Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
Aisha C. Yetman shared you a document..msg

Overview

General Information

Sample name:Aisha C. Yetman shared you a document..msg
Analysis ID:1520486
MD5:67340fb3a621311ccd27846c46349c6d
SHA1:a23b24990392237da809f5b724ec05ebeff2a54f
SHA256:99b0d83c116ab9470d1a50bb9d1616b28afe02930eaccdf1349e3b447b178297
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Phishing site or detected (based on various text indicators)
Suspicious MSG / EML detected (based on various text indicators)
Detected non-DNS traffic on DNS port
HTML body contains password input but no form action
HTML page contains hidden javascript code
Queries the volume information (name, serial number etc) of a device
Sigma detected: Office Autorun Keys Modification
Stores files to the Windows start menu directory

Classification

  • System is w10x64_ra
  • OUTLOOK.EXE (PID: 5768 cmdline: "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" /f "C:\Users\user\Desktop\Aisha C. Yetman shared you a document..msg" MD5: 91A5292942864110ED734005B7E005C0)
    • ai.exe (PID: 4860 cmdline: "C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe" "28AD7FEA-D827-475F-A769-030CD0CBFDB2" "49BEB033-A781-49F9-956C-7A79B1FDBEF4" "5768" "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" "WordCombinedFloatieLreOnline.onnx" MD5: EC652BEDD90E089D9406AFED89A8A8BD)
    • chrome.exe (PID: 4996 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://lsaustralasia-my.sharepoint.com/:f:/g/personal/janine_lsaust_com_au/Eh_UbyNHz6NNpYjJVdYgrwcBqGq7dVVPWUd1_5bX4K66JQ?e=69hdpQ MD5: 83395EAB5B03DEA9720F8D7AC0D15CAA)
      • chrome.exe (PID: 6220 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2180 --field-trial-handle=1980,i,10088438625339154242,9140440464760541525,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 83395EAB5B03DEA9720F8D7AC0D15CAA)
  • cleanup
No yara matches
Source: Registry Key setAuthor: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): Data: Details: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 , EventID: 13, EventType: SetValue, Image: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE, ProcessId: 5768, TargetObject: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Outlook\Addins\OneNote.OutlookAddin\1
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

Phishing

barindex
Source: Chrome DOM: 0.13OCR Text: OneDrive + New Download Sort v 81 Details My files > Law Offices of Shaevitz & Shaevitz 3 Activity Name v Modified Modified By File size Sharing Janine Kennedy -CLICK HERE TO REVIEW DOCUMENT.url Yesterday at 1:05 PM 70 bytes 00 Shared
Source: MSG / EMLOCR Text: ShareFile Attachments Expires October 6, 2024 September Claim Report.pdf 423 KB VIEW SHARED DOCUMENT Aisha C. Yetman uses ShareFile to share documents securely. Best regards, Aisha C. Yetman Legal Assistant Law Offices of Shaevitz & Shaevitz 148-55 Hillside Avenue Jamaica, NY 11435 Telephone: (718) 291-3400 Ext, 240 Fax: (718) 739-5654 E-Mail: aisha.yetman@shaevitzandshaevitz.com
Source: https://www.instagram.com/HTTP Parser: <input type="password" .../> found but no <form action="...
Source: https://stellarnetwork.sucileton.com/EQn1RAKa/HTTP Parser: Base64 decoded: {"version":3,"sources":["/cfsetup_build/src/orchestrator/turnstile/templates/turnstile.scss","%3Cinput%20css%20qtFLbZ%3E"],"names":[],"mappings":"AAmCA,gBACI,GACI,uBClCN,CACF,CDqCA,kBACI,GACI,mBCnCN,CACF,CDsCA,iBACI,MAEI,cCrCN,CDwCE,IACI,mBCtCN,CACF,CDyCA...
Source: https://www.instagram.com/HTTP Parser: <input type="password" .../> found
Source: https://stellarnetwork.sucileton.com/EQn1RAKa/HTTP Parser: No favicon
Source: https://stellarnetwork.sucileton.com/EQn1RAKa/HTTP Parser: No favicon
Source: https://www.instagram.com/HTTP Parser: No <meta name="author".. found
Source: https://www.instagram.com/HTTP Parser: No <meta name="author".. found
Source: https://www.instagram.com/HTTP Parser: No <meta name="copyright".. found
Source: https://www.instagram.com/HTTP Parser: No <meta name="copyright".. found
Source: unknownHTTPS traffic detected: 40.126.32.134:443 -> 192.168.2.17:49708 version: TLS 1.2
Source: unknownHTTPS traffic detected: 40.126.32.134:443 -> 192.168.2.17:49708 version: TLS 1.2
Source: unknownHTTPS traffic detected: 40.126.32.134:443 -> 192.168.2.17:49709 version: TLS 1.2
Source: unknownHTTPS traffic detected: 40.126.32.134:443 -> 192.168.2.17:49724 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.114.59.183:443 -> 192.168.2.17:49725 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.17:49761 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.17:49769 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.242.39.171:443 -> 192.168.2.17:51028 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.12.23.50:443 -> 192.168.2.17:51040 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.12.23.50:443 -> 192.168.2.17:51052 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.12.23.50:443 -> 192.168.2.17:51063 version: TLS 1.2
Source: chrome.exeMemory has grown: Private usage: 1MB later: 27MB
Source: global trafficTCP traffic: 192.168.2.17:51023 -> 162.159.36.2:53
Source: global trafficTCP traffic: 192.168.2.17:51023 -> 162.159.36.2:53
Source: global trafficTCP traffic: 192.168.2.17:51023 -> 162.159.36.2:53
Source: global trafficTCP traffic: 192.168.2.17:51023 -> 162.159.36.2:53
Source: global trafficTCP traffic: 192.168.2.17:51023 -> 162.159.36.2:53
Source: global trafficTCP traffic: 192.168.2.17:51023 -> 162.159.36.2:53
Source: global trafficTCP traffic: 192.168.2.17:51023 -> 162.159.36.2:53
Source: global trafficTCP traffic: 192.168.2.17:51023 -> 162.159.36.2:53
Source: global trafficTCP traffic: 192.168.2.17:51023 -> 162.159.36.2:53
Source: global trafficTCP traffic: 192.168.2.17:51023 -> 162.159.36.2:53
Source: global trafficTCP traffic: 192.168.2.17:51023 -> 162.159.36.2:53
Source: global trafficTCP traffic: 192.168.2.17:51023 -> 162.159.36.2:53
Source: global trafficTCP traffic: 192.168.2.17:51023 -> 162.159.36.2:53
Source: global trafficTCP traffic: 192.168.2.17:51023 -> 162.159.36.2:53
Source: global trafficTCP traffic: 192.168.2.17:51023 -> 162.159.36.2:53
Source: global trafficTCP traffic: 192.168.2.17:51023 -> 162.159.36.2:53
Source: global trafficTCP traffic: 192.168.2.17:51023 -> 162.159.36.2:53
Source: global trafficTCP traffic: 192.168.2.17:51023 -> 162.159.36.2:53
Source: global trafficTCP traffic: 192.168.2.17:51023 -> 162.159.36.2:53
Source: global trafficTCP traffic: 192.168.2.17:51023 -> 162.159.36.2:53
Source: global trafficTCP traffic: 192.168.2.17:51023 -> 162.159.36.2:53
Source: global trafficTCP traffic: 192.168.2.17:51023 -> 162.159.36.2:53
Source: global trafficTCP traffic: 192.168.2.17:51023 -> 162.159.36.2:53
Source: global trafficTCP traffic: 192.168.2.17:51023 -> 162.159.36.2:53
Source: global trafficTCP traffic: 192.168.2.17:51023 -> 162.159.36.2:53
Source: global trafficTCP traffic: 192.168.2.17:51023 -> 162.159.36.2:53
Source: global trafficTCP traffic: 192.168.2.17:51023 -> 162.159.36.2:53
Source: global trafficTCP traffic: 192.168.2.17:51023 -> 162.159.36.2:53
Source: global trafficTCP traffic: 192.168.2.17:51023 -> 162.159.36.2:53
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.134
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.134
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.134
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.134
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.134
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.134
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.134
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.134
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.134
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.134
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.134
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.134
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.134
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.134
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.134
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.134
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.134
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.134
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.134
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.134
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.134
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.134
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.134
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.134
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.134
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.134
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.134
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.134
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.134
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.134
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.134
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.134
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.134
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.134
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.134
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.134
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.134
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.134
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.134
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.134
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.134
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.134
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.134
Source: global trafficDNS traffic detected: DNS query: lsaustralasia-my.sharepoint.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: spo.nel.measure.office.net
Source: global trafficDNS traffic detected: DNS query: australiasoutheast0-0.pushnp.svc.ms
Source: global trafficDNS traffic detected: DNS query: 171.39.242.20.in-addr.arpa
Source: global trafficDNS traffic detected: DNS query: stellarnetwork.sucileton.com
Source: global trafficDNS traffic detected: DNS query: 50.23.12.20.in-addr.arpa
Source: global trafficDNS traffic detected: DNS query: code.jquery.com
Source: global trafficDNS traffic detected: DNS query: challenges.cloudflare.com
Source: global trafficDNS traffic detected: DNS query: cdnjs.cloudflare.com
Source: global trafficDNS traffic detected: DNS query: lsaustralasia.sharepoint.com
Source: global trafficDNS traffic detected: DNS query: r4.res.office365.com
Source: global trafficDNS traffic detected: DNS query: config.fp.measure.office.com
Source: global trafficDNS traffic detected: DNS query: zlwjxwhb6dotuxwnzgx1nxd8jxfxz9jvftopkpgzlutlkcerpzndneucb8in.gatertati.ru
Source: global trafficDNS traffic detected: DNS query: instagram.com
Source: global trafficDNS traffic detected: DNS query: www.instagram.com
Source: global trafficDNS traffic detected: DNS query: www.facebook.com
Source: global trafficDNS traffic detected: DNS query: static.cdninstagram.com
Source: global trafficDNS traffic detected: DNS query: 2937715f9d67cf3a3e5dcb8ab195f6ab.fp.measure.office.com
Source: global trafficDNS traffic detected: DNS query: tr-ooc-atm.office.com
Source: global trafficDNS traffic detected: DNS query: outlook.office365.com
Source: global trafficDNS traffic detected: DNS query: upload.fp.measure.office.com
Source: global trafficDNS traffic detected: DNS query: m365cdn.nel.measure.office.net
Source: global trafficDNS traffic detected: DNS query: a.nel.cloudflare.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51027
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51148
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51149
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51028
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51147
Source: unknownNetwork traffic detected: HTTP traffic on port 51044 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49795 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51067 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51151
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51152
Source: unknownNetwork traffic detected: HTTP traffic on port 51210 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51150
Source: unknownNetwork traffic detected: HTTP traffic on port 51147 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51124 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 64697
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 51164 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49732
Source: unknownNetwork traffic detected: HTTP traffic on port 49732 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51187 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51227 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51336 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51034
Source: unknownNetwork traffic detected: HTTP traffic on port 51135 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51155
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51035
Source: unknownNetwork traffic detected: HTTP traffic on port 51244 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51274
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51033
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51154
Source: unknownNetwork traffic detected: HTTP traffic on port 49784 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51157
Source: unknownNetwork traffic detected: HTTP traffic on port 51170 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51162
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51163
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51160
Source: unknownNetwork traffic detected: HTTP traffic on port 49823 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51040
Source: unknownNetwork traffic detected: HTTP traffic on port 64697 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49725
Source: unknownNetwork traffic detected: HTTP traffic on port 51050 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49724
Source: unknownNetwork traffic detected: HTTP traffic on port 51274 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51056 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51226 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51306 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51045
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51166
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51167
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51043
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51164
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51044
Source: unknownNetwork traffic detected: HTTP traffic on port 51113 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51165
Source: unknownNetwork traffic detected: HTTP traffic on port 51194 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51049
Source: unknownNetwork traffic detected: HTTP traffic on port 51175 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51152 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51136 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51168
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51169
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51170
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51052
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51173
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51053
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51174
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51050
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51171
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51051
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51172
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49719
Source: unknownNetwork traffic detected: HTTP traffic on port 49680 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 51107 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
Source: unknownNetwork traffic detected: HTTP traffic on port 51141 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51204 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51221 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51056
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51177
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51178
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51054
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51175
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51058
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51059
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51180
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51060
Source: unknownNetwork traffic detected: HTTP traffic on port 51045 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51130 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51063
Source: unknownNetwork traffic detected: HTTP traffic on port 51073 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51184
Source: unknownNetwork traffic detected: HTTP traffic on port 51215 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51064
Source: unknownNetwork traffic detected: HTTP traffic on port 51102 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51185
Source: unknownNetwork traffic detected: HTTP traffic on port 51209 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51182
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51183
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49708
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49707
Source: unknownNetwork traffic detected: HTTP traffic on port 51090 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51169 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51186 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49823
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51108
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51109
Source: unknownNetwork traffic detected: HTTP traffic on port 51060 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49786
Source: unknownNetwork traffic detected: HTTP traffic on port 51192 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51227
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49785
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51107
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51228
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49784
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51221
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51222
Source: unknownNetwork traffic detected: HTTP traffic on port 49785 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51119 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51225
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51346
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51226
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51102
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51223
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51103
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51224
Source: unknownNetwork traffic detected: HTTP traffic on port 51237 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51208 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51214 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51346 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51160 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51183 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51119
Source: unknownNetwork traffic detected: HTTP traffic on port 64701 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51166 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49707 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51239
Source: unknownNetwork traffic detected: HTTP traffic on port 64690 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51065 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51230
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51231
Source: unknownNetwork traffic detected: HTTP traffic on port 49724 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51237
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51113
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51234
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51235
Source: unknownNetwork traffic detected: HTTP traffic on port 51177 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51198 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51089 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51054 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49769
Source: unknownNetwork traffic detected: HTTP traffic on port 51108 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51125 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51033 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51165 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51188 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51203 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49761
Source: unknownNetwork traffic detected: HTTP traffic on port 51329 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51027 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51122
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51123
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51244
Source: unknownNetwork traffic detected: HTTP traffic on port 49725 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51120
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51121
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51242
Source: unknownNetwork traffic detected: HTTP traffic on port 51043 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51126
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51124
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51125
Source: unknownNetwork traffic detected: HTTP traffic on port 51171 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49719 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51072 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51103 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51130
Source: unknownNetwork traffic detected: HTTP traffic on port 51231 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51126 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51225 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51139
Source: unknownNetwork traffic detected: HTTP traffic on port 51120 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
Source: unknownNetwork traffic detected: HTTP traffic on port 49818 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 64690
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51133
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51134
Source: unknownNetwork traffic detected: HTTP traffic on port 51242 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49786 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51137
Source: unknownNetwork traffic detected: HTTP traffic on port 51193 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51138
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51259
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51135
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51136
Source: unknownNetwork traffic detected: HTTP traffic on port 51137 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51154 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51140
Source: unknownNetwork traffic detected: HTTP traffic on port 51049 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51066 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51141
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51260
Source: unknownNetwork traffic detected: HTTP traffic on port 51219 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51182 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51148 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51306
Source: unknownNetwork traffic detected: HTTP traffic on port 51058 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51201 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51224 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51035 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51167 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51087 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51230 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51064 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51196 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51150 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51173 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51138 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49769 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51109 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51191 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51206 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49691
Source: unknownNetwork traffic detected: HTTP traffic on port 51207 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51184 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49798 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51121 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51259 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51207
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51208
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51329
Source: unknownNetwork traffic detected: HTTP traffic on port 51081 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51205
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51206
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51209
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51200
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51203
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51204
Source: unknownNetwork traffic detected: HTTP traffic on port 51155 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51201
Source: unknownNetwork traffic detected: HTTP traffic on port 51235 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51178 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51212 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51053 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51122 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51149 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51339
Source: unknownNetwork traffic detected: HTTP traffic on port 51034 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49798
Source: unknownNetwork traffic detected: HTTP traffic on port 51189 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51219
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51217
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49795
Source: unknownNetwork traffic detected: HTTP traffic on port 51059 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51172 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51210
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51211
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51332
Source: unknownNetwork traffic detected: HTTP traffic on port 51028 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51197 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51214
Source: unknownNetwork traffic detected: HTTP traffic on port 51133 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51215
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51336
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51212
Source: unknownNetwork traffic detected: HTTP traffic on port 51260 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49808 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51339 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51140 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51205 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51067
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51188
Source: unknownNetwork traffic detected: HTTP traffic on port 51134 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51189
Source: unknownNetwork traffic detected: HTTP traffic on port 49691 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51065
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51186
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51066
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51187
Source: unknownNetwork traffic detected: HTTP traffic on port 51228 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51157 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51191
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51192
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51190
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51074
Source: unknownNetwork traffic detected: HTTP traffic on port 51097 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51074 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51196
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51072
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51193
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51073
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51194
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49818
Source: unknownNetwork traffic detected: HTTP traffic on port 51051 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51332 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51223 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51040 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51197
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51198
Source: unknownNetwork traffic detected: HTTP traffic on port 51174 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51139 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51081
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51080
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51085
Source: unknownNetwork traffic detected: HTTP traffic on port 51234 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49809
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49808
Source: unknownNetwork traffic detected: HTTP traffic on port 51217 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51180 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 64701
Source: unknownNetwork traffic detected: HTTP traffic on port 51163 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51190 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51085 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51222 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51089
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51087
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51090
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51097
Source: unknownNetwork traffic detected: HTTP traffic on port 49809 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51185 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51168 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51239 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51162 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51200 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51080 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51063 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49761 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51151 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51211 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51052 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 51123 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
Source: unknownHTTPS traffic detected: 40.126.32.134:443 -> 192.168.2.17:49708 version: TLS 1.2
Source: unknownHTTPS traffic detected: 40.126.32.134:443 -> 192.168.2.17:49708 version: TLS 1.2
Source: unknownHTTPS traffic detected: 40.126.32.134:443 -> 192.168.2.17:49709 version: TLS 1.2
Source: unknownHTTPS traffic detected: 40.126.32.134:443 -> 192.168.2.17:49724 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.114.59.183:443 -> 192.168.2.17:49725 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.17:49761 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.17:49769 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.242.39.171:443 -> 192.168.2.17:51028 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.12.23.50:443 -> 192.168.2.17:51040 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.12.23.50:443 -> 192.168.2.17:51052 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.12.23.50:443 -> 192.168.2.17:51063 version: TLS 1.2
Source: classification engineClassification label: mal48.phis.winMSG@22/14@36/276
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEFile created: C:\Users\user\Documents\Outlook Files\~Outlook Data File - NoEmail.pst.tmp
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEFile created: C:\Users\user\AppData\Local\Temp\Outlook Logging\OUTLOOK_16_0_16827_20130-20240927T0548320627-5768.etl
Source: unknownProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" /f "C:\Users\user\Desktop\Aisha C. Yetman shared you a document..msg"
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe "C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe" "28AD7FEA-D827-475F-A769-030CD0CBFDB2" "49BEB033-A781-49F9-956C-7A79B1FDBEF4" "5768" "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" "WordCombinedFloatieLreOnline.onnx"
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://lsaustralasia-my.sharepoint.com/:f:/g/personal/janine_lsaust_com_au/Eh_UbyNHz6NNpYjJVdYgrwcBqGq7dVVPWUd1_5bX4K66JQ?e=69hdpQ
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2180 --field-trial-handle=1980,i,10088438625339154242,9140440464760541525,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe "C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe" "28AD7FEA-D827-475F-A769-030CD0CBFDB2" "49BEB033-A781-49F9-956C-7A79B1FDBEF4" "5768" "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" "WordCombinedFloatieLreOnline.onnx"
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://lsaustralasia-my.sharepoint.com/:f:/g/personal/janine_lsaust_com_au/Eh_UbyNHz6NNpYjJVdYgrwcBqGq7dVVPWUd1_5bX4K66JQ?e=69hdpQ
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2180 --field-trial-handle=1980,i,10088438625339154242,9140440464760541525,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: apphelp.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: c2r64.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: userenv.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: msasn1.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: kernel.appcore.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: cryptsp.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: rsaenh.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: cryptbase.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: gpapi.dll
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}\InprocServer32
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEWindow found: window name: SysTabControl32
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Common
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information queried: ProcessInformation
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeQueries volume information: C:\Program Files (x86)\Microsoft Office\root\Office16\AI\WordCombinedFloatieLreOnline.onnx VolumeInformation
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
DLL Side-Loading
1
Process Injection
1
Masquerading
OS Credential Dumping1
Process Discovery
Remote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/Job1
Registry Run Keys / Startup Folder
1
DLL Side-Loading
1
Process Injection
LSASS Memory12
System Information Discovery
Remote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)1
Registry Run Keys / Startup Folder
1
DLL Side-Loading
Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive2
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin Hook1
Extra Window Memory Injection
1
Extra Window Memory Injection
NTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
Aisha C. Yetman shared you a document..msg0%ReversingLabs
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
196394-ipv4v6.farm.dprodmgd106.aa-rt.sharepoint.com
52.105.236.27
truefalse
    unknown
    star-mini.c10r.facebook.com
    157.240.251.35
    truefalse
      unknown
      dual-spo-0005.spo-msedge.net
      13.107.136.10
      truefalse
        unknown
        a.nel.cloudflare.com
        35.190.80.1
        truefalse
          unknown
          instagram.com
          157.240.253.174
          truefalse
            unknown
            stellarnetwork.sucileton.com
            104.21.36.45
            truefalse
              unknown
              z-p42-instagram.c10r.instagram.com
              157.240.0.174
              truefalse
                unknown
                scontent.cdninstagram.com
                157.240.0.63
                truefalse
                  unknown
                  zlwjxwhb6dotuxwnzgx1nxd8jxfxz9jvftopkpgzlutlkcerpzndneucb8in.gatertati.ru
                  188.114.97.3
                  truefalse
                    unknown
                    code.jquery.com
                    151.101.66.137
                    truefalse
                      unknown
                      cdnjs.cloudflare.com
                      104.17.25.14
                      truefalse
                        unknown
                        challenges.cloudflare.com
                        104.18.94.41
                        truefalse
                          unknown
                          mira-ooc.tm-4.office.com
                          52.98.152.162
                          truefalse
                            unknown
                            www.google.com
                            142.250.186.68
                            truefalse
                              unknown
                              FRA-efz.ms-acdc.office.com
                              40.99.149.98
                              truefalse
                                unknown
                                www.facebook.com
                                unknown
                                unknownfalse
                                  unknown
                                  r4.res.office365.com
                                  unknown
                                  unknownfalse
                                    unknown
                                    tr-ooc-atm.office.com
                                    unknown
                                    unknownfalse
                                      unknown
                                      m365cdn.nel.measure.office.net
                                      unknown
                                      unknownfalse
                                        unknown
                                        spo.nel.measure.office.net
                                        unknown
                                        unknownfalse
                                          unknown
                                          outlook.office365.com
                                          unknown
                                          unknownfalse
                                            unknown
                                            static.cdninstagram.com
                                            unknown
                                            unknownfalse
                                              unknown
                                              2937715f9d67cf3a3e5dcb8ab195f6ab.fp.measure.office.com
                                              unknown
                                              unknownfalse
                                                unknown
                                                australiasoutheast0-0.pushnp.svc.ms
                                                unknown
                                                unknownfalse
                                                  unknown
                                                  www.instagram.com
                                                  unknown
                                                  unknownfalse
                                                    unknown
                                                    lsaustralasia-my.sharepoint.com
                                                    unknown
                                                    unknownfalse
                                                      unknown
                                                      upload.fp.measure.office.com
                                                      unknown
                                                      unknownfalse
                                                        unknown
                                                        config.fp.measure.office.com
                                                        unknown
                                                        unknownfalse
                                                          unknown
                                                          lsaustralasia.sharepoint.com
                                                          unknown
                                                          unknownfalse
                                                            unknown
                                                            50.23.12.20.in-addr.arpa
                                                            unknown
                                                            unknownfalse
                                                              unknown
                                                              171.39.242.20.in-addr.arpa
                                                              unknown
                                                              unknownfalse
                                                                unknown
                                                                NameMaliciousAntivirus DetectionReputation
                                                                https://stellarnetwork.sucileton.com/EQn1RAKa/false
                                                                  unknown
                                                                  https://www.instagram.com/false
                                                                    unknown
                                                                    about:blankfalse
                                                                      unknown
                                                                      https://lsaustralasia-my.sharepoint.com/personal/janine_lsaust_com_au/_layouts/15/onedrive.aspx?id=%2Fpersonal%2Fjanine%5Flsaust%5Fcom%5Fau%2FDocuments%2FLaw%20Offices%20of%20Shaevitz%20%26%20Shaevitz&ga=1false
                                                                        unknown
                                                                        • No. of IPs < 25%
                                                                        • 25% < No. of IPs < 50%
                                                                        • 50% < No. of IPs < 75%
                                                                        • 75% < No. of IPs
                                                                        IPDomainCountryFlagASNASN NameMalicious
                                                                        142.250.186.68
                                                                        www.google.comUnited States
                                                                        15169GOOGLEUSfalse
                                                                        52.168.117.174
                                                                        unknownUnited States
                                                                        8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                        2.23.209.11
                                                                        unknownEuropean Union
                                                                        1273CWVodafoneGroupPLCEUfalse
                                                                        2.16.238.152
                                                                        unknownEuropean Union
                                                                        20940AKAMAI-ASN1EUfalse
                                                                        13.107.136.10
                                                                        dual-spo-0005.spo-msedge.netUnited States
                                                                        8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                        2.23.209.12
                                                                        unknownEuropean Union
                                                                        1273CWVodafoneGroupPLCEUfalse
                                                                        52.109.116.88
                                                                        unknownUnited States
                                                                        8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                        40.99.170.2
                                                                        unknownUnited States
                                                                        8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                        157.240.0.63
                                                                        scontent.cdninstagram.comUnited States
                                                                        32934FACEBOOKUSfalse
                                                                        20.189.173.5
                                                                        unknownUnited States
                                                                        8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                        23.38.98.104
                                                                        unknownUnited States
                                                                        16625AKAMAI-ASUSfalse
                                                                        104.18.94.41
                                                                        challenges.cloudflare.comUnited States
                                                                        13335CLOUDFLARENETUSfalse
                                                                        20.42.65.84
                                                                        unknownUnited States
                                                                        8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                        20.189.173.1
                                                                        unknownUnited States
                                                                        8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                        52.111.236.35
                                                                        unknownUnited States
                                                                        8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                        40.79.150.121
                                                                        unknownUnited States
                                                                        8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                        142.250.185.202
                                                                        unknownUnited States
                                                                        15169GOOGLEUSfalse
                                                                        40.99.149.98
                                                                        FRA-efz.ms-acdc.office.comUnited States
                                                                        8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                        2.19.126.160
                                                                        unknownEuropean Union
                                                                        16625AKAMAI-ASUSfalse
                                                                        52.109.89.19
                                                                        unknownUnited States
                                                                        8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                        151.101.66.137
                                                                        code.jquery.comUnited States
                                                                        54113FASTLYUSfalse
                                                                        95.101.54.113
                                                                        unknownEuropean Union
                                                                        34164AKAMAI-LONGBfalse
                                                                        142.250.186.132
                                                                        unknownUnited States
                                                                        15169GOOGLEUSfalse
                                                                        104.21.36.45
                                                                        stellarnetwork.sucileton.comUnited States
                                                                        13335CLOUDFLARENETUSfalse
                                                                        104.102.55.235
                                                                        unknownUnited States
                                                                        16625AKAMAI-ASUSfalse
                                                                        157.240.0.174
                                                                        z-p42-instagram.c10r.instagram.comUnited States
                                                                        32934FACEBOOKUSfalse
                                                                        142.250.184.227
                                                                        unknownUnited States
                                                                        15169GOOGLEUSfalse
                                                                        35.190.80.1
                                                                        a.nel.cloudflare.comUnited States
                                                                        15169GOOGLEUSfalse
                                                                        52.113.194.132
                                                                        unknownUnited States
                                                                        8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                        52.105.236.27
                                                                        196394-ipv4v6.farm.dprodmgd106.aa-rt.sharepoint.comUnited States
                                                                        8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                        2.23.209.44
                                                                        unknownEuropean Union
                                                                        1273CWVodafoneGroupPLCEUfalse
                                                                        1.1.1.1
                                                                        unknownAustralia
                                                                        13335CLOUDFLARENETUSfalse
                                                                        2.23.209.45
                                                                        unknownEuropean Union
                                                                        1273CWVodafoneGroupPLCEUfalse
                                                                        52.98.152.162
                                                                        mira-ooc.tm-4.office.comUnited States
                                                                        8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                        13.89.179.11
                                                                        unknownUnited States
                                                                        8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                        13.107.6.163
                                                                        unknownUnited States
                                                                        8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                        64.233.167.84
                                                                        unknownUnited States
                                                                        15169GOOGLEUSfalse
                                                                        239.255.255.250
                                                                        unknownReserved
                                                                        unknownunknownfalse
                                                                        142.250.185.174
                                                                        unknownUnited States
                                                                        15169GOOGLEUSfalse
                                                                        188.114.97.3
                                                                        zlwjxwhb6dotuxwnzgx1nxd8jxfxz9jvftopkpgzlutlkcerpzndneucb8in.gatertati.ruEuropean Union
                                                                        13335CLOUDFLARENETUSfalse
                                                                        2.16.168.7
                                                                        unknownEuropean Union
                                                                        20940AKAMAI-ASN1EUfalse
                                                                        157.240.253.174
                                                                        instagram.comUnited States
                                                                        32934FACEBOOKUSfalse
                                                                        172.217.16.195
                                                                        unknownUnited States
                                                                        15169GOOGLEUSfalse
                                                                        157.240.251.35
                                                                        star-mini.c10r.facebook.comUnited States
                                                                        32934FACEBOOKUSfalse
                                                                        104.17.25.14
                                                                        cdnjs.cloudflare.comUnited States
                                                                        13335CLOUDFLARENETUSfalse
                                                                        IP
                                                                        192.168.2.17
                                                                        Joe Sandbox version:41.0.0 Charoite
                                                                        Analysis ID:1520486
                                                                        Start date and time:2024-09-27 11:48:02 +02:00
                                                                        Joe Sandbox product:CloudBasic
                                                                        Overall analysis duration:
                                                                        Hypervisor based Inspection enabled:false
                                                                        Report type:full
                                                                        Cookbook file name:defaultwindowsinteractivecookbook.jbs
                                                                        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                                                        Number of analysed new started processes analysed:17
                                                                        Number of new started drivers analysed:0
                                                                        Number of existing processes analysed:0
                                                                        Number of existing drivers analysed:0
                                                                        Number of injected processes analysed:0
                                                                        Technologies:
                                                                        • EGA enabled
                                                                        Analysis Mode:stream
                                                                        Analysis stop reason:Timeout
                                                                        Sample name:Aisha C. Yetman shared you a document..msg
                                                                        Detection:MAL
                                                                        Classification:mal48.phis.winMSG@22/14@36/276
                                                                        Cookbook Comments:
                                                                        • Found application associated with file extension: .msg
                                                                        • Exclude process from analysis (whitelisted): dllhost.exe, TextInputHost.exe
                                                                        • Excluded IPs from analysis (whitelisted): 52.113.194.132, 52.109.89.19, 2.19.126.160, 2.19.126.151, 52.111.236.35, 52.111.236.33, 52.111.236.34, 52.111.236.32
                                                                        • Excluded domains from analysis (whitelisted): ecs.office.com, omex.cdn.office.net, weu-azsc-000.roaming.officeapps.live.com, ctldl.windowsupdate.com, prod.roaming1.live.com.akadns.net, s-0005-office.config.skype.com, eur.roaming1.live.com.akadns.net, ecs-office.s-0005.s-msedge.net, roaming.officeapps.live.com, osiprod-weu-buff-azsc-000.westeurope.cloudapp.azure.com, prod1.naturallanguageeditorservice.osi.office.net.akadns.net, nleditor.osi.office.net, prod-eu-resolver.naturallanguageeditorservice.osi.office.net.akadns.net, s-0005.s-msedge.net, ecs.office.trafficmanager.net, omex.cdn.office.net.akamaized.net, a1864.dscd.akamai.net
                                                                        • Not all processes where analyzed, report is missing behavior information
                                                                        • Report size getting too big, too many NtQueryAttributesFile calls found.
                                                                        • Report size getting too big, too many NtQueryValueKey calls found.
                                                                        • Report size getting too big, too many NtReadVirtualMemory calls found.
                                                                        • VT rate limit hit for: Aisha C. Yetman shared you a document..msg
                                                                        InputOutput
                                                                        URL: Email Model: jbxai
                                                                        {
                                                                        "error":"Can't patch loop of type <class 'uvloop.Loop'>"}
                                                                        URL: https://stellarnetwork.sucileton.com/EQn1RAKa/ Model: jbxai
                                                                        {
                                                                        "error":"Can't patch loop of type <class 'uvloop.Loop'>"}
                                                                        URL: https://stellarnetwork.sucileton.com/EQn1RAKa/ Model: jbxai
                                                                        {
                                                                        "error":"Can't patch loop of type <class 'uvloop.Loop'>"}
                                                                        URL: https://stellarnetwork.sucileton.com/EQn1RAKa/ Model: jbxai
                                                                        {
                                                                        "error":"Can't patch loop of type <class 'uvloop.Loop'>"}
                                                                        URL: https://www.instagram.com/ Model: jbxai
                                                                        {
                                                                        "error":"Can't patch loop of type <class 'uvloop.Loop'>"}
                                                                        URL: https://www.instagram.com/ Model: jbxai
                                                                        {
                                                                        "error":"Can't patch loop of type <class 'uvloop.Loop'>"}
                                                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                        File Type:data
                                                                        Category:dropped
                                                                        Size (bytes):231348
                                                                        Entropy (8bit):4.387200850251327
                                                                        Encrypted:false
                                                                        SSDEEP:
                                                                        MD5:4756597A721A5812437D6221CFA7137A
                                                                        SHA1:7734731A04E34EFFB9E1C492A74D7FB70F2FA4F9
                                                                        SHA-256:6BE4C2C23B19B0FAF53628086837F4EE44C98B1C2245F5807A5F9F51522378FD
                                                                        SHA-512:2DA3CB56911760DE51F718DA12D288691EB61163F03454D2B7BAE8A58F7A904FB0EC6CC942FCADC5433C2FE7660237BD1721214902731B50F8B6AC42F3E3A6D8
                                                                        Malicious:false
                                                                        Reputation:unknown
                                                                        Preview:TH02...... ....`........SM01X...,....t.`............IPM.Activity...........h...............h............H..h........]65....h........ 7 .H..h\tor ...AppD...h....0...h......hE4.............h........_`.k...h.5..@...I.+w...h....H...8..k...0....T...............d.........2h...............k..............!h.............. h).............#h....8.........$h 7 .....8....."h........8.....'h..............1hE4..<.........0h....4.....k../h....h......kH..h...p.........-h .............+h=4.......................... ..............F7..............FIPM.Activity....Form....Standard....Journal Entry...IPM.Microsoft.FolderDesign.FormsDescription................F.k..........1122110020000000.GwwMicrosoft...This form is used to create journal entries.........kf...... ..........&...........(.......(... ...@.....................................................................................................................fffffffff........wwwwwwww.p....pp..............p...............pw..............pw..DDDDO..
                                                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                        File Type:XML 1.0 document, ASCII text, with very long lines (1869), with no line terminators
                                                                        Category:dropped
                                                                        Size (bytes):1869
                                                                        Entropy (8bit):5.089506666618127
                                                                        Encrypted:false
                                                                        SSDEEP:
                                                                        MD5:3004C27A7E7D067613C834794E63BB9A
                                                                        SHA1:39BEEE4B3EC1E6408E974A9B3F76B30C7857713C
                                                                        SHA-256:A718E7DA363DFEAFF7F33916FDF71EB8D8BBDCAC903D392EB3EE137D4D74BE54
                                                                        SHA-512:EBA58DF4C8A899F99AC14903CF543D5220D907279DB02EE5A5E0DF543FB61E7EBEA8583DE0D40E9E556E99004022943BDBABE445B2807AB902C92AB5E98AC662
                                                                        Malicious:false
                                                                        Reputation:unknown
                                                                        Preview:<?xml version="1.0" encoding="UTF-8" standalone="yes"?><root><version>1</version><Count>12</Count><Resource><Id>Aptos_26215680</Id><LAT>2024-09-27T09:48:33Z</LAT><key>29939506207.ttf</key><folder>Aptos</folder><type>4</type></Resource><Resource><Id>Aptos_45876480</Id><LAT>2023-10-06T09:55:52Z</LAT><key>27160079615.ttf</key><folder>Aptos</folder><type>4</type></Resource><Resource><Id>Aptos Display_26215680</Id><LAT>2023-10-06T09:55:52Z</LAT><key>23001069669.ttf</key><folder>Aptos Display</folder><type>4</type></Resource><Resource><Id>Aptos Narrow_26215426</Id><LAT>2023-10-06T09:55:52Z</LAT><key>37262344671.ttf</key><folder>Aptos Narrow</folder><type>4</type></Resource><Resource><Id>Aptos Display_26215682</Id><LAT>2023-10-06T09:55:52Z</LAT><key>28367963232.ttf</key><folder>Aptos Display</folder><type>4</type></Resource><Resource><Id>Aptos Narrow_45876224</Id><LAT>2023-10-06T09:55:52Z</LAT><key>24153076628.ttf</key><folder>Aptos Narrow</folder><type>4</type></Resource><Resource><Id>Aptos_
                                                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                        File Type:ASCII text, with very long lines (65536), with no line terminators
                                                                        Category:dropped
                                                                        Size (bytes):322260
                                                                        Entropy (8bit):4.000299760592446
                                                                        Encrypted:false
                                                                        SSDEEP:
                                                                        MD5:CC90D669144261B198DEAD45AA266572
                                                                        SHA1:EF164048A8BC8BD3A015CF63E78BDAC720071305
                                                                        SHA-256:89C701EEFF939A44F28921FD85365ECD87041935DCD0FE0BAF04957DA12C9899
                                                                        SHA-512:16F8A8A6DCBAEAEFB88C7CFF910BCCC71B76A723CF808B810F500E28E543112C2FAE2491D4D209569BD810490EDFF564A2B084709B02963BCAF6FDF1AEEC59AC
                                                                        Malicious:false
                                                                        Reputation:unknown
                                                                        Preview:51253fe60063c31af0d295afb42228b0:v2:2:1:1590:2:8479:76bd602437550e98c9043d06a55186ab7d95dea5a0e935a599f73e62a8c9b158e0afcb19351f6c353940c06a38172b94d18c02cf92bb8a80184eccca0392b259ab3e71dae73e491c7941997cb36ad4a198661f622dad478d840f66d530a0dde78acea3367f91fff62fbb3dc18faff0c708ad30edef5bea8b22c5fd782b770d8993386eaa784fd19a3c3e1db3b537b1a94d3d4fbd46f8df8fddf6d16611969fe0a97c50e0f3ac24750c93257cf5c161184aa7385800c87d803b339632a3d8ec7fe17a0afd83ce9e9d0e3f7b8d579637928a811f1f7e6d1887df2ddc7d4f752c4d600235e426c92c7bf8a1362f95457998cc0e5d4261f0efa4fada0f866dbcefb407dacab7a2914e91c2f08200f38c2d9d621962145b1464b0f204b326118a53ecdcab22bff005fdd5257c99a6dc51ac0600a49f2ef782396987e78c08b846dad5db55e8ccefffc64863bc2c3e90b95a09d25d0814a848c98fe01a82d4e30e6682dd546e12c45ca0d280a45295ab4bd632dafb070edfdc3c9e38313d5aeb195972986f8011b66817028fd8c78b67a0ac7e780eecc3fb6a31f5a025b8a9a3db278a98c0696aeaac739b18688b0f9c7d751bba02cc5f4e41853fb119b3c0c915059aaa92971244a1989124f12881ca88e6410df70b793a2c3a736ff4
                                                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                        File Type:ASCII text, with no line terminators
                                                                        Category:dropped
                                                                        Size (bytes):10
                                                                        Entropy (8bit):2.7219280948873625
                                                                        Encrypted:false
                                                                        SSDEEP:
                                                                        MD5:DE3B1B9DE0F08343FEED48D327754380
                                                                        SHA1:5BA126F93272971ACA7F05BD507D5B9B276170E0
                                                                        SHA-256:79A69295BBEFCAFEEF0A7C28A57226167BE79B5035E2CDF393F946CBE22BFF91
                                                                        SHA-512:2AC609FC6B51868D2026023E543979F9AD65AD5CD72CCAC9FEA566C7A1F713E7FC012AF9910F889915B14688356C83EE0F15CC882A00464E1908897C1B52D4DD
                                                                        Malicious:false
                                                                        Reputation:unknown
                                                                        Preview:1727430515
                                                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                        File Type:SQLite Rollback Journal
                                                                        Category:dropped
                                                                        Size (bytes):4616
                                                                        Entropy (8bit):0.1384465837476566
                                                                        Encrypted:false
                                                                        SSDEEP:
                                                                        MD5:6A1B8F5A68DF51062EDEBB35ACF0646E
                                                                        SHA1:EB8E3CE02D70957C991698EE90D45E880D0BAB3C
                                                                        SHA-256:1BD7665AC8098359337827F618A3D8C791FE53E9A62632A21388BCB6DAE0A739
                                                                        SHA-512:362E60949011F1CA6C80D98563203EBF5C9EE1E276C7BD386EA4EF5D3104EC6D0CC0A6F2BE69BFF8025EB04B4926786E03CA50E69E4CE51C57645D7E75BFA6A5
                                                                        Malicious:false
                                                                        Reputation:unknown
                                                                        Preview:.... .c.....xv.O....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................SQLite format 3......@ ..........................................................................K.................................................................................................................................................................................................................................................................................................................................................................................................
                                                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                        File Type:PNG image data, 960 x 438, 8-bit/color RGBA, non-interlaced
                                                                        Category:dropped
                                                                        Size (bytes):46357
                                                                        Entropy (8bit):7.79720532633092
                                                                        Encrypted:false
                                                                        SSDEEP:
                                                                        MD5:86B281A6D9B1A4EA65525ED42D87927B
                                                                        SHA1:9C2693CB80AC165C3248E63C577FD864421FAC65
                                                                        SHA-256:1E758D5FFC7769A4B2173E96EE5F83C4E12C73B84E68C91349192AC96053C30B
                                                                        SHA-512:64FE2E47D85DE6D429472C9C5A5AB379868C5E53C6AFF5A991F2F34975E47CF5977789CA191E9A54AE14135D7E7C48A1E171C6D56A427F80C011F150F57D8DA6
                                                                        Malicious:false
                                                                        Reputation:unknown
                                                                        Preview:.PNG........IHDR..............2.n....iCCPICC Profile..H....PSY...{.!.$!.).7A:.....(H..!..J.. `CD\..ED..AWE.\. kE......Y..u.`C.{..v.....;3g..w...{.... +r..dX...Q.$................./M............l..Oj....jJ|A...(..X~./....%...."q....InG.&A.D.w..yd.c....rB........\I<.$..gd.....;.".P...a..T>...6Fr..iR.......i..4..x.O.e...4q27..<..m)..5..'%H|.....YoR...E...gX.....o......3..z...&/...8.7G.....aA.W..KR.ek.I...Jf.&......L?;!4b.3...g8-)..6.-.K....."...u.e{OI..~.....P_.....D.Y.HYm|...lN.,_..![K..$..$...i.!.....9;7Hv..\....l........@.<.H.d.On..*......,......b.........:.9..O.C.~}6..........X.>.'7.@|>.3:.....W.yRI.tl..a..(..P.Z@...s`..3p.^....P.....H.)H.+.j...B...........Qp.4.3."..n...<.}`........ ...!*..iC...d.1!W......((...D..Z.m............E....=...a.-..F.$..k..<...`.8.^...+.l8..............>..<..(9....2G1QlT *.......Pe.ZT.......C..>..h*..6G;.}.ah.z.z-..].>.nB........2F.c.q.p0..x.JL>..s.s.s....|.b.t......&bWa...........v.....p..@................>....xk.7>./
                                                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                        File Type:data
                                                                        Category:dropped
                                                                        Size (bytes):30
                                                                        Entropy (8bit):1.2389205950315936
                                                                        Encrypted:false
                                                                        SSDEEP:
                                                                        MD5:18E9B70B626E836A0765D15F28902596
                                                                        SHA1:9E25EC9B138D68D7BE9DA66775CDCFB66CAD2DAB
                                                                        SHA-256:45660B06EBD04558FEEAC03A71D85B6DF26A2511E555069B1C8B009F155B9D04
                                                                        SHA-512:37EDCB0ECE38F4B15B3965CE2930F907390A719ECA69A0C95176884E46FEAFC0DF7783950E93456F7F8A4990016625DBECE4C026F836523838C4849E9592B6B4
                                                                        Malicious:false
                                                                        Reputation:unknown
                                                                        Preview:....].........................
                                                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                                        Category:dropped
                                                                        Size (bytes):18
                                                                        Entropy (8bit):2.725480556997868
                                                                        Encrypted:false
                                                                        SSDEEP:
                                                                        MD5:A5E51FDFAF429614FB5218AB559D299A
                                                                        SHA1:262EC76760BB9A83BCFF955C985E70820DF567AE
                                                                        SHA-256:3E82E9F60CE38815C28B0E5323268BDA212A84C3A9C7ACCC731360F998DF0240
                                                                        SHA-512:9B68F1C04BDE0024CECFC05A37932368CE2F09BD96C72AB0442E16C8CF5456ED9BB995901095AC1BBDF645255014A5E43AADEE475564F01CA6BE3889C96C29C9
                                                                        Malicious:false
                                                                        Reputation:unknown
                                                                        Preview:..t.o.r.r.e.s.....
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Sep 27 08:48:40 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                                                        Category:dropped
                                                                        Size (bytes):2677
                                                                        Entropy (8bit):3.991168719304806
                                                                        Encrypted:false
                                                                        SSDEEP:
                                                                        MD5:8B09723FC2D3F7B898CF28BAB5F9141E
                                                                        SHA1:484F78929142C42186EFFD90243ADEB9F88A87F9
                                                                        SHA-256:343FC314840FEB87D5E4B0EC553C221FA6AF55C98D22CDBCEEF8D29E853F37EE
                                                                        SHA-512:5D75D3EBBE7333208E71E7930C807BAC1145B2EF3D90534A86196B9F5B6C25DDD8A94421FCAE53404E364693243BDE9D21A61BB54F3808B2E8F72EB4336362DC
                                                                        Malicious:false
                                                                        Reputation:unknown
                                                                        Preview:L..................F.@.. ...$+.,....(:.n........y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FWoN..PROGRA~1..t......O.I;Y.N....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V;Y.N....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.V;Y.N....M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.V;Y.N...........................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.V;Y.N...........................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........K........C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Sep 27 08:48:40 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                                                        Category:dropped
                                                                        Size (bytes):2679
                                                                        Entropy (8bit):4.007148326809975
                                                                        Encrypted:false
                                                                        SSDEEP:
                                                                        MD5:A7B512758440B922D67E6BBCD49640A5
                                                                        SHA1:A89971B6F93E80C3131175675062CE9E0F1A52A5
                                                                        SHA-256:39CAD30D5FED7272A874ADEB8CCC05B741EE09EF7D3D3D80846328F6CB47B56B
                                                                        SHA-512:A6C22AC5223501822077D4B0BA5BFFA501C7FC4DEC81B37CA3F2392E57F569768234A6B25DAE7DA01EB283834182608620DC7B95BFDF62D33D860F030E45F334
                                                                        Malicious:false
                                                                        Reputation:unknown
                                                                        Preview:L..................F.@.. ...$+.,.....A.n........y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FWoN..PROGRA~1..t......O.I;Y.N....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V;Y.N....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.V;Y.N....M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.V;Y.N...........................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.V;Y.N...........................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........K........C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:54:41 2023, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                                                        Category:dropped
                                                                        Size (bytes):2693
                                                                        Entropy (8bit):4.016061497687677
                                                                        Encrypted:false
                                                                        SSDEEP:
                                                                        MD5:14E694BF147D4C7259850B24235BA9C5
                                                                        SHA1:6F3F6AF896B3C1C6C5E03002459156CFABCA22D6
                                                                        SHA-256:1B830347E281CA6B4586F4988FFFA25B197B5FD1B095E4B7CBED281F51E768E2
                                                                        SHA-512:739C84466D2A77C9499178ACF84AF25610E6DF8E6F74831E9D7CE612BB536193C68D54747001E30918119BD8D7D5BA51727A334D75914FB3EE407FCF79EB6D5D
                                                                        Malicious:false
                                                                        Reputation:unknown
                                                                        Preview:L..................F.@.. ...$+.,.....v. ;.......y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FWoN..PROGRA~1..t......O.I;Y.N....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V;Y.N....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.V;Y.N....M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.V;Y.N...........................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.VFW.N...........................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........K........C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Sep 27 08:48:40 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                                                        Category:dropped
                                                                        Size (bytes):2681
                                                                        Entropy (8bit):4.005540020805763
                                                                        Encrypted:false
                                                                        SSDEEP:
                                                                        MD5:360DFAE4160C0A5651AD6C8C914C9F20
                                                                        SHA1:62CC4F965342317C5DBE2BF89B64FACABE3690FA
                                                                        SHA-256:9DBCE9EC7996FF665AB8C99BE410D2C37E889A3A320723354B0E781E8F650D17
                                                                        SHA-512:66CAFCEBD8103DB933A6F6B14DE1DF6D9A9A3C375CF4C7052B196FD311168CDAA7AD53FDCEAD9D34D67C0D19D8020B28D22A720D73B3CC354EA092DD434113F0
                                                                        Malicious:false
                                                                        Reputation:unknown
                                                                        Preview:L..................F.@.. ...$+.,.......n........y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FWoN..PROGRA~1..t......O.I;Y.N....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V;Y.N....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.V;Y.N....M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.V;Y.N...........................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.V;Y.N...........................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........K........C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Sep 27 08:48:40 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                                                        Category:dropped
                                                                        Size (bytes):2681
                                                                        Entropy (8bit):3.9947274789923717
                                                                        Encrypted:false
                                                                        SSDEEP:
                                                                        MD5:7855FDE6C48023A7367FF3B5B35CDE5C
                                                                        SHA1:3ACA3543FAEF9D8F1AD005496AFEE90D665E0D31
                                                                        SHA-256:CD3C64DC86B91A699E49BA341DDA57DA2C66563601CCA51C3E5A62DE1C0A6719
                                                                        SHA-512:70061EF4695DFAF1391C91C784E98DD72496CAAE5A63E5687BAE5A4A94ED9582E8B1D5C6460F301B24CB02EC3D2E965D418D4AA7D1B6044D606EF714551E7542
                                                                        Malicious:false
                                                                        Reputation:unknown
                                                                        Preview:L..................F.@.. ...$+.,.....n........y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FWoN..PROGRA~1..t......O.I;Y.N....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V;Y.N....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.V;Y.N....M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.V;Y.N...........................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.V;Y.N...........................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........K........C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                        File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Sep 27 08:48:40 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                                                        Category:dropped
                                                                        Size (bytes):2683
                                                                        Entropy (8bit):4.00546027884774
                                                                        Encrypted:false
                                                                        SSDEEP:
                                                                        MD5:0233A82AD801FD0CD5E2A519AC706123
                                                                        SHA1:130651B226FAC01D05913B9EFB212A59D46ACF43
                                                                        SHA-256:CFBB293B43A84C46AEDCC354B3B9B99F02D7130BB4924FC1EB387507159B9BC5
                                                                        SHA-512:4BBB637B5F29E5E166A4F185D332CABBD98FE81698BABE79F7FA3C66E28A06DA61946820A10757E5747D2C48AA2AEF352CD2EFF21C034214B0BB51B39FDFDE05
                                                                        Malicious:false
                                                                        Reputation:unknown
                                                                        Preview:L..................F.@.. ...$+.,......zn........y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FWoN..PROGRA~1..t......O.I;Y.N....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V;Y.N....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.V;Y.N....M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.V;Y.N...........................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.V;Y.N...........................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........K........C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                        File type:CDFV2 Microsoft Outlook Message
                                                                        Entropy (8bit):6.034978939814106
                                                                        TrID:
                                                                        • Outlook Message (71009/1) 58.92%
                                                                        • Outlook Form Template (41509/1) 34.44%
                                                                        • Generic OLE2 / Multistream Compound File (8008/1) 6.64%
                                                                        File name:Aisha C. Yetman shared you a document..msg
                                                                        File size:111'616 bytes
                                                                        MD5:67340fb3a621311ccd27846c46349c6d
                                                                        SHA1:a23b24990392237da809f5b724ec05ebeff2a54f
                                                                        SHA256:99b0d83c116ab9470d1a50bb9d1616b28afe02930eaccdf1349e3b447b178297
                                                                        SHA512:6a209bb77a587fc1e808e75efa96466d9d2d6d5ce79a24da99fec550acfda64190413c20a2b956ef5547ce540fa078c23b10122f1f1b2458b555f3a6bea069d6
                                                                        SSDEEP:1536:G8SvkKW7cWxW+WspvrWnWrWBWuq8RCoVgElnula5BQN5GtuApCZ8y:G8SvkPvUqu+mnulakHGRDy
                                                                        TLSH:FBB3E82175F94616F2BF9F321AE281878532BCD1DD28D64F3281339E1B725D1A871B3A
                                                                        File Content Preview:........................>.......................................................q..............................................................................................................................................................................
                                                                        Subject:Aisha C. Yetman shared you a document.
                                                                        From:Aisha Yetman <aisha.yetman@shaevitzandshaevitz.com>
                                                                        To:Aisha Yetman <aisha.yetman@shaevitzandshaevitz.com>
                                                                        Cc:
                                                                        BCC:
                                                                        Date:Thu, 26 Sep 2024 22:23:38 +0200
                                                                        Communications:
                                                                        • <https://lsaustralasia-my.sharepoint.com/:f:/g/personal/janine_lsaust_com_au/Eh_UbyNHz6NNpYjJVdYgrwcBqGq7dVVPWUd1_5bX4K66JQ?e=69hdpQ> Best regards, Aisha C. Yetman Legal Assistant Law Offices of Shaevitz & Shaevitz 148-55 Hillside Avenue Jamaica, NY 11435 Telephone: (718) 291-3400 Ext. 240 Fax: (718) 739-5654 E-Mail: aisha.yetman@shaevitzandshaevitz.com <mailto:aisha.yetman@shaevitzandshaevitz.com>
                                                                        Attachments:
                                                                        • image001.png
                                                                        Key Value
                                                                        Receivedfrom MN2PR18MB3024.namprd18.prod.outlook.com
                                                                        MN2PR18MB3024.namprd18.prod.outlook.com with HTTPS; Thu, 26 Sep 2024 2023:43
                                                                        Authentication-Resultsdkim=none (message not signed)
                                                                        by DM4PR18MB4159.namprd18.prod.outlook.com (260310b6:5:38a::8) with
                                                                        2024 2023:38 +0000
                                                                        ([fe80:2b20:5516:eedc:41b1%5]) with mapi id 15.20.7982.022; Thu, 26 Sep 2024
                                                                        2023:38 +0000
                                                                        Content-Typeapplication/ms-tnef; name="winmail.dat"
                                                                        Content-Transfer-Encodingbinary
                                                                        FromAisha Yetman <aisha.yetman@shaevitzandshaevitz.com>
                                                                        ToAisha Yetman <aisha.yetman@shaevitzandshaevitz.com>
                                                                        SubjectAisha C. Yetman shared you a document.
                                                                        Thread-TopicAisha C. Yetman shared you a document.
                                                                        Thread-IndexAdsQUbf2sgJoW/5IS/qfagvFQYmvmQ==
                                                                        DateThu, 26 Sep 2024 20:23:38 +0000
                                                                        Message-ID<MN2PR18MB3024FCB52E2A6B33CB7BE9C8886A2@MN2PR18MB3024.namprd18.prod.outlook.com>
                                                                        Accept-Languageen-US
                                                                        Content-Languageen-US
                                                                        X-MS-Has-Attachyes
                                                                        X-MS-Exchange-Organization-SCL1
                                                                        X-MS-TNEF-Correlator<MN2PR18MB3024FCB52E2A6B33CB7BE9C8886A2@MN2PR18MB3024.namprd18.prod.outlook.com>
                                                                        MIME-Version1.0
                                                                        X-MS-Exchange-Organization-MessageDirectionalityOriginating
                                                                        X-MS-Exchange-Organization-AuthSourceMN2PR18MB3024.namprd18.prod.outlook.com
                                                                        X-MS-Exchange-Organization-AuthAsInternal
                                                                        X-MS-Exchange-Organization-AuthMechanism04
                                                                        X-MS-Exchange-Organization-Network-Message-Id347df392-f917-4540-b732-08dcde691b2a
                                                                        X-MS-PublicTrafficTypeEmail
                                                                        X-MS-TrafficTypeDiagnosticMN2PR18MB3024:EE_|DM4PR18MB4159:EE_|MN2PR18MB3024:EE_
                                                                        Return-Pathaisha.yetman@shaevitzandshaevitz.com
                                                                        X-MS-Exchange-Organization-ExpirationStartTime26 Sep 2024 20:23:39.0765
                                                                        X-MS-Exchange-Organization-ExpirationStartTimeReasonOriginalSubmit
                                                                        X-MS-Exchange-Organization-ExpirationInterval1:00:00:00.0000000
                                                                        X-MS-Exchange-Organization-ExpirationIntervalReasonOriginalSubmit
                                                                        X-MS-Office365-Filtering-Correlation-Id347df392-f917-4540-b732-08dcde691b2a
                                                                        X-Microsoft-AntispamBCL:0;ARA:13230040|4073399012|366016|41050700001;
                                                                        X-Forefront-Antispam-ReportCIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:MN2PR18MB3024.namprd18.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230040)(4073399012)(366016)(41050700001);DIR:INT;
                                                                        X-MS-Exchange-CrossTenant-OriginalArrivalTime26 Sep 2024 20:23:38.7958
                                                                        X-MS-Exchange-CrossTenant-FromEntityHeaderHosted
                                                                        X-MS-Exchange-CrossTenant-Id8f12cb22-e721-4d6c-ba3c-552c7b3705a4
                                                                        X-MS-Exchange-CrossTenant-AuthSourceMN2PR18MB3024.namprd18.prod.outlook.com
                                                                        X-MS-Exchange-CrossTenant-AuthAsInternal
                                                                        X-MS-Exchange-CrossTenant-Network-Message-Id347df392-f917-4540-b732-08dcde691b2a
                                                                        X-MS-Exchange-CrossTenant-MailboxTypeHOSTED
                                                                        X-MS-Exchange-CrossTenant-UserPrincipalNameFMGIS6eTv8xBThSG9Q2vg8tmpuzh47vjZI1FhF6JUfjwvEPBTLrZb4pidjmmdnTXIqdCl/eA4ATMUXlEjhXpkkIrGZunj/FD4QIRPwCSfYXdCGrdpBUzDuZmXLYkpDiw
                                                                        X-MS-Exchange-Transport-CrossTenantHeadersStampedDM4PR18MB4159
                                                                        X-MS-Exchange-Transport-EndToEndLatency00:00:04.2672507
                                                                        X-MS-Exchange-Processed-By-BccFoldering15.20.7982.022
                                                                        X-Microsoft-Antispam-Mailbox-Deliveryucf:1;jmr:0;auth:0;dest:C;OFR:CustomRules;ENG:(910001)(944506478)(944626604)(920097)(425001)(930097)(140003);
                                                                        X-Microsoft-Antispam-Message-Info9q+dqZzuCI8zyOEKNNTN5pUbcO9FpeyHacXy7zL4dbniOu8i1l9C0OL6zC0y00Tb7fIQriVoQz4O47SRxN+nqkidMHsjeVuGHohMSSLL5LENbpmF7WeEF8vl8N4+4r5fOV165a3I+1R0yNhLHCqViWfrsXTYW8CWm8ZfWdBnxa7BZSAkcf0K5gae5xCCbc6MxiZ2c9ZD/2RcgFecUtd9Vw2tcjbDPUWx2Wg9qeoMtkloymnsZGYnwptSZktI2Ndg+cvOjnMByorMquM7pVEUJf57isA32Thtl0FSQWGolYYx9LshRMSqlZSgiQAoLLK2oiAWRvM+5xXYODzO+Nx31VmPDPPyV1nKHzbGpOymgzRlYKhk9LzPP/FxvcfoGZmKX576R+2f785HG72sjdGFa8dQ+/vA6zFd53Rg7/m3v7V8EWd4NltFSHzNv4gzOKEjSff1FoLU4/2OaIVNBpzWSfA/jLEA+CAEuzd58GUb8Clu1O7mk2U29Uv6UZ5AMXD/1uC6Ikjg2nEIu9VTP9VjXHoOo/9/rMe5JgtMhVh6/v1YoZ/RT1+koUfvANSwC6s+33HHqAm6yc8Me+PHoNWasdH6UDI6LOhYiWrSIPsFYyVR+XX5K+gXeTnXPn5MKj64I7xx+8Wrh4GzJZ55K92WIvFuNsjuHTC9Lgoz1A8VwQLnp/71DM1Ls4ckMeIJRooUCO5Rjd/wRyXrqo7xefD5d4uU9k9hughFJ4ekwcuAkRI460fM0AcKpOIt6+7xD65ZMpL/sI2iqMdkugs+fT34Rjk7tGdwUKwiV4rSuprw6OPJoXyUHHSWRfQNs10u28X5EqpFGtdQEK2bFFGM3FT1kyIb8ktXzVWPBSAwyZfsFSdPANxwlS8tkhlWJ7Em1/zrSH/FDml2XoP2WgGvV16SBUBXqCT/pJrNLlOJqooVmus=
                                                                        dateThu, 26 Sep 2024 22:23:38 +0200

                                                                        Icon Hash:c4e1928eacb280a2