22ADB64645F979F5873FF094D5A4DA36A3903D8F22DE7EF12F876B8B52EF324625AF397BBE6
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......P...v...D...................................................?....?..........................................................................2...>...,.......v...x............................I.......I.qk..B.....LZE;......E;.x).....I7..znE;.x).....I7..znE;...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'................X/.'.=.../.....N...^...............Ne.zM.O...d.<C.........f........................................I.qk..B.....LZ...............X/.'.=.../............X/.'.=.../..........E;......E;......E;..........................................E;.j....E;.T.]..E;......E;..B..E;.H....E;...B..E;...>.)E;...J...................;........4...4...4.."..............E;..E;..E;...z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4.........E;......E;.....#E;.............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:12:29], progressive, precision 8, 598x766, components 3
                                      Category:dropped
                                      Size (bytes):70028
                                      Entropy (8bit):7.742089280742944
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:EC7811912ACA47F6AEB912469761D70D
                                      SHA1:C759BC2D908705D599B03BDB366C951B11F99A4E
                                      SHA-256:FBB4573E3BEE1B337077691BEBAE15D6FAC52432405D31396D526D7694A8283D
                                      SHA-512:881828150993A8C56E36CDA2051D89C1F6E0322643902C9506392C163E8734A2933A46486F40E5BC8C8D0164E180605E52620EF22FE14540AEA787A38B22E98E
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....H.H.....7Exif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop CS Windows.2004:03:12 11:12:29.............................V.......................................................&.(.........................................H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d...................................................................................................................................................}.."................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?.....H.yM..? .Z.. .^.x..p.8.A...K.... .\{..)..y....t..=.^y)..v.@.W>. .h.. ..p.:.\)(.$....$.I).....!....E..Z.....&.5.).
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.339552648911778
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:31AE32F4AFBD29B2EF7B35316C94DE69
                                      SHA1:B13D096CF3F0716B312D0EECE9F23BD584AC93E8
                                      SHA-256:F986EF6F5091E6E1C85B44DB471E008946F3B53E5169AB0A845EA5DF5DEB7D9E
                                      SHA-512:03127521CE042B43F1403B608F4169C721D71717BF833A539ACE9B8B9EC5A3CBF3509522B0E32984393A0D4A092D3721EBADB1E6480181A5ECD9C47B89F8A60B
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......N...v...B...................................................................................................................................2...>...*.......v...v............................I.......I.qk..B.....LZ................".>.|P.#........".>.|P.#.....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.................["...x.V|.6....N...^................."ho..D....}..........f........................................I.qk..B.....LZ................["...x.V|.6............["...x.V|.6........................................................................j.......T.]...............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4........................#...............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.343786889191925
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:3F0B5C5FA685B79304662F1FE4172670
                                      SHA1:CE01876DBF29ECBD23E6A981BEDAC5B0A5A84492
                                      SHA-256:639438DFD3A1F3786EDC07E621426FF0D66A2A07381E7D0C1A7A5B90B5AA96B6
                                      SHA-512:57C21C030303C1228D36B90DB74C9535B3A6D3F5BF85E5605C478E8FE85273E1172B1A62D79D4C0D454DB8E5495A7300B7FE3980DAD4108681619BEC1C634410
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......N...v...B...................................................................................................................................2...>...*.......v...v............................I.......I.qk..B.....LZ.7.......7.%;0..?4GG.:0Z.7.%;0..?4GG.:0Z.7...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..................?.......XV....N...^................wD%..K.&H....m........f........................................I.qk..B.....LZ.................?.......XV.............?.......XV..........7.......7.......7...........................................7.j.....7.T.]...7.......7...B...7.H.....7...B...7...>.).7...J...................;........4...4...4.."...............7...7...7...z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4..........7.......7.....#.7.............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                      Category:dropped
                                      Size (bytes):47294
                                      Entropy (8bit):7.497888607667405
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:7A450E086AD14BA7D89BA5DB3D3AE6C7
                                      SHA1:E7AEAFCFCE476390E18C19456BDF6529D863D518
                                      SHA-256:BDD997068701ED3A00A224EB694B003C01AC69B857FE7B4147D6C34875B1632B
                                      SHA-512:9B6D50A6CDB6081DA107A2CDDB1BD2811A5764994C8E3F67D56CA81084BE0D068C27435154E867199F38688EA65E8DE02A56DCAC47D0F5E55F0FBB6598814938
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d.............................................................................................!1..A..Qa"..q..2.......B#...R%.r...$&b...3Ss.4dU6F.cE..'GC..t..5eufW......................!.1..AQ.aq..".....2BR......r.#3.d...b..Ccs.t......$4T...SD%5Ue&Vf............?..M.7(..).:.a.q.......>..[:O...afQ.uCO..U.....go.l..p..YqVklQ.{i.w&.]Z.\+JQw._.n.'.h..,.bj..X.].k&.Q.>gU..f...1|....[...jQ.%Zb.......t..........*..V..j.6....Vj..i.....?...IY.P.....$.j........[l.....S.4.J9.U\.......7I..[..=*N5....xW..../...=?n....uG.D..S.>...8..3........n.S....]k.*...4.>.R.o..{..l.H.#.^....<amG.m&.......,....wDY.W.m.X....We.IR.Nu...y..Z.l.._S.mr.m...y.]m.R.MT...6.5.5}.K..#%..k].7.Y.q]...%.r.7.R^jR..z.K.T[t.a..d.)glW.r.v,.`....O..^..o:.Uc.\..D....f..D......yt.Q...Y.....
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.480331021984489
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:5F5A9AFE78BF52DF23DACCA4FC5ADDF9
                                      SHA1:D60A2BCD34E8341612799F50D5117CB18F4D68C4
                                      SHA-256:34FE33E189C52FFFDA1CF0BC06D2ABDD8727867E1F9833357EF0A84CE079B371
                                      SHA-512:58D362E51A66EF8186DCE29DC50B9BCD745EC526E2A1A0044D6F72BC84F52A7ACDC6C191FB973657F0C54E7CBFC6411B10890458464AD3773D3609D83A798233
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......n...v...b...................................................................................................................................2...>...J.......v................................I.......I.qk..B.....LZ.34......34...0.-.k....34...0.-.k....34..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.................../.Q.R/.~....N...^..................z..A.s.y.(Qk........f........................................I.qk..B.....LZ................../.Q.R/.~............../.Q.R/.~..........34......34......34..........................................34j.....34T.]...34......34..B...34H.....34..B...34..>.).34..J...................;........4...4...4.."...............34..34..34..z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4..........34......34....#.34............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.369181721492281
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:9A4FE7C0723DA492B522591B04DE0833
                                      SHA1:79A8A842F7286F0CA78D9ECB550C2970D595A757
                                      SHA-256:DCD22495C72BE5754EF37A1CEAAB313C18C9908BC56393B0B921FC8CF5ED7766
                                      SHA-512:21A0464CEF541AB9B2C74BCE3A0F4C2ECE2F47217CAFEBAAEE79D0CE82D6B76FA3C397C37B61DC95E2605C2B5B46CBF4EE96F50E6CDB0551AE703EF4F19AF2EB
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......R...v...F...................................................................................................................................2...>...........v...z............................I.......I.qk..B.....LZ.b......b... .,~.?P.a..b... .,~.?P.a..b..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'........................DB-......N...^................s...3.@....5."N........f........................................I.qk..B.....LZ.......................DB-.....................DB-............b......b......b..........................................bj.....bT.]...b......b..B...bH.....b..B...b..>.).b..J...................;........4...4...4.."...............b..b..b..z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4..........b......b....#.b............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:PNG image data, 40 x 617, 8-bit colormap, non-interlaced
                                      Category:dropped
                                      Size (bytes):827
                                      Entropy (8bit):7.23139555596658
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:3E675D61F588462FB452342B14BCF9C0
                                      SHA1:86B62019BC3C5BE48B654256B5D10293FC8C842A
                                      SHA-256:639EADAD468B6B32B9124B1F4395A8DA3027FF7258D102173BA070AE2ED541AE
                                      SHA-512:E6EA855B642ED36FA82F8E469A826DC57EB0C36E307045FF8D166F67AF9242C87840833BE31FBE4706DC54100E999D6A3D3A78D0633A3114735818874AD34758
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:.PNG........IHDR...(...i..........`PLTE...................................................................................................bKGD....H....cmPPJCmp0712....H.s....qIDATx^...0.Cg.;......@j..2c.=~KP.[H~..@..8...?U.g.n.a=.=.).....3..u^(.....L....5..........8.}..T.f.n.a=.=.).....3..u^(.....L..r....s..8.....W]....,..9..G?.a..`c.z...E.p...)Y.P.....#....@9.7].....,..9..G?.a..`c.z...E.p...)Y.P...`b....0.b.+~{.Pu...1..<..0._.l.@O.y.(...V3%..J....s... .(g.+.qyWu...1..<..0._.l.@O.y.(...V3%...%R.L.Q..x..R.<t.o......7.............:/.E..j.da@i..`b..Z......u.>.?...7.............:/.E..j.da@.Dj..9.W....s. .....:.......L...">w..7... .....:..."...L..."..a....D..Ya.l....E.{.@&.|.._...7..D..Ya.l.....{.@&.|....0.J.."z.0s..s....=g ..>........"z.0s..s....=g ..>..l..1...y..g......IEND.B`.
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.33724578137257
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:C3BA3A1643B1EC968C0F9487B2454A61
                                      SHA1:1E31FB785B410703FFC0FD2A1D8CE4D4166319B6
                                      SHA-256:2FE2A6C85996E386D49B2E187A1125209E64DA5451C94D768EEEC7D1E7DC2C40
                                      SHA-512:75B4172588BAB655B507E858EEE3F5D0EDB8E137E9634DA9841B067B5F84837F6027877B4B254270D0FBAFB1181692270AFA8C397E1096359F93174CA158A6C9
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......N...v...B...................................................................................................................................2...>...*.......v...v............................I.......I.qk..B.....LZ.+.......+.1.i...v..:2.+.1.i...v..:2.+...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............j.1....3..w......N...^................A.8j..L.u./.No.........f........................................I.qk..B.....LZ............j.1....3..w..........j.1....3..w............+.......+.......+...........................................+.j.....+.T.]...+.......+..B...+.H.....+...B...+...>.).+...J...................;........4...4...4.."...............+...+...+...z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4..........+.......+.....#.+.............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:PNG image data, 50 x 600, 8-bit colormap, non-interlaced
                                      Category:dropped
                                      Size (bytes):4410
                                      Entropy (8bit):7.857636973514526
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:2494381A1ACDC83843B912CFCDE5643B
                                      SHA1:98F9D1CC140076D1AE5A9EA19F47658FD5DF0D66
                                      SHA-256:5EEBE803E434A845D19BC600DF3C75E98BB69BD0DE473CEEC410D1B3A9154E28
                                      SHA-512:0E64CC3723DC41D94910F7ADFB6A0DFB5049350FD15A873695614E4A89ABD78B166BA4E9C8CB95E275FB56981539DECD2A7F28FBC25E80DD5E2DEA8077CC9489
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:.PNG........IHDR...2...X.......E.....PLTE...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................B..(....bKGD....H....cmPPJCmp0712....H.s.....IDATx^.].\TU.?3"...(..L........q.Q...H.*j......W..Xd.ie.f..%.XT...em..m.m.vkik...>.}..}|..{'.U..~......}....s.............,CVu.x.:C..5...;.
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.353218720622823
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:F621A83C1DA306EA05D0DF5B236B152A
                                      SHA1:9EDDC3A7CFAF9141AA42D334CE640B52E5F09746
                                      SHA-256:D1AB6AB09390E03531E34AEFB8A96ED7EE5CD47592D2ECE3B6378213D9A6C67E
                                      SHA-512:108822C15E4BE7028F7883AD8252073476BA60144C1F7B36C1242C4427C0DE9A4EA84104FD7DE25DB4DACCA48CA6412F25C1E7210E1E03D150CEFC91B3109DB6
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......P...v...D...................................................?....?..........................................................................2...>...,.......v...x............................I.......I.qk..B.....LZ..3.......3.w...9...@....3.w...9...@....3..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'...............A*.{...tL..`.....N...^...................t.J..rA.C..........f........................................I.qk..B.....LZ..............A*.{...tL..`...........A*.{...tL..`............3.......3.......3...........................................3j......3T.]....3.......3..B....3H......3..B....3..>.)..3..J...................;........4...4...4.."................3...3...3..z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4...........3.......3....#..3............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                      Category:dropped
                                      Size (bytes):136726
                                      Entropy (8bit):7.973487854173386
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:4A2472AC2A9434E35701362D1C56EDDF
                                      SHA1:16FA2EA2D2808D75445896E03B67A93000EEDDD8
                                      SHA-256:505F731CB7707EFAB2EB06685B392DC7E59265A40B55AAE43E5DC15C0A86CBA4
                                      SHA-512:5E28D8FB2AC62ED270968072A30013334461F7CAE96058AF9EAA6E10912989DC47112D2133892BF61F7A516B77C6FF71BA2A000B750A9F95C787E538B09595C2
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d.............................................................................................!1..AQaq".....2B....R#..b3...r...C$...X.....Sc...9.%'.(Hs4Dgw..T..5GW.x.)......................!.1..AQa"2.q.......B..#c........b6.Rr.3s$.&..S...C4.%5............?.........(......(......(......(......(......(......(......(.G/.GE&...)..P.x..B.({i2Y;.z?G...Yfc.)H..^....#.....}3..Sc^.H..+...M.a.P.....GS.....H_.3..<....1f........1.<.\..nn-..s.s.\9Y....=.......S.0.......N..cA..Io..r.3..........ay.....K.....,.;9..Q......xO.Fa.2..>........{4k.....|....?U....3.8..._/3....#.. t.y......yY.......e.<........#.....B.....Z.%.Y..S.ye.W4...l.......X...%.@y}>....l.yi..D..W......L..._D.Q....)...E....n.%...*..K.4#.8`..I....h..h.o..I......-...hB...3..u.(5..........n...,.@....a.t.9.....@.s.>.&...@
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.331635401777845
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:A2226385060D0594C98E33745AE98CC3
                                      SHA1:7603FADA21A39CAA2364EB43BCEC75F469CE06E9
                                      SHA-256:09D96C695B3F9D4A858FA5B0C7CC4EE193A5CFC840AB54FABF42CE2016CE5DE7
                                      SHA-512:E75675DC48F73E79301DA61DBF0FB4B6BCBECBFAE3979357E8D342AE3AAD177AD776691797366CE815A636E53D5102E9B484E5F3A796110A6603CA58BBD10B6D
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......N...v...B...................................................................................................................................2...>...*.......v...v............................I.......I.qk..B.....LZ...........`.{p..V......`.{p..V........I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............8+......9..F.......N...^...............Z?..<..B...MK...........f........................................I.qk..B.....LZ............8+......9..F...........8+......9..F...........................................................................j.......T.]...............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4........................#...............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:PNG image data, 77 x 627, 8-bit colormap, non-interlaced
                                      Category:dropped
                                      Size (bytes):5136
                                      Entropy (8bit):7.622045262603241
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:FA38AFA965141EA3F17863EE8DCCDE61
                                      SHA1:2B4611E651AF7549C1AA73932B1136B561A7602F
                                      SHA-256:E1CB1A0EC9BE62D5445C73AA84DF38234002A7E164EE830C9DF24997802CB5D2
                                      SHA-512:A372674F5CA343321BA9C413D346070709F7685706C9C6C3DC7F61846B59253A5E6FE800DBA10AE870FD3887439B2AA106FBBB51751E92A163938A4393C43E28
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:.PNG........IHDR...M...s.....}8nv....PLTE.................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................z`.....tRNS...................................................................................................................................................................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.41988923738575
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:A4C4AFF87C0165466FD91E0FDA578B36
                                      SHA1:2937870274A9A5C158432681691007E2BDAC848C
                                      SHA-256:4E4407C7C3A47D92B696ACC63535CF8BCA76756F267BE38121EF98C1B214F8D1
                                      SHA-512:44BBF2E0685F4DA6CA9E8A76407F7F135A852D22DAB2AE32D3C30D0986272BDE5815A57FE2BA92A5423F7C1819D9AFC7B993D022581CDEE2A3DAFAD2D3CBF5DA
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......h...v...\...................................................................................................................................2...>...D.......v...............................6.......6...}.K..*..8"F..I.......I.qk..B.....LZ6...}.K..*..8"F.6....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'....................!'..O\.w....N...^.................oiN.F......8!........f........................................I.qk..B.....LZ...................!'..O\.w...............!'..O\.w.........6.......6.......6...........................................6..j....6..T.]..6.......6....B..6..H....6....B..6....>.)6....J...................;........4...4...4.."..............6...6...6....z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4.........6.......6......#6..............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.460625880077187
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:C75FAE8C22E1C47E71D8D14FF4AD82FD
                                      SHA1:67771BC139F7627BE7858F5B47A8EE08ACC117E3
                                      SHA-256:BED882D21A13B4B3B7573E61F4C69D5F278BB0E080EEE1D6538037ABE2E8432A
                                      SHA-512:5164A06325D05C0BBE75B8B6BDA067FE7D73BB0D22893983F32A7D3BF45506F3E750BB677DB1765C8A58F4B5BD9C89CA9E662D46CCB92954C82B505D3DE51EF3
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......h...v...\...................................................................................................................................2...>...D.......v................................I.......I.qk..B.....LZ..C.......C.^.4.0....`"c..C.^.4.0....`"c..C..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............<.^.....K...q.....N...^.................3.v.~I..b.0.P.........f........................................I.qk..B.....LZ............<.^.....K...q.........<.^.....K...q............C.......C.......C...........................................Cj......CT.]....C.......C..B....CH......C..B....C..>.)..C..J...................;........4...4...4.."................C...C...C..z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4...........C.......C....#..C............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.45022602798087
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:FAA0DAB1A838A10D9B82E9517436B1EE
                                      SHA1:02AA94F2EAB96B79DF17B4309FBC44383E210DDC
                                      SHA-256:14ACA1A78C54A6B731941ED5F6217A55BC4CC4D413D48A4836D4BE5B9636BAD3
                                      SHA-512:0471196EF8DC55B46CDA95D5FD29D533F0227C9412FBADE711D03EEA3DCDC17AF470154D1ACFABDE4DC491F2C072880DDAEB84C6FE07767162D192A1EF22ECD0
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......p...v...d.....................................................?....?........................................................................2...>...L.......v................................I.......I.qk..B.....LZ............)...6Z.d1.0.....)...6Z.d1.0......I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.................|..3TM(..IH....N...^...............X..9..WC.R.............f................................... ....I.qk..B.....LZ................|..3TM(..IH............|..3TM(..IH........................................................................j.......T.]..............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4...*..7*..7........................;........4...4...4........................#...............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.3293015076733985
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:18C2F30AE738C232245866C3021E636F
                                      SHA1:D9543ED1A9E02A2CC49B47B13C2CD37A552E4A34
                                      SHA-256:767C6D9DC7A8C61189FB6B2805F48AEE75EABB7FB70B1FA147F2FBE23C632F8A
                                      SHA-512:759640A662FA6A102C23C1B12ABCEC06D2815502F3D5BD1045B9606F55107A00AD35D71969ACAFD80F38F218955B3B0F7C8A52B16AFDD011A24C5D7A90C98F2D
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......P...v...D...................................................?....?..........................................................................2...>...,.......v...x............................I.......I.qk..B.....LZ.........x].i."8...SK..x].i."8...SK....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............I..k......Q........N...^.................nvrfD.C....)k........f........................................I.qk..B.....LZ............I..k......Q............I..k......Q........................................................................j......T.].............B....H........B......>.)....J...................;........4...4...4.."........................z...y.. x.. ...........$........4...*..7*..7........................;........4...4...4......................#..............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.4332493285589125
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:88FFA9CDD060B67A01360AFD8B212245
                                      SHA1:E119E61AC0F5FCD2E06ED20DC3BE03319F0C464F
                                      SHA-256:DA58B9DAE1523CF8A8BCBB3C657837582ED815F30C99350407A3E7E493415BBA
                                      SHA-512:5CA6ED65AD9C7E7643D4F215BC9ACA9A6C1EC8C954B1D1113F0484277297540E5B5919CF54478E419295876530D3797632026F7CBF56FA31699D074E7E88A81B
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......t...v...h...................................................................................................................................2...>...P.......v................................I.......I.qk..B.....LZO!......O!..*.......|.&nO!..*.......|.&nO!...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............BI./~P..<..pj..H....N...^....................#J.......e........f...................................$....I.qk..B.....LZ............BI./~P..<..pj..H........BI./~P..<..pj..H.........O!......O!......O!..........................................O!.j....O!.T.]..O!......O!...B..O!.H....O!...B..O!...>.)O!...J...................;........4...4...4.."..............O!..O!..O!...z...y.. x.. ...........$........4...*..7*..7........................;........4...4...4.........O!......O!.....#O!.............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:PNG image data, 176 x 513, 8-bit colormap, non-interlaced
                                      Category:dropped
                                      Size (bytes):11043
                                      Entropy (8bit):7.96811228801767
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:8E9AB9C28B155A66BC5C0DA5E2A4EFB5
                                      SHA1:972E61F162D48F1CEE21963ECBB2FE439105DB55
                                      SHA-256:B243A24FA13BC8523450E22F408F9EFF15301C938F8CA52A57018B58CE6785DE
                                      SHA-512:12062D69E676B3B34AFCEF25AC17B40294282D5BAB6C0110680293D7CC96EC17EBCFE104C284E64A30EE3C483E319E9C37C03F6EE82C79632180E45C7A684E8C
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:.PNG........IHDR..............`....`PLTE............................................................................................... .......bKGD....H....cmPPJCmp0712....H.s...*YIDATx^.]...,.N.8.i......0..e..y.......8.6....Fo.........=...F..._..........O..{..............3.|.L.|.............>.....v..n.1J...k...."....7........J._.5LQ`..k...._Z.W.x:..k...g..._.....u<.Q{...1...q6.cs...l............30.g...< W...a.5..>O....9}..c..........s|I.).>.fo4.<q......>...c.:.u..co.#.7,.O..G./.K.|..q.p...(.(....iH.......m..+.7...../..{W.l....b....?.`^.q.9L&.>.hN2`1..m...]$.0J....rBy......{.._...G....;.r.Q..;..,...9..F...t;.+..2.Ub......V...8.k..5.........'[..s.H..).......%j._.&.....BN..V..q...T...#..........0.E&.o7....$..m..8g.f._$..k.8...5......HgQ...L..\.........)B.I.r.(..8.a..$N.9.=..o..Q..(.e.a..O.....c.= .......$0..X.S,..(p......$..l.c.I...=."......g....^..#~,&.a9iK..ZNE`...pFJ.@Wd?.<..Bt.E.......e...i.%d...}.!..B......9.........B}.....5...;..hL.D.....4z.....|.)
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.372546838358891
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:EEE941C8A59192F6AD3BAE0CEB2EB5CC
                                      SHA1:FB2D8CCFA9A692B83058C6381C317F02A9A98D94
                                      SHA-256:523A764415CA8A91673237A459B11692C3E59CAC3BF0FBC87DDAA2932407E953
                                      SHA-512:085D69E060FC12FD56A7EDCC663B713420F860F19C8D47601A5B9FA8535D6EFF8909E61BDEE52474EA45D9E0CE008F70B9437AF1297E2F81571351CFF6A76602
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......R...v...F...................................................................................................................................2...>...........v...z............................I.......I.qk..B.....LZ.f.......f.}$9..?W.....K.f.}$9..?W.....K.f...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............C......_.e8......N...^...............:.....TA..1..yu.........f........................................I.qk..B.....LZ............C......_.e8..........C......_.e8............f.......f.......f...........................................f.j.....f.T.]...f.......f..B...f.H.....f...B...f...>.).f...J...................;........4...4...4.."...............f...f...f...z...y.. x.. ...........$........4...*..7*..7........................;........4...4...4..........f.......f.....#.f.............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:PNG image data, 40 x 650, 8-bit colormap, non-interlaced
                                      Category:dropped
                                      Size (bytes):647
                                      Entropy (8bit):6.854433034679255
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:DD876AA103BEC3AC83C769D768AD39FB
                                      SHA1:1833603AA9B6A7E53F9AD8A336F96CCE33088234
                                      SHA-256:1262DD23AD54E935CFA10FEB1BE56648E43BEF1116696CA71D87E6E033B1CA7D
                                      SHA-512:946DB2277213104A3B29EC4388578B05027B974A3093B4CCAD8847397AA51AE308BC6A199E5705E1F901D6E4B1BA34D8DECFD6E5B6685184A307D749D7CFAEDD
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:.PNG........IHDR...(.........xk....`PLTE.........................................................................................>.S.....bKGD....H....cmPPJCmp0712....H.s.....IDATx^.)..1..7w....6.*.H`T6.ha.k.............b!....Ba..C..P.4K..@.....h.E..X....PX+.P.-.....@@"...o.O4....xZ<...B...B..,A..y.s<......b!....Ba..C..0_p. .......=..,...i. ...=.j..N...........{4+...xZ<...B....|.....$.K<.vyE..X....PX+.P.-.:... .'p......\,...i. ...=.j........K.....%J..S+.....q..k.H.@DD.s...:..J.K.DDL.\.@`,.DD.:.(]..N....KD....A M.....F..S+.....1.sq........\.t..;..../...~k...4.DD.:..]..N....KD........@DD.s...:..J.K..[...Q....V......IEND.B`.
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.364308483469834
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:5EE63D0E0DC5E09B36070398F25AE638
                                      SHA1:CDD2A67D4D275AD4A3D0A1A83ABB78B351480387
                                      SHA-256:D8EEEDB6A226793A5D4341E7DA9C1B92FF5D9536545FF74E88BD19D89E8B33F1
                                      SHA-512:916056A8E69D723A74D7258932F6F73981AF4F52B45C1C8849AA0EC4906B2E1B912CBA0B0B6866506D6BCBAF02558E0710A03B3C065273011CA041477CAEA001
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......T...v...H...................................................................................................................................2...>...0.......v...|............................I.......I.qk..B.....LZ.~.......~. .=`.1.....YG.~. .=`.1.....YG.~...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'...............N..]k..e...8.n....N...^...............?&.....M.0u.'..........f........................................I.qk..B.....LZ..............N..]k..e...8.n..........N..]k..e...8.n..........~.......~.......~...........................................~.j.....~.T.]...~.......~..B...~.H.....~...B...~...>.).~...J...................;........4...4...4.."...............~...~...~...z...y.. x.. ...........$........4...*..7*..7........................;........4...4...4..........~.......~.....#.~.............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.304956787215713
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:C7CD481CD999704307BF5A28DE246CB3
                                      SHA1:FFBED7D327E4DF876CE6DC5BCB14AFC51AE1FBD8
                                      SHA-256:748BA570EAC6E736D5A0DDA41EBE1E1F3D8FC2F2E225BE1EBD3C1F117D31418B
                                      SHA-512:0D8A336F11F23FEFCBE220FFE3578FEC0FED0C8632334B3116EF1846EAA15F2F3951DFADB0B76A7A50A2869BB6A172CD1F3ADBC7B8776ED28765999EB9CAC366
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......N...v...B...................................................................................................................................2...>...*.......v...v............................I.......I.qk..B.....LZ.B^......B^m.....|.......B^m.....|.......B^..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............)..5...5...>.....N...^................e?R...G..@...."........f........................................I.qk..B.....LZ.............)..5...5...>..........)..5...5...>...........B^......B^......B^..........................................B^j.....B^T.]...B^......B^..B...B^H.....B^..B...B^..>.).B^..J...................;........4...4...4.."...............B^..B^..B^..z...y.. x.. ...........$........4...*..7*..7........................;........4...4...4..........B^......B^....#.B^............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2004:03:04 13:18:09], progressive, precision 8, 164x641, components 3
                                      Category:dropped
                                      Size (bytes):27862
                                      Entropy (8bit):7.238903610770013
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:E62F2908FA5F7189ED8EEBD413928DEE
                                      SHA1:CA249B4A70924B73BDA52972E9C735AEC35A0C5D
                                      SHA-256:20ABE389C885E42B6EBE9E902976229BB6FD63C8C34CB61AA70B8B746209F90A
                                      SHA-512:EE8D1821A918BE8714F431895E7223D08036E88A4FDB9A5485EFF246640EE969A69A8AA4E2E9DDC35BA75FB6D4E95092A286E90B477BD6998C313639C2C31F25
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....H.H......Exif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop 7.0.2004:03:04 13:18:09......................................................................................(.....................&...................H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d...................................................................................................................................................!.."................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?..P.v..+..n(a..Q..S\6....Y....D......} w#.b..]l.5.RU..k...... ]$.$.........f........?.z@2uU...7....?..|.Q..I.&.. ......"T4)wdH.
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.477012895343524
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:4EB9FA650A3E1D9A99322D243AD384A8
                                      SHA1:275CC4FCCDA66F8B44AE5BC0CEA0BDC96259C1C4
                                      SHA-256:77E01A6BE4A612D5B573F3653E80AEB7CC6896D9459D8AF368D65AE2A1946299
                                      SHA-512:6319887077C8D4E403423E739B3F3A766184B7440F5D71A0638EDD0FC1E81615F31D72EB9513C25DB20EEE864EDE5E9556CDA2162D79F6694CAA010EA42B55A4
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......r...v...f...................................................................................................................................2...>...N.......v................................I.......I.qk..B.....LZ.J.......J.{...3...L...J.{...3...L...J...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'...............34D....{*..?h.....N...^...............\6....5D.m..5..........f..................................."....I.qk..B.....LZ..............34D....{*..?h...........34D....{*..?h...........J.......J.......J...........................................J.j.....J.T.]...J.......J...B...J.H.....J...B...J...>.).J...J...................;........4...4...4.."...............J...J...J...z...y.. x.. ...........$........4...*..7*..7........................;........4...4...4..........J.......J.....#.J.............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:PNG image data, 50 x 556, 8-bit colormap, non-interlaced
                                      Category:dropped
                                      Size (bytes):977
                                      Entropy (8bit):7.231269197132181
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:B7F74C18002A81A578A4EE60C407A8D3
                                      SHA1:70A7D4BB1B3ADF4397D168AD0D81B286F88EBDE0
                                      SHA-256:95F59A0433050180D4C0E8858B83363D51BEA6752A8B7CA516A8677854D8F5B6
                                      SHA-512:13186A7CDCE80BCA9D2238666D6D7A989FA1887EABFA5D8A9A63EEC304DFD4BE8EFF652205FA56E1D1CEE7D3680AF8C70A952AF73AB3C246400E8D4EBECBDBA9
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:.PNG........IHDR...2...,........A....PLTE...................................................................................................................................................................................$.y.....bKGD....H....cmPPJCmp0712....H.s.....IDATx^...0.D_.......cck.....%a...X.a0Y...-..!.G...[....(.r.H.$...1 .zq.4V.e|a.6.X..4..kl.%....=w....6..TN.....{.4..T/.z...../.....3..!~..t.#b..^.....E!.SFb ...-.....^...,..C.!.b...i._c...s.X.w.. lsQH..H.gKc@@...i. ....m...;Ci....@G.; V{..lO..\.R9e$..{.....P...E.+.2.0D.B,..P...56.?......K.6..TN....^z.4..T/.z...../.....3..!~..t.]b........E!.SFb ...-.....^...,..C.!.b...i._c..Y.O...?.9k2.M.?5 .n.P...,...d._..%M?....6....,.1..R.4.a.R.+..U.Q..P...vd..T........j .]@....."..lJ../.90.4...Y. ...9.%...{......Hc%.....i..%M?aG..H....o.q.......4.......X.d9.r..CI.O.5.Ri0?.s\b....w...>/k..4V.)Y....P...vd..T........j .]@....."..lJ../.90..2..MP..l..?....K.X.....IEND.B`.
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.312303965617739
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:7BED7FC56FF5953CC1EC03C0733B5375
                                      SHA1:40A922A238D58E00AAB1345D4257D665B90BE9A6
                                      SHA-256:7108E68B4CEC82440D232D6F96A0D0564826BBF163477626340B42531D24A218
                                      SHA-512:EDD70CACB76B26081F9F2E3F7758C4729EB94C1634B901DB7CF13EB63A64F39FC0D3F1ED1303793D19FA3BD49F4F1038ADFB9BE9ACEB783F3A98B1B6147CA9FB
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......R...v...F...................................................................................................................................2...>...........v...z............................I.......I.qk..B.....LZ.^.......^..V...8.=~.:.^..V...8.=~.:.^...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............7 :.)......ju.....N...^...............Y.#.z.=L.a.Q..c........f........................................I.qk..B.....LZ.............7 :.)......ju..........7 :.)......ju...........^.......^.......^...........................................^.j.....^.T.]...^.......^..B...^.H.....^...B...^...>.).^...J...................;........4...4...4.."...............^...^...^...z...y.. x.. ...........$........4...*..7*..7........................;........4...4...4..........^.......^.....#.^.............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.3228641822541
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:1528D1BE32BC9A9BF01A0CDC613B4826
                                      SHA1:1FD86C3AED08342E777969A4D69DD60A0378B5EC
                                      SHA-256:05DAFC2AAEA5EE503A3887367DEBDE612A5BDC5D9B528B4436767401FE6318ED
                                      SHA-512:E9AFABFC225533F8314680CFDC393AB058962EB4E4781ECDD2BD844A5DEA7077376C456F080D87F2A8BD6A57E33B2A080918245364792C8C94F16BD569AEAAA1
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......N...v...B...................................................................................................................................2...>...*.......v...v......................................k..<.....KR.I.......I.qk..B.....LZ....k..<.....KR....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............<.....^.4.OCzi4.....N...^...................-UC....6?..........f........................................I.qk..B.....LZ............<.....^.4.OCzi4.........<.....^.4.OCzi4.....................................................................j......T.].............B....H........B......>.)....J...................;........4...4...4.."........................z...y.. x.. ...........$........4...*..7*..7........................;........4...4...4......................#..............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:PNG image data, 171 x 552, 8-bit colormap, non-interlaced
                                      Category:dropped
                                      Size (bytes):10056
                                      Entropy (8bit):7.956064700093514
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:E1B57A8851177DD25DC05B50B904656A
                                      SHA1:96D2E31A325322F2720722973814D2CAED23D546
                                      SHA-256:2035407A0540E1C4F7934DB08BA4ADD750FCB9A62863DDD9553E7871C81A99E3
                                      SHA-512:BC7DC1201884E6DAFDC1F9D8E32656BFAEE0BB4905835E09B65299FE2D7C064B27EAA10B531F9BECF970C986E89A5FD8A0B83F508BBA34EB4E38B3F7F5FC623A
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:.PNG........IHDR.......(.....!..t....PLTE.......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................4.....bKGD....H....cmPPJCmp0712....H.s...#.IDATx^.w`......$..B....... ....fz5..6`l\.8...Nsz{.//y./....{.7}g.....e.....~.......s...f.....%c...6....O.PJ...Y.oi...9..'j.2..6.-
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.317176839107834
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:11464116E5BBD47AA2C4488559190103
                                      SHA1:E06156B1FCDBFB55E000A7ADFC929383872A9F69
                                      SHA-256:681858B87049BDA8588399D64EF86F4F562002DCEFA90F703928A2552F56C746
                                      SHA-512:C6B597B122FE7A8209B1924A9DF6F90AADB4D625B1975149D192B32E5AFE75AC93491006D9E083DEEE8ECBEA6EB47DBD793FDB26AEE6B58685BCC0FBAB15995E
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......N...v...B...................................................................................................................................2...>...*.......v...v............................I.......I.qk..B.....LZ7=......7=.6.pV.*.E...g.7=.6.pV.*.E...g.7=...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............7..{F.+ri.........N...^...............E......N..R*M.\n........f........................................I.qk..B.....LZ.............7..{F.+ri..............7..{F.+ri..............7=......7=......7=..........................................7=.j....7=.T.]..7=......7=...B..7=.H....7=...B..7=...>.)7=...J...................;........4...4...4.."..............7=..7=..7=...z...y.. x.. ...........$........4...*..7*..7........................;........4...4...4.........7=......7=.....#7=.............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.316960669095152
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:A3F03376987F13C6F6C27F71F7AA536C
                                      SHA1:CA30F6C1982EF14CAA401144B940DAE40C58F21E
                                      SHA-256:0CE5EC848FF38097B175AB645ED4F0582901EDA6B405FEC3F394047D562815D2
                                      SHA-512:441F94D1A6D5AE56B7D6D7D3E00B4CE482FE88F9BB918605B70855593CEF3BADA75067EEB9763746EA85482B265E88E2ECCC4C3DE4A7DE3EAE4892B8E65ED590
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......L...v...@...................................................................................................................................2...>...(.......v...t............................I.......I.qk..B.....LZ..s.......s........G.>w...s........G.>w...s..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'...............K.................N...^.................`.,.L.Y....f.........f........................................I.qk..B.....LZ..............K.......................K........................s.......s.......s...........................................sj......sT.]....s.......s..B....sH......s..B....s..>.)..s..J...................;........4...4...4.."................s...s...s..z...y.. x.. ...........$........4...*..7*..7........................;........4...4...4...........s.......s....#..s............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2004:03:04 13:26:15], progressive, precision 8, 216x792, components 3
                                      Category:dropped
                                      Size (bytes):64118
                                      Entropy (8bit):7.742974333356952
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:864EEA0336F8628AE4A1ED46D4406807
                                      SHA1:CFCD7A751DFDBE52A20C03EE0C60FDFFA7A45B93
                                      SHA-256:7CE10D1EA660D2F9CF8B704F3FAB2966A4CE2627D9858D32C75D857095012098
                                      SHA-512:0CAA0C54C14571C279A75F0D5922F78A17803CF6EE1724D66819F7F5944C0F5B25CB586BB686A52808CDF2F8FEB3E4864052A914884054EF7DE44124A8CA951E
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....H.H......Exif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop 7.0.2004:03:04 13:26:15.....................................................................................(.....................&...........s.......H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d...................................................................................................................................................#.."................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?....NC+n....<.=.7..&.8A56..@^.Q..\\...E.>..".&G.......J .'....$.I)........0.../..mv...D....<v0=..ugc+..l.o...=.c.......x.&D..{`8...v
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.339840759562698
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:09BBD1E6F0DDA427B44F26BC1CDEA4E4
                                      SHA1:109103DA97B1E9B53BB262F66630A59B0A46940E
                                      SHA-256:901DEA7E089ACA6F5B52E29F9A477E2607231455E62177AFAAA3202C352CD2A9
                                      SHA-512:CDE7B75F50631412C5A20600FBD632B124339F0D5085445071686F7BC3475A7ADE7F6FBD1866BFBA203E16850DD3AED8E8F81A03695A746F6461A6FE8C68CE67
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......N...v...B...................................................................................................................................2...>...*.......v...v............................I.......I.qk..B.....LZE.R.....E.R..X........%E.R..X........%E.R..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.................!`..9..!x......N...^.................g>.7zG...<..zx........f........................................I.qk..B.....LZ................!`..9..!x..............!`..9..!x...........E.R.....E.R.....E.R.........................................E.Rj....E.RT.]..E.R.....E.R..B..E.RH....E.R..B..E.R..>.)E.R..J...................;........4...4...4.."..............E.R.E.R.E.R..z...y.. x.. ...........$........4...*..7*..7........................;........4...4...4.........E.R.....E.R....#E.R............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):8192
                                      Entropy (8bit):3.2456661240020477
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:1FE4F41DFAD97477674AB27CE8E722D1
                                      SHA1:41189AA95078225685277291D7CBAFEABDDBA760
                                      SHA-256:8C5B6F076AF2D5C263BCD97D0ECFA8540DEEAC32714FB5DA963477E53EF0D55C
                                      SHA-512:75E1455BF2F079BE860BDD442D51ED757BDDA95F771B0F8C0CCB5DF227A475EFD4F7E80CC103EC62006D073A55937D5E8000C969C51365C465F69022330FB58F
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>...........v.......................................................................................................................................2...>...j.......v................................I.......I.qk..B.....LZ...........&c....?..Z:R...&c....?..Z:R.....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............<.}Z.oN..U..c'.....N...^.................N..=.@....."W`........&...................................>....I.qk..B.....LZ............<.}Z.oN..U..c'.........<.}Z.oN..U..c'.........................................................................j.......T.a..............D.....H.........N.......?.#....9...................;........4...4...4.."...........................z...y.. x.. ...........$........4...*..7*..7...........Op.b..F.$..i.................;........4...4...4........................#...............................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:PNG image data, 189 x 305, 8-bit/color RGBA, non-interlaced
                                      Category:dropped
                                      Size (bytes):12824
                                      Entropy (8bit):7.974776104184905
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:2628353534C5AD86CBFE57B6616D46DD
                                      SHA1:244B7E39D6CEF5B07FCDE80554D31F7DA240BB0D
                                      SHA-256:69BDB000AC7E030B0B28E6CE78F19547D235355B3B841146951AD1294429FA51
                                      SHA-512:2529F97BE62DE038445D1C86EE2C01404FB1A2D83A5D16C7B5F4E21723C17EC86FA180DFE10342536CFD7D334EA3AF1FFE151B77F2FBFFFE8E7B2A0C2A3ACD59
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:.PNG........IHDR.......1.....).'....sRGB.........pHYs..........+....1.IDATx^.}.w\.n...A.H...E.J...l.......p...\{.w...e.-K.%..d.9..DN...^}..p.L...._$.t...n.=U..ID..]~(.?.)J...-.../.......0V..........'.)1X..c..D..2..A'f."...Ru..R=b..\....\.n.0...7.~".'..s!bd.|..p.u....-w'.....R.........i]..r....A.........r#...W..f{O.2~C.O........{.....3..W.}e:...~.....4.......t.Mv_....}*f..I...x11....d..6.@..O.......f.e..K.....L]..gohj&D..+.....#...#.J...n/]...8~.....zx.'.LI6..W....p...................V.F.. ...y.[.kl<?.^....N..$..7j.biU....c.51{S{.....q....c...<..x..............zG.F*.........U.w..fE.....DU.......WG7.5uC...7.....j..7yM...~jU..;J..a|LoG..x..<^.Z ...Z.....ip....._.4......f.rg..[...z....x1k.....z...K.l...;6.\..Y.#.WT.p.@{W....>.+..*..W....'v.nV...YA[.q!\.\...9..3.[|....7...HO......2<.....w.,].T^eN..XB.....M3...I.k...e..8...lZ.R...T.%......|N.w..9..!..O.-p..NA.eD_.d..nW2!...N...z>..;....=t#....H,.N.|. ......EC..............1.\
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:Windows Enhanced Metafile (EMF) image data version 0x10000
                                      Category:dropped
                                      Size (bytes):32656
                                      Entropy (8bit):3.9517299510231485
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:DD4CA4BC0A73FCB71BEBAA3C29CB8F66
                                      SHA1:1A7085771D7941540EC94A1BD24D7CC8EA556D4B
                                      SHA-256:0401451E1D1D7DFDC29AD1B2B68A6C8AC0B706E9868BF22FAB26A01CD48620CE
                                      SHA-512:5B7D386C46EC75E21DE94DBCA922FB9A6E5358DEB3D60FEEE7B197D739F15D11050825D9323502EDFAF60720F1074DE896B23E71C44D07C9C7E943C31FDC078A
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:....l...r...1...*...^...bX.......^...... EMF........h...................`...E...........................(...F...,... ...EMF+.@..................,...,...F...\...P...EMF+"@...........@..........$@..........0@.............?!@...........@..........F...(.......GDIC....s...2...+...^.......F...(.......GDIC....s...2.......N.......F...........EMF+*@..$..........?...........?.........@........................(E..HB.'E..HB.0'EI.`B.0'EU5.B.0'E..B.'EU5.B..(EU5.B.(EU5.B..(E..B..(EU5.B..(EI.`B.(E..HB..(E..HB.................@..............!.......b...........$...$......>...........>............'......................%.......................;.......U...P........................T...S...S...S...S8..Si..Ti.@Ti.qT8.qT..qT..@T...T..<.......>.......r...1.......N...............%...........$...$......A...........A............"...........F...........EMF+.@..........F...........GDIC....F...(.......GDIC........2.......N.......F...........EMF+*@..$..........?...........?.........@.......................}*E
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.338220659222451
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:359091753FEE4A5FA73FC02B96FE2E69
                                      SHA1:864E471312A3F98A0BC577BA8774CA1FC66AEE4A
                                      SHA-256:01660178C7217584CD77083DAF3C70D344059199681C842A7ABB73692FC1CB5A
                                      SHA-512:04A50AC64A154FFE3D294DA8DDE3D84D1C5384BE712ABFEC22883E684A4034837D0436C7369B3A4619DF89C964F511D86FACF485AE18DA981BFC674559389372
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......P...v...D...................................................?....?..........................................................................2...>...,.......v...x............................I.......I.qk..B.....LZ.............>..$$.iX.......>..$$.iX.......I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............,.NiY>.....Y.(......N...^..................@.G<@...*.^........f........................................I.qk..B.....LZ............,.NiY>.....Y.(..........,.NiY>.....Y.(..........................................................................j.......T.]..............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4...*..7*..7........................;........4...4...4........................#...............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.4132708910025285
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:CD30BED05D870059DEA153363FAE5F01
                                      SHA1:C8DD98B1075CFF9EFECCE161BB4CD5C7E78A92D6
                                      SHA-256:1E77F72892C03561B0B89F30CE45FE44126ECFC36ECDE2618984C0B52DD5AF06
                                      SHA-512:82EFED740C7B49E3E8483429C1F2E63D0F5385168E2D38F137A51F29F76585684F663AE857C2B8CDAD51E5BEA1A1B78694A62A5E4F242ABBA4F0443F8A47D344
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......h...v...\...................................................................................................................................2...>...D.......v...............................}3......}3.g............I.......I.qk..B.....LZ}3.g...........}3...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............<;......(V...~......N...^...............a5x...K.M............f........................................I.qk..B.....LZ............<;......(V...~..........<;......(V...~...........}3......}3......}3..........................................}3.j....}3.T.]..}3......}3...B..}3.H....}3...B..}3...>.)}3...J...................;........4...4...4.."..............}3..}3..}3...z...y.. x.. ...........$........4...+..7+..7........................;........4...4...4.........}3......}3.....#}3.............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                      Category:dropped
                                      Size (bytes):25622
                                      Entropy (8bit):7.058784902089801
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:F8CCFC24DEB1D991EBE085E1B2D7D9BF
                                      SHA1:AF76C22A765434AEDA134924C517C84107F4FED5
                                      SHA-256:7354001527AB554C44E7D6981B86DD933B7DC2E0D3DC8512AD3EECD843245C52
                                      SHA-512:818BC3690B01B30BC571E4CF45EC8D1AFCAECBAB003532644381F1CF730A5B3486862D08F7579B2D3D89167AD7DF35028881245C9550B0DA23D1F81A720A9704
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d........................................................................................!...1A.Qaq.........."2Rr.#.t6..B..3S$4..v.b..Cs.%5..8..cUV.(.DEe.&Ff...T.d.......................!.1A..Qaq...s4....2r..S"BR.3....b#C$.....c............?..D.."}:......&&...?3..W.q*.......]...m.Y.k1......K).J...uV.b.../.0.E.H..4..W_T.[t.V.w.9.x.qe.L..o.oL.....d.\.....6.|.o...}..H{Yn..E...6Y3.l.e..D.:,.n.%...t...m.........,+,..|..n.....6.*...f........6.../$../Vi..H...e.f.F.zn.).n.E..2sTn.i...Yb?6+H&...Bf..*....z.o.^7[..u.:o....t.s=.....(.s.....f.g....q9o.u1L.N...smzE..[>...+\O....j.<....j.c.W.............U..+.F/.'..W...T./W...>i01./....j.s."..Q...{...a._~OW...Rp.)*.e..W..Q4)<..'..W...q...'..U..z..g......U}...O....w....0F:.N..V.3W.|..'z0.]...j..U[v..g$D.Lc[.e...UW.m0+
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.298964300601803
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:F1740A0CADFF1A0C0DB00C2D5FCF05C0
                                      SHA1:B28F1938E1EB40E349A7DDD5EEC3D6A751D5F31E
                                      SHA-256:D2AC7785FD8D45EA8E77D711E959D51F0B77A26DFF596F06FDD7BAAF0A5DBB96
                                      SHA-512:71994EC5B26F319720444DE8E0D063F4D7E66D4D4170B270C1846942B5C5F3C05F9F59305C15AF0AE01816DC7AA25460B3F306C8EBEF602ADD624636A5E2E09A
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......P...v...D...................................................?....?..........................................................................2...>...,.......v...x............................I.......I.qk..B.....LZX.......X.....a.........X.....a.........X....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............t4...9......|:*....N...^..................x.9.L.o...7.A........f........................................I.qk..B.....LZ............t4...9......|:*........t4...9......|:*.........X.......X.......X...........................................X..j....X..T.]..X.......X....B..X..H....X....B..X....>.)X....J...................;........4...4...4.."..............X...X...X....z...y.. x.. ...........$........4...+..7+..7........................;........4...4...4.........X.......X......#X..............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.320595914017893
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:7A039772A7D9FB7AF4E6B7B27CB7A37C
                                      SHA1:09E40AE9E05D53283634772911B6C6790BE28F46
                                      SHA-256:66008A635C1E0F9D04E4DB292E7D2C0C38F2480613209791CCF6C6598C61FB4E
                                      SHA-512:177AEED289AA9ADBD0F9835A95A1D67C43DFA65B032B36E7EB894A7C073E9E84F43861302385A1D88A92814B30AC2BD0CCE0C133054C07293BBFFE9DD17B5634
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......N...v...B...................................................................................................................................2...>...*.......v...v............................I.......I.qk..B.....LZ,"L.....,"L|.0....U..YI.,"L|.0....U..YI.,"L..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............S.O.&*....^..c....N...^...............k..f.m.L..e..E?........f........................................I.qk..B.....LZ............S.O.&*....^..c........S.O.&*....^..c.........,"L.....,"L.....,"L.........................................,"Lj....,"LT.]..,"L.....,"L..B..,"LH....,"L..B..,"L..>.),"L..J...................;........4...4...4.."..............,"L.,"L.,"L..z...y.. x.. ...........$........4...+..7+..7........................;........4...4...4.........,"L.....,"L....#,"L............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.485141852521049
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:04FB78EFE7B6AD043094DDC8EBF42874
                                      SHA1:5762962574A25698803252894AC1CD183F2FFF74
                                      SHA-256:D37434B96BCED60B3E20B28E1B167C93CD9D1ECEF5E2294B6457BB00E1B3A7BF
                                      SHA-512:1DFA664E96A2AC13B7C3B19F7EA5366C94C60A890CC15B9D31A9CF6FE0EBFD357BC474C0BA9324CC51476F252C10279AD7CDFAFC3D3B4C92546D5DD657774FA5
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......n...v...b...................................................................................................................................2...>...J.......v................................I.......I.qk..B.....LZ.A.......A..r;...C.p....A..r;...C.p....A...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'...................P..B..W.......N...^.................B..v.I...s:.s.........f........................................I.qk..B.....LZ..................P..B..W.................P..B..W.............A.......A.......A...........................................A.j.....A.T.]...A.......A...B...A.H.....A...B...A...>.).A...J...................;........4...4...4.."...............A...A...A...z...y.. x.. ...........$........4...+..7+..7........................;........4...4...4..........A.......A.....#.A.............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:08:07], baseline, precision 8, 595x450, components 3
                                      Category:dropped
                                      Size (bytes):59832
                                      Entropy (8bit):7.308211468398169
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:DCDD543A4E0BA2C1909BA095D46FFBCB
                                      SHA1:B86C89537138FE07255354202D3EAD0B53B3C54D
                                      SHA-256:28F334B77068F71F5F92A95695433B950610204A0E5580CE567DB8FAD4993ECB
                                      SHA-512:5408C3259B7F3288A4BEB04342799AD5FE3A6F0EC7E92353B29B7E7E538DFA9903B39637226919E0421BC422635D25F5F8069DC7441864DC03E1B909BF5C2C84
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....H.H.....fExif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop CS Windows.2004:03:12 11:08:07.............................S.......................................................&.(.................................0.......H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d.................................................................................................................................................y...."................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?......;R~+'....xh..~.n-}.......Te................^B..IU_....._...S......h.......!....9...A}6V=J......C..c.....Ug.Wh......
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.3451909880655055
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:932D9660ADC4B746E085063C7C95CAE5
                                      SHA1:435D02EFDB6466DDD0BA3F8369DACC10B7FF3C7A
                                      SHA-256:4A99CA9AE96E9E7683CAEBB2AE48BD684BC5C540815885F1A5F45537DC4627F3
                                      SHA-512:23CC08CD7082A6A0C245C048565AF680E1FD7EA30BC443791F2ABEA33E07DE1C4C6CD1FB0BA40CF88BF9F48D8AE794BABFA24F7E4EBD18E50D530ADE57299000
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......T...v...H...................................................................................................................................2...>...0.......v...|............................I.......I.qk..B.....LZ6-......6-.&X>..?s.(.~M6-.&X>..?s.(.~M6-...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............^$..Wp..&...\N&.....N...^...............(.!d.dZO...X..8........H........................................I.qk..B.....LZ............^$..Wp..&...\N&.........^$..Wp..&...\N&..........6-......6-......6-..........................................6-.j....6-.T.^..6-......6-..B..6-...C..6-...>..6-...|..6-. .3...................;........4...4...4.."..............6-..6-..6-...z...y.. x.. ...........$........4...+..7+..7........................;........4...4...4.........6-......6-.....#6-.............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.330510880871807
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:361C2417F0C64BD4F379D622BDAA3F5E
                                      SHA1:0EE9FC3FB96B6FDCF6EC1741E0C5EC5FDBD562B4
                                      SHA-256:8A639E1C4ECB6ECFF26AEE8B0F5A244184E9462545FC677064768AC977D20195
                                      SHA-512:DB11EB37322ACC163D82DD1EAB0E60ACBF7B1680C3C547DA312579E255BAD2B4AD1D044B18BE9C926ADE43DDB5CAC4792838E18975075435B36EE12DED072BA8
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......R...v...F...................................................................................................................................2...>...........v...z............................I.......I.qk..B.....LZ.EA......EA......rx..e..EA......rx..e..EA..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............m=.6.. ....c.....N...^...............O...1h.M..^5.k0.........f........................................I.qk..B.....LZ.............m=.6.. ....c..........m=.6.. ....c...........EA......EA......EA..........................................EAj.....EAT.]...EA......EA..B...EAH.....EA..B...EA..>.).EA..J...................;........4...4...4.."...............EA..EA..EA..z...y.. x.. ...........$........4...+..7+..7........................;........4...4...4..........EA......EA....#.EA............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.338850618371781
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:955D04158794A5211DA91CDA2B67694D
                                      SHA1:1DDC96F3E40D950B38125B34363936EBB3F2A6F1
                                      SHA-256:010B036141E9DC4FCC40DCB7316662E3EFE9F2E4419BB288B19B74E6FA9A864B
                                      SHA-512:428B8018DFC9DC1369BF1BAFD567C7B30A9A074C0079BD0E803BD5BD8E0C1FA116098ED9F89616DFD8B8C5BE32BC806184F2022012302BD5D339CD3ED8084252
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......T...v...H...................................................................................................................................2...>...0.......v...|............................I.......I.qk..B.....LZ..C.......C..#...R..p.<..C..#...R..p.<..C..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'...................\...e...1.....N...^...............6......J..............f........................................I.qk..B.....LZ..................\...e...1...............\...e...1............C.......C.......C...........................................Cj......CT.]....C.......C..B....CH......C..B....C..>.)..C..J...................;........4...4...4.."................C...C...C..z...y.. x.. ...........$........4...,..7,..7........................;........4...4...4...........C.......C....#..C............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.356938988833846
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:CCE7446E93C66C4712D0133615416E4E
                                      SHA1:0A45488EAEF3E82A20C1F22870C61BEB91E6E207
                                      SHA-256:E8242B5BF39BB5DD53CAA602DBF33F49A243BC42575AE1BC1354FA410000C34E
                                      SHA-512:3B20DFED88B21DCEFF07F6B3E222CEEEA5C0FBD53C462C415E999E6C581A82B542DF1727A1D810691996ACC07B105E1EFF63807A75DEF58343B32BA10BB24704
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......R...v...F...................................................................................................................................2...>...........v...z............................I.......I.qk..B.....LZ"......"....A.6r...d,."....A.6r...d,."...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............K...x.&..H....(&....N...^...............R.s...!F...._}.........f........................................I.qk..B.....LZ............K...x.&..H....(&........K...x.&..H....(&........."......"......"..........................................".j....".T.].."......"...B..".H...."...B.."...>.)"...J...................;........4...4...4..".............."..".."...z...y.. x.. ...........$........4...,..7,..7........................;........4...4...4........."......".....#".............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2004:03:04 13:44:07], progressive, precision 8, 611x163, components 3
                                      Category:dropped
                                      Size (bytes):36740
                                      Entropy (8bit):7.48266872907324
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:9C205C8D770516C5AA70D31B2CA00AF3
                                      SHA1:9A1002F0CF7F92F1BE2BB25BAD61CEBFAC282482
                                      SHA-256:E111F96490755C7D71E87C88ACAEA38AFE55BB865B1A14A83C5BD239648D5E2C
                                      SHA-512:A3E105208B32831265428572B0937DD3C17B793D8611B2DA8D4939F1BEC6050999D375E3F6B87D53AD49DFA0EAE737B0141D37597AA42116C310761973D4A134
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....H.H......Exif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop 7.0.2004:03:04 13:44:07............................c.........................................................(.....................&...........n.......H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d................................................................................................................................................."...."................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?..o...4.gP.~.c...K{...V.=...].<.........vS.........s....(.t......X......kk7....~-...yF}^c.Z.\.G./.?t...>....:.>......./.ib..).
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.451632932137392
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:9826D5B90640EE341E3736A8D3910BB2
                                      SHA1:CAF7FBBABEF7A35C41E982F3B9F401A2EF758096
                                      SHA-256:4622B743C87CEDE5901C4B3D1E38F0266931E8FBD0E3088DFA405A58BDCD6318
                                      SHA-512:AAC0CC7F3BE6A3CC0522312FEFD197360C926F8DB87FE941A128125F108D1A8EA26BEFA62DD7D5A84EEFF76BE6C072C24ED617BA5B71DD18AF0240460331EED2
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......l...v...`...................................................................................................................................2...>...H.......v................................I.......I.qk..B.....LZ...........XL"q.3..&.......XL"q.3..&.........I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'............._U8..AH.. ..:.......N...^.................s.Z.|I..-.dX..........f........................................I.qk..B.....LZ............_U8..AH.. ..:..........._U8..AH.. ..:...........................................................................j.......T.]..............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4...,..7,..7........................;........4...4...4........................#...............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.347099215203252
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:DE430D9094437372F3D0D9EF8CBEA6B5
                                      SHA1:94AECD177005860A2E70CAE3170C0AC6BEF47721
                                      SHA-256:D05530EAE37016C35F61D4B55C08B860CA00A9A700D4C934322D074DCDF8CDBC
                                      SHA-512:7C92E8F5B1281BFB7DE9042F274FC7EA9A0D04571B4A899E75905C381443B71ACB13BE21FC28B0E139E827689B206021E5CB40428E1C6F3279EA2707E49FB820
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......N...v...B...................................................................................................................................2...>...*.......v...v............................I.......I.qk..B.....LZ.u.......u.6....,..W.....u.6....,..W.....u...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'...............M.....6W-k..u....N...^...............Lp...f.F....Y.........f........................................I.qk..B.....LZ..............M.....6W-k..u..........M.....6W-k..u..........u.......u.......u...........................................u.j.....u.T.]...u.......u...B...u.H.....u...B...u...>.).u...J...................;........4...4...4.."...............u...u...u...z...y.. x.. ...........$........4...,..7,..7........................;........4...4...4..........u.......u.....#.u.............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                      Category:dropped
                                      Size (bytes):60924
                                      Entropy (8bit):7.758472758205366
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:D58C51D2CF586A5E14A9EC8529C3B0A8
                                      SHA1:F4811A353797C29B1E3F5A61B125C46E1534D587
                                      SHA-256:F927C7825851974A2149868146970706523A49165133CEE6027A43E8C9ABDF27
                                      SHA-512:34B963173AFBDF07432F4B983D29F10376E4771FE666E9D50B1A81DA0B9F6001FD86B4A08B9711386DE153BF6E03C8E932E2D181C8EAF94EFF34D20FCA7570E0
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d................................................................................................!1AQ.aq....".....2B...Rbr#.s.4...3$.5u.6v..CSc...DT..f..t..&F........................!1..A.Qaq....."2....B.s....Rbr..#4...35...CSc.$...DTdt..%..............?....O<......X.O.Fg..{.W&u.u.T~.|r;g!.._X..N.p.4.........................................................yK..xd...6..|%....\j..e.=...Y..f..I.|-....e...$R.j.......~.W#....{.....V.k.|F..z^..:.~..f......"x.....L..K..r../.;..[..l...;.U...W...X.........8.....y?..B...m.......j..Q.g3..G.K....GL.o..n7a..Y..[.'.........x........\......~...f...0\Wc.n?k.|.....1.ww;..2..?...r4uF.MXdB6..W..mG2NJ.E........u...2.q...Z..=(l)jU.X...U.\X.......O<......X.O.Fg..{.W&u.u.T~.|r;g!.._X..N.p.4.......................................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.331966391732968
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:4131D817243D0C108D8EAC7504140C75
                                      SHA1:7DB01802DC49D2329EAE721DC7A5EF1BBA8BE6AD
                                      SHA-256:A28F88528EE5A554DFE045ED90948B98E9CDDEB90E81BC0BD0FC778085E38194
                                      SHA-512:3B710A238A5D5C66405E0C634437E88773722D05853F58958AC650CAB867C3A02B351851461217BDEEB97C8A4CAC1E316CAE5D5446B0683F0E49B4C146C75763
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......R...v...F...................................................................................................................................2...>...........v...z............................I.......I.qk..B.....LZFA......FA.P8.w.9..X].3.FA.P8.w.9..X].3.FA...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............O.8j....E.K..q.....N...^...............M^....^A."..9>).........f........................................I.qk..B.....LZ.............O.8j....E.K..q..........O.8j....E.K..q..........FA......FA......FA..........................................FA.j....FA.T.]..FA......FA...B..FA.H....FA...B..FA...>.)FA...J...................;........4...4...4.."..............FA..FA..FA...z...y.. x.. ...........$........4...,..7,..7........................;........4...4...4.........FA......FA.....#FA.............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:PNG image data, 39 x 579, 8-bit colormap, non-interlaced
                                      Category:dropped
                                      Size (bytes):515
                                      Entropy (8bit):6.740133870626016
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:E96BE30D892A5412CF262FEE652921CA
                                      SHA1:8190A0BFE21D04BC6F3A406E91B87CA69C03A2DE
                                      SHA-256:0E31DA4DFCFF4A36C64C1CE940362D2309769F36369E4C43C317D5F2FA15658E
                                      SHA-512:D647F51ABBD013226A6ADD0D551D058C633F867F9AF5A9E099B85D6E291D220F7B85958B07381CD4C7C4F72356DBAFE2A86932AE398E28C56CDDF0744E92EE24
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:.PNG........IHDR...'...C........b...`PLTE..................................................................................................bKGD....H....cmPPJCmp0712....H.s....9IDATx^..I..@.C..<..?mo.#C((.J}...~..B...b.I.i.\<.e.....(p.I.EO...q.x.......dRz....K..b0.:.<c.o..0.x\:...F....I&..ap....."P@....DO...q)p*..@Y.CL2)=......1.........4....._.G..^`..lDO...q...X....SL..z....K..#.L#..I6..ap.Ls.,....7&..ap.p..lI...,GO...q.....k.n1..4......3=.f.x.$..4.....o....x.$+..0.x\.,&6...............IEND.B`.
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.301122222484397
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:2AED46C3A28B25FEE38F875AE8204C84
                                      SHA1:DC8685BD1AD95CFA1AD464922536FFC2FEAF7E7E
                                      SHA-256:23E99BF6E91E0248F4BAB2319CB8F3A4827428055A6AA13B09F5819908BF632D
                                      SHA-512:B101485697C57F30F913BBD00809803703D77B4E11450B3ACB7D8FFA722B7E7B81BA2FB859D087F8648FE4FA55318F1F8CDDA304216EF1B5809457EFB4F359A7
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......T...v...H...................................................................................................................................2...>...0.......v...|......................................n.)..&j..2....I.......I.qk..B.....LZ...n.)..&j..2........I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'...............'..#.1..P..e.....N...^................".....A.n...q..........f........................................I.qk..B.....LZ..............'..#.1..P..e...........'..#.1..P..e.........................................................................j.......T.]...............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4...,..7,..7........................;........4...4...4........................#...............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:PNG image data, 30 x 700, 8-bit colormap, non-interlaced
                                      Category:dropped
                                      Size (bytes):1547
                                      Entropy (8bit):6.4194805172468286
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:0BA36A74DFBF411FAB348404CCEC3348
                                      SHA1:4C619790E517416E178161028987DF1CD3B871CC
                                      SHA-256:2E7AAF26BEC32148B96442E8FFF1BD2CEF2D72630969F23B9A2ABEDB6CFEC93B
                                      SHA-512:90AF53DB7C413E2ADB970AC345F73E4ED8AF626E179C929E6560118F7A9E98DC7C5FF02B2B3F6C98D397E0FE2D85F3427C6928C328872149E176FA8A99E91F54
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:.PNG........IHDR...............\....PLTE.......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................D......bKGD....H....cmPPJCmp0712....H.s.....IDATx^.WSTA........b.0gPPP0..E.9b@L(.c.N.U>..@......;...}..B.(....$......5..XS...I....).!....D^.uE...\..5........F."o..-...m.n. .^.....q= .
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.327297339208695
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:6BF0734327A1369691551DF028149C55
                                      SHA1:2199974004B7633A478666E71460F285D2BBDF7B
                                      SHA-256:6C55FEE8B9F3AF6ED7ED3158F7CD81775C4573E1113C7E821442FF2FBB1A2B3C
                                      SHA-512:873B53441E71E8C6BEAE61DEF4378737D24976920719DEFC988C62A7556C54EF18DE958912E9FDAF1EFB7FAACA75F8356B567A7F63473B90DC2D757980F41D9B
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......N...v...B...................................................................................................................................2...>...*.......v...v............................I.......I.qk..B.....LZ9......9.GD....%-.M...9.GD....%-.M...9...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............B..<..M....,>.;E....N...^................i..E..I..:.............f........................................I.qk..B.....LZ............B..<..M....,>.;E........B..<..M....,>.;E.........9......9......9..........................................9.j....9.T.]..9......9..B..9.H....9...B..9...>.)9...J...................;........4...4...4.."..............9..9..9...z...y.. x.. ...........$........4...,..7,..7........................;........4...4...4.........9......9.....#9.............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.348575349059517
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:FCAFBEC74305EE25DD98FE806E29C44C
                                      SHA1:2D8CA6D4516D0CEC8CC95DD1751783645AA02917
                                      SHA-256:4E4E6CF3FCA540A198A2BD926C101A1B254E1D7A78299A4D38D975011BCFB6A6
                                      SHA-512:C45FDB17E34FAB1396293EC10FD8DE90E620A7350CFCD2CE54965ACA8E7803372BFE1436527A7CFF88FA6E37BB42779AF62B26AB74BB40170731364D39A9B556
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......N...v...B...................................................................................................................................2...>...*.......v...v............................I.......I.qk..B.....LZ.........{Pa....E).S....{Pa....E).S......I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............H.DEh)..6yM...l.....N...^................N#..QA..BW.Q .........f........................................I.qk..B.....LZ............H.DEh)..6yM...l.........H.DEh)..6yM...l.....................................................................j......T.].............B....H........B......>.)....J...................;........4...4...4.."........................z...y.. x.. ...........$........4...,..7,..7........................;........4...4...4......................#..............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.3467354018032
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:4C605CA5D313D04C5713BF861F81F869
                                      SHA1:4EE84CBCFEC539D0560D4A2353715EE3E42271C7
                                      SHA-256:276F2C3106E916FD5A29722EDD47C351BFE640C28092F041C8DAD1CA29F0DB15
                                      SHA-512:71CD9326B9ADA381D06D568698F47BD4499DEC48728BC57C3F0097ED97E2396E346D98B6831543BE40F65261B7DFFED2BAC2A7E9958AC561A478954BFD60B6E6
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......R...v...F...................................................................................................................................2...>...........v...z............................I.......I.qk..B.....LZ..[.......[pC.K....]x.*5..[pC.K....]x.*5..[..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............`.........{.o.....N...^...............%"?...<C.1...)F.........f........................................I.qk..B.....LZ.............`.........{.o..........`.........{.o............[.......[.......[...........................................[j......[T.]....[.......[..B....[H......[..B....[..>.)..[..J...................;........4...4...4.."................[...[...[..z...y.. x.. ...........$........4...,..7,..7........................;........4...4...4...........[.......[....#..[............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.432865357768294
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:8594D1B4D422D7C3F3973DC15E288871
                                      SHA1:DCB80C0F0F459BF660E4946FD1AE3A2E32C156F5
                                      SHA-256:5A5EFD01BE38A321C8BA821A280767B0D88B095B29F598C050CBB083733757B9
                                      SHA-512:F0E3608D709BEA32E2B4ADF9C587A241EF68A064D02EDE37900DDB1901BB06FCD8CF782444E1CCF6CA2E951EAD95E27C5564F4775CCA9E25263F8FE7DD91D716
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......l...v...`...................................................................................................................................2...>...H.......v................................I.......I.qk..B.....LZ...........3.O...7m..|....3.O...7m..|......I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'................G.q~..&>........N...^................v.....D.R?.5.6C........f........................................I.qk..B.....LZ...............G.q~..&>...............G.q~..&>............................................................................j.......T.]...............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4...,..7,..7........................;........4...4...4........................#...............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.344143804438009
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:43270B5638DD26172896576FDDE326B9
                                      SHA1:A568384E41B96D001584DFC1C17556FAEE61CC72
                                      SHA-256:1CE26B0D2D2E051ED06344C3378CE05331F2BA1A520A5B76943C7B08E173E5E9
                                      SHA-512:9ECB96C826151336A2FB35C6F60A1D6D8A6CA7210A3F7CEE01747A728FF462CDC5894223553976CCAAD242F85008B44239E0F3C9D6F17EE674B3ACBDE10E0437
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......N...v...B...................................................................................................................................2...>...*.......v...v............................I.......I.qk..B.....LZj!......j!.S....&....7..j!.S....&....7..j!...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............o.`.........*}G.....N...^...............Jk.{..K..)..$.4........f........................................I.qk..B.....LZ............o.`.........*}G.........o.`.........*}G..........j!......j!......j!..........................................j!.j....j!.T.]..j!......j!...B..j!.H....j!...B..j!...>.)j!...J...................;........4...4...4.."..............j!..j!..j!...z...y.. x.. ...........$........4...,..7,..7........................;........4...4...4.........j!......j!.....#j!.............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                      Category:dropped
                                      Size (bytes):86187
                                      Entropy (8bit):7.951356272886186
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:FEE4785DF76E93A9DC2F4501CBAEAE12
                                      SHA1:8FB4527BDE05EF208FCDB168098A07707C27501F
                                      SHA-256:F091DED5E283AF6848670A3172E7C43C6099875D39B3FC69C2BDBA914F609602
                                      SHA-512:7E99D33151A0D3873D6A819C98EA8E62D928C087B7BA2080F11C7BCF746AD60A44D4FF6EE3D2D2E8DFA4BF1FC6285ED56BB83F91C2FC6FC4FDFF2000105F10B1
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d...........................................................................................1.!Aq...Qa."...2..BR#...br......6v.7..3.CSc...$4.s..&dt%u.f.......................!1.AQ..aq........"2.B#....Rb3..t.5u.67.8.r..$....C4.cs.Sd%.DEUe&.............?............w.....c.....i.A.....3...7.......7..P......%.........?Th..l./?.;.....$}..=5Oa...F.c.A/...D.D..]..y..3e.5\%.fo2.X.*]q.5Ee.}..i..md.T....#...-...Mu...9...-+..~w5O.);..G..'.;..).....A_...M.vV..y.q......,<.3.(...._K:..XM.......w.......9..T.......?b..a-%.c;.}..>....|.,lZKCEB.t...fw|.Sw^..Y..:.J.................t._P..v..j.1.R8.R....G..W*H<(Xi........i..xcu...WM.dqM>'W..g....M.q.....+.....b'..~....>..T.~Jc....fj.X.x..9...N.w.6:..>.......&.(h..u...t._...)_k#7Za...cZ....P...Y..;.V.,..xo.....f........Y...\6...M'L._
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.653062586189288
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:468FDEC4D6FA18334424530D7B6C616B
                                      SHA1:754C2CC63C14CFAA66E205F747F0ABBDD0E47260
                                      SHA-256:B9C2ABBCDE65EFE3B43BF94F935A6D09150271E70575D876B58CF94A315BA390
                                      SHA-512:0E7C83CC61CA55233AA77EF7C2CA1642699F3AC69836FA0A1C19C09ED0A40E5C69C094A780016E995245E090E83CB723379836BE54B0DF9FCB63F73206FC6977
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>...........v.......................................................................................................................................2...>...t.......v................................I.......I.qk..B.....LZ.>U......>U,...5T..33..>U,...5T..33..>U..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............6(..Q..8.U........N...^.................."J..A....,..7........f...................................H....I.qk..B.....LZ.............6(..Q..8.U.............6(..Q..8.U..............>U......>U......>U..........................................>Uj.....>UT.]...>U......>U..B...>UH.....>U..B...>U..>.).>U..J...................;........4...4...4.."...............>U..>U..>U..z...y.. x.. ...........$........4...,..7,..7........................;........4...4...4..........>U......>U....#.>U............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.3186627352792994
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:65FA5A2F165723F5F233107F8E020190
                                      SHA1:7717B85F8DBCA56F6B8C6119068ECAB3B4C6818A
                                      SHA-256:6A33D0A3907838557F7EEE502F0891D4A1D261E7326776385C2686C8FAA75CEB
                                      SHA-512:C2074B96B6F0C69B9886E494F7FAF47E4DB219128F53508CDDE2E06D29B4D8E689792932A331DD9A3504C12CD42D794DFD87B8269CC0F5D596081455FD0E6F34
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......N...v...B...................................................................................................................................2...>...*.......v...v............................I.......I.qk..B.....LZ..T.......T....4.9...u..T....4.9...u..T..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............y.]<.[.4n..(.......N...^................D.E.Q.M.@.1..:.........f........................................I.qk..B.....LZ............y.]<.[.4n..(...........y.]<.[.4n..(..............T.......T.......T...........................................Tj......TT.]....T.......T..B....TH......T..B....T..>.)..T..J...................;........4...4...4.."................T...T...T..z...y.. x.. ...........$........4...,..7,..7........................;........4...4...4...........T.......T....#..T............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:PNG image data, 88 x 574, 8-bit colormap, non-interlaced
                                      Category:dropped
                                      Size (bytes):19920
                                      Entropy (8bit):7.987696084459766
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:1BDAD9B3B6DE549162F9567697389E1C
                                      SHA1:5D9C09159F07A3A9BDCC6C4B9BD9CB72D0184E6F
                                      SHA-256:0908A4CFA23F93011176D47F45843E9CA2973030421996E8E27484781F54B0EC
                                      SHA-512:475040779AC247BB5C3E11862FB55FBDDFA12D759EE86A33E11BC1F3B656D6CD0F9B25146C0113E43E1D8001D8867D3BC3BF7E6FE21F3A0016CB1F8B70B7A15A
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:.PNG........IHDR...X...>......y=h....PLTE..................................t........iw..............................................._n|...Tds...ky......................................................p~.....................................................dr.................v.............................................n{.......ap}..........x.....z...................u......................|..Vfu............r.....w........................................~...................Zjx...................................Yiw............w..|....................Xgv{.....y...........................jx..............\lz.........}..z.....t..[ky........u..y.....gu................................{..........}.....u....................~...........y....r.....bKGD....H....cmPPJCmp0712....H.s...JfIDATx^...\.W./.}....Sy...(..4....D.-.....H...% .$"D.Qr.......`..;...6...N......s...^...L.....Y{.GQU`..~...j....{...-Ax.K..&.....F..I\i..
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):8192
                                      Entropy (8bit):2.905910489612257
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:CEC4997A1F24101E3A1C63799588A9A0
                                      SHA1:5C11314AB5ABF32C4750C3BF67EE846DE23E3EED
                                      SHA-256:03AE283AF172F72A53F55EF2440FBE6B96B7B13101AE16050FC528923CBFADE5
                                      SHA-512:0962C5BAC12E1EBBE79CA1BAA0882174C9A0CBBB9F64D8D5C78BD7D9362A45E2912187FA588AA3397C6D64797D94C4588649E8FA45A6B923955A7C1A4BC1A0B7
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>...........v.......................................................................................................................................2...>.......H...v................................I.......I.qk..B.....LZQ.......Q..3.j0.1......Q..3.j0.1......Q....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'...............D..J.......x.....N...^...............n2K...SD.......}........f........................................I.qk..B.....LZ..............D..J.......x...........D..J.......x..........Q.......Q.......Q...........................................Q..j....Q..T.]..Q.......Q....B..Q..H....Q....B..Q....>.)Q....J...................;........4...4...4.."..............Q...Q...Q....z...y.. x.. ...........$........4...,..7,..7........................;........4...4...4.........Q.......Q......#Q..............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                      Category:dropped
                                      Size (bytes):179460
                                      Entropy (8bit):7.979020171518325
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:4E131DBFEC5C2462273CA7B35675B9D9
                                      SHA1:CA037F444D819A118AC37D7AA3782B9BF94C1616
                                      SHA-256:2A4A3530D652E227DDD5ADC096A95F6034718F7C380B07DB622022D768815059
                                      SHA-512:C333ECEB1439D0238BF44FB7896E62DBA4C645B70413AA0F99C1F10E8DCD20C2EEE5C83F2E9DDE9A2494C85A6D8D13CFFFC4160E2F598E17867015F5244D656A
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d.............................................................................................!.1AQ.aq...".....2Rr..Bb..#34.....CSs.$5c.t....%.Dd.6.T..u.U....E.7w........................!.1A.Qaq......2."r.3....BRb.#4......CsSc...$.5..%.DT.t67d..Uu...'............?..c.......p..z..i.....z......kj........F>f......3N...M....RM.&..-.~.Q..'.....q.a..w...-~......g.{..&.......V.n.D....>FS!n.....@..)...W..q..Wr{..J.gf.{.M$.P@m.,..9..&m.D...w.._...-.O........s.....h.k~......(.K...V..l.-...+.9.k......*......#.p#.O..9M..mF...C.......7+.AI....4vw.;..H......e..Q.u[.eUK.....z.....[.Kt...s..Lf.4..l{.....sh.............=..;..iqkj.m.a...NH......v..H..$..q.y......c...U[Mcf.......+...S-...^....4..T..YtL.x.v.;.....<...Ik|B.$.s8......3.+.8.l.. h.:....%B..W..I.QRS..,*x.
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.337180932729368
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:2F56B5A6A901C238937177DAC6C8C453
                                      SHA1:0036DE5BD12981C23271398A6D23B42E1FA1C96B
                                      SHA-256:3BF1C37DB498089A4C652B6E205DA84D2B8D7E2A819FE1899FF03D1DB7566646
                                      SHA-512:439737CBD1DDE7218C490B4FB20D0FA1C8635A2BE6286A6700C84FAEFE1E50BA3E274EC07E355B65CE6147B0BC6BBBB55F06C84E6DB93958DBEECD52A6280A94
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......T...v...H...................................................................................................................................2...>...0.......v...|............................I.......I.qk..B.....LZa.2.....a.2j.....Fk.0...a.2j.....Fk.0...a.2..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'................Oy....9.g......N...^..................=}`EJ.)...B.........f........................................I.qk..B.....LZ...............Oy....9.g.............Oy....9.g...........a.2.....a.2.....a.2.........................................a.2j....a.2T.]..a.2.....a.2..B..a.2H....a.2..B..a.2..>.)a.2..J...................;........4...4...4.."..............a.2.a.2.a.2..z...y.. x.. ...........$........4...,..7,..7........................;........4...4...4.........a.2.....a.2....#a.2............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                      Category:dropped
                                      Size (bytes):109698
                                      Entropy (8bit):7.954100577911302
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:8D804A60E86627383BED6280ED62F1CF
                                      SHA1:E23FF14B10AD0762DD67FBA3CD6EFC85647C0384
                                      SHA-256:494547E566FB7A63DD429EB0699FE41AA8998F8EA2F758D813FE3D56C3075719
                                      SHA-512:0FB19F3D00159F2748C3A54E952E551B9FEA6910D67A54DECA8D099992E50383EADB92768FF1F75CFFAE82A7A157B1E0F77A2F0BE7EC64FD2324304FDCA46577
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d...............................................................................................!"#.123..AQB$..aq.RCS...b..c4%..rs..D&....5E6'..TdUte...u.....FV...7.......................!"..1A2B..QaqR.#.br3.........C%...$5.....c4U..Eeu&SsD.6T..................?.....O.C.....^..R<A.g...[....3.....r.0.....nX.S....}...[.?Z.....A.?..~~I..rY|N.o...9......!...o7r../-.y...'5.3.U.s".-.0.1......SS...&.Q.j.*.$m.e..:x....`}...EP.?.7..~G(so.......O.....z.N..<....~^a.e...........p9.?<._..|......~.<@.D.9..G..?.?z.y?z.C.U.w..[.,..A.+........s......g...G.^....pz.xY.....d8.y.X...P..O(A.O..~:._.......<...o..4s..^.^b..x......_a.....|{c...:..X.....}.._...[?..NK.c...}.<......H.G....+x.Z..|....n...o....`.nk.#.%x......-|...|7......N!=././..w.8x.".8....'x........w...,>....j[w8a..}..lS..?.
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):4.3337266451544965
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:85F762872E21FAB1936C509897919B57
                                      SHA1:1784C31F5A634302DCE640BE49CF47FC4792CF29
                                      SHA-256:B9ED56C784AE7729E453A5872F650BFFC7B26415AEA2D406749EC80FE62C0BB8
                                      SHA-512:6FA14985A540759CD46D19C09C4FF62C400388BAC2533D7D8A7F41B96FDA89946B9221B31B04ACF6ABE85F4C2AEA5A1F49DBA3AED4F22E5CE4F31918953D22CE
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>.......N...v...B...................................................................................................................................2...>...*.......v...v............................I.......I.qk..B.....LZ..a.......aG.T..7..".....aG.T..7..".....a..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'...............h......al...*.....N...^.................B.=.1@...W=u..........f........................................I.qk..B.....LZ..............h......al...*...........h......al...*............a.......a.......a...........................................aj......aT.]....a.......a..B....aH......a..B....a..>.)..a..J...................;........4...4...4.."................a...a...a..z...y.. x.. ...........$........4...,..7,..7........................;........4...4...4...........a.......a....#..a............................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):3.289256855694684
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:EFE95B00A4FF683BE42E1AB1E853F624
                                      SHA1:9A1B51B14373452741574C80372DD735106633AB
                                      SHA-256:EAAA1B85CCB9810ABC6109ACFD6F017922B09143C3B272E383531A986A95ED30
                                      SHA-512:98527651B9D8634ABD660EBBD1B5A5B15016B6774A3F6B73FECC928AFCF670C110962B2F47790F65F3E9FD30F432810473B19176E587BC89C9E56272B0AB0EB6
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:........$...........t......................................?....................................................................................................\..................................................w.kHC..9q..Ii.B.....i.B.1...).0.x.[.X.U.]....i.....X....Go..Z./.#!5..^..G.i.B.1...).0.x.[i.B.......................................................................T&d......w....X........4.............$..XO.T.9.....T(P................4..(.....x.(.......G.......Go..Z./.#!5..^.X.......X.U.]....i....2...v.......4...................i.B..X..............................XO......i.B..c..,0...e...B4.$........[.-...I.......9.........................w.kHC..9q..I.......M.#.G....9......XO.1..O...A|\0.XO......>.................Go..Z./.#!5..^i.B.1...).0.x.[..........................Y0...b...71.XO......XO.1..O...A|\0...............X...c..,0...e...B4.$..............E........................................0...........e....4..................T.o. .D.o. .L.i.s.t........s.)..O@
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):12288
                                      Entropy (8bit):3.9095183501121764
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:79D90E1E817154A222737C22F746710D
                                      SHA1:923205AECDFD8FC6DDF845F75C44B97AF56E6045
                                      SHA-256:1B8A51DCE4F43A9D69A374AA453F44AE2D1500EB51E537238F311AEC32227185
                                      SHA-512:788053C1935844C64E978CA7A6B2C673FE40625AE1376209D66580E3EC1155D4989D40D3227B4CB1149F70F25DAEB73E7729D19A5F51DA685BD6ABBD2B4784DA
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>...........v.......X .. "..2...>...d...<...v.......@....!...........................................................................................................................................I.......I.qk..B.....LZ.Bd.;....Bd..#$.....&..a.Bd..#$.....&..a.Bd..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............W.B.&.....D.x....N...^...............? ..r..O..:.............h...L...............................D....I.qk..B.....LZ............W.B.&.....D.x..................................Bd......Bd......Bd..........................................Bdj.....BdT&n...Bd......Bd......BdH.....Bd..K...Bd......Bd$.........Bd-.BdJ.Bd..z...y.. x.. ...........$........2..72..7.....*...o.e.L.o.c.I.D...o.e.L.o.c.C.o.m.m.e.n.t.......0.0.0.5............(.Bd#.Bd8.Bd..z...,4. .......$>........4...4.@..7.....................D..n4..o4..p4...4. .F
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):20480
                                      Entropy (8bit):4.049278276834875
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:AA5BD62432F5FB47E9E15569543BFA98
                                      SHA1:18EF091B46C508B9E3F242F1FB3F4DBF90D280BC
                                      SHA-256:01F9750FFE1F436B37C619295A0777CD4FAA63ABD5D9F2BC80755A561C490208
                                      SHA-512:647D8F7FD502BA4BB6CCCA5AA0440ADC71E3B628FF04ED4ED4A3C91C3F7E4EC94195253F35F9C787E05B76BB367932544CCC803301E72FF08D10FE47C67A1BB2
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:N...>.......L...d... .... ...9..N...>...........d...h...@...@;...........................................................................................................................................I.......I.qk..B.....LZ.|.......|....e....|9.F..|....e....|9.F..|..J............QJ....I.qk..B.....LZ.I...........J.......J.......J...........................................J..j....J..T.7..J....~..J.......J..H....J.......J......&J..........'J..2J....z...,4. ...."......$>........4..`..7......L.o.w. .P.r.i.o.r.i.t.y......................J..:J...J....z...y.. x.. ...........$........2..72..7.....*...o.e.L.o.c.I.D...o.e.L.o.c.C.o.m.m.e.n.t.......0.0.0.2.3............|...z... ..$........................................2..7.........1.h...?.......?...?....rA\.-?>...o.u.t.l.i.n.e.L.o.c.I.D...o.u.t.l.i.n.e.L.o.c.C.o.m.m.e.n.t.......0.0.0.4........?ff.A......'J..%J...J....z...,4. .......$>........4.@.4..`..7.....................D..n4..o4..p4...4. ..1.......J..*....J......%J..#...'J..&...9J......
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):20480
                                      Entropy (8bit):3.2136473082750383
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:35D42F48078806988C4A2F69C829CFC9
                                      SHA1:B9ACE2495BD999DF21CB66E48FF7F28DF66698B5
                                      SHA-256:AE2D9959235BC987FCB5EC765C5ABB60B7B60298B7D3B572D90D8C466399F809
                                      SHA-512:F25339E9FD7ABFAF80C04FCE5FF62EA6650BFB60156B3299C677838A83A1F55984807A334D72D22A52D1E3337FF80005E185F83833272499C175F8F64921AD91
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:2...>...........v........ ...-..2...>...B.......v.......@....,...........................................................................................................................................I.......I.qk..B.....LZ0.z.P...0.z.y.].&......=0.z.y.].&......=0.z..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'................S}M_...."........N...^................'V....L....8..p.............................'V....L....8..p.........'V....L....8..p...........S}M_....".....................................0.z.....0.z.....0.z.........................................0.zj.^..0.zT'...0.z.....0.z.....0.z..-..0.z.....0.z.....0.z .L......0.z30.zI0.z..z...y.. x.. ...........$........2..72..7.....*...o.e.L.o.c.I.D...o.e.L.o.c.C.o.m.m.e.n.t.......0.0.0.6.............0.z30.z90.z..z...y.. x.. ...........$........2..72..7.....*...o.e.L.o.c.I.D...o.e.L.o.c.C.o
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                      Category:modified
                                      Size (bytes):53259
                                      Entropy (8bit):7.651662052139301
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:2EE369ABB7936F8C28FF0ABDD224EA05
                                      SHA1:FE9D304A7B49E31EAE439369ABC548E265149636
                                      SHA-256:FB12D59B8BE911247BBAFDD416852E8B74B028005A141CB4DBBBA109B4B6ED2C
                                      SHA-512:5CF396CA472C32AE988600176114106CB1619404DD899A3867A5AB43DC90583B771EF69B14EF50E56A21F038BF51D8463C6ADD2DE9D4CB523F6290E24A4DECB3
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d............................................................................................!1..AQa....q........"2..R..Bbr..#S....3$.....C.4v..(X.DtEUV.....cs..Td.5uf'Wgw8Hh........................!1Q.Aa....q.2...."R...r..3.t..U...B#S.4ub..C$d.5Ee&'7c.D%sT..............?.....?...k,lk^...M".Yo5.Qp.&s}b.m.:...W.x}.*.a......N1..d-n.-..^..b..TZ.W..."....F....^......ve5...^...2.:i...........~u2pK.z./&..u..L[I....Y....@y{|>..MN=:....Q[..H....a........|%..4fV....).....^.9b.f...F...p.=.W...aZ.........Z.t.n.....z3..[..lVh..\.N-.._.sK.y.._e.G.jig.a.7^....u...*.p.5.a.].........u/u..D.yl.XA..f.z..~.x.....N.....b=.uv.2.t.'.N.-.H..n.v.a.A[.Z.....T2...._...:....h..l.E..sm..a.3I...RE...fWb.Ek.0.#.)..Y#T...........u{....U....s.].7_H.2.`O6...P......}..4LR....]4.mid...
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4096
                                      Entropy (8bit):2.493294569659402
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:91160002A76920D0B1DF2DF4E6D82C6F
                                      SHA1:F556AB18C0651F18551C1E08506B22B4EA470CF8
                                      SHA-256:1EA1AF73AF4CDB66217EE64D861FAFC79FA28462D1ACC2A9DC47ACCD5EF1E216
                                      SHA-512:ECB90AF7748D18780C1345E1E3D6F48DCDA46758EEA7F5206BD8B52D9B8157C999516D93030DB498C7BD9FAE82CDA2218EC72BEDC9B6C3263EFA03CBED01813B
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:..........................................................................................................................................................................................................3.......3E.....- M.M.$..@.......@.}.GL...a.v..u....T$........u........O..,.c;.>........@.}.GL...a.v....@............@.......@...................................................@..k....@`....s....8..s....Q..s....[..s....b..s....o....................4..~...1...(...(.......C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.M.i.c.r.o.s.o.f.t. .O.f.f.i.c.e.\.r.o.o.t.\.T.e.m.p.l.a.t.e.s.\.1.0.3.3.\.O.N.E.N.O.T.E.\.1.6.\.S.t.a.t.i.o.n.e.r.y.......S.t.a.t.i.o.n.e.r.y.........1.......S.t.a.t.i.o.n.e.r.y............s....1... ..$....S.t.a.t.i.o.n.e.r.y.........H.......H)G...&.?..=@0u.......u....T$........2.................................@...H.u................................u....c..,.......................u....c..,0..............T...B.Y....Jh...............s...s....1... ..$....S.t.a.t.i.o.n.e.r.y...
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:ASCII text, with very long lines (1299), with CRLF line terminators
                                      Category:dropped
                                      Size (bytes):20971520
                                      Entropy (8bit):0.014817384403292295
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:2DA6C0B9F9E6E36DE685AE34F3BA7EE6
                                      SHA1:A2D6E14A57BE1DF5F1F1B92887E7D694831FDFB7
                                      SHA-256:6C224E7A2E8E352F0F6B49A520CB1A9805BEA71365E9E7AFC6530B400D7BA886
                                      SHA-512:9AC73D28AF62E054D83D0FBEC421A2F4AEE66ED7263056C0D6DCFF99DDBAF81B1D350A7BFACCEE0EA8A486F2F74EE0A52A7F7471F1D2CB1E9D2576D51E64AF2A
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:Timestamp.Process.TID.Area.Category.EventID.Level.Message.Correlation..07/11/2024 21:44:08.216.ONENOTE (0x12D0).0x12FC.Microsoft OneNote.Telemetry Event.b7vzq.Medium.SendEvent {"EventName":"Office.Telemetry.LoadXmlRules","Flags":33777014401990913,"InternalSequenceNumber":20,"Time":"2024-07-11T21:44:08.216Z","Contract":"Office.System.Activity","Activity.CV":"56pljx5n/UKtG8P+K8ayMw.6.1","Activity.Duration":184,"Activity.Count":1,"Activity.AggMode":0,"Activity.Success":false,"Activity.Result.Code":-2147024890,"Activity.Result.Type":"HRESULT","Activity.Result.Tag":528307459}...07/11/2024 21:44:08.216.ONENOTE (0x12D0).0x12FC.Microsoft OneNote.Telemetry Event.b7vzq.Medium.SendEvent {"EventName":"Office.Telemetry.ProcessIdleQueueJob","Flags":33777014401990913,"InternalSequenceNumber":21,"Time":"2024-07-11T21:44:08.216Z","Contract":"Office.System.Activity","Activity.CV":"56pljx5n/UKtG8P+K8ayMw.6","Activity.Duration":500,"Activity.Count":1,"Activity.AggMode":0,"Activity.Success":false,"Data.Fai
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):20971520
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:8F4E33F3DC3E414FF94E5FB6905CBA8C
                                      SHA1:9674344C90C2F0646F0B78026E127C9B86E3AD77
                                      SHA-256:CD52D81E25F372E6FA4DB2C0DFCEB59862C1969CAB17096DA352B34950C973CC
                                      SHA-512:7FB91E868F3923BBD043725818EF3A5D8D08EBF1059A18AC0FE07040D32EEBA517DA11515E6A4AFAEB29BCC5E0F1543BA2C595B0FE8E6167DDC5E6793EDEF5BB
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 17x608, components 3
                                      Category:dropped
                                      Size (bytes):1873
                                      Entropy (8bit):7.534961703340853
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:4FC8500BD304AD127AF4B5E269DFF59B
                                      SHA1:9A5E3432358A0FCDECE86AEB967319B93A65D14A
                                      SHA-256:B4DAA90D5A53FCBC85119050B5B76962443C4DD18D7F42CDC6D4E0AD8EFAD872
                                      SHA-512:E5E07054A522EB91EFD39722AFB3776389632B8F5F923C1D29796716D68CEC93BE5E44F79913804CEC7ED631FF520CBBBAAB841E01FB90AF8E8ADF84DCD47481
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.............C................................... $.' ",#..(7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222222222222222222222222......`...."........................................>.......................tu.....45.!#$%1s."fr...2Fq..AQe.Eav............................... .........................!AQR.............?..e4.bbu."m.G......u.S.-Qq.b.a..'#..E.......u.|:.f[O..jS.S.&....=.....[.....S...N.~~...'...q....N.T.Oyf..a.6..%.I.1j.e~.4..[5.WW.Y..Xp.gn...u.......Gb.O.W..k.!mJgfq....~.F.......m..}bn4.5........s,F...z.b)..O..*...5).-.-\....=`.fP....%...A..Q.&..9.....QQbD.%.:u.f...r$.10..W.F.T..MI...9...ZQH._..).....D..n.F].........*.:.j...!6Z..S....0...B.6..Ga..S.O.....U8S_.J.>...i..?..<.P..........M..F.T.C..7.E...`.4BKcMh1j....4y...+.|.^......2[.WG.W..+......E..r/V^".R...."..6..hht..f...........;E..Kx....)}Le.A.x.>..$/).._S.n.L......}..H^Sw...2. .v.io...../.........x.>..$/).._S.n.t^;O.....n...[.S...h.v.io...../....:/...[..7yK.c-
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:Windows Enhanced Metafile (EMF) image data version 0x10000
                                      Category:dropped
                                      Size (bytes):33032
                                      Entropy (8bit):2.941351060644542
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:ACF4A9F470281F475EA45E113E9FB009
                                      SHA1:B20698DDA5E5AFDD86BB359A6578C9860D5DF71F
                                      SHA-256:5DC2367A80588A7518DB5014122510BF0FD784711015EF83A8718336584F82D0
                                      SHA-512:998B7DB9DB08FD15A293267E2371052E436E024AF8D34F96D3C8FF04B1316678DFC1674C921CB404121FF381A4FC39DC759E6698F19D42A6261CBD39469B0A08
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:....l...........................Ac...... EMF........$...................`...E...........................(...F...,... ...EMF+.@..................,...,...F...\...P...EMF+"@...........@..........$@..........0@.............?!@...........@..........F...(.......GDIC........................F...(.......GDIC............^...........F...........EMF+*@..$..........?...........?.........@..X...L........................."B...B...B...................?...........??.....n............;...<..@<...<...<...<...<...=...=.. =..0=..@=..P=..`=..p=...=...=...=...=...=...=...=...=...=...=...=...=...=...=...=...=...>...>...>...>...>...>...>...>.. >..$>..(>..,>..0>..4>..8>..<>..@>..D>..H>..L>..P>..T>..X>..\>..`>..d>..h>..l>..p>..t>..x>..|>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...?...?...?...?...?...?
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                      Category:dropped
                                      Size (bytes):41893
                                      Entropy (8bit):7.52654558351485
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:F25427EFECFEE786D5A9F630726DD140
                                      SHA1:BC612A86FF985AB569ED1A1EA5FFC4FDB18FC605
                                      SHA-256:5A36960DF32817E8426BD40A88F88B04FB55B84BAEF60F1E71E0872217FDB134
                                      SHA-512:B102F34385196D630F198667E874F25ADBC737426FDAE0747EC799B33632E5DC92999C7C715DC84D904342738930267AB1709870BDAA842243E4C283FE5E1554
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d...........................................................................................!.1AQ....aq......"......2...Xx..9BRr#.b3$..&..g.8....%F'G.(H.Ss..D5E..v..W..Cc.deu..7w.h.).....................!.1....A..Qaq...Ttu.6..."R..5...2B..S....bcs.Dd%&r3C...#$...Ue.............?..R...%.R...t.MQ*.l...v...V]..n...Zw....M....4..F.&&bb0.:]l......ay.r<..3.l.Q^.........I54.N2.8..2s...w..r6.......[1Zh....O...9..>...B......x]...r.\.\..v..~....y.QT.3.......=....r..}.l.....o;....M..C1....w)...+o1f.]...MoA.E..s5..i.\....miGsy..m\.Zj....I'YU.\tU6La5v.>.K..m.]1.......k..0....</5v.V7lY.e.vV.+./[....f..u{....s.}.Rb.Z.....Y.6]..m....V.\...Mr.=r...K...l..%..m^.......X.(..fG..[F*ly.jL.a4..vs..o.e..q.9km..w1.yg.....r_.*h.n..5i.-.{Y.l...<...'Or.s..Z....../JP.....\FV.S..............m
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:11:38], progressive, precision 8, 577x757, components 3
                                      Category:dropped
                                      Size (bytes):84097
                                      Entropy (8bit):7.78862495530604
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:37EED97290E8ECB46A576C84F0810568
                                      SHA1:18D9FACB4CFA3CBF63B882CABCF30B203EDF4126
                                      SHA-256:140DD943D0F0CFE6AAA98470B7D1A7CB62CA02CB1D8F522DD2AC77433232EF41
                                      SHA-512:E0F57314C136211B8253EB2AC0093DED82198E7170D4F97C40D82FD4EC4123D2AAFE3EB4EBC3E7523C4DF4D77619408773871BDE15B6DC6C4049C71D5B9D4222
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....H.H.....hExif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop CS Windows.2004:03:12 11:11:38.............................A.......................................................&.(.................................2.......H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d...................................................................................................................................................z.."................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?....b.xH......T..I...S.q.~..../s.R.x.....8.a..vE.5...-.G.A.4...._......$K..d.@NC.q....J.....>e".I.%...I0).R.I$........M3.F .
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                      Category:dropped
                                      Size (bytes):95763
                                      Entropy (8bit):7.931689087616878
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:177DD42CA99CAA2CCBF2974221680334
                                      SHA1:35FD86B3DD082A6D4930C67BC0E05D3B5817465A
                                      SHA-256:525A857D0EDA855A64D3619DF58B1C2D013A73E60FA0D49B155ECFCB2C134C7C
                                      SHA-512:6FB6D9A6C97B1115C3246690A2F339CD612899AC25ACBA00296EAEAA0A1D094E7339D670969764FE23EB7C08FCDD01C6F78FBC0735D504D5E02AD342901719B3
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d........................................................................................!..1AQa...q......."...2..B#Rb3..r$...6..C4....Ss%5...tu.c..Dd.EU7....................!.1.AQ..aq......"r..2...4Rb#3$B.Ss............?..H..dV....U..-..0]Cp.%O.Z.Y.e.=/.q.....j76.w@s...5.&&&5...n..w..>.1....;.vR..[.......=.......KtY]u3.g18...).r....&.IZ'.....g..4kY..X..b.......y<...r1........e.._...X...w....op.m%Jr31...S.Vo.._....OI\]....F..V-....\...2j..X.....y.p.$4.....&#..]..n.V..x..P...F..C.f....])..~..Z\.....,..#..v..v...2V.k.SuaydO../[.*c._..oTV<Z.s.[...o.x..>....-....v...#....-.X..L.Z./#.XG.-.0......%w..H.@aZ....C.}...N~.;..R......5.D......I.... .R........s.>..ks....(...S...9....2=. :^.. p.+?(....$..Q..I.........=|..`2. v..t......U*.8.u.. ...'...*...2;u....& 3..$.
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 357x69, components 3
                                      Category:dropped
                                      Size (bytes):5465
                                      Entropy (8bit):7.79401348966645
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:8470F9A96B6C6CAD9EE60961E96D19B2
                                      SHA1:AFE1F01FFA4E4CB06B1D770C9C59DA75B434D1AC
                                      SHA-256:2DF453410796AEC7B9EFEC00059B6CE64BCF67313A95AE458BA600EA5DE14811
                                      SHA-512:CAE5C2ED091BA49761F0348516D53491E578FB165F32F93AC7DAD927383E9A398B06229FAC6A8233777DF708E5001AE0037A1FA960293BDA49892C40B37F2240
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....H.H.....C....................................................................C.......................................................................E.e.............................................8...............................!"1...2A#Qa.$34bBDSqt..........................................................?.....`0.....O...3Sd..@..5.0....Q.pw....;....!pN.DR....`0......N^...k.=.u.e.7{.b........?z....zV...M.....P:a.SPj.....WRK.=x.2.h..2..AS..s..A..|.Z/f$D.YX1pr......}G6._.~..)j...+.s.r".{..q..-.^@...#w|.H..*.K)....g...y..`0......2.w@.Ro.d....@...K....}...&... y..f.y.0.|DC..>p.[E.2......v..N.)Z..4.RF.D.8]..Z.|f/..+\ID.r/.o........0i..*.G.O..uj..RN. ....j...xnF...Q.Ls.U.c.D0m....z.k.P;f...b.=..L.hH.,./;.U..`sa.I...?*...I....M.0<.u....!..C..U.T.....s.Q......_..7K..*.....?....R\&=.<.u..oQ}WZ..Yu...{Fe3.h...@.s..mW.G..^....1.W.#[.q2.&u.c.G......`J./..X.C....M;.....3k$}.i.3...#/x.m.Oh.}FH]. ..5NNDIS.-.M~...6..w.d....P.;..k...........v*..T..L.P...s.!B.4..w
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2004:03:04 13:27:10], progressive, precision 8, 102x792, components 3
                                      Category:dropped
                                      Size (bytes):52912
                                      Entropy (8bit):7.679147474806877
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:1122BF4C2A42B4FA7F29D3C94954A7C9
                                      SHA1:3750077A830FE21735A43ABD35C63BA9A4D4B0DE
                                      SHA-256:423B0DD1A93B391D15B1DC8D8757C3BF5725FF2E7A59E6E3140033E2876B67F6
                                      SHA-512:4626EFE2EDED2361D6296B57F994DC434CC9D02357A8A6A67D84A544FB8A1CFE0005EA98F846AB963BED7F2B6CE96BC9181182C9459843A52A98D3A731A4FE73
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....H.H......Exif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop 7.0.2004:03:04 13:27:10............................f.........................................................(.....................&...................H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d......................................................................................................................................................"................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?....]+\.9.9.P.d..Z.?~>.-...]6=....*.......S.9G...b<$..Z..........>.v.o:.o%.e...z.F`...[.wo..z.....k..E...5....G..7.......c2..
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:PNG image data, 50 x 500, 8-bit colormap, non-interlaced
                                      Category:dropped
                                      Size (bytes):2033
                                      Entropy (8bit):6.8741208714657
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:CA7D2BECCBC3741D73453DCF21D846E0
                                      SHA1:E34B7788498E33FFF0CFB00125E6BA9E090F6CED
                                      SHA-256:E9EAD0BFC09D32CB366010CDFEDE1C432A2D1D550CB7332BADAC1BEE9482BC86
                                      SHA-512:7FE2C3654262B1EEBED4F6D83DA7D3450E1BE52500A3964185FC0092041506A237A2728E5D7EEA0A3814E413E822B803B789C49CF744D51816A2E4EDE5B4247B
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:.PNG........IHDR...2.........H'......PLTE........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................[....bKGD....H....cmPPJCmp0712....H.s.....IDATx^.\.W.G...=a.ewA..a.!r( ...%Dc..x.x....N.OO...3=...S...........~.z.D.0...g.2P.7.*M.#'....z.......3TPj.Z.[5....V..z'L3...a.j9..C>..9.z
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:PNG image data, 60 x 336, 4-bit colormap, non-interlaced
                                      Category:dropped
                                      Size (bytes):347
                                      Entropy (8bit):6.85024426015615
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:78762C169F8B104CB57DFF5A1669D2DF
                                      SHA1:9638B71B584CD636834016A635ABF8D9C0887711
                                      SHA-256:E64FDCD0B108737D8B8F7B677029F924031D6BBAA50585D9C3DEF7C7E92ECAF2
                                      SHA-512:5ED899AAF73B72DEC32E171FFA112382667D5BF3FBA98C92E313E66C0A6975EA97068F4CD32B62283F18DBD5345C11E3610F7EEAC2F2DE71FC44593180B9CEAC
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:.PNG........IHDR...<...P.............PLTE......................=l......bKGD....H....cmPPJCmp0712....Om......IDATh......@..aI...B..C..l...^.%.`....>.]..|0.....a...hb...0......q.......p"....;...K..x=...p...y.yy~J....|...\.......y..X.......'...>1...Ky..f....&........N`..f0..b...3.......`Z.3..3.....o.......4.&........SV...4.....IEND.B`.
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                      Category:dropped
                                      Size (bytes):67991
                                      Entropy (8bit):7.870481231782746
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:1271B1905D18A40D79A5B9DB27EE97EA
                                      SHA1:9618608FBD7342DE6C71220A36C3F4995BA9C13E
                                      SHA-256:5B321A4D81BD499B289B1755F6450A42047C494DFBC112DBD56DA4CED2C15C1A
                                      SHA-512:C32DD26047F6B8AA061085B38AC2B8335868E1BFD8731DB65544309223A955FA4BF45B06AC8D244408658F51A1775B6F19FF0FFC804989DE706DE8EB36F1436F
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d............................................................................................!.1..AQa..q..".........2...BR#b.r.3...$.'...)..C%7gw..(.S.W89.......................!1.A.Qa.q".....2...#....B.t......rc.$%67Rb3s&'CUu.v....S.d5.V4T.e.............?...?..Wj.e.e.......w/..E..eOw_.....6......u..C6h.,..;.g.D8Z..-)O..jy..e;.u.g..w..[.L""k'w.......'1'.[......=..P...S.9a.V./O....q=8xk]...........9......F...e9'....9.O.... .&.....p......c.4...mr...?.......L..'.....0....+..|_...POM=7.?.2.a....};.Z..y./....>./.C.<...;.....|.1>...........S.8.o.O...+..n2...k../.X..9...Y...:.....\...Dk......q.K..\.Wuh.!Z?.mu...R.5.A.S.h.0..[..v..+M.....aUi*.k..?#..._...X..R.&]..[..;../]L..f..V......*.e...ut&.#.J.5....c%..o.$..v.<K.6..T.IP.....6X.*.uf..t0^..-.)m$.!.q(.j.f;..WB6.b.B..R.
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 814x45, components 3
                                      Category:dropped
                                      Size (bytes):1717
                                      Entropy (8bit):7.154087739587035
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:943371B39CA847674998535110462220
                                      SHA1:5CA79B7BD7E0E93271463FAEF3280F1644CBA073
                                      SHA-256:9C552717E8D5079BBB226948641FF13532DF3D7BE434C6CE545F1692FA57D45A
                                      SHA-512:812541836C8B6F356A4D530E5CCF1CFDCC4CA54AF048CAC19FE86707CE5EA0F41D73C501821AC627AD330291EF58C040DFC017923A7886CEEC308048DA2CE7C9
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.............C................................... $.' ",#..(7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222222222222222222222222......-...."........................................&.....................U.....1T..S.R.Q.................................................R....Q.a............?..d.. ...............................................+A...Z+E...V+E...U..R.....}........Q..Ah....Ah..b.AX..b.PZ+A...V+E...V..J*....Q...b.Q..Ah....Ah..b.Ah..b.PZ*.(.@z.?.`;2.......................................................Q...b.Q..EZ*.(..Z>.G.....`Z+E......J*....F+D...F+E.......b.Q...h....PZ+E...V+E......J*....F+D...F+E..............[u#...a-...f<.9^[...l0..H..6.Kn.t...&..3a...GG...[u#..8.y6.q..%.R:8....6a.+.3..a-....l0..H..9^M..f..m..3a...GM.q..m..6.Kn.tq..%.R:l.W.lg...[u#...a-...f.r..c8.....f..m..0.....l0..H..6.Kn.t...&..3a...GG...[u#..8.y6.q..%.R:8....6a.+.3..a-....l0..H..9^M..f..m..3a...GM.q..m..6.Kn.tq..%.R:l.W.lg...[u#...a-...f.r..c8.....f..m.
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                      Category:dropped
                                      Size (bytes):59707
                                      Entropy (8bit):7.858445368171059
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:47ADB0DF6FDA756920225A099B722322
                                      SHA1:851946B8C2BD0BB351BAEECA9E5BB6648A87D7CA
                                      SHA-256:EC8CD7250F3D82E900E99114869777EE859EC73EFFABED108815F65742078C3A
                                      SHA-512:85A9920E1CE4A2FCCEBAFA425C925DF33580FA3C3C00178F058539B2FBC0163866DB8A41B320E2EF2CD217F00FFA06A1A831C728D3F9F910C9EAC58B5DA76E2D
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d............................................................................................!1..A..Qaq"....2........B#..R.b3$..8xrC4&'W.%e.(.c.d.5E6Ff..h..SsTt..u...Gg..H.....................!.1..AQ.aq.".......2..st.BR..56.r#3.b.S.4c%...$d.CT............?....3.7...G:../P....z..K.:6..w......6....... .z7...~.....{gdF60...9....{...'[N....m.........z...g{.......7...4..1..=.z...._..p...m..Icd.~.v..9.P..0Z(.<j.......R6zm.....v.z...>x..)=g........zo{..w..f..y.t.....%.D..#.}.I.>).H.QM..cLD..x.../.^y.{.............y.=^.......I.T.......U..0_?...u..og..3.ky..K....6w...Dc......~........ik.z....N...en......_.....x....._u...4.{..P...>.....}.......>.R.....m.....[mt.....}.........|.....m......~....B.F.]C.36..q....yg...{]...+.DZv.9<.o..;..N.n&im.,....w.3...V.s...Y..e#$.
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 76x97, components 3
                                      Category:dropped
                                      Size (bytes):784
                                      Entropy (8bit):6.962539208465222
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:14105A831FE32590E52C2E2E41879624
                                      SHA1:078FA63FC7DB5830E9059DF02D56882240429D90
                                      SHA-256:D0A3A1C3CD63C4023FE5716CBE2C211307D0E277E444D9EF76C7FC097A845FD4
                                      SHA-512:8FC0ED24E8EC14C46EA523D9265DE28F85C5FC57AA54AD5B9CA162E95F79221E2AD3DD67D1293CF756B67F3D3DECAE122254134EA8D4D00DDED02114B5383947
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.............C................................... $.' ",#..(7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222222222222222222222222......a.L..".......................................-........................!A."1.Qbq....2Ba.........................................................1............?.....3.Ty\......vs....>.>..a.W..s89.d...Z}......rz...`...Z.r.do....u.W.%....gf.>.L..xz....B8=w...g.~g."HD...$..IKJ......nn..*ly..I....L...\q...Q;6.KrxZ.,...j$..ZQ..)f...q`.*..C1..cZ2]-..\.~..J.....^..(.f..9m?..C.NI.UL..X.fy.Z.........+n....r."Z...d..R./\.#...kd.D.5.!...h.3*s-+.......Xjt..}i..rK..y.../>u..]N.....Y..J......1.x./.....F6.......I...._3...k.sM.+..v;.%|.f.~.......:y....S....UKovh...W'........lF... .................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:09:29], progressive, precision 8, 609x675, components 3
                                      Category:dropped
                                      Size (bytes):65998
                                      Entropy (8bit):7.671031449942883
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:B4F0A040890EE6F61EF8D9E094893C9C
                                      SHA1:303BCBA1D777B03BFD99CC01A48E0BB493C93E04
                                      SHA-256:1F81DDE3B42F23F0666D92EBF14D62893B31B39D72C07AEE070EAE28C2E6980E
                                      SHA-512:8F07E4D519F2FD001006BB34F7F8274B9AF9EC55367B88D41D24E5824FCE4354FD1290CE4735E43930829702ED53F41DF02C673904A7091E9354C28E029AD4EF
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....H.H......Exif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop CS Windows.2004:03:12 11:09:29.............................a.......................................................&.(.........................................H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d......................................................................................................................................................"................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?..-O..s(...gO..@...[..+....+...H.'m........L.......@.......[k...S..O..p.'{X..3......]W..w.+.V....[.-.....2..i..i$.p.
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 700x114, components 3
                                      Category:dropped
                                      Size (bytes):2266
                                      Entropy (8bit):5.563021222358941
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:DB8A181E3F0EAD4A9472099E42ED6BE3
                                      SHA1:92096AF05CC6167B1AA816811A1160B809393FA2
                                      SHA-256:E9746B4E9AE9CE7B3B0068779DB3E113E2DFC9880F25373D745D0E700E69A906
                                      SHA-512:A9E246E10E28D057090BA9F034ECE6131780D7F794C5C9421523388997C7EDFBB49BC32B863B6C6668911B359C304AA54969B48CB9234950D5CECD2A6F3EFFF8
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....H.H.....C....................................... ! ..''**''555556666666666...C......................&.....&,$ $,(+&&&+(//,,//666666666666666......r...........................................5.......................!1AQ..2a...."Rq..#3BSr..C..................................................................?...X.....U...j...F.W.V]'KV.uWt.iT...{.......`.(.....V%..=.....z......V..ct+.U.B...@.............................................{.....5.........0...x4....c..;...........+......|.7E.%.9.1+}..d.........+.V#.P.HUL.E...g.li...8.>U.";0pi.]5.\..zo..."@.........................................y.6.mLN..S.....@...i..A..p.......~|V9.+.Xy.........+,L.....7Z7..p...-X...\.....:-...i....v.1...-..H....9.zk....l....^.......:.."^.t.Q.F...X..B..$............................................a.%f&3..1.5+.X..'b7bwr.).e.x....!...H...aa_..kD...b..g..p..K^.k..qX.[,.........Q...U..x...YMvj...w..:k.....j.W.8..4....c.u.}m.....o.=@.......j.S.t.|.....5h.y.%.~...G
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:PNG image data, 3005 x 184, 8-bit/color RGBA, non-interlaced
                                      Category:dropped
                                      Size (bytes):12180
                                      Entropy (8bit):5.318266117301791
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:5C859FF69B3A271A9AAB08DFA21E8894
                                      SHA1:3156302A7450ADFF4D1B6EC893E955D3764D4DD4
                                      SHA-256:B4A8E9A67EE0B897615AC4CCE388FFC175AB92D9E192E6875C79A4E7C1B5BB6E
                                      SHA-512:4CF518136EEBCA4F400A115D9B7BB0CAC9FA650BF910B99E15F04A259B7D3EFCFFD6796886FE09DB08C37C332B14BC8500845C09C8EAE1F2306F90E98D3C99E0
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:.PNG........IHDR..............;j.....sRGB.........pHYs..........+..../9IDATx^...dW...S=.dL$.............-.`...'...x.7.D...(...$.?cO....9S]=.v...Z.......{..wNuf.&.....a.k5~...._..\.yk..v.....}{._.Q...5...._9o.n.....}7.].1v..t......q....3.<..0<.p.......0....s...... @....... @....... @....... @....... @...X.'..U-..... @....... @....... @....... @....... @......,I......+..... @....... @....... @....... @....... @........z...r.. @....... @....... @....... @....... @....... .$.C.KJ[.... @....... @....... @....... @....... @........&`.=X`.%@....... @....... @....... @....... @....... @....../)m.. @....... @....... @....... @....... @....... @ ....`.)....... @....... @....... @....... @....... @....K.0.....J....... @....... @....... @....... @....... @...`.....\.... @....... @....... @....... @....... @......,I......+..... @....... @....... @....... @....... @........z...r.. @....... @....... @....... @....... @....... .$.C.KJ[.... @....... @....... @....... @....... @........&`.=X`.%
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:05:55], progressive, precision 8, 612x618, components 3
                                      Category:dropped
                                      Size (bytes):68633
                                      Entropy (8bit):7.709776384921022
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:41241EE59AB7BC9EB34784E3BCE31CB4
                                      SHA1:98680761A51E9199CF3C89F68B5309FBEC7EE3CB
                                      SHA-256:035B26DF61855A3F36DBD30FDAB0C157C04C9E8AE2197EA4D4AEB3E82E6A4C2B
                                      SHA-512:3EE331D5BCEE4AD5D3FC9661D4AB4053F7D351591A094334F963C33C9D0E32CCCABE9334AD7C308108CE99617E064FE848DCD469ACD8D83FBE5C4452DE523D8F
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....H.H......Exif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop CS Windows.2004:03:12 11:05:55.............................d...........j...........................................&.(.........................................H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d......................................................................................................................................................"................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?../$.W:SZ./...9.....-...u......r.....].c...@W_.7...+......v.+PD.I..-<1.pDn-\.....p.$....0.}V....\..>.~..XN.o..l(E....ik..o.
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 105x441, components 3
                                      Category:dropped
                                      Size (bytes):2268
                                      Entropy (8bit):7.384274251000273
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:09A7AE94AA8E517298A9618A13D6E0E2
                                      SHA1:FA5181A7414BA32F816BF0C4278EC20C615E8B1A
                                      SHA-256:3C68C7EE798E62A4A99C740153F3980D7DF029605C843410942C7F85E794823B
                                      SHA-512:074E9A2BE2039D0AFEAD360157550B934FABD0CB86B5AF476C1FBC885EE60331F5A68EAF70BF76E23C8248A20FB900346839F4AA8892370B5889E64948DCC6E2
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.............C................................... $.' ",#..(7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222222222222222222222222........i..".......................................3......................!.A..1Q."q.2BRa.b...#$................................... .......................!12AqQ.............?..D.z.4....;.....7...3.t<!..d.O.....+O+.;.z6.4cz7E.........U.Z)-..@..y...........}(W...<.xv/...5.ew......yN....n.Tk.Tm.Ty.vA=...T..U....h...e.8.5%....'......e^......L.g.$.~e..O.._...... .F`.....xnL.<.......]jfv...}..\G..c.......-%...#.C.|.].`..^..W..c..B..5D.QSTaZ.5A=....BU..z%.4.h.6..=..U...W.$..l...7.:...........IPQT_...~..i..x....~.l.|.n.J..TV.21.Tg.....................j.z!+.-............"j.j...)*..TT...."....T.Tc.**j..............j.z!*.h...&.&.&..e.%..TksTW%G.?".l+$..c._9..[x...TU..........i~X..#'.qm?ttO.....}*.i...q.....9..r..?..W..d.w...f;..q...tZh..0.....2.......OD%Q-.......$......56.K.O...y._..*_C.k..p9.p..O..vu...'........0v
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 728x77, components 3
                                      Category:dropped
                                      Size (bytes):2695
                                      Entropy (8bit):7.434963358385164
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:B23DE98D5B4AFC269ED7EBFDDECE9716
                                      SHA1:10AF507A8079293A9AE0E3B96CF63A949B4588AA
                                      SHA-256:646586CB71742A2369A529876B41AF6A472C35CC508D1AE5D8395D55784814F2
                                      SHA-512:BBACBE205EC0A4F4E3AB7E2B1DEE36FCF087DDF77C7D18B53AEA4B15984A47C64E19F9B8D8FA568620619CEA0361D94FE7ABEA6E502EC6ECAEFE957F42ED7EE8
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.............C................................... $.' ",#..(7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222222222222222222222222......M....".......................................,.......................1....!ABQRq.2a."CbS.......................................................Qa1A............?....{............i........l..-D.q.~..|cS.S...R\..d.8,!.....]f$....Q..di.;~5......vj......MqCe..=.*.f^..=.}.Cm]qCd..s=..u.e..v..t'.,.....S.s..N...>.d4'.,..k...N...d..9....G...y....6J.Y.l.{Vf...^B..i.3.z....:5W#4@.S\fj.%..Mb.5.v.5......S.E..#.v.I.....I......m..H....D..|.Y|...W.Wf..o..U.0.E..@.T.....................................'.S../...Z......!J..1K..rI...T.f.>.+.N..o.....\..^u........e..q.qK.GXP..-...F8".;5J...]Y......j.a.,R.......J.N........z}<qu..J.)`.}X:..}.............B...[. ......,B.).b.......(Y.O....c\.o.e&.W.#Bo..N|..N8.#J.>1D.1..b.&....q.#..UT%,.d.....m&..^...VXA..b.nbTV~.....^........q..#./.I..=Q..=..Y.*.Ib...VZ+......Y.........'.
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:PNG image data, 39 x 600, 8-bit colormap, non-interlaced
                                      Category:dropped
                                      Size (bytes):2104
                                      Entropy (8bit):7.252780160030615
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:F6C596F505504044DF1E36BA5DA3F09B
                                      SHA1:BCF17EC408899B822492B47E307DE638CC792447
                                      SHA-256:EDBB86F160050FBF1F9860276802BAE292DBFD0BC98E3EA90D43D981E9F0C54A
                                      SHA-512:E8D067A1932CED8746FE7D665EEC34EA92A98AFF3DF26FFA9DD02742DDEA3C5654124A88A649FA33DB596F96A5FC9CB2C693D03132F1C8B254ACB56DB4763BD8
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:.PNG........IHDR...'...X.......:....PLTE.............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................{.....bKGD....H....cmPPJCmp0712....H.s.....IDATx^..c.%i.F...m.m.f.m.m.m{&....X...9.....M.WUW.d.N.O...E$...$...)H....n....N.k..v.....v1L[w)w.}..!...Y.X.V.D.......[....;..[..;....
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                      Category:dropped
                                      Size (bytes):40884
                                      Entropy (8bit):7.545929039957292
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:7379775A1E2AB7FAB95CFFCE01AE05F3
                                      SHA1:3D3DDFD8AC7E07203561BAE423D66F0806833AB3
                                      SHA-256:9301DB6D2D87282FCEE450189AEACE16D85F64273BF62713A3044992B6B7A9E9
                                      SHA-512:4B5006E620E80D3A146944649CF4CA619782CAD7E8C4CD0D1DE0EBCA0FA05EACB7378DAFCEED3E26F5698B07F19604614D906C8F51F898660E2F129D8DEC6F62
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d............................................................................................!.1A.....Qaq....".....2....BR#S..br...3T...C$.7(Hx....4D.G..Xh.cs..'..t...%...8.....................1...!AQ..a...q"2.4Tt.......R3S....Br...#s...Uu.bc.de..$D..6..C%E..............?...z...;sB.yv...........]t.\...n...../....m....M.=.3G+..x+.....S).*&.J../..8..O/+..sG...p...<!....~.c..C.w..,[oHom.wc-.J.~.......L[..6...'..i_..S;...!Y.z.q].EK..M.x...i.x.+.;.+...}....#......f.)........e6V..p.;........s.)..Ml.J......IU.6...<9+9.^..l..Y...[._...2..^..j.ia...._..3.;...~..<3...;......z.^.......]..Qk.,...Yk...3.3Jy^p.}....q...I...&..t.......;..9.g.GH;..'...%...)..[..y..../...zCn..>...'...1e.Y..;....]..7...N>t..m-.j.............H^..T\.q.ru...}...eTn]I'r.^].#..wOY....v
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                      Category:dropped
                                      Size (bytes):55804
                                      Entropy (8bit):7.433623355028275
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:4126992F65FE53D3E3E78F6B27FD49DC
                                      SHA1:BC0D76B69310DA9B909D3EE4CECBFE5F386BFB45
                                      SHA-256:3FBE3C1C238BD7DBC67F8CFF5F3BDDFD513C96A9851B9616477947D21DFF4B2E
                                      SHA-512:624853F5E56D224C8188F122B2C4724F867D4099E7FAAFB9C945BE7E2907900ADCF4AE97AB08909CF94E96FB6F381E3B6396D560D93EB2731E4E69CBFE628F10
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d..............................................................................................!1...AQ.aq"2.....BR..8x..r#..9b....3....CS$.'.cs.......7Gw.(.4%5&..Wg.h......tEVfv..H..........................!1A..Qa.q...."2..u6....BRr.#...b..3s..d...7.Cc.$Tt..S4.5Ue..&..%.................?...,...8..{..S.y.N....%..q.8..H[5....o..xg........)c(.eO.YO..._D..x.U.....%.S.r.r._.^..Su.h.Q.t.:.#?....x..B.S...Q.....oqF..%..8'.qx....%.2JKjF..{y.w0.*a.RMb.c.Q{%....eW'..[IV..'ZW3...[...MN.....rO.:....$.i..7....Vrrr...I.r..M..Qo..j....q.^...N...J......%.J..)F...>$.....u........o...+......[...*..t....R}.I..R..S..GB..:......).6_[^Xft...F.1.....zP....,.#....MG.T..Q.F.....)Fi../.I...,%.voEb.b.Z..V3..FT.}..[Z{....wd.z.e.....QwW(.).t..\..'....:)<W.<..&k...caRT.X(..K.....:f...]...q..
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                      Category:dropped
                                      Size (bytes):34299
                                      Entropy (8bit):7.247541176493898
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:E9C52A7381075E4EBC59296F96C79399
                                      SHA1:BE295AD24D46E2420D7163642B658BF3234A27EA
                                      SHA-256:D56CEFE9EE2FAE72E31BDBA7DD2AA4426EA22E3CEB22EF68C8F63F9F24D5A8BC
                                      SHA-512:95CC96DD4459EBAE623176033BA204CCDC50681A768F8CBAE94C16927D140224E49D5197CAE669C83C77010C5C04C1346CF126BEF49DB686F636C5480342A77F
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d.......................................................................................!.1..A..Qaq......".#4.2r3.$.%...B.5U&6....Rb.Cs.7..cDTEFVf'...S..dtevw.u.........Gg.....................!1..AQ.aq.2....."#3.4....r..BRb$CS.D............?..5..............#....v.q.m.}\..{....;...r....h.....J..q|..'.;\..6..v......e...../.k..|.8..i..|..]..3e.m....n..Z.GS..n".y..w.-...[a...7A.....i.4.)9\..~C...=.........s..\V]c.D1<./.g.l.&v..~.h..]....zb>G..y:vNS.\......LU....t.{*..Z#.?..v-...wn.rR...P.....y\=.v....../..9_...m4...V.|.+.o.#.......xj....}..>.s.>C...m.[;.>.p...=^.i.X.(..1...{.F#N.W...xi.z...4..u[{...yO.....8..}\..2...KlX.nbya...2.&.F...R.b.k.7.GV.x.h.y\.Q..O<\>......-...=...r......\......Z.Z...Jf.'....z..Y.q>.p....o..K....h..R..c.lg?......A.Z...Y.q3.L|.'5...
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                      Category:dropped
                                      Size (bytes):52945
                                      Entropy (8bit):7.6490972666456765
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:AD003F032F32FAC4672D4CE237FA5C5B
                                      SHA1:AE234931B452F0D649D91291763B919CF350EA49
                                      SHA-256:ADB1EBBE18D6CD8FF08AA9BF5C83CDB83BF9AA179698E34E93DBCDDE12F04D32
                                      SHA-512:ECA25FA657ECE3A66D3E650628E0F65D3BADD38864C028AB6553950A1A66D7D55482C85E9E565573E9E5AAFA91C2D53235971C644A266D41EB69F8E72E3A843B
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d.............................................................................................!1..AQ..aq....".....2....BR#r.b3$...C.Sc%...s5E......................!1.A..Q.aq"...2...#...B...Rb3..$..CSr...6............?......y_N.e.H7?........W..w....k|...S..d.4.>.RW5z.$.i.)V.O....>o...c..*&1.D..O..".ufbb..1...t..u=..K...m...~.....F..-.fb:i..=f..C.w.[{..~.7k....;..:..3....4.....$..m]...}....~q...9T.#..7.~..8...q.N;c..ffo.w...W..d........../t_........lWJE..).>..v;:=....Rrw#.m.n.n...E...vm.J}2N*..|.4...80.#..e....t.J..ZQ.x|g/....F..e....k+vK...M..W.X.e.L..~...j.....kz....=...n:O.:..[.L,.+R...Y..zKNI....,..{e..U.'...}.......|..t.]...~...b4......_.i..../.......m...a..n...v.j.?..Rc.$G|.31..#..$?.........h.w....-... .a.%z..u......u.A....Fm..J.......G..[...w.....:....w/.
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:PNG image data, 85 x 470, 8-bit colormap, non-interlaced
                                      Category:dropped
                                      Size (bytes):11197
                                      Entropy (8bit):7.975073010774664
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:DDC3CC30794277500EFE4BC6667EC123
                                      SHA1:EFC9642C1F95B5FC38764476AE481649C016FA0C
                                      SHA-256:7F5B660A1A0BF46C75AAF19B4F77A0E086DE003EC03AFC1F58D871D55AA5BA9E
                                      SHA-512:25232A84604C3959634D33090238FEC8D51E40AD84EB3A08BB8522A81BE1E83378649C014E98E1DFCDF46B7BFAC92D8D2429211CD11D7EE0334C9C3DF7C1B6A6
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:.PNG........IHDR...U.........1x5.....PLTE....................................e........................................................s...............x..........................o..............................................................................................................................................................~.............................m...............................................j...............................................p.......z......................................................x..............|........................................v.......................y..........................................................h...........................................................................P..{....bKGD....H....cmPPJCmp0712....H.s...(SIDATx^.}i@S..N....h...!..)....AI%..p.L."a..)..`U..,h..:O.b.:.j+.Z).b..zN.s..{O...&|..N}...${....~.....k}.[k}{.o^.D_..W:35ly..7rL....6n0.A...b
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 613x144, components 3
                                      Category:dropped
                                      Size (bytes):29187
                                      Entropy (8bit):7.971308326749753
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:DF99CAAAB9A7DE97B63343E60A699AB6
                                      SHA1:B84334135CFB73BC6EF55F85926770D5AC6DFEA8
                                      SHA-256:74C131777E7C437FD654427417097BC01B0813BA8E1E50E4B937BD50A1BEBCDB
                                      SHA-512:5D15AAAA8B71DDFE01A7C0ADE16D9E1F5E9AAE484BCD711B38CCB103ED9564CAAC23A0031471167B660E15972D70179C2A387509B213C05D60261042A0456025
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....H.H.....C....................................................................C.........................................................................e..............................................`.............................!1Qq...2ARa..."#.....3BSbr...$4C...Tcs......%&DUd...E....56Fe....................................H........................!1Qa..Aq..."b....2R...BSr..#...3..Cc....$%4...............?...b.d.8T1.;#.S.DO...~.R.......3.xe...z.6..."m..k...;*.'.f.5^.....m..<$....8.R.j.D.v..>...*dT..vGbt...I......sEWp.r3.. ..G...6.....w...l.S..q...b.....-R....^Zu5+u6...A..Z].:...5..Uzn.,l.L.....?%.*.S.+zVg7.=.s.Q.....8..:,c.......ZE...>'IF..W.0.d.......c.e.d.V.t..S$.DNR.[....g..#i.$. .U.SK2.....k...J5u u\R.....T.[4..A.O..,.T..................] .i...B.m.^f....._...{S.....<......:..|D...+...NA....Y.^f.1|..%K~1..B..^...S..v=.c..g.tX[..kTJ..t.gr....R..@.F....5j..2.K.9..g.1N.....*.U...^w......>+.l.v...@N....%Qd...t.Ni.....0;lggm...K".+!.,.....[J...>..?f.]._;
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2004:03:04 13:06:24], progressive, precision 8, 38x792, components 3
                                      Category:dropped
                                      Size (bytes):22203
                                      Entropy (8bit):6.977175130747846
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:2D3128554F6286809B2C8E99DE5FD3F6
                                      SHA1:FC42CB04151D36F448093BDEFE33031A9B8D797D
                                      SHA-256:14FA2D16310485AA1CE41F6D774A3D637E8CF8B03C4F72990155DF274FDB6BD9
                                      SHA-512:D8531247A6E89ECABEA9C4A78F596CCE3493334EDF71AE4F7998FDDD0F80705948609C89756AB56FDFAB6D04DEC5F699A693801A772CA2EE2465BDD2CE5D2D5A
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....H.H.....XExif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop 7.0.2004:03:04 13:06:24............................&.........................................................(.....................&...........*.......H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d......................................................................................................................................................"................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?...H.....Go.Kxn.b..g...........%?_....O......q......7G......%%.V..8zm.].v?...jJ~._..>.......O;........o..rI.A.....n.a.........
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 14x341, components 3
                                      Category:dropped
                                      Size (bytes):3361
                                      Entropy (8bit):7.619405839796034
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:A994063FF2ABEB78917C5382B2F5FA8C
                                      SHA1:BD5C4D816B04A2B6596DFE38DB01228F553FACCC
                                      SHA-256:D72900E8DA72D1A7F3729971AA558E1E9B6E9CF9A0D51E83852E567256DBBFEF
                                      SHA-512:CF2279033DD3EDFE6F6F9E5C517BEBD9A52863EEFD90F57F7A5AE0E0485E705254BE7ED6B50E6CA142669687727AE85E2E6035F69930B75F2E6D3EEFA961EF88
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....H.H.....C....................................................................C.......................................................................U..........................................>...............................8H........59...$%&7F#'Ddf.....................................>.................................58EG........!#124$%&ACFbcde............?...n.p..v..a.~.._.>......#....8.....w.G...&.W...i...%6m..K;...4."...=..?.~......P..O...j.l..AW.jo..,..=d.h.ta..../.."...z|).J.......Ww._..<Wp.3+8...-5...G:..2.D..I>o..K.F;-.....#...`...6..T...M.....OOgV~..5...np...P..TYr...........b..{r.2.9..].DA.%C....=.v.z......CK."..R..l..y}.i..;.{....JzS.....~.?..Z....=c.h~*..p.@(@..G.....O.]...Hsd.xf".V]..S"..w...4e>....3*U.7..|M.x...|\......FD./.cIe.;.bId..+=...w.......[.k>....}.u...j.xZ.....Q4..+.....B....1O~\......I..h....LaXJ%&.w.<C...n/`.W..U.W.U.}~...}>..^.0.J.....@....LN.b.......5W...m].Eu...:....G..:4.=4ixx..@_0=.mab.T.U.....w..~.V.
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                      Category:dropped
                                      Size (bytes):79656
                                      Entropy (8bit):7.966459570826366
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:39FF3ACAE544EAC172B1269F825B9E9F
                                      SHA1:2D40DE8D90BD21D56314D3F99CEF4FBAE3712C0F
                                      SHA-256:70475431CCA3C91A4EFA3B8F04864371D2D3A45696674A1A0562FE9CD8DB287C
                                      SHA-512:3B9F3B32696AB7779864E83DC0C45960114A130BEE0CF4D0643DE57FF952171E5D775AA49141EE31A28A9B5D052B26EB421F26EA736D7EF4B3A7EC812CA411CB
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d.............................................................................................!.1A.Qa"..q.....2#..BRb..r3$.Cc..Ss.4...D%5&..T...'7....................!1.A..Q.aq..."2.....B3.r.#..R...bc$4..D.s%............?..Y..T.o.\......=.a..j..'^..s..[../........Y.......<...(..4.....7y..Ln.[9.cK.ilN...u@$.V.9.V?3..s.KL.z..w.jW.C.............@.~+.o?o8...k....,.m..9.".....q.....d....z.W...q...~...'..e..>..f#...S.....F....pU.......7..N.vfK......S..G.#.....}.c.........RXt.bq1.`.....[+8\.*.N..:......}.....r..........')......Na...&...m......c...a4_%d.............co..0.n.L.Q..E.Lt..y.|..F..4.i(>.._..\.eNL8..?z9I:hLgC.@.p....g.t......'.I!d..?1f..R..........|..4.wJ*..%g..~0bt.....*...v.......O...:.~.>~..o.x...9.@>...s.&.E.0/G.c..t.<..F.t.A.z. ......;.........Gp.P
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 69x630, components 3
                                      Category:dropped
                                      Size (bytes):11040
                                      Entropy (8bit):7.929583162638891
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:02775A1E41CF53AC771D820003903913
                                      SHA1:2951A94A05ECF65E86D44C3C663B9B44BAD2BC9D
                                      SHA-256:83245F217DEAE4A4143B565E13C045DBB32A9063E8C6B2E43BB15CD76C5F9219
                                      SHA-512:5A1FCC24BDD5EE16BC2C9BACF45BCECF35ED895EAC22D2C4EE99C1B7E79C8E8B9E5186E3D026BA08FF70E08113F0A88FBF5E61C57AF4F3EA9BA80CE9F33410E9
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....H.H.....C....................................................................C.......................................................................v.E.............................................S..........................Aa..!12Qqw.....3568rv........".....4Btu.....#Rs.(W..bg.................................D.....................1..2.!4Aqrs....Qa......t..."3BRb....#.$S.Cc..............?...K/h._+.N6.-.a...5...;.r....,...0B.s(..zp..4.%r|q..E.Q^.../...C.R..?u.q8XN.>.e..:..gJ...._.n>.70G,..(........3b.&.5m...Q../...7Ie..k....e.l6..&..`Gt.P.Y^r...=..Y.e...N.B...O.#..J+........u.V;G.'.....V.]8..C.]..........E.....c..w&lX..f..\T.J?...F.,..m|..93........,.....+.R..WG...%.....(@.....p].iEz<.8.^...J.h.....a8P.1......(z..y~.........H.Z^.>..<.....L.k..IG...R.(.%..m....&u...B|.....@]ey.W.J...!d..R.8...[..>8....(.G......!.)X.....,'..F2.Z.t..Aw./..Z..#..i.kK.......b.i...qR.(....RE.............O.XP.#..(...9J..]...,.2.[w....KrW'...tY.......{~.:.+..
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):4456
                                      Entropy (8bit):0.43888406571865174
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:E11377A4D2ABA7C213113CFE83E5372A
                                      SHA1:2819F583A8B418144065F5FF1BA44C9861D4AAD2
                                      SHA-256:6F29AACC457640B3A97E352B486B3D91DC5A5CD8AF5F52F153F743B811BD9A38
                                      SHA-512:66CFC5DEF3D3CA2D11470CE1266158BACE8DE3F0BAB07D4DC1F6D59F9E5F972B9A8F80676A35E33A832245990EA5065FEA1A883341A165330DA2019E0EB7EFE6
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:.%c....L..=../\m..w.Z.K.Z.T?...................?.....I.......*...*...*...*...........................................................................................h...........................h................ 8..EH.c=.W.m...............J.".5.Y............................... :.. :.. :.. :................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                      Category:dropped
                                      Size (bytes):18
                                      Entropy (8bit):2.725480556997868
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:A5E51FDFAF429614FB5218AB559D299A
                                      SHA1:262EC76760BB9A83BCFF955C985E70820DF567AE
                                      SHA-256:3E82E9F60CE38815C28B0E5323268BDA212A84C3A9C7ACCC731360F998DF0240
                                      SHA-512:9B68F1C04BDE0024CECFC05A37932368CE2F09BD96C72AB0442E16C8CF5456ED9BB995901095AC1BBDF645255014A5E43AADEE475564F01CA6BE3889C96C29C9
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:..t.o.r.r.e.s.....
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:Unicode text, UTF-16, little-endian text, with no line terminators
                                      Category:dropped
                                      Size (bytes):2
                                      Entropy (8bit):1.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:F3B25701FE362EC84616A93A45CE9998
                                      SHA1:D62636D8CAEC13F04E28442A0A6FA1AFEB024BBB
                                      SHA-256:B3D510EF04275CA8E698E5B3CBB0ECE3949EF9252F0CDC839E9EE347409A2209
                                      SHA-512:98C5F56F3DE340690C139E58EB7DAC111979F0D4DFFE9C4B24FF849510F4B6FFA9FD608C0A3DE9AC3C9FD2190F0EFAF715309061490F9755A9BFDF1C54CA0D84
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:..
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:Matlab v4 mat-file (little endian) \253\373\277\272, sparse, rows 1, columns 0, imaginary
                                      Category:dropped
                                      Size (bytes):0
                                      Entropy (8bit):0.0
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:4FCB2A3EE025E4A10D21E1B154873FE2
                                      SHA1:57658E2FA594B7D0B99D02E041D0F3418E58856B
                                      SHA-256:90BF6BAA6F968A285F88620FBF91E1F5AA3E66E2BAD50FD16F37913280AD8228
                                      SHA-512:4E85D48DB8C0EE5C4DD4149AB01D33E4224456C3F3E3B0101544A5CA87A0D74B3CCD8C0509650008E2ABED65EFD1E140B1E65AE5215AB32DE6F6A49C9D3EC3FF
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:........................
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:Matlab v4 mat-file (little endian) \253\373\277\272, sparse, rows 1, columns 0, imaginary
                                      Category:dropped
                                      Size (bytes):24
                                      Entropy (8bit):2.163890986728065
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:4FCB2A3EE025E4A10D21E1B154873FE2
                                      SHA1:57658E2FA594B7D0B99D02E041D0F3418E58856B
                                      SHA-256:90BF6BAA6F968A285F88620FBF91E1F5AA3E66E2BAD50FD16F37913280AD8228
                                      SHA-512:4E85D48DB8C0EE5C4DD4149AB01D33E4224456C3F3E3B0101544A5CA87A0D74B3CCD8C0509650008E2ABED65EFD1E140B1E65AE5215AB32DE6F6A49C9D3EC3FF
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:........................
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Jul 11 20:44:29 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                      Category:dropped
                                      Size (bytes):2677
                                      Entropy (8bit):4.00061769053027
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:6BA84EBCF8C8030B6BFBAD00E31CF70C
                                      SHA1:479C5F1D568EFBDE6B16A46B7AF3403DB848F9E3
                                      SHA-256:9E51CF42E89DDAE98ECE1338CE215B8342D3F20113A7629A7E491F777D5951C2
                                      SHA-512:4AB210FDAA769718A2F90E1D36722F6D954A793C3E5196C4CCC2690D977BB246C8D6D765A9B8EA177C6939FBF2EBC27F7A324C059940AA1A98C63C3FA85044DB
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:L..................F.@.. ...$+.,...............y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FWoN..PROGRA~1..t......O.I.X|.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X......L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.V.X......M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.V.X.............................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.V.X.............................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............H.6.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Jul 11 20:44:29 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                      Category:dropped
                                      Size (bytes):2679
                                      Entropy (8bit):4.013489528799993
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:19CA6C759F952866FE32E1DFD82A6718
                                      SHA1:C01428DE66B37524A058FC71C7543DC5E9C5100D
                                      SHA-256:C396679BAA0BFCD00DC2944CBEB70A07F51FF3B04AF1D4DADDE778BE5DAA1847
                                      SHA-512:CB52E3D02BC1758860E3C9EC5BD1936B9A12BD5FF872036A2BC714F5780137CE60ED8928704FB0BEE9CEA2942E165645F475DD97B80C1A23208101B5621B7C90
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:L..................F.@.. ...$+.,....s..........y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FWoN..PROGRA~1..t......O.I.X|.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X......L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.V.X......M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.V.X.............................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.V.X.............................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............H.6.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:54:41 2023, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                      Category:dropped
                                      Size (bytes):2693
                                      Entropy (8bit):4.019796312545074
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:3371E0616FE24DC1F73B5CB5BAFAC53F
                                      SHA1:7D47410FB6E15C5BC8AA272FD2A285CBDF8AA758
                                      SHA-256:FC01F31A7BD1399589FFAAB3244119EA911FB8FC8685A2901DAF21E8A585A65E
                                      SHA-512:7E2C8715987B6C27A9C72CC1A7A11CE16EB324C5145549EA828BC619F48D8E9C4881255FB721BE9FBAFFA0C390957653921F2D3D7A935827247758ECF23406CF
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:L..................F.@.. ...$+.,.....v. ;.......y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FWoN..PROGRA~1..t......O.I.X|.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X......L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.V.X......M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.V.X.............................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.VFW.N...........................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............H.6.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Jul 11 20:44:29 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                      Category:dropped
                                      Size (bytes):2681
                                      Entropy (8bit):4.012632938727151
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:8C673D20F09FE69DE306439C7457EEA2
                                      SHA1:D365E3E481FA077095D4A5E04E62B40E8935A7F0
                                      SHA-256:DA299E26BFAFDE84B4191D4714430C07469302D6483B41AEC069D9C6CCF257DE
                                      SHA-512:0F043B466E2DA54AE030A623092908F07FEC6ABA574FB810758441313D4F46E0682F371A27940C2B4DFDA3C6949E6F990287457A3B779931AE2D9271DBCA160D
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:L..................F.@.. ...$+.,....W..........y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FWoN..PROGRA~1..t......O.I.X|.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X......L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.V.X......M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.V.X.............................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.V.X.............................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............H.6.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Jul 11 20:44:29 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                      Category:dropped
                                      Size (bytes):2681
                                      Entropy (8bit):4.001020313233016
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:6DF28776C9C2B32144EF372937D3388C
                                      SHA1:2467D4C57DB20C733DB5C66E651407B63F21A88C
                                      SHA-256:696E4BCF4F07314DC8B37AB4E01E0B69B5D7B46BB4BFDF54B0EBE605311E8808
                                      SHA-512:528A1F05D6D48CD075085D1D50DD9EFED633C52B61526E0C3942B3EFD3440E61F86B41443164B0A2C73AB7A18338F75BDB27AA98A580DFED4BD174ADC2524884
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:L..................F.@.. ...$+.,...............y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FWoN..PROGRA~1..t......O.I.X|.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X......L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.V.X......M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.V.X.............................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.V.X.............................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............H.6.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Jul 11 20:44:29 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                      Category:dropped
                                      Size (bytes):2683
                                      Entropy (8bit):4.013832489484172
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:17A3740BDF422CCC735F07D566BA6E87
                                      SHA1:0BFC3BECCCB188FF4C3AFE630C5A372A999A4C97
                                      SHA-256:6EEAEBDF1C364A40CAD4AE3BAA27BB17636FF23EBE9E6938A1CC64E6C1AE5815
                                      SHA-512:9B5200E6C0576723F34F5EAA410B8D855A99070ACDB4D8C57BA42EB27C636FDD666C485AAC44A77F57C95471E203C98D405C4F2AC5FB3CBF7EECA7E87779B87A
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:L..................F.@.. ...$+.,.....w.........y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FWoN..PROGRA~1..t......O.I.X|.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X......L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.V.X......M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.V.X.............................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.V.X.............................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............H.6.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Description string, Has Relative path, Has command line arguments, Archive, ctime=Fri Oct 6 08:49:18 2023, mtime=Thu Jul 11 20:44:18 2024, atime=Fri Oct 6 08:49:18 2023, length=172960, window=hide
                                      Category:dropped
                                      Size (bytes):1344
                                      Entropy (8bit):4.631577523045964
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:01A51E5DAA470A04A1A1197BC57CDB2B
                                      SHA1:0612F56C2038F6DA8742D4CA8E6F0CEBB41725F2
                                      SHA-256:2CF9AC333ED4F3E34AEEE4763ACE6017A4989C6DD715F71CC51010445435D7D5
                                      SHA-512:26C16E7F5BFCF26CFCFC9B6330DF149D745D1CEF57F14B86BEDEAA56CA73ADDB656E435A5724072652E96581FEA71BBFC038D15C81D39BED75BA3ECAAFB51D80
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:L..................F.... ...._._:.....{....._._:...........................?....P.O. .:i.....+00.../C:\.....................1......X....PROGRA~2.........O.I.X......................V......R..P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.)...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.7.....j.1.....FWHN..MICROS~2..R......FWHN.X}.....".........................M.i.c.r.o.s.o.f.t. .O.f.f.i.c.e.....N.1.....FWHN..root..:......FWFN.X|...........................cj..r.o.o.t.....Z.1.....FWHN..Office16..B......FWGN.X|.....{9......................0.O.f.f.i.c.e.1.6.....f.2.....FW*N .ONENOTEM.EXE..J......FW*N.X.......y........................O.N.E.N.O.T.E.M...E.X.E.......q...............-.......p............F.......C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE....S.e.n.d. .t.o. .O.n.e.N.o.t.e.Z.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.M.i.c.r.o.s.o.f.t. .O.f.f.i.c.e.\.r.o.o.t.\.O.f.f.i.c.e.1.6.\.O.N.E.N.O.T.E.M...E.X.E.../.t.s.r.........*.
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (65339), with CRLF line terminators
                                      Category:downloaded
                                      Size (bytes):659798
                                      Entropy (8bit):5.352921769071548
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:9786D38346567E5E93C7D03B06E3EA2D
                                      SHA1:23EF8C59C5C9AA5290865933B29C9C56AB62E3B0
                                      SHA-256:263307E3FE285C85CB77CF5BA69092531CE07B7641BF316EF496DCB5733AF76C
                                      SHA-512:4962CDF483281AB39D339A7DA105A88ADDB9C210C9E36EA5E36611D7135D19FEC8B3C9DBA3E97ABB36D580F194F1860813071FD6CBEDE85D3E88952D099D6805
                                      Malicious:false
                                      Reputation:unknown
                                      URL:https://r4.res.office365.com/owa/prem/15.20.7762.23/scripts/boot.worldwide.1.mouse.js
                                      Preview:.window.scriptsLoaded = window.scriptsLoaded || {}; window.scriptProcessStart = window.scriptProcessStart || {}; window.scriptProcessStart['boot.worldwide.1.mouse.js'] = (new Date()).getTime();..;_a.d.G=function(n,t){this.b=n;this.a=t};_a.d.G.prototype={b:0,a:0};_a.fo=function(n){this.s=n};_a.fo.prototype={s:null,t:null,i:function(){return this.s.currentTarget},e:function(){return this.t?this.t.x:this.s.pageX},f:function(){return this.t?this.t.y:this.s.pageY},o:function(){return this.s.relatedTarget},b:function(){return this.s.target},n:function(){return this.s.timeStamp||+new Date},a:function(){var n=this.s.which;!n&&_a.o.a().K&&this.s.type==="keypress"&&(n=this.u());return n},u:function(){return this.s.keyCode},m:function(){return this.s.originalEvent},j:function(){return this.s.type},k:function(){return this.s.originalEvent.touches},q:function(){return this.s.isDefaultPrevented()},g:function(){return this.s.shiftKey},h:function(){return _j.G.a().P?this.s.metaKey:this.s.ctrlKey},l:
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:ASCII text, with very long lines (65536), with no line terminators
                                      Category:downloaded
                                      Size (bytes):232394
                                      Entropy (8bit):5.54543362321178
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:AF8D946B64D139A380CF3A1C27BDBEB0
                                      SHA1:C76845B6FFEAF14450795C550260EB618ABD60AB
                                      SHA-256:37619B16288166CC76403F0B7DF6586349B2D5628DE00D5850C815D019B17904
                                      SHA-512:C5CFB514F993310676E834C8A5477576BD57C82A8665387F9909BA0D4C3C2DE693E738ACAA74E7B4CA20894EA2FEEA5CF9A2428767D03FE1DE9C84538FDC3EE9
                                      Malicious:false
                                      Reputation:unknown
                                      URL:https://r4.res.office365.com/owa/prem/15.20.7762.23/resources/styles/0/boot.worldwide.mouse.css
                                      Preview:.feedbackList{-webkit-animation-duration:.17s;-moz-animation-duration:.17s;animation-duration:.17s;-webkit-animation-name:feedbackListFrames;-moz-animation-name:feedbackListFrames;animation-name:feedbackListFrames;-webkit-animation-fill-mode:both;-moz-animation-fill-mode:both;animation-fill-mode:both}@-webkit-keyframes feedbackListFrames{from{-webkit-transform:scale(1,1);transform:scale(1,1);-webkit-animation-timing-function:cubic-bezier(.33,0,.67,1);animation-timing-function:cubic-bezier(.33,0,.67,1)}to{-webkit-transform:scale(1.03,1.03);transform:scale(1.03,1.03)}}@-moz-keyframes feedbackListFrames{from{-moz-transform:scale(1,1);transform:scale(1,1);-moz-animation-timing-function:cubic-bezier(.33,0,.67,1);animation-timing-function:cubic-bezier(.33,0,.67,1)}to{-moz-transform:scale(1.03,1.03);transform:scale(1.03,1.03)}}@keyframes feedbackListFrames{from{-webkit-transform:scale(1,1);-moz-transform:scale(1,1);transform:scale(1,1);-webkit-animation-timing-function:cubic-bezier(.33,0,.67,
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:PNG image data, 73 x 24, 8-bit/color RGB, non-interlaced
                                      Category:downloaded
                                      Size (bytes):61
                                      Entropy (8bit):3.9821736799861007
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:DC27690DBE7EF4D2D9B30DE1AA4AC572
                                      SHA1:8280AF19D7A1A55390FBFD6BCFE776919DF88431
                                      SHA-256:C2D835404AA2FF9728DFC5BDC338E02AD263AE77755824E6448EF8BFEFFA8634
                                      SHA-512:68A0F2B47B13A6134F8EB32754CF4971D31D41DD141F7BAE22C257EA1326367B4F7D1D4A2639845769840B65D6A47C602EAF9B07B41DE8204AAFBB7141FEA673
                                      Malicious:false
                                      Reputation:unknown
                                      URL:https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/i/8a1bf9aa5f0642d4/1720734272774/38GTeqglHnc-a8t
                                      Preview:.PNG........IHDR...I.........9.G.....IDAT.....$.....IEND.B`.
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:PNG image data, 2 x 2, 8-bit/color RGB, non-interlaced
                                      Category:dropped
                                      Size (bytes):61
                                      Entropy (8bit):3.990210155325004
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:9246CCA8FC3C00F50035F28E9F6B7F7D
                                      SHA1:3AA538440F70873B574F40CD793060F53EC17A5D
                                      SHA-256:C07D7D29E3C20FA6CA4C5D20663688D52BAD13E129AD82CE06B80EB187D9DC84
                                      SHA-512:A2098304D541DF4C71CDE98E4C4A8FB1746D7EB9677CEBA4B19FF522EFDD981E484224479FD882809196B854DBC5B129962DBA76198D34AAECF7318BD3736C6B
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:.PNG........IHDR...............s....IDAT.....$.....IEND.B`.
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:HTML document, ASCII text, with very long lines (3437), with CRLF line terminators
                                      Category:downloaded
                                      Size (bytes):3439
                                      Entropy (8bit):5.12253249098629
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:6635D7000669B3B00D3577DB7EE58F5D
                                      SHA1:7DB793D847EDC78B731185C85AD93BA4761D139B
                                      SHA-256:4E52043A45804E7CDB6C9D09A0F64A4293082E6F32BB3D689BE4822A6E18BACB
                                      SHA-512:FE3D01776B8D98E975D4DB6E956196B0D5602563E0252BD960A5A739D591F3AC96F5F2EF48EF6B49286822D80106932C104B324BD355EBE1D2FEFCB124D5866B
                                      Malicious:false
                                      Reputation:unknown
                                      URL:https://login.live.com/Me.htm?v=3
                                      Preview:<script type="text/javascript">!function(t,e){for(var s in e)t[s]=e[s]}(this,function(t){function e(n){if(s[n])return s[n].exports;var i=s[n]={exports:{},id:n,loaded:!1};return t[n].call(i.exports,i,i.exports,e),i.loaded=!0,i.exports}var s={};return e.m=t,e.c=s,e.p="",e(0)}([function(t,e){function s(t){for(var e=f[S],s=0,n=e.length;s<n;++s)if(e[s]===t)return!0;return!1}function n(t){if(!t)return null;for(var e=t+"=",s=document.cookie.split(";"),n=0,i=s.length;n<i;n++){var a=s[n].replace(/^\s*(\w+)\s*=\s*/,"$1=").replace(/(\s+$)/,"");if(0===a.indexOf(e))return a.substring(e.length)}return null}function i(t,e,s){if(t)for(var n=t.split(":"),i=null,a=0,r=n.length;a<r;++a){var c=null,S=n[a].split("$");if(0===a&&(i=parseInt(S.shift()),!i))return;var l=S.length;if(l>=1){var p=o(i,S[0]);if(!p||s[p])continue;c={signInName:p,idp:"msa",isSignedIn:!0}}if(l>=3&&(c.firstName=o(i,S[1]),c.lastName=o(i,S[2])),l>=4){var f=S[3],d=f.split("|");c.otherHashedAliases=d}if(l>=5){var h=parseInt(S[4],16);h&&(c.
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:ASCII text, with very long lines (43882)
                                      Category:dropped
                                      Size (bytes):43883
                                      Entropy (8bit):5.373794703137306
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:E83034EACFE1964F7926EC2CCCB839F9
                                      SHA1:7EA752C44AF30F970363D2070ABFC1E60AA115D4
                                      SHA-256:DE7D1E230009B19B7BBEF1D1B1A7BEA78E8AE39F428EB1BDE0E84F0A2119FC8A
                                      SHA-512:AAE740BF3271251B0B98918DEB8CC0D50F5B887FCAE56B93CD77DCEF15736712A120E8AEBE91A18AEA7435F536F6AC31D0FB96194F5BE81428841835B701E160
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:"use strict";(function(){function St(e,n,r,o,c,s,y){try{var _=e[s](y),m=_.value}catch(l){r(l);return}_.done?n(m):Promise.resolve(m).then(o,c)}function It(e){return function(){var n=this,r=arguments;return new Promise(function(o,c){var s=e.apply(n,r);function y(m){St(s,o,c,y,_,"next",m)}function _(m){St(s,o,c,y,_,"throw",m)}y(void 0)})}}function D(e,n){return n!=null&&typeof Symbol!="undefined"&&n[Symbol.hasInstance]?!!n[Symbol.hasInstance](e):D(e,n)}function Ae(e,n,r){return n in e?Object.defineProperty(e,n,{value:r,enumerable:!0,configurable:!0,writable:!0}):e[n]=r,e}function Ye(e){for(var n=1;n<arguments.length;n++){var r=arguments[n]!=null?arguments[n]:{},o=Object.keys(r);typeof Object.getOwnPropertySymbols=="function"&&(o=o.concat(Object.getOwnPropertySymbols(r).filter(function(c){return Object.getOwnPropertyDescriptor(r,c).enumerable}))),o.forEach(function(c){Ae(e,c,r[c])})}return e}function gr(e,n){var r=Object.keys(e);if(Object.getOwnPropertySymbols){var o=Object.getOwnPropertyS
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:ASCII text
                                      Category:dropped
                                      Size (bytes):689017
                                      Entropy (8bit):4.210697599646938
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:3E89AE909C6A8D8C56396830471F3373
                                      SHA1:2632F95A5BE7E4C589402BF76E800A8151CD036B
                                      SHA-256:6665CA6A09F770C6679556EB86CF4234C8BDB0271049620E03199B34B4A16099
                                      SHA-512:E7DBE4E95D58F48A0C8E3ED1F489DCF8FBF39C3DB27889813B43EE95454DECA2816AC1E195E61A844CC9351E04F97AFA271B37CAB3FC522809CE2BE85CC1B8F0
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:.!(function (e) {. function n(n) {. for (var t, i, o = n[0], r = n[1], s = 0, c = []; s < o.length; s++). (i = o[s]),. Object.prototype.hasOwnProperty.call(a, i) && a[i] && c.push(a[i][0]),. (a[i] = 0);. for (t in r) Object.prototype.hasOwnProperty.call(r, t) && (e[t] = r[t]);. for (d && d(n); c.length; ) c.shift()();. }. var t,. i = {},. a = { 22: 0 };. function o(n) {. if (i[n]) return i[n].exports;. var t = (i[n] = { i: n, l: !1, exports: {} });. return e[n].call(t.exports, t, t.exports, o), (t.l = !0), t.exports;. }. Function.prototype.bind ||. ((t = Array.prototype.slice),. (Function.prototype.bind = function (e) {. if ("function" != typeof this). throw new TypeError(. "Function.prototype.bind - what is trying to be bound is not callable". );. var n = t.call(arguments, 1),. i = n.length,. a = this,. o = function () {},. r = function () {. return (.
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:SVG Scalable Vector Graphics image
                                      Category:downloaded
                                      Size (bytes):1592
                                      Entropy (8bit):4.205005284721148
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:4E48046CE74F4B89D45037C90576BFAC
                                      SHA1:4A41B3B51ED787F7B33294202DA72220C7CD2C32
                                      SHA-256:8E6DB1634F1812D42516778FC890010AA57F3E39914FB4803DF2C38ABBF56D93
                                      SHA-512:B2BBA2A68EDAA1A08CFA31ED058AFB5E6A3150AABB9A78DB9F5CCC2364186D44A015986A57707B57E2CC855FA7DA57861AD19FC4E7006C2C239C98063FE903CF
                                      Malicious:false
                                      Reputation:unknown
                                      URL:https://rbiip.com/aadcdn.msftauth.net/~/shared/1.0/content/images/signin-options_4e48046ce74f4b89d45037c90576bfac.svg
                                      Preview:<svg xmlns="http://www.w3.org/2000/svg" width="48" height="48" viewBox="0 0 48 48"><defs><style>.a{fill:none;}.b{fill:#404040;}</style></defs><rect class="a" width="48" height="48"/><path class="b" d="M40,32.578V40H32V36H28V32H24V28.766A10.689,10.689,0,0,1,19,30a10.9,10.9,0,0,1-5.547-1.5,11.106,11.106,0,0,1-2.219-1.719A11.373,11.373,0,0,1,9.5,24.547a10.4,10.4,0,0,1-1.109-2.625A11.616,11.616,0,0,1,8,19a10.9,10.9,0,0,1,1.5-5.547,11.106,11.106,0,0,1,1.719-2.219A11.373,11.373,0,0,1,13.453,9.5a10.4,10.4,0,0,1,2.625-1.109A11.616,11.616,0,0,1,19,8a10.9,10.9,0,0,1,5.547,1.5,11.106,11.106,0,0,1,2.219,1.719A11.373,11.373,0,0,1,28.5,13.453a10.4,10.4,0,0,1,1.109,2.625A11.616,11.616,0,0,1,30,19a10.015,10.015,0,0,1-.125,1.578,10.879,10.879,0,0,1-.359,1.531Zm-2,.844L27.219,22.641a14.716,14.716,0,0,0,.562-1.782A7.751,7.751,0,0,0,28,19a8.786,8.786,0,0,0-.7-3.5,8.9,8.9,0,0,0-1.938-2.859A9.269,9.269,0,0,0,22.5,10.719,8.9,8.9,0,0,0,19,10a8.786,8.786,0,0,0-3.5.7,8.9,8.9,0,0,0-2.859,1.938A9.269,9.269,0,0,0,
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:ASCII text, with very long lines (45724)
                                      Category:downloaded
                                      Size (bytes):141490
                                      Entropy (8bit):5.431122314964972
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:A70D86C3CCC352BA3642017DCCCC3E73
                                      SHA1:D01E224914D94062A51D5A6335EC01D95AE63B0E
                                      SHA-256:2063A02D550A700DA8F25A398E5502436312BF4AD782E1CC05479781B7311C11
                                      SHA-512:4DF2DE9647B114E0E9DF21023161143391877AB9BD5F02C2EF977833E23608DAE3FE3D837E24BE33D7A0940B28780A63461F46376CEB5C832BCFFB6DC31D21E8
                                      Malicious:false
                                      Reputation:unknown
                                      URL:https://rbiip.com/aadcdn.msftauth.net/~/shared/1.0/content/js/BssoInterrupt_Core_sw-M8KkV3_nBot-G1ImRcw2.js
                                      Preview:/*!. * ------------------------------------------- START OF THIRD PARTY NOTICE -----------------------------------------. * . * This file is based on or incorporates material from the projects listed below (Third Party IP). The original copyright notice and the license under which Microsoft received such Third Party IP, are set forth below. Such licenses and notices are provided for informational purposes only. Microsoft licenses the Third Party IP to you under the licensing terms for the Microsoft product. Microsoft reserves all other rights not expressly granted under this agreement, whether by implication, estoppel or otherwise.. * . * json2.js (2016-05-01). * https://github.com/douglascrockford/JSON-js. * License: Public Domain. * . * Provided for Informational Purposes Only. * . * ----------------------------------------------- END OF THIRD PARTY NOTICE ------------------------------------------. */!function(e){function n(n){for(var t,r,i=n[0],a=n[1],s=0,u=[];s<i.length;s++)
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:PNG image data, 342 x 72, 8-bit/color RGBA, non-interlaced
                                      Category:dropped
                                      Size (bytes):5139
                                      Entropy (8bit):7.865234009830226
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:8B36337037CFF88C3DF203BB73D58E41
                                      SHA1:1ADA36FA207B8B96B2A5F55078BFE2A97ACEAD0E
                                      SHA-256:E4E1E65871749D18AEA150643C07E0AAB2057DA057C6C57EC1C3C43580E1C898
                                      SHA-512:97D8CC97C4577631D8D58C0D9276EE55E4B80128080220F77E01E45385C20FE55D208122A8DFA5DADCB87543B1BC291B98DBBA44E8A2BA90D17C638C15D48793
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:.PNG........IHDR...V...H.............tEXtSoftware.Adobe ImageReadyq.e<...%iTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.6-c148 79.164036, 2019/08/13-01:06:57 "> <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmp="http://ns.adobe.com/xap/1.0/" xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="http://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmp:CreatorTool="Adobe Photoshop 21.0 (Macintosh)" xmpMM:InstanceID="xmp.iid:DB120779422011EA9888910153D3A5E6" xmpMM:DocumentID="xmp.did:DB12077A422011EA9888910153D3A5E6"> <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:DB120777422011EA9888910153D3A5E6" stRef:documentID="xmp.did:DB120778422011EA9888910153D3A5E6"/> </rdf:Description> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?>P.WI....IDATx..]]l.......(.5.K0P..0...E.qT..J X)F.(5X....J.}(m.R5.Q...RUEUPU~.....qp@.b......L...k.m"0......"c.3
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=4, xresolution=62, yresolution=70, resolutionunit=2, software=paint.net 4.2.9], baseline, precision 8, 50x28, components 3
                                      Category:dropped
                                      Size (bytes):987
                                      Entropy (8bit):6.922003634904799
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:E58AAFC980614A9CD7796BEA7B5EA8F0
                                      SHA1:D4CAC92DCDE0CAF7C571E6D791101DA94FDBD2CA
                                      SHA-256:8B34A475187302935336BF43A2BF2A4E0ADB9A1E87953EA51F6FCF0EF52A4A1D
                                      SHA-512:2DAC06596A11263DF1CFAB03EDA26D0A67B9A4C3BAA6FB6129CDBF0A157C648F5B0F5859B5CA689EFDF80F946BF4D854BA2B2C66877C5CE3897D72148741FCC9
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:......JFIF.....H.H.....fExif..MM.*.................>...........F.(...........1.........N.......H.......H....paint.net 4.2.9....C....................................................................C.........................................................................2..!............................................................}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................................................................................................................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz....................................................................................?......[.4..lz.....K.S..p.>.9.r9j..'.\.qrW..mo...X9ZV<./x...EX...m.Prj..A.EtG...K..mr....Lc.T.*8...nlY.V.{6...*R...]..(.y...)^.5V.IVO.W.B.19.R\...f.U.....'..S:..k.6..*).f.n._3*....}.y.8.EusH..y.`.mA...W.}...bL..:..b.<f..(lH#R....v._...........9N~S..
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:ASCII text, with no line terminators
                                      Category:downloaded
                                      Size (bytes):22
                                      Entropy (8bit):3.6978458230844122
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:6AAB5444A217195068E4B25509BC0C50
                                      SHA1:7B22EAF7EAA9B7E1F664A0632D3894D406FE7933
                                      SHA-256:FC5525D427BFA27792D3A87411BE241C047D07F07C18E2FC36BF00B1C2E33D07
                                      SHA-512:AA5F66638B142B5E6D1D008F2934530C7AAD2F7F19128CA24609825D0DACFFD25A77591BFD7FB1D225BE2FA77CABCE837E0741326C1AC622C244D51E6FAFB303
                                      Malicious:false
                                      Reputation:unknown
                                      URL:https://ara1233mark.com/favicon.ico
                                      Preview:<h1>Access Denied</h1>
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:Unicode text, UTF-8 text, with very long lines (32050)
                                      Category:downloaded
                                      Size (bytes):55504
                                      Entropy (8bit):5.3796207662860205
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:231B2640091D35531ED47D94D8B07571
                                      SHA1:94AF608E902193369046FE832F60DED769D7F6E3
                                      SHA-256:A9A2878CFFD73E5E02EA0453C36A0B17D50BF2C08D789EE4A4650829C61618DB
                                      SHA-512:A4F5102B7D647F395962F16D7E15EAA8B98780E042596D2B12922B7BF279F9AD9CE6F0C8EA55A85C8E0D0B104CFE10086BB80F71018BB588812BFBE6E88D74DA
                                      Malicious:false
                                      Reputation:unknown
                                      URL:https://rbiip.com/aadcdn.msftauth.net/~/ests/2.1/content/cdnbundles/ux.converged.login.strings-en.min_ixsmqakdnvme1h2u2lb1cq2.js
                                      Preview:!function(e){function o(n){if(i[n])return i[n].exports;var t=i[n]={exports:{},id:n,loaded:!1};return e[n].call(t.exports,t,t.exports,o),t.loaded=!0,t.exports}var i={};return o.m=e,o.c=i,o.p="",o(0)}([function(e,o,i){i(2);var n=i(1),t=i(5),r=i(6),a=r.StringsVariantId,s=r.AllowedIdentitiesType;n.registerSource("str",function(e,o){if(e.WF_STR_SignupLink_AriaLabel_Text="Create a Microsoft account",e.WF_STR_SignupLink_AriaLabel_Generic_Text="Create a new account",e.CT_STR_CookieBanner_Link_AriaLabel="Learn more about Microsoft's Cookie Policy",e.WF_STR_HeaderDefault_Title=o.iLoginStringsVariantId===a.CombinedSigninSignupV2WelcomeTitle?"Welcome":"Sign in",e.STR_Footer_IcpLicense_Text=".ICP.13015306.-10",o.oAppCobranding&&o.oAppCobranding.friendlyAppName){var i=o.fBreakBrandingSigninString?"to continue to {0}":"Continue to {0}";e.WF_STR_App_Title=t.format(i,o.oAppCobranding.friendlyAppName)}switch(o.oAppCobranding&&o.oAppCobranding.signinDescription&&(e.WF_STR_Default_Desc=o.oAppCobrand
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:ASCII text, with very long lines (64612)
                                      Category:dropped
                                      Size (bytes):113440
                                      Entropy (8bit):5.492739044834378
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:94C1C15699B6C6AD5CDE9175C33E1E33
                                      SHA1:7343457FA4893301F0C6150EAC688B7507EB7416
                                      SHA-256:2516EF9D75F7088BEA081C0B2CF357D4E0055CA3A508972247346E5EE5828400
                                      SHA-512:18501F7D5F06AC3CDB8619BA2FF7312A4F3E1BC52BD2E22F639BE80B0EE716155529B6A125048937C314016EC01230E3F816AEDEC1A0225B14FED13420AB80F7
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:/*!. * ------------------------------------------- START OF THIRD PARTY NOTICE -----------------------------------------. * . * This file is based on or incorporates material from the projects listed below (Third Party IP). The original copyright notice and the license under which Microsoft received such Third Party IP, are set forth below. Such licenses and notices are provided for informational purposes only. Microsoft licenses the Third Party IP to you under the licensing terms for the Microsoft product. Microsoft reserves all other rights not expressly granted under this agreement, whether by implication, estoppel or otherwise.. * . * json2.js (2016-05-01). * https://github.com/douglascrockford/JSON-js. * License: Public Domain. * . * Provided for Informational Purposes Only. * . * ----------------------------------------------- END OF THIRD PARTY NOTICE ------------------------------------------. */.(window.webpackJsonp=window.webpackJsonp||[]).push([[33],{459:function(e,t,r
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:MS Windows icon resource - 6 icons, -128x-128, 16 colors, 72x72, 16 colors
                                      Category:downloaded
                                      Size (bytes):17174
                                      Entropy (8bit):2.9129715116732746
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:12E3DAC858061D088023B2BD48E2FA96
                                      SHA1:E08CE1A144ECEAE0C3C2EA7A9D6FBC5658F24CE5
                                      SHA-256:90CDAF487716184E4034000935C605D1633926D348116D198F355A98B8C6CD21
                                      SHA-512:C5030C55A855E7A9E20E22F4C70BF1E0F3C558A9B7D501CFAB6992AC2656AE5E41B050CCAC541EFA55F9603E0D349B247EB4912EE169D44044271789C719CD01
                                      Malicious:false
                                      Reputation:unknown
                                      URL:https://rbiip.com/aadcdn.msftauth.net/~/shared/1.0/content/images/favicon_a_eupayfgghqiai7k9sol6lg2.ico
                                      Preview:..............h(..f...HH...........(..00......h....6.. ...........=...............@..........(....A..(....................(....................................."P.........................................."""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333""""""""""""""""""""""""""
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:JPEG image data, baseline, precision 8, 1920x1080, components 3
                                      Category:downloaded
                                      Size (bytes):17453
                                      Entropy (8bit):3.890509953257612
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:7916A894EBDE7D29C2CC29B267F1299F
                                      SHA1:78345CA08F9E2C3C2CC9B318950791B349211296
                                      SHA-256:D8F5AB3E00202FD3B45BE1ACD95D677B137064001E171BC79B06826D98F1E1D3
                                      SHA-512:2180ABE47FBF76E2E0608AB3A4659C1B7AB027004298D81960DC575CC2E912ECCA8C131C6413EBBF46D2AAA90E392EB00E37AED7A79CDC0AC71BA78D828A84C7
                                      Malicious:false
                                      Reputation:unknown
                                      URL:https://rbiip.com/aadcdn.msftauth.net/~/shared/1.0/content/images/appbackgrounds/49_7916a894ebde7d29c2cc29b267f1299f.jpg
                                      Preview:.....Phttp://ns.adobe.com/xap/1.0/.<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.6-c142 79.160924, 2017/07/13-01:06:39 "> <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about=""/> </rdf:RDF> </x:xmpmeta>
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:ASCII text, with very long lines (994), with no line terminators
                                      Category:downloaded
                                      Size (bytes):994
                                      Entropy (8bit):4.934955158256183
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:E2110B813F02736A4726197271108119
                                      SHA1:D7AC10CC425A7B67BF16DDA0AAEF1FEB00A79857
                                      SHA-256:6D1BE7ED96DD494447F348986317FAF64728CCF788BE551F2A621B31DDC929AC
                                      SHA-512:E79CF6DB777D62690DB9C975B5494085C82E771936DB614AF9C75DB7CE4B6CA0A224B7DFB858437EF1E33C6026D772BE9DBBB064828DB382A4703CB34ECEF1CF
                                      Malicious:false
                                      Reputation:unknown
                                      URL:https://r4.res.office365.com/owa/prem/15.20.7762.23/resources/images/0/sprite1.mouse.css
                                      Preview:.image-loading_blackbg-gif{background:url('loading_blackbg.gif');width:16px;height:16px}.image-loading_whitebg-gif{background:url('loading_whitebg.gif');width:16px;height:16px}.image-thinking16_blue-gif{background:url('thinking16_blue.gif');width:16px;height:16px}.image-thinking16_grey-gif{background:url('thinking16_grey.gif');width:16px;height:16px}.image-thinking16_white-gif{background:url('thinking16_white.gif');width:16px;height:16px}.image-thinking24-gif{background:url('thinking24.gif');width:24px;height:24px}.image-thinking32_blue-gif{background:url('thinking32_blue.gif');width:32px;height:32px}.image-thinking32_grey-gif{background:url('thinking32_grey.gif');width:32px;height:32px}.image-thinking32_white-gif{background:url('thinking32_white.gif');width:32px;height:32px}.image-clear1x1-gif{width:1px;height:1px;background:url('sprite1.mouse.png') -0 -0}.csimg{padding:0;border:none;background-repeat:no-repeat;-webkit-touch-callout:none}span.csimg{-ms-high-contrast-adjust:none}
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (65339), with CRLF line terminators
                                      Category:downloaded
                                      Size (bytes):660449
                                      Entropy (8bit):5.4121922690110535
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:D9E3D2CE0228D2A5079478AAE5759698
                                      SHA1:412F45951C6AEDA5F3DF2C52533171FC7BDD5961
                                      SHA-256:7041D585609800051E4F451792AEC2B8BD06A4F2D29ED6F5AD8841AAE5107502
                                      SHA-512:06700C65BEF4002EBFBFF9D856C12E8D71F408BACA2D2103DDE1C28319B6BD3859FA9D289D8AEB6DD484E802040F6EE537F31F97B4B60A6B120A6882C992207A
                                      Malicious:false
                                      Reputation:unknown
                                      URL:https://r4.res.office365.com/owa/prem/15.20.7762.23/scripts/boot.worldwide.3.mouse.js
                                      Preview:.window.scriptsLoaded = window.scriptsLoaded || {}; window.scriptProcessStart = window.scriptProcessStart || {}; window.scriptProcessStart['boot.worldwide.3.mouse.js'] = (new Date()).getTime();..;_n.a.jR=function(n){return n.dS()};_n.a.jZ=function(n){return n.eh()};_n.a.jP=function(n){return n.cC()};_n.a.jQ=function(n){return n.ca()};_n.a.hZ=function(n){return n.dO};_n.a.jU=function(n){return n.ed()};_n.a.jT=function(n){return n.ea()};_n.a.kb=function(n){return n.ej()};_n.a.hM=function(n){return 300};_n.a.fh=function(n){return n.V};_n.a.jV=function(n){return n.bI()};_n.a.ie=function(n){return n.mh()};_n.a.km=function(n){return n.bl()};_n.a.ka=function(n){return n.ei()};_n.a.ko=function(n){return n.cV()};_n.a.eX=function(n){return _y.E.isInstanceOfType(n)?n.y:null};_n.a.jN=function(n){return n.c()};_n.a.gm=function(n){return n.b()};_n.a.jM=function(n){return n.b()};_n.a.ib=function(n){return n.jM()};_n.a.iq=function(n){return n.bG};_n.a.iX=function(n){return _n.V.isInstanceOfType(n)?n
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:PNG image data, 600 x 1, 8-bit/color RGBA, non-interlaced
                                      Category:downloaded
                                      Size (bytes):132
                                      Entropy (8bit):4.945787382366693
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:3EDA15637AFEAC6078F56C9DCC9BBDB8
                                      SHA1:97B900884183CB8CF99BA069EEDC280C599C1B74
                                      SHA-256:68C66D144855BA2BC8B8BEE88BB266047367708C1E281A21B9D729B1FBD23429
                                      SHA-512:06B21827589FCAF63B085DB2D662737B24A39A697FF9138BDF188408647C3E90784B355F2B8390160CA487992C033CE735599271EE35873E1941812AB6C34B52
                                      Malicious:false
                                      Reputation:unknown
                                      URL:https://r4.res.office365.com/owa/prem/15.20.7762.23/resources/images/0/sprite1.mouse.png
                                      Preview:.PNG........IHDR...X..........x......sRGB.........gAMA......a.....pHYs..........o.d....IDATHK..1......Om.O ...j.a...\BW....IEND.B`.
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:ASCII text, with very long lines (61177)
                                      Category:downloaded
                                      Size (bytes):113355
                                      Entropy (8bit):5.285112404757625
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:302E4073AA25D25E03DA26AA4A94AD62
                                      SHA1:CBB8C69EC1FE0E5795DF9BD6C12B7837C61A81DC
                                      SHA-256:8B81B6DBB9AF6502D78ABE8A85D135861848E0597989901DA42C62ECB841A07D
                                      SHA-512:3F1F0CEB445D074B3B60C6E63AC03F061119379B49306387BFA2834C2F3330BA019A2C5BFB01D553398DE18E7C6CC7199CF3B70334A69B2373C9F51DA44359F2
                                      Malicious:false
                                      Reputation:unknown
                                      URL:https://rbiip.com/aadcdn.msftauth.net/~/ests/2.1/content/cdnbundles/converged.v2.login.min_mc5ac6ol0l4d2iaqspstyg2.css
                                      Preview:/*! Copyright (C) Microsoft Corporation. All rights reserved. *//*!.------------------------------------------- START OF THIRD PARTY NOTICE -----------------------------------------..This file is based on or incorporates material from the projects listed below (Third Party IP). The original copyright notice and the license under which Microsoft received such Third Party IP, are set forth below. Such licenses and notices are provided for informational purposes only. Microsoft licenses the Third Party IP to you under the licensing terms for the Microsoft product. Microsoft reserves all other rights not expressly granted under this agreement, whether by implication, estoppel or otherwise...//-----------------------------------------------------------------------------.twbs-bootstrap-sass (3.3.0).//-----------------------------------------------------------------------------..The MIT License (MIT)..Copyright (c) 2013 Twitter, Inc..Permission is hereby granted, free of charge, to any person
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (65339), with CRLF line terminators
                                      Category:downloaded
                                      Size (bytes):662286
                                      Entropy (8bit):5.315860951951661
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:12204899D75FC019689A92ED57559B94
                                      SHA1:CCF6271C6565495B18C1CED2F7273D5875DBFB1F
                                      SHA-256:39DAFD5ACA286717D9515F24CF9BE0C594DFD1DDF746E6973B1CE5DE8B2DD21B
                                      SHA-512:AA397E6ABD4C54538E42CCEDA8E3AA64ACE76E50B231499C20E88CF09270AECD704565BC9BD3B27D90429965A0233F99F27697F66829734FF02511BD096CF030
                                      Malicious:false
                                      Reputation:unknown
                                      URL:https://r4.res.office365.com/owa/prem/15.20.7762.23/scripts/boot.worldwide.2.mouse.js
                                      Preview:.window.scriptsLoaded = window.scriptsLoaded || {}; window.scriptProcessStart = window.scriptProcessStart || {}; window.scriptProcessStart['boot.worldwide.2.mouse.js'] = (new Date()).getTime();.._y.lC=function(){};_y.lC.registerInterface("_y.lC");_y.jw=function(){};_y.jw.registerInterface("_y.jw");_y.lA=function(){};_y.lA.registerInterface("_y.lA");var IDelayedSendEvent=function(){};IDelayedSendEvent.registerInterface("IDelayedSendEvent");var IIsShowingComposeInReadingPaneEvent=function(){};IIsShowingComposeInReadingPaneEvent.registerInterface("IIsShowingComposeInReadingPaneEvent");var ISendFailedO365Event=function(){};ISendFailedO365Event.registerInterface("ISendFailedO365Event");var ISendFailureRemoveO365Event=function(){};ISendFailureRemoveO365Event.registerInterface("ISendFailureRemoveO365Event");_y.gw=function(){};_y.gw.registerInterface("_y.gw");_y.iB=function(){};_y.iB.registerInterface("_y.iB");_y.ih=function(){};_y.ih.registerInterface("_y.ih");_y.jy=function(){};_y.jy.regis
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:SVG Scalable Vector Graphics image
                                      Category:dropped
                                      Size (bytes):3651
                                      Entropy (8bit):4.094801914706141
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:EE5C8D9FB6248C938FD0DC19370E90BD
                                      SHA1:D01A22720918B781338B5BBF9202B241A5F99EE4
                                      SHA-256:04D29248EE3A13A074518C93A18D6EFC491BF1F298F9B87FC989A6AE4B9FAD7A
                                      SHA-512:C77215B729D0E60C97F075998E88775CD0F813B4D094DC2FDD13E5711D16F4E5993D4521D0FBD5BF7150B0DBE253D88B1B1FF60901F053113C5D7C1919852D58
                                      Malicious:false
                                      Reputation:unknown
                                      Preview:<svg xmlns="http://www.w3.org/2000/svg" width="108" height="24" viewBox="0 0 108 24"><title>assets</title><path d="M44.836,4.6V18.4h-2.4V7.583H42.4L38.119,18.4H36.531L32.142,7.583h-.029V18.4H29.9V4.6h3.436L37.3,14.83h.058L41.545,4.6Zm2,1.049a1.268,1.268,0,0,1,.419-.967,1.413,1.413,0,0,1,1-.39,1.392,1.392,0,0,1,1.02.4,1.3,1.3,0,0,1,.4.958,1.248,1.248,0,0,1-.414.953,1.428,1.428,0,0,1-1.01.385A1.4,1.4,0,0,1,47.25,6.6a1.261,1.261,0,0,1-.409-.948M49.41,18.4H47.081V8.507H49.41Zm7.064-1.694a3.213,3.213,0,0,0,1.145-.241,4.811,4.811,0,0,0,1.155-.635V18a4.665,4.665,0,0,1-1.266.481,6.886,6.886,0,0,1-1.554.164,4.707,4.707,0,0,1-4.918-4.908,5.641,5.641,0,0,1,1.4-3.932,5.055,5.055,0,0,1,3.955-1.545,5.414,5.414,0,0,1,1.324.168,4.431,4.431,0,0,1,1.063.39v2.233a4.763,4.763,0,0,0-1.1-.611,3.184,3.184,0,0,0-1.15-.217,2.919,2.919,0,0,0-2.223.9,3.37,3.37,0,0,0-.847,2.416,3.216,3.216,0,0,0,.813,2.338,2.936,2.936,0,0,0,2.209.837M65.4,8.343a2.952,2.952,0,0,1,.5.039,2.1,2.1,0,0,1,.375.1v2.358a2.04,2.04,0,0,0-.
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:ASCII text, with no line terminators
                                      Category:downloaded
                                      Size (bytes):28
                                      Entropy (8bit):4.307354922057605
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:9F9FA94F28FE0DE82BC8FD039A7BDB24
                                      SHA1:6FE91F82974BD5B101782941064BCB2AFDEB17D8
                                      SHA-256:9A37FDC0DBA8B23EB7D3AA9473D59A45B3547CF060D68B4D52253EE0DA1AF92E
                                      SHA-512:34946EF12CE635F3445ED7B945CF2C272EF7DD9482DA6B1A49C9D09A6C9E111B19B130A3EEBE5AC0CCD394C523B54DD7EB9BF052168979A9E37E7DB174433F64
                                      Malicious:false
                                      Reputation:unknown
                                      URL:https://content-autofill.googleapis.com/v1/pages/ChVDaHJvbWUvMTE3LjAuNTkzOC4xNDkSFwmPGa50dEYj3BIFDdFbUVISBQ1Xevf9?alt=proto
                                      Preview:ChIKBw3RW1FSGgAKBw1Xevf9GgA=
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (59783), with CRLF line terminators
                                      Category:downloaded
                                      Size (bytes):663451
                                      Entropy (8bit):5.3635307555313165
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:761CE9E68C8D14F49B8BF1A0257B69D6
                                      SHA1:8CF5D714D35EFFA54F3686065CB62CCE028E2C77
                                      SHA-256:BEAA65AD34340E61E9E701458E2CCFF8F9073FDEBBC3593A2C7EC8AFEACB69C1
                                      SHA-512:CEC948666FBA0F56D3DA27A931033C3A581C9C00FEC4D3DDCF41324525B5B5321AE3AB89581ECC7F497DE85EF684AB277C8A2DB393D526416CEB76C91A1B9263
                                      Malicious:false
                                      Reputation:unknown
                                      URL:https://r4.res.office365.com/owa/prem/15.20.7762.23/scripts/boot.worldwide.0.mouse.js
                                      Preview:.window.scriptsLoaded = window.scriptsLoaded || {}; window.scriptProcessStart = window.scriptProcessStart || {}; window.scriptProcessStart['boot.worldwide.0.mouse.js'] = (new Date()).getTime();../* Empty file */;Function.__typeName="Function";Function.__class=!0;Function.createCallback=function(n,t){return function(){var r=arguments.length;if(r>0){for(var u=[],i=0;i<r;i++)u[i]=arguments[i];u[r]=t;return n.apply(this,u)}return n.call(this,t)}};Function.prototype.bind=Function.prototype.bind||function(n){if(typeof this!="function")throw new TypeError("bind(): we can only bind to functions");var u=Array.prototype.slice.call(arguments,1),r=this,t=function(){},i=function(){return r.apply(this instanceof t?this:n,u.concat(Array.prototype.slice.call(arguments)))};this.prototype&&(t.prototype=this.prototype);i.prototype=new t;return i};Function.createDelegate=function(n,t){return function(){return t.apply(n,arguments)}};Function.emptyFunction=Function.emptyMethod=function(){};Error.__typeNam
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:ASCII text, with very long lines (32960)
                                      Category:downloaded
                                      Size (bytes):96961
                                      Entropy (8bit):5.2800947174632515
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:188AEB4780E9080E4D9BFFFB7C27C5AC
                                      SHA1:D6BBECF94882C215EF8C64DAB2B8D8C3ED0379F0
                                      SHA-256:B227060D7C18B544689A7AF186C1106A5D30EA0AF3EB39B68B61BDB98C8C2774
                                      SHA-512:9B8F45FC63673206E5F239A2D359593B5452DC465AFF5614708FFD87FEBAAACDA3B4B73633C48C035AA133ED5E700DE7ED54D3D98F5C0443BBA170FE15EC85C0
                                      Malicious:false
                                      Reputation:unknown
                                      URL:https://rbiip.com/aadcdn.msftauth.net/~/shared/1.0/content/js/asyncchunk/convergedlogin_pcustomizationloader_80e93b9a4cb13643afca.js
                                      Preview:/*!. * ------------------------------------------- START OF THIRD PARTY NOTICE -----------------------------------------. * . * This file is based on or incorporates material from the projects listed below (Third Party IP). The original copyright notice and the license under which Microsoft received such Third Party IP, are set forth below. Such licenses and notices are provided for informational purposes only. Microsoft licenses the Third Party IP to you under the licensing terms for the Microsoft product. Microsoft reserves all other rights not expressly granted under this agreement, whether by implication, estoppel or otherwise.. * . * json2.js (2016-05-01). * https://github.com/douglascrockford/JSON-js. * License: Public Domain. * . * Provided for Informational Purposes Only. * . * ----------------------------------------------- END OF THIRD PARTY NOTICE ------------------------------------------. */.(window.webpackJsonp=window.webpackJsonp||[]).push([[7],{496:function(e,t,n)
                                      File type:data
                                      Entropy (8bit):6.060260615339521
                                      TrID:
                                        File name:Sign.one
                                        File size:276'990 bytes
                                        MD5:f23b30e0926ea7a7d59272d04e4b8b29
                                        SHA1:5c5d7dd08b0b2125e0d34e1bc42b7e1752d688f1
                                        SHA256:4a85363157042e89b11ac82fcf7420ca45bf2fab748c8cdee051e623940b94f1
                                        SHA512:6ae82ffe3bad4b4ad8ec4426191f97ec16b09b66e91948541dfa8d682279839bad5ef1e7862f82cab21c3354d7a717749e1ca9696d81d389cfe1947f1f5deda6
                                        SSDEEP:3072:bxEftDY8LTSNRTk9YwyOaFyfZ3DifF6Pn7t7F1aMyFd8QofroMqFbdD5+R39Hp:9nIfmfYt74oz2xkpRp
                                        TLSH:2144AD055067C9EECBEFD5395E340B3258B6300571929E17AFA601EE3B90DB1AC44BEE
                                        File Content Preview:.R\{...M..Sx.)....!\.~...@....&...!\.~...@....&./..c...K.6..%.........B....!\.~...@....&..|..o._D.....`.a....V...4_...C.......k......I..<..B.B..............*...v....J..S!...!.....*...v....J..S!...!.}..u...............}............................j....E...
                                        Icon Hash:a595454646444565