Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
(No subject) (91).eml

Overview

General Information

Sample name:(No subject) (91).eml
Analysis ID:1541504
MD5:efb174e1f0f5b73ab950ab361960ea50
SHA1:6757a77fad6b662c487a08654862f804a7304f04
SHA256:2e1c79b2e09a2c9f1cd2df545a2a4b1ae62939c34db1fc0bea633c5e0cfca773
Infos:

Detection

Score:21
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

AI detected potential phishing Email
Queries the volume information (name, serial number etc) of a device
Sigma detected: Office Autorun Keys Modification
Stores large binary data to the registry

Classification

  • System is w10x64_ra
  • OUTLOOK.EXE (PID: 6460 cmdline: "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" /eml "C:\Users\user\Desktop\(No subject) (91).eml" MD5: 91A5292942864110ED734005B7E005C0)
    • ai.exe (PID: 4760 cmdline: "C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe" "C8D29D07-5E0B-4309-9B21-2D2C223BD71C" "F9248E8B-C36B-4A38-B94D-97D9F1873580" "6460" "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" "WordCombinedFloatieLreOnline.onnx" MD5: EC652BEDD90E089D9406AFED89A8A8BD)
  • HxOutlook.exe (PID: 2188 cmdline: "C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exe" -ServerName:microsoft.windowslive.mail.AppXfbjsbkxvprcgqg6q4c9jfr0pn3kv9x5s.mca MD5: 6F8EAC2C377C8F16D91CB5AC8B8DBF5F)
  • HxAccounts.exe (PID: 6744 cmdline: "C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exe" -ServerName:microsoft.windowslive.manageaccounts.AppXdbf3yp5apt3t7q877db3gnz5zqpf71zj.mca MD5: 6FEB00C9A2C3FF66230658B3012BAB6A)
  • cleanup
No configs have been found
No yara matches
Source: Registry Key setAuthor: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): Data: Details: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 , EventID: 13, EventType: SetValue, Image: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE, ProcessId: 6460, TargetObject: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Outlook\Addins\OneNote.OutlookAddin\1
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: http://b.c2r.ts.cdn.office.net/pr
Source: 57C8EDB95DF3F0AD4EE2DC2B8CFD4157.0.drString found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: http://f.c2r.ts.cdn.office.net/pr
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: http://olkflt.edog.officeapps.live.com/olkflt/outlookflighting.svc/api/glides
Source: HxAccounts.exe, 0000000B.00000002.2481062917.000001AAC022B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://test-exp-s2s.msedge.net/ab/
Source: HxAccounts.exe, 0000000B.00000002.2481062917.000001AAC022B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://test-exp-s2s.msedge.net/ab/c
Source: HxAccounts.exe, 0000000B.00000002.2481062917.000001AAC022B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://test-exp-s2s.msedge.net/ab/gehttp://test-exp-s2s.msedge.net/ab/blocklowlabelimageloadsropcall
Source: HxAccounts.exe, 0000000B.00000002.2481062917.000001AAC022B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://test-exp-s2s.msedge.net/ab/http://test-exp-s2s.msedge.net/ab/https://config.edge.skype.net/co
Source: HxAccounts.exe, 0000000B.00000002.2481062917.000001AAC022B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://test-exp-s2s.msedge.net/ab/https://config.edge.skype.com/config/v1/cacheMemoryFullNotificatio
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: http://weather.service.msn.com/data.aspx
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://addinsinstallation.store.office.com/app/acquisitionlogging
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://addinsinstallation.store.office.com/app/download
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://addinsinstallation.store.office.com/appinstall/authenticated
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://addinsinstallation.store.office.com/appinstall/preinstalled
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://addinsinstallation.store.office.com/appinstall/unauthenticated
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://addinsinstallation.store.office.com/orgid/appinstall/authenticated
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://addinslicensing.store.office.com/apps/remove
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://addinslicensing.store.office.com/commerce/query
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://addinslicensing.store.office.com/entitlement/query
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://addinslicensing.store.office.com/orgid/apps/remove
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://addinslicensing.store.office.com/orgid/entitlement/query
Source: (No subject) (91).emlString found in binary or memory: https://aka.ms/LearnAboutSenderIdentification
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://analysis.windows.net/powerbi/api
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://api.aadrm.com
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://api.aadrm.com/
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://api.addins.omex.office.net/api/addins/search
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://api.addins.omex.office.net/appinfo/query
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://api.addins.omex.office.net/appstate/query
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://api.addins.store.office.com/addinstemplate
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://api.addins.store.office.com/app/query
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://api.addins.store.officeppe.com/addinstemplate
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://api.cortana.ai
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://api.diagnostics.office.com
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://api.diagnosticssdf.office.com
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://api.diagnosticssdf.office.com/v2/feedback
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://api.diagnosticssdf.office.com/v2/file
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://api.microsoftstream.com
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://api.microsoftstream.com/api/
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://api.office.net
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://api.officescripts.microsoftusercontent.com/api
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://api.onedrive.com
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://api.powerbi.com/beta/myorg/imports
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://api.powerbi.com/v1.0/myorg/datasets
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://api.powerbi.com/v1.0/myorg/groups
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://api.scheduler.
Source: HxAccounts.exe, 0000000B.00000002.2481062917.000001AAC022B000.00000004.00000020.00020000.00000000.sdmp, 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://apis.live.net/v5.0/
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://apis.mobile.m365.svc.cloud.microsoft
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://app.powerbi.com
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://arc.msn.com/v4/api/selection
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://asgsmsproxyapi.azurewebsites.net/
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://augloop.office.com
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://augloop.office.com/v2
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://augloop.office.com;https://augloop-int.officeppe.com;https://augloop-dogfood.officeppe.com;h
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://autodiscover-s.outlook.com/
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://autodiscover-s.outlook.com/autodiscover/autodiscover.xml
Source: HxAccounts.exe, 0000000B.00000002.2480679692.000001AAC0200000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://az804205.vo.msecnd.net/
Source: HxAccounts.exe, 0000000B.00000002.2480679692.000001AAC0200000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://az804205.vo.msecnd.net/f
Source: HxAccounts.exe, 0000000B.00000002.2480679692.000001AAC0200000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://az815563.vo.msecnd.net/
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://canary.designerapp.
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://cdn.designerapp.osi.office.net
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://cdn.designerapp.osi.office.net/designer-mobile
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://cdn.designerapp.osi.office.net/designerapp/fonts
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://cdn.designerapp.osi.office.net/designerapp/mobile-assets
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://cdn.designerapp.osi.office.net/designerapp/mobile-dynamic-strings
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://cdn.designerapp.osi.office.net/designerapp/mobile-home-screen
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://cdn.designerapp.osi.office.net/designerapp/mobile-toolbar
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://cdn.entity.
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://cdn.hubblecontent.osi.office.net/
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://cdn.int.designerapp.osi.office.net/fonts
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://client-office365-tas.msedge.net/ab
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://clients.config.office.net
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://clients.config.office.net/
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://clients.config.office.net/c2r/v1.0/DeltaAdvisory
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://clients.config.office.net/c2r/v1.0/InteractiveInstallation
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://clients.config.office.net/user/v1.0/android/policies
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://clients.config.office.net/user/v1.0/ios
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://clients.config.office.net/user/v1.0/mac
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://clients.config.office.net/user/v1.0/tenantassociationkey
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://cloudfiles.onenote.com/upload.aspx
Source: HxAccounts.exe, 0000000B.00000002.2481062917.000001AAC022B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://config.edge.skype.com/config/v1/
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://config.edge.skype.com/config/v1/Office
Source: HxAccounts.exe, 0000000B.00000002.2481062917.000001AAC022B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://config.edge.skype.com/config/v1/cacheFileFullNotificationPercentagecacheFileFullNotification
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://config.edge.skype.com/config/v2/Office
Source: HxAccounts.exe, 0000000B.00000002.2481062917.000001AAC022B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://config.edge.skype.net/config/v1/
Source: HxAccounts.exe, 0000000B.00000002.2481062917.000001AAC022B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://config.edge.skype.net/config/v1/http://test-exp-s2s.msedge.net/ab/cacheMemoryFullNotificatio
Source: HxAccounts.exe, 0000000B.00000002.2481062917.000001AAC022B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://config.edge.skype.net/config/v1/standardprotections
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://consent.config.office.com/consentcheckin/v1.0/consents
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://consent.config.office.com/consentweb/v1.0/consents
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://cortana.ai
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://cortana.ai/api
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://cr.office.com
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://d.docs.live.net
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://dataservice.o365filtering.com
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://dataservice.o365filtering.com/
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://dataservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPolicies
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://designerapp.azurewebsites.net
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://designerappservice.officeapps.live.com
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://dev.cortana.ai
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://dev0-api.acompli.net/autodetect
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://devnull.onenote.com
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://directory.services.
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://ecs.office.com
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://ecs.office.com/config/v1/Designer
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://ecs.office.com/config/v2/Office
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://edge.skype.com/registrar/prod
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://edge.skype.com/rps
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://enrichment.osi.office.net/
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/Refresh/v1
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/Resolve/v1
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/Search/v1
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/StockHistory/v1
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/ipcheck/v1
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/web/Metadata/
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/web/Metadata/metadata.json
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/web/view/desktop/main.cshtml
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/web/view/web/main.cshtml
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://entitlement.diagnostics.office.com
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://entitlement.diagnosticssdf.office.com
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://excel.uservoice.com/forums/304936-excel-for-mobile-devices-tablets-phones-android
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://globaldisco.crm.dynamics.com
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://graph.ppe.windows.net
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://graph.ppe.windows.net/
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://graph.windows.net
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://graph.windows.net/
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/api/pivots/
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/api/telemetry
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/browse?cp=remix3d
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/browse?secureurl=1
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=icons&premium=1
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=stockimages&premium=1
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=stockvideos&premium=1
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsofticon?
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://ic3.teams.office.com
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://incidents.diagnostics.office.com
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://incidents.diagnosticssdf.office.com
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://inclient.store.office.com/gyro/client
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://inclient.store.office.com/gyro/clientstore
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://insertmedia.bing.office.net/images/hosted?host=office&adlt=strict&hostType=Immersive
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Bing
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=ClipArt
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Facebook
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Flickr
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=OneDrive
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://insertmedia.bing.office.net/odc/insertmedia
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://invites.office.com/
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://learningtools.onenote.com/learningtoolsapi/v2.0/GetFreeformSpeech
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://learningtools.onenote.com/learningtoolsapi/v2.0/Getvoices
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://lifecycle.office.com
Source: HxAccounts.exe, 0000000B.00000002.2488670547.000001AAC748B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://login.live.com
Source: HxAccounts.exe, 0000000B.00000002.2488670547.000001AAC748B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://login.live.com/
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://login.microsoftonline.com
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://login.microsoftonline.com/
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://login.microsoftonline.com/organizations
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://login.windows-ppe.net/common/oauth2/authorize
Source: HxAccounts.exe, 0000000B.00000002.2488670547.000001AAC748B000.00000004.00000020.00020000.00000000.sdmp, 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://login.windows.local
Source: HxAccounts.exe, 0000000B.00000002.2488670547.000001AAC748B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://login.windows.local/
Source: OUTLOOK_16_0_16827_20130-20241024T1625420668-6460.etl.0.drString found in binary or memory: https://login.windows.local0
Source: OUTLOOK_16_0_16827_20130-20241024T1625420668-6460.etl.0.drString found in binary or memory: https://login.windows.localnulle.O
Source: HxAccounts.exe, 0000000B.00000002.2488670547.000001AAC748B000.00000004.00000020.00020000.00000000.sdmp, App1729801542873750200_FCB8E314-5706-4211-BDB3-A6A9C8D05545.log.0.drString found in binary or memory: https://login.windows.net
Source: HxAccounts.exe, 0000000B.00000002.2488670547.000001AAC748B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://login.windows.net/
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorize
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://login.windows.net/common/oauth2/authorize
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://loki.delve.office.com/api/v1/configuration/officewin32/
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://lookup.onenote.com/lookup/geolocation/v1
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://make.powerautomate.com
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://management.azure.com
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://management.azure.com/
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://messagebroker.mobile.m365.svc.cloud.microsoft
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://messaging.action.office.com/
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://messaging.action.office.com/setcampaignaction
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://messaging.action.office.com/setuseraction16
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://messaging.engagement.office.com/
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://messaging.engagement.office.com/campaignmetadataaggregator
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://messaging.lifecycle.office.com/
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://messaging.lifecycle.office.com/getcustommessage16
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://messaging.office.com/
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://metadata.templates.cdn.office.net/client/log
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://mss.office.com
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://my.microsoftpersonalcontent.com
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://ncus.contentsync.
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://ncus.pagecontentsync.
Source: HxAccounts.exe, 0000000B.00000002.2480857218.000001AAC0213000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://nexus.officeapps.live.com
Source: HxAccounts.exe, 0000000B.00000002.2480857218.000001AAC0213000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://nexusrules.officeapps.live.com0
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://o365auditrealtimeingestion.manage.office.com/api/userauditrecord
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://ocos-office365-s2s.msedge.net/ab
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://odc.officeapps.live.com/odc/stat/images/OneDriveUpsell.png
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://odc.officeapps.live.com/odc/xml?resource=OneDriveSignUpUpsell
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://odc.officeapps.live.com/odc/xml?resource=OneDriveSyncClientUpsell
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://ods-diagnostics-ppe.trafficmanager.net
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://ofcrecsvcapi-int.azurewebsites.net/
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://officeapps.live.com
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://officeci.azurewebsites.net/api/
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://officemobile.uservoice.com/forums/929800-office-app-ios-and-ipad-asks
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://officepyservice.office.net/
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://officepyservice.office.net/service.functionality
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://officesetup.getmicrosoftkey.com
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://ogma.osi.office.net/TradukoApi/api/v1.0/
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officeentities
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officeentitiesupdated
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officesharedentities
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officesharedentitiesupdated
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://onedrive.live.com
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://onedrive.live.com/about/download/?windows10SyncClientInstalled=false
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://onedrive.live.com/embed?
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://otelrules.azureedge.net
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://otelrules.svc.static.microsoft
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://outlook.office.com
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://outlook.office.com/
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://outlook.office.com/autosuggest/api/v1/init?cvid=
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://outlook.office365.com
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://outlook.office365.com/
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://outlook.office365.com/api/v1.0/me/Activities
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://outlook.office365.com/autodiscover/autodiscover.json
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://outlook.office365.com/connectors
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://ovisualuiapp.azurewebsites.net/pbiagave/
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://pages.store.office.com/appshome.aspx?productgroup=Outlook
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://pages.store.office.com/review/query
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://pages.store.office.com/webapplandingpage.aspx
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://partnerservices.getmicrosoftkey.com/PartnerProvisioning.svc/v1/subscriptions
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.json
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://pf.directory.live.com/profile/mine/WLX.Profiles.IC.json
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://portal.office.com/account/?ref=ClientMeControl
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://posarprodcssservice.accesscontrol.windows.net/v2/OAuth2-13
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://powerlift-frontdesk.acompli.net
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://powerlift.acompli.net
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://powerpoint.uservoice.com/forums/288952-powerpoint-for-ipad-iphone-ios
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://prod-global-autodetect.acompli.net/autodetect
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://prod.mds.office.com/mds/api/v1.0/clientmodeldirectory
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://pushchannel.1drv.ms
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://r4.res.office365.com/footprintconfig/v1.7/scripts/fpconfig.json
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://res.cdn.office.net
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://res.cdn.office.net/mro1cdnstorage/fonts/prod/4.40
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://res.cdn.office.net/polymer/models
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://res.getmicrosoftkey.com/api/redemptionevents
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://rpsticket.partnerservices.getmicrosoftkey.com
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://safelinks.protection.outlook.com/api/GetPolicy
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://service.officepy.microsoftusercontent.com/
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://service.powerapps.com
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://settings.outlook.com
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://shell.suite.office.com:1443
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://skyapi.live.net/Activity/
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://sr.outlook.office.net/ws/speech/recognize/assistant/work
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://staging.cortana.ai
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://storage.live.com/clientlogs/uploadlocation
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://store.office.cn/addinstemplate
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://store.office.de/addinstemplate
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://substrate.office.com
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://substrate.office.com/Notes-Internal.ReadWrite
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://substrate.office.com/search/api/v1/SearchHistory
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://substrate.office.com/search/api/v2/init
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://tasks.office.com
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://templatesmetadata.office.net/
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://uci.cdn.office.net/mirrored/smartlookup/current/
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://uci.officeapps.live.com/OfficeInsights/web/views/insights.desktop.html
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://uci.officeapps.live.com/OfficeInsights/web/views/insights.immersive.html
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://useraudit.o365auditrealtimeingestion.manage.office.com
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://visio.uservoice.com/forums/368202-visio-on-devices
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://web.microsoftstream.com/video/
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://webshell.suite.office.com
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://word-edit.officeapps.live.com/we/rrdiscovery.ashx
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://word.uservoice.com/forums/304948-word-for-ipad-iphone-ios
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://wus2.contentsync.
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://wus2.pagecontentsync.
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://www.bingapis.com/api/v7/urlpreview/search?appid=E93048236FE27D972F67C5AF722136866DF65FA2
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://www.odwebp.svc.ms
Source: 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drString found in binary or memory: https://www.yammer.com
Source: HxAccounts.exe, 0000000B.00000002.2489009272.000001AAC74DA000.00000004.00000020.00020000.00000000.sdmp, HxAccounts.exe, 0000000B.00000002.2488670547.000001AAC748B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://xsts.auth.xboxlive.com
Source: HxAccounts.exe, 0000000B.00000002.2488670547.000001AAC748B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://xsts.auth.xboxlive.com/1xI
Source: classification engineClassification label: sus21.winEML@5/20@0/0
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEFile created: C:\Users\user\Documents\Outlook Files\~Outlook Data File - NoEmail.pst.tmpJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEFile created: C:\Users\user\AppData\Local\Temp\Outlook Logging\OUTLOOK_16_0_16827_20130-20241024T1625420668-6460.etlJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: unknownProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" /eml "C:\Users\user\Desktop\(No subject) (91).eml"
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe "C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe" "C8D29D07-5E0B-4309-9B21-2D2C223BD71C" "F9248E8B-C36B-4A38-B94D-97D9F1873580" "6460" "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" "WordCombinedFloatieLreOnline.onnx"
Source: unknownProcess created: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exe "C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exe" -ServerName:microsoft.windowslive.mail.AppXfbjsbkxvprcgqg6q4c9jfr0pn3kv9x5s.mca
Source: unknownProcess created: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exe "C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exe" -ServerName:microsoft.windowslive.manageaccounts.AppXdbf3yp5apt3t7q877db3gnz5zqpf71zj.mca
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe "C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe" "C8D29D07-5E0B-4309-9B21-2D2C223BD71C" "F9248E8B-C36B-4A38-B94D-97D9F1873580" "6460" "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" "WordCombinedFloatieLreOnline.onnx"Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: c2r64.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: userenv.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: msasn1.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: cryptsp.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: rsaenh.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: cryptbase.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: gpapi.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: microsoft.applications.telemetry.windows.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: msoimm.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: mso40uiimm.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: mso30imm.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: mso20imm.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: office.ui.xaml.core.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: office.ui.xaml.word.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: vccorlib140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: msvcp140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: vccorlib140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: vcruntime140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: msvcp140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: vcruntime140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: vccorlib140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: vcruntime140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: msvcp140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: vcruntime140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: msvcp140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: vcruntime140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: msvcp140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: mso98imm.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: mso50imm.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: vcruntime140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: msvcp140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: vcruntime140_1_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: vcruntime140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: msvcp140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: vcruntime140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: vcruntime140_1_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: mso98imm.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: hxoutlook.model.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: windows.storage.applicationdata.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: twinapi.appcore.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: hxcomm.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: cryptsp.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: windows.applicationmodel.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: windows.globalization.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: bcp47langs.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: bcp47mrm.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: onecorecommonproxystub.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: profapi.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: windows.staterepositorycore.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: windows.networking.connectivity.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: windows.networking.hostname.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: windows.energy.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: rmclient.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: wldp.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: propsys.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: rometadata.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: windows.system.diagnostics.telemetry.platformtelemetryclient.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: hxoutlook.view.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: office.ui.xaml.hxshared.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: hxoutlook.viewmodel.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: clipc.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: hxoutlook.resources.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: logoncli.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: windows.ui.xaml.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: iertutil.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: dcomp.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: windows.ui.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: windowmanagementapi.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: inputhost.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: onecoreuapcommonproxystub.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: urlmon.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: srvcli.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: netutils.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: dxgi.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: mrmcorer.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: windows.staterepositoryclient.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: resourcepolicyclient.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: d3d11.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: dxcore.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: dwrite.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: d2d1.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: windows.shell.servicehostbuilder.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: execmodelproxy.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: uiamanager.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: windows.ui.core.textinput.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: windows.ui.immersive.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: dataexchange.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: cryptbase.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: userenv.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: profext.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: office.ui.xaml.hx.mail.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: threadpoolwinrt.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: windows.graphics.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: twinapi.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: office.ui.xaml.hxcalendar.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: windows.ui.xaml.controls.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: windows.system.remotedesktop.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: winsta.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: directmanipulation.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: windows.system.profile.systemid.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: windows.system.profile.retailinfo.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: msxml6.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: wininet.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: winhttp.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: mswsock.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: iphlpapi.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: winnsi.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: winrttracing.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: dnsapi.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: rasadhlp.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: fwpuclnt.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: schannel.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: windows.staterepositoryps.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: windowscodecs.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: photometadatahandler.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: ploptin.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: mskeyprotect.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: ntasn1.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: ncrypt.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: ncryptsslp.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: msasn1.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: dpapi.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: rsaenh.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: gpapi.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: webservices.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: dwmapi.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: userdataaccountapis.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: userdataplatformhelperutil.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: windows.accountscontrol.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: xmllite.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: accountsrt.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: aphostclient.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeSection loaded: execmodelclient.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: hxoutlook.model.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: microsoft.applications.telemetry.windows.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: mso20imm.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: vccorlib140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: vcruntime140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: msvcp140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: mso30imm.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: vccorlib140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: mso20imm.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: vccorlib140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: msvcp140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: vcruntime140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: msvcp140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: vcruntime140_1_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: vcruntime140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: msvcp140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: vcruntime140_1_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: windows.ui.xaml.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: bcp47langs.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: iertutil.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: dcomp.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: twinapi.appcore.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: windows.staterepositorycore.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: windows.ui.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: windowmanagementapi.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: inputhost.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: propsys.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: onecoreuapcommonproxystub.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: urlmon.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: srvcli.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: netutils.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: dxgi.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: resourcepolicyclient.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: office.ui.xaml.hxaccounts.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: d3d11.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: windows.storage.applicationdata.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: dxcore.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: d2d1.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: hxcomm.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: cryptsp.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: dwrite.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: windows.applicationmodel.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: windows.globalization.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: bcp47mrm.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: onecorecommonproxystub.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: profapi.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: windows.networking.connectivity.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: windows.networking.hostname.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: windows.energy.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: rmclient.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: wldp.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: rometadata.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: windows.system.diagnostics.telemetry.platformtelemetryclient.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: mrmcorer.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: windows.staterepositoryclient.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: windows.shell.servicehostbuilder.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: execmodelproxy.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: uiamanager.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: windows.ui.core.textinput.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: windows.ui.immersive.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: dataexchange.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: cryptbase.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: windows.accountscontrol.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: xmllite.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: windows.security.authentication.web.core.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: vaultcli.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: windows.ui.xaml.controls.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: userenv.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: profext.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: directmanipulation.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: winrttracing.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: hxoutlook.resources.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: msftedit.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: globinputhost.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: windowscodecs.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: windows.graphics.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: wuceffects.dllJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeSection loaded: threadpoolwinrt.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}\InprocServer32Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEWindow found: window name: SysTabControl32Jump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeFile opened: C:\Windows\SYSTEM32\msftedit.dllJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\CommonJump to behavior

Persistence and Installation Behavior

barindex
Source: EmailLLM: Detected potential phishing email: The sender's email domain (cromex.net) does not match the claimed organization (City of Santa Clara CA)
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEKey value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\outlook\ConfigContextData 1Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEFile Volume queried: C:\Windows\SysWOW64 FullSizeInformationJump to behavior
Source: settings.dat.LOG1.4.drBinary or memory string: VMware, Inc. VMware20,17
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information queried: ProcessInformationJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeQueries volume information: C:\Program Files (x86)\Microsoft Office\root\Office16\AI\WordCombinedFloatieLreOnline.onnx VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeQueries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeQueries volume information: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\images\offsym.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeQueries volume information: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\images\offsym.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeQueries volume information: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\en-gb\locimages\offsym.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeQueries volume information: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\en-gb\locimages\offsym.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeQueries volume information: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\images\offsymsb.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeQueries volume information: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\images\offsymsb.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeQueries volume information: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\en-gb\locimages\offsymsb.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeQueries volume information: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\en-gb\locimages\offsymsb.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeQueries volume information: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\images\offsymsl.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeQueries volume information: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\images\offsymsl.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeQueries volume information: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\en-gb\locimages\offsymsl.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeQueries volume information: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\en-gb\locimages\offsymsl.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeQueries volume information: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\images\offsymsl.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeQueries volume information: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\images\offsymsl.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeQueries volume information: C:\Windows\Fonts\segoeuil.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeQueries volume information: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\images\offsym.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeQueries volume information: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\images\offsym.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exeQueries volume information: C:\Windows\Fonts\segoeuisl.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeQueries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exeQueries volume information: C:\Windows\Fonts\segmdl2.ttf VolumeInformationJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Browser Extensions
1
Process Injection
1
Masquerading
OS Credential Dumping1
Security Software Discovery
Remote ServicesData from Local SystemData ObfuscationExfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/Job1
DLL Side-Loading
1
DLL Side-Loading
1
Modify Registry
LSASS Memory1
Process Discovery
Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
Process Injection
Security Account Manager14
System Information Discovery
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
DLL Side-Loading
NTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1541504 Sample: (No subject) (91).eml Startdate: 24/10/2024 Architecture: WINDOWS Score: 21 21 AI detected potential phishing Email 2->21 6 OUTLOOK.EXE 96 110 2->6         started        9 HxOutlook.exe 77 18 2->9         started        11 HxAccounts.exe 1 2->11         started        process3 file4 15 C:\...\~Outlook Data File - NoEmail.pst.tmp, data 6->15 dropped 17 C:\Users\...\Outlook Data File - NoEmail.pst, Microsoft 6->17 dropped 19 C:\Users\user\AppData\Roaming\...19oEmail.srs, Composite 6->19 dropped 13 ai.exe 6->13         started        process5

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://api.diagnosticssdf.office.com0%URL Reputationsafe
https://login.microsoftonline.com/0%URL Reputationsafe
https://shell.suite.office.com:14430%URL Reputationsafe
https://designerapp.azurewebsites.net0%URL Reputationsafe
https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorize0%URL Reputationsafe
https://autodiscover-s.outlook.com/0%URL Reputationsafe
https://useraudit.o365auditrealtimeingestion.manage.office.com0%URL Reputationsafe
https://outlook.office365.com/connectors0%URL Reputationsafe
https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Flickr0%URL Reputationsafe
https://cdn.entity.0%URL Reputationsafe
https://api.addins.omex.office.net/appinfo/query0%URL Reputationsafe
https://clients.config.office.net/user/v1.0/tenantassociationkey0%URL Reputationsafe
https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/0%URL Reputationsafe
https://powerlift.acompli.net0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://lookup.onenote.com/lookup/geolocation/v10%URL Reputationsafe
https://cortana.ai0%URL Reputationsafe
https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech0%URL Reputationsafe
https://cloudfiles.onenote.com/upload.aspx0%URL Reputationsafe
https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
https://entitlement.diagnosticssdf.office.com0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://ofcrecsvcapi-int.azurewebsites.net/0%URL Reputationsafe
https://canary.designerapp.0%URL Reputationsafe
https://ic3.teams.office.com0%URL Reputationsafe
https://www.yammer.com0%URL Reputationsafe
https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPolicies0%URL Reputationsafe
https://insertmedia.bing.office.net/images/hosted?host=office&adlt=strict&hostType=Immersive0%URL Reputationsafe
https://cr.office.com0%URL Reputationsafe
https://messagebroker.mobile.m365.svc.cloud.microsoft0%URL Reputationsafe
https://portal.office.com/account/?ref=ClientMeControl0%URL Reputationsafe
https://clients.config.office.net/c2r/v1.0/DeltaAdvisory0%URL Reputationsafe
https://edge.skype.com/registrar/prod0%URL Reputationsafe
https://graph.ppe.windows.net0%URL Reputationsafe
https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
https://powerlift-frontdesk.acompli.net0%URL Reputationsafe
https://tasks.office.com0%URL Reputationsafe
https://officeci.azurewebsites.net/api/0%URL Reputationsafe
https://sr.outlook.office.net/ws/speech/recognize/assistant/work0%URL Reputationsafe
https://api.scheduler.0%URL Reputationsafe
https://store.office.cn/addinstemplate0%URL Reputationsafe
https://api.aadrm.com0%URL Reputationsafe
https://edge.skype.com/rps0%URL Reputationsafe
https://globaldisco.crm.dynamics.com0%URL Reputationsafe
https://messaging.engagement.office.com/0%URL Reputationsafe
https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech0%URL Reputationsafe
https://dev0-api.acompli.net/autodetect0%URL Reputationsafe
https://www.odwebp.svc.ms0%URL Reputationsafe
https://api.diagnosticssdf.office.com/v2/feedback0%URL Reputationsafe
https://api.powerbi.com/v1.0/myorg/groups0%URL Reputationsafe
https://web.microsoftstream.com/video/0%URL Reputationsafe
https://api.addins.store.officeppe.com/addinstemplate0%URL Reputationsafe
https://graph.windows.net0%URL Reputationsafe
https://dataservice.o365filtering.com/0%URL Reputationsafe
https://officesetup.getmicrosoftkey.com0%URL Reputationsafe
https://analysis.windows.net/powerbi/api0%URL Reputationsafe
https://aka.ms/LearnAboutSenderIdentification0%URL Reputationsafe
https://prod-global-autodetect.acompli.net/autodetect0%URL Reputationsafe
https://substrate.office.com0%URL Reputationsafe
https://outlook.office365.com/autodiscover/autodiscover.json0%URL Reputationsafe
https://powerpoint.uservoice.com/forums/288952-powerpoint-for-ipad-iphone-ios0%URL Reputationsafe
https://consent.config.office.com/consentcheckin/v1.0/consents0%URL Reputationsafe
https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech0%URL Reputationsafe
https://learningtools.onenote.com/learningtoolsapi/v2.0/Getvoices0%URL Reputationsafe
https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.json0%URL Reputationsafe
https://safelinks.protection.outlook.com/api/GetPolicy0%URL Reputationsafe
https://ncus.contentsync.0%URL Reputationsafe
https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/0%URL Reputationsafe
http://weather.service.msn.com/data.aspx0%URL Reputationsafe
https://apis.live.net/v5.0/0%URL Reputationsafe
https://officepyservice.office.net/service.functionality0%URL Reputationsafe
https://officemobile.uservoice.com/forums/929800-office-app-ios-and-ipad-asks0%URL Reputationsafe
https://templatesmetadata.office.net/0%URL Reputationsafe
https://word.uservoice.com/forums/304948-word-for-ipad-iphone-ios0%URL Reputationsafe
https://messaging.lifecycle.office.com/0%URL Reputationsafe
https://autodiscover-s.outlook.com/autodiscover/autodiscover.xml0%URL Reputationsafe
https://mss.office.com0%URL Reputationsafe
https://pushchannel.1drv.ms0%URL Reputationsafe
https://management.azure.com0%URL Reputationsafe
https://outlook.office365.com0%URL Reputationsafe
https://login.windows.net0%URL Reputationsafe
https://wus2.contentsync.0%URL Reputationsafe
https://incidents.diagnostics.office.com0%URL Reputationsafe
https://clients.config.office.net/user/v1.0/ios0%URL Reputationsafe
https://make.powerautomate.com0%URL Reputationsafe
https://api.addins.omex.office.net/api/addins/search0%URL Reputationsafe
https://insertmedia.bing.office.net/odc/insertmedia0%URL Reputationsafe
https://outlook.office365.com/api/v1.0/me/Activities0%URL Reputationsafe
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.210.172
truefalse
    unknown
    NameSourceMaliciousAntivirus DetectionReputation
    https://api.diagnosticssdf.office.com8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
    • URL Reputation: safe
    unknown
    https://login.microsoftonline.com/8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
    • URL Reputation: safe
    unknown
    https://shell.suite.office.com:14438095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
    • URL Reputation: safe
    unknown
    https://designerapp.azurewebsites.net8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
    • URL Reputation: safe
    unknown
    https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorize8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
    • URL Reputation: safe
    unknown
    https://autodiscover-s.outlook.com/8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
    • URL Reputation: safe
    unknown
    https://useraudit.o365auditrealtimeingestion.manage.office.com8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
    • URL Reputation: safe
    unknown
    https://outlook.office365.com/connectors8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
    • URL Reputation: safe
    unknown
    https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Flickr8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
    • URL Reputation: safe
    unknown
    https://cdn.entity.8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
    • URL Reputation: safe
    unknown
    https://api.addins.omex.office.net/appinfo/query8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
    • URL Reputation: safe
    unknown
    https://clients.config.office.net/user/v1.0/tenantassociationkey8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
    • URL Reputation: safe
    unknown
    https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
    • URL Reputation: safe
    unknown
    https://config.edge.skype.net/config/v1/standardprotectionsHxAccounts.exe, 0000000B.00000002.2481062917.000001AAC022B000.00000004.00000020.00020000.00000000.sdmpfalse
      unknown
      https://powerlift.acompli.net8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
      • URL Reputation: safe
      unknown
      https://rpsticket.partnerservices.getmicrosoftkey.com8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
      • URL Reputation: safe
      unknown
      https://lookup.onenote.com/lookup/geolocation/v18095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
      • URL Reputation: safe
      unknown
      https://cortana.ai8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
      • URL Reputation: safe
      unknown
      https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
      • URL Reputation: safe
      unknown
      https://cloudfiles.onenote.com/upload.aspx8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
      • URL Reputation: safe
      unknown
      https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
      • URL Reputation: safe
      unknown
      https://entitlement.diagnosticssdf.office.com8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
      • URL Reputation: safe
      unknown
      https://api.aadrm.com/8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
      • URL Reputation: safe
      unknown
      https://ofcrecsvcapi-int.azurewebsites.net/8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
      • URL Reputation: safe
      unknown
      https://canary.designerapp.8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
      • URL Reputation: safe
      unknown
      https://ic3.teams.office.com8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
      • URL Reputation: safe
      unknown
      https://config.edge.skype.net/config/v1/HxAccounts.exe, 0000000B.00000002.2481062917.000001AAC022B000.00000004.00000020.00020000.00000000.sdmpfalse
        unknown
        https://www.yammer.com8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
        • URL Reputation: safe
        unknown
        https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPolicies8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
        • URL Reputation: safe
        unknown
        https://api.microsoftstream.com/api/8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
          unknown
          https://insertmedia.bing.office.net/images/hosted?host=office&adlt=strict&hostType=Immersive8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
          • URL Reputation: safe
          unknown
          https://cr.office.com8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
          • URL Reputation: safe
          unknown
          https://augloop.office.com;https://augloop-int.officeppe.com;https://augloop-dogfood.officeppe.com;h8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
            unknown
            https://xsts.auth.xboxlive.com/1xIHxAccounts.exe, 0000000B.00000002.2488670547.000001AAC748B000.00000004.00000020.00020000.00000000.sdmpfalse
              unknown
              https://messagebroker.mobile.m365.svc.cloud.microsoft8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
              • URL Reputation: safe
              unknown
              https://otelrules.svc.static.microsoft8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
                unknown
                https://portal.office.com/account/?ref=ClientMeControl8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
                • URL Reputation: safe
                unknown
                https://clients.config.office.net/c2r/v1.0/DeltaAdvisory8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
                • URL Reputation: safe
                unknown
                https://edge.skype.com/registrar/prod8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
                • URL Reputation: safe
                unknown
                https://graph.ppe.windows.net8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
                • URL Reputation: safe
                unknown
                https://res.getmicrosoftkey.com/api/redemptionevents8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
                • URL Reputation: safe
                unknown
                https://powerlift-frontdesk.acompli.net8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
                • URL Reputation: safe
                unknown
                https://tasks.office.com8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
                • URL Reputation: safe
                unknown
                https://officeci.azurewebsites.net/api/8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
                • URL Reputation: safe
                unknown
                https://sr.outlook.office.net/ws/speech/recognize/assistant/work8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
                • URL Reputation: safe
                unknown
                https://api.scheduler.8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
                • URL Reputation: safe
                unknown
                https://my.microsoftpersonalcontent.com8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
                  unknown
                  https://store.office.cn/addinstemplate8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
                  • URL Reputation: safe
                  unknown
                  https://api.aadrm.com8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
                  • URL Reputation: safe
                  unknown
                  https://edge.skype.com/rps8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
                  • URL Reputation: safe
                  unknown
                  https://outlook.office.com/autosuggest/api/v1/init?cvid=8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
                    unknown
                    https://globaldisco.crm.dynamics.com8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
                    • URL Reputation: safe
                    unknown
                    https://messaging.engagement.office.com/8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
                    • URL Reputation: safe
                    unknown
                    https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
                    • URL Reputation: safe
                    unknown
                    https://dev0-api.acompli.net/autodetect8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
                    • URL Reputation: safe
                    unknown
                    https://www.odwebp.svc.ms8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
                    • URL Reputation: safe
                    unknown
                    https://api.diagnosticssdf.office.com/v2/feedback8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
                    • URL Reputation: safe
                    unknown
                    https://api.powerbi.com/v1.0/myorg/groups8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
                    • URL Reputation: safe
                    unknown
                    https://web.microsoftstream.com/video/8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
                    • URL Reputation: safe
                    unknown
                    https://api.addins.store.officeppe.com/addinstemplate8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
                    • URL Reputation: safe
                    unknown
                    https://graph.windows.net8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
                    • URL Reputation: safe
                    unknown
                    https://dataservice.o365filtering.com/8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
                    • URL Reputation: safe
                    unknown
                    https://officesetup.getmicrosoftkey.com8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
                    • URL Reputation: safe
                    unknown
                    https://analysis.windows.net/powerbi/api8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
                    • URL Reputation: safe
                    unknown
                    https://aka.ms/LearnAboutSenderIdentification(No subject) (91).emlfalse
                    • URL Reputation: safe
                    unknown
                    https://prod-global-autodetect.acompli.net/autodetect8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
                    • URL Reputation: safe
                    unknown
                    https://substrate.office.com8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
                    • URL Reputation: safe
                    unknown
                    https://login.windows.net/HxAccounts.exe, 0000000B.00000002.2488670547.000001AAC748B000.00000004.00000020.00020000.00000000.sdmpfalse
                      unknown
                      https://outlook.office365.com/autodiscover/autodiscover.json8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
                      • URL Reputation: safe
                      unknown
                      https://powerpoint.uservoice.com/forums/288952-powerpoint-for-ipad-iphone-ios8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
                      • URL Reputation: safe
                      unknown
                      https://consent.config.office.com/consentcheckin/v1.0/consents8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
                      • URL Reputation: safe
                      unknown
                      https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
                      • URL Reputation: safe
                      unknown
                      https://learningtools.onenote.com/learningtoolsapi/v2.0/Getvoices8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
                      • URL Reputation: safe
                      unknown
                      https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.json8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
                      • URL Reputation: safe
                      unknown
                      https://d.docs.live.net8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
                        unknown
                        https://safelinks.protection.outlook.com/api/GetPolicy8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
                        • URL Reputation: safe
                        unknown
                        https://ncus.contentsync.8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
                        • URL Reputation: safe
                        unknown
                        https://onedrive.live.com/about/download/?windows10SyncClientInstalled=false8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
                          unknown
                          https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
                          • URL Reputation: safe
                          unknown
                          http://weather.service.msn.com/data.aspx8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
                          • URL Reputation: safe
                          unknown
                          https://apis.live.net/v5.0/HxAccounts.exe, 0000000B.00000002.2481062917.000001AAC022B000.00000004.00000020.00020000.00000000.sdmp, 8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
                          • URL Reputation: safe
                          unknown
                          https://officepyservice.office.net/service.functionality8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
                          • URL Reputation: safe
                          unknown
                          https://officemobile.uservoice.com/forums/929800-office-app-ios-and-ipad-asks8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
                          • URL Reputation: safe
                          unknown
                          https://templatesmetadata.office.net/8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
                          • URL Reputation: safe
                          unknown
                          https://word.uservoice.com/forums/304948-word-for-ipad-iphone-ios8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
                          • URL Reputation: safe
                          unknown
                          https://messaging.lifecycle.office.com/8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
                          • URL Reputation: safe
                          unknown
                          https://autodiscover-s.outlook.com/autodiscover/autodiscover.xml8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
                          • URL Reputation: safe
                          unknown
                          https://mss.office.com8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
                          • URL Reputation: safe
                          unknown
                          https://pushchannel.1drv.ms8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
                          • URL Reputation: safe
                          unknown
                          https://management.azure.com8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
                          • URL Reputation: safe
                          unknown
                          https://outlook.office365.com8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
                          • URL Reputation: safe
                          unknown
                          https://login.windows.netHxAccounts.exe, 0000000B.00000002.2488670547.000001AAC748B000.00000004.00000020.00020000.00000000.sdmp, App1729801542873750200_FCB8E314-5706-4211-BDB3-A6A9C8D05545.log.0.drfalse
                          • URL Reputation: safe
                          unknown
                          https://wus2.contentsync.8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
                          • URL Reputation: safe
                          unknown
                          https://incidents.diagnostics.office.com8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
                          • URL Reputation: safe
                          unknown
                          https://clients.config.office.net/user/v1.0/ios8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
                          • URL Reputation: safe
                          unknown
                          https://make.powerautomate.com8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
                          • URL Reputation: safe
                          unknown
                          https://api.addins.omex.office.net/api/addins/search8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
                          • URL Reputation: safe
                          unknown
                          https://insertmedia.bing.office.net/odc/insertmedia8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
                          • URL Reputation: safe
                          unknown
                          https://xsts.auth.xboxlive.comHxAccounts.exe, 0000000B.00000002.2489009272.000001AAC74DA000.00000004.00000020.00020000.00000000.sdmp, HxAccounts.exe, 0000000B.00000002.2488670547.000001AAC748B000.00000004.00000020.00020000.00000000.sdmpfalse
                            unknown
                            https://outlook.office365.com/api/v1.0/me/Activities8095E2CC-07E8-49AD-AF2A-4FECF10FF61C.4.drfalse
                            • URL Reputation: safe
                            unknown
                            No contacted IP infos
                            Joe Sandbox version:41.0.0 Charoite
                            Analysis ID:1541504
                            Start date and time:2024-10-24 22:25:14 +02:00
                            Joe Sandbox product:CloudBasic
                            Overall analysis duration:0h 4m 8s
                            Hypervisor based Inspection enabled:false
                            Report type:full
                            Cookbook file name:defaultwindowsinteractivecookbook.jbs
                            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                            Number of analysed new started processes analysed:18
                            Number of new started drivers analysed:0
                            Number of existing processes analysed:0
                            Number of existing drivers analysed:0
                            Number of injected processes analysed:0
                            Technologies:
                            • EGA enabled
                            • AMSI enabled
                            Analysis Mode:default
                            Analysis stop reason:Timeout
                            Sample name:(No subject) (91).eml
                            Detection:SUS
                            Classification:sus21.winEML@5/20@0/0
                            Cookbook Comments:
                            • Found application associated with file extension: .eml
                            • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, BackgroundTransferHost.exe, HxTsr.exe, SIHClient.exe, SgrmBroker.exe, conhost.exe, svchost.exe
                            • Excluded IPs from analysis (whitelisted): 52.113.194.132, 52.109.76.243, 2.19.126.151, 2.19.126.160, 199.232.210.172, 20.42.72.131, 52.109.28.46, 13.107.42.16
                            • Excluded domains from analysis (whitelisted): omex.cdn.office.net, config.edge.skype.com.trafficmanager.net, slscr.update.microsoft.com, eur.roaming1.live.com.akadns.net, neu-azsc-000.roaming.officeapps.live.com, ecs-office.s-0005.s-msedge.net, roaming.officeapps.live.com, login.live.com, config-edge-skype.l-0007.l-msedge.net, officeclient.microsoft.com, l-0007.l-msedge.net, wu-b-net.trafficmanager.net, config.edge.skype.com, a1864.dscd.akamai.net, ecs.office.com, self-events-data.trafficmanager.net, fs.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, self.events.data.microsoft.com, prod.configsvc1.live.com.akadns.net, ctldl.windowsupdate.com, prod.roaming1.live.com.akadns.net, s-0005-office.config.skype.com, fe3cr.delivery.mp.microsoft.com, outlookmobile-office365-tas.msedge.net, s-0005.s-msedge.net, l-0007.config.skype.com, config.officeapps.live.com, osiprod-neu-buff-azsc-000.northeurope.cloudapp.azure.com, onedscolprdeus00.eastus.cloudapp.azure.com, settings.data.microsoft.com, ecs.office.tr
                            • Not all processes where analyzed, report is missing behavior information
                            • Report size exceeded maximum capacity and may have missing behavior information.
                            • Report size getting too big, too many NtOpenKey calls found.
                            • Report size getting too big, too many NtOpenKeyEx calls found.
                            • Report size getting too big, too many NtProtectVirtualMemory calls found.
                            • Report size getting too big, too many NtQueryAttributesFile calls found.
                            • Report size getting too big, too many NtQueryValueKey calls found.
                            • VT rate limit hit for: (No subject) (91).eml
                            No simulations
                            No context
                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                            bg.microsoft.map.fastly.netDoc-Secure6033.pdfGet hashmaliciousUnknownBrowse
                            • 199.232.210.172
                            https://email.sg.on24event.com/ls/click?upn=u001.7kf5QUY4LGF7Fzt7LGE4bbPPsSPtBC4KXSPVJqWhtiGKYA8h-2Fs2ZE4k4Mw5OTNkG7MXiFSxnNtW0j6ofSHAXW1HldotIiuSczAWXKMwqPC9SEFfmHbhfPeJSnLL1byLqHFtV-2B5-2Bzlu3aEmkvEsjdF4pfPyN0cCie5qLdpyqXEVc-3DdW75_nptsQERiP2bxDplO0Yopma5-2B3-2BHXjIBfjCSriTnBL6bDAIVjKAbvVGNCWdU9DqIsFlkV1hwq0qq8QFfBJ4Jw83lxfQiag11eNjful-2F5DZNB0MfOdNL9CUK7i3u0XSRn3tgRxnTXYhlIImrFKtd24RJvAaDi0YLYq-2F-2Bnuc9osPPDAYREdTeCb9pcHCOzNWNquq3heowckATHcFvqXT76Jk2gcbZFXWlQRsFjG8eDMpM-2FLXpgzBvYnGXnUOibU2YR8sPRE-2FoPHFza-2Fw01eQ45phCwYix9qckBwiXG0HXQmAbfGqimPLouUL92q8izxx4IU5EnAunMVPc46qKMPXhEF7g-3D-3DGet hashmaliciousUnknownBrowse
                            • 199.232.214.172
                            QN1BkRVd.emlGet hashmaliciousUnknownBrowse
                            • 199.232.210.172
                            https://na2.docusign.net/Signing/EmailStart.aspx?a=c6104538-ac3b-4407-b24b-a0b641ee4589&etti=24&acct=7853161b-6814-4528-85bc-ffe96cfca42f&er=09ab18a7-8de5-4c92-931d-cb9cd9f7b00dGet hashmaliciousUnknownBrowse
                            • 199.232.214.172
                            https://egift.activationshub.com/gift-card/view/8lPFUrjq1LGzg7JHwS8hJJRdLGet hashmaliciousUnknownBrowse
                            • 199.232.214.172
                            https://www.canva.com/design/DAGUUU-VdiI/DdL4Z-_loK4X7NMMbGGnJg/view?utm_content=DAGUUU-VdiI&utm_campaign=designshare&utm_medium=link&utm_source=editorGet hashmaliciousUnknownBrowse
                            • 199.232.214.172
                            Windows-StandardCollector-x64.exeGet hashmaliciousCodoso GhostBrowse
                            • 199.232.210.172
                            Payment for outstanding statements.pdfGet hashmaliciousHTMLPhisherBrowse
                            • 199.232.214.172
                            ATT25322.htmlGet hashmaliciousUnknownBrowse
                            • 199.232.210.172
                            https://app.pandadoc.com/document/v2?token=69b8ae0059c2551a9a27ed1b65653c1a0b5ee1ffGet hashmaliciousUnknownBrowse
                            • 199.232.214.172
                            No context
                            No context
                            No context
                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                            File Type:data
                            Category:dropped
                            Size (bytes):338
                            Entropy (8bit):3.4494683590191086
                            Encrypted:false
                            SSDEEP:6:kKUsK8B3JFN+SkQlPlEGYRMY9z+s3Ql2DUevat:8rIckPlE99SCQl2DUevat
                            MD5:37283C47053B3FCD31D23DCE5101804D
                            SHA1:80256E9CDBA78D84F5ACF112F2A608E5067F3F74
                            SHA-256:74C2BB5DDA0E3B87C170776221BBB0451CFED46B853B7251E97DECE2C91F2D63
                            SHA-512:0657099C762C95ED34CF2DA65860D9D76DBF95F4ABE001BBDCED4D8BB2C7022AC048C493CE749BB3C063ED826A62FD275A5F856A11FCE1C96122453FB23F27B5
                            Malicious:false
                            Reputation:low
                            Preview:p...... .........?..R&..(...............................................9p,.VZ.. .........p.........$...............h.t.t.p.:././.c.t.l.d.l...w.i.n.d.o.w.s.u.p.d.a.t.e...c.o.m./.m.s.d.o.w.n.l.o.a.d./.u.p.d.a.t.e./.v.3./.s.t.a.t.i.c./.t.r.u.s.t.e.d.r./.e.n./.d.i.s.a.l.l.o.w.e.d.c.e.r.t.s.t.l...c.a.b...".7.4.6.7.8.7.a.3.f.0.d.9.1.:.0."...
                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                            File Type:data
                            Category:dropped
                            Size (bytes):231348
                            Entropy (8bit):4.392352922368157
                            Encrypted:false
                            SSDEEP:3072:vRgE8TgEmiGu2UqoQcrt0Fv3ajNXgm+d9:vCpmi2RMjNXgm+v
                            MD5:19D332ABC084C1F5700D4F6B41796AED
                            SHA1:63CE111BA7F64E3D1E4108A6CB127CC36AA141D7
                            SHA-256:7A6C637871E91620063FCD15730626AA4473A398FF307ED5F60E44A414E9D95E
                            SHA-512:7EC6162258A45AF264485EC710FAF52E685E462C8B6E6995C1F2C0DCC473CB40728C37545631A86B2573319184A29A8935F4390714CA63B7615BB484F5612B5B
                            Malicious:false
                            Reputation:low
                            Preview:TH02...... ....R&......SM01X...,.....}.R&..........IPM.Activity...........h...............h............H..hL........K.....h............H..h\nor ...ppDa...h0...0..........h.P.b...........h........_`.k...h.S.b@...I..w...h....H...8..k...0....T...............d.........2h...............k..............!h.............. h...L..........#h....8.........$h........8....."h........X.....'h..}...........1h.P.b<.........0h....4....k../h....h......kH..h....p...L.....-h ...........+hjQ.b....@................... ..............F7..............FIPM.Activity....Form....Standard....Journal Entry...IPM.Microsoft.FolderDesign.FormsDescription................F.k..........1122110020000000....Microsoft...This form is used to create journal entries.........kf...... ..........&...........(.......(... ...@.....................................................................................................................fffffffff........wwwwwwww.p....pp..............p...............pw..............pw..DDDDO..
                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                            File Type:ASCII text, with very long lines (65536), with no line terminators
                            Category:dropped
                            Size (bytes):322260
                            Entropy (8bit):4.000299760592446
                            Encrypted:false
                            SSDEEP:6144:dztCFLNyoAHq5Rv2SCtUTnRe4N2+A/3oKBL37GZbTSB+pMZIrh:HMLgvKz9CtgRemO3oUHi3SBSMZIl
                            MD5:CC90D669144261B198DEAD45AA266572
                            SHA1:EF164048A8BC8BD3A015CF63E78BDAC720071305
                            SHA-256:89C701EEFF939A44F28921FD85365ECD87041935DCD0FE0BAF04957DA12C9899
                            SHA-512:16F8A8A6DCBAEAEFB88C7CFF910BCCC71B76A723CF808B810F500E28E543112C2FAE2491D4D209569BD810490EDFF564A2B084709B02963BCAF6FDF1AEEC59AC
                            Malicious:false
                            Reputation:high, very likely benign file
                            Preview:51253fe60063c31af0d295afb42228b0:v2:2:1:1590:2:8479:76bd602437550e98c9043d06a55186ab7d95dea5a0e935a599f73e62a8c9b158e0afcb19351f6c353940c06a38172b94d18c02cf92bb8a80184eccca0392b259ab3e71dae73e491c7941997cb36ad4a198661f622dad478d840f66d530a0dde78acea3367f91fff62fbb3dc18faff0c708ad30edef5bea8b22c5fd782b770d8993386eaa784fd19a3c3e1db3b537b1a94d3d4fbd46f8df8fddf6d16611969fe0a97c50e0f3ac24750c93257cf5c161184aa7385800c87d803b339632a3d8ec7fe17a0afd83ce9e9d0e3f7b8d579637928a811f1f7e6d1887df2ddc7d4f752c4d600235e426c92c7bf8a1362f95457998cc0e5d4261f0efa4fada0f866dbcefb407dacab7a2914e91c2f08200f38c2d9d621962145b1464b0f204b326118a53ecdcab22bff005fdd5257c99a6dc51ac0600a49f2ef782396987e78c08b846dad5db55e8ccefffc64863bc2c3e90b95a09d25d0814a848c98fe01a82d4e30e6682dd546e12c45ca0d280a45295ab4bd632dafb070edfdc3c9e38313d5aeb195972986f8011b66817028fd8c78b67a0ac7e780eecc3fb6a31f5a025b8a9a3db278a98c0696aeaac739b18688b0f9c7d751bba02cc5f4e41853fb119b3c0c915059aaa92971244a1989124f12881ca88e6410df70b793a2c3a736ff4
                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                            File Type:ASCII text, with no line terminators
                            Category:dropped
                            Size (bytes):10
                            Entropy (8bit):2.9219280948873623
                            Encrypted:false
                            SSDEEP:3:LMq:N
                            MD5:64901B6D1E45B972F323E0C46AA037E2
                            SHA1:682D5ADCBA3A9968304BD537C975EE59DBC944DE
                            SHA-256:4F3BC505DFE0F3E81E477496755B51B6A74C8CF047E699A4B34BBF10ACA8739C
                            SHA-512:32E0170FAA4DB2BDD941F427EF6CE6D9FB4995D8F69956164E1C8B7FC69DBF754F5B6BF72788E856C813C699254DFD8A3B32191A995A99AF4EDBE34669CAADC8
                            Malicious:false
                            Preview:1729801547
                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                            File Type:SQLite 3.x database, last written using SQLite version 3023002, writer version 2, read version 2, file counter 2, database pages 1, cookie 0, schema 0, largest root page 1, unknown 0 encoding, version-valid-for 2
                            Category:dropped
                            Size (bytes):4096
                            Entropy (8bit):0.09216609452072291
                            Encrypted:false
                            SSDEEP:3:lSWFN3l/klslpF/4llfll:l9F8E0/
                            MD5:F138A66469C10D5761C6CBB36F2163C3
                            SHA1:EEA136206474280549586923B7A4A3C6D5DB1E25
                            SHA-256:C712D6C7A60F170A0C6C5EC768D962C58B1F59A2D417E98C7C528A037C427AB6
                            SHA-512:9D25F943B6137DD2981EE75D57BAF3A9E0EE27EEA2DF19591D580F02EC8520D837B8E419A8B1EB7197614A3C6D8793C56EBC848C38295ADA23C31273DAA302D9
                            Malicious:false
                            Preview:SQLite format 3......@ .......................................................................... .....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                            File Type:SQLite Rollback Journal
                            Category:dropped
                            Size (bytes):4616
                            Entropy (8bit):0.13760166725504608
                            Encrypted:false
                            SSDEEP:3:7FEG2l+vdo/FllkpMRgSWbNFl/sl+ltlslVlllfllkg:7+/lBg9bNFlEs1EP/Ug
                            MD5:8C550B50CE277F5202CD901E647EF0B6
                            SHA1:02054786A2B4AAF88B4FF84AAA69AC74FAA04E9D
                            SHA-256:8A675F29D7643C0E3F09ACEDD7A44BD5834F66C928EF46C80BA950855EF7C063
                            SHA-512:B8372D16CCB3AE3F8AD8D52C5450FB86C5E21959037B44A2113548A56AC19AF7CEF8565410C491F4AF4EBB4EFE04CF80F82F355B26E3F5AD20D2D4301CF5704C
                            Malicious:false
                            Preview:.... .c.....J8......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................SQLite format 3......@ .......................................................................... .................................................................................................................................................................................................................................................................................................................................................................................................
                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                            File Type:data
                            Category:dropped
                            Size (bytes):32768
                            Entropy (8bit):0.043911192123703015
                            Encrypted:false
                            SSDEEP:6:G4l2I4shvwTHY/4l2I4shvwLlSL9XXPH4l942U:l2chvGYA2chvV5A0
                            MD5:B1736E9CB773C7B287E1758F171DBEA9
                            SHA1:4B1EF5E58E1D514644335106257B13328668A196
                            SHA-256:48B7AA0D9C503230DDAB3581C9DEC54919F4532341D1C9CC464DB5E8317A3BEB
                            SHA-512:0112D66016906F19811FB30B64BEB99E2494DFA432AD2FBA7DE60990BEA8B31CD34B86DA6EE5563FF8298D1D336D3CEFCF80792150B923E998C78C95DB6E8912
                            Malicious:false
                            Preview:..-.....................c..0.,....H.....'..h....-.....................c..0.,....H.....'..h..........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                            File Type:SQLite Write-Ahead Log, version 3007000
                            Category:modified
                            Size (bytes):45352
                            Entropy (8bit):0.39526885845810644
                            Encrypted:false
                            SSDEEP:24:Kq9llIoQ3zRDTmU38Ull7DBtDi4kZERDibzqt8VtbDBtDi4kZERDz:t9llIoQ1/Z8Ull7DYMmbzO8VFDYMf
                            MD5:A3695756B5723F51A023E3D0AF4AA48D
                            SHA1:35857A85C83FC835ACD8BE21BFB64B5EFF3FE361
                            SHA-256:95418208BAC7084B11B406F832C273B3E4B2B4532DABFD75E44D8B745FEDD197
                            SHA-512:F0BED997B4F818231502D097A94E03C57ED0A5ADE279780832935D06C9E84C2B8B6C5E33DE77D3EA5A69BFB763747C525691B064CA4AD6E700AE3203ED7EB6BB
                            Malicious:false
                            Preview:7....-..............H.......u...............H....&8.tA..SQLite format 3......@ .......................................................................... .............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                            Process:C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exe
                            File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                            Category:dropped
                            Size (bytes):175027
                            Entropy (8bit):5.293168411531623
                            Encrypted:false
                            SSDEEP:1536:Ci2XPRAqFbz41gwErLe7HW8QM/hMdcAZl1p5ihs7gXXSEIJROdYgo:yHe7HW8QM/FXfZfo
                            MD5:28C1AFF0B55A3D9EE0F785F6B22F2742
                            SHA1:852EEE988D4FCA63EBE38EE5259AC874AB9B16CE
                            SHA-256:49A4807F2797EEDE23E2B24CD3EE991396F81CF4C199B5E31D9CC63B846534C8
                            SHA-512:42CBA2176B28299CD064F6F28307A3D9F54188B8B08DCF5C8EFAE189D7683149D900E2CCED67672B1C7AAF668E3F8930D9B5081B3D118E422568328229BBD73F
                            Malicious:false
                            Preview:<?xml version="1.0" encoding="utf-8"?>..<o:OfficeConfig xmlns:o="urn:schemas-microsoft-com:office:office">.. <o:services o:GenerationTime="2024-10-24T20:25:57">.. Build: 16.0.18209.40127-->.. <o:default>.. <o:ticket o:headerName="Authorization" o:headerValue="{}" />.. </o:default>.. <o:service o:name="Research">.. <o:url>https://word-edit.officeapps.live.com/we/rrdiscovery.ashx</o:url>.. </o:service>.. <o:service o:name="ORedir">.. <o:url>https://o15.officeredir.microsoft.com/r</o:url>.. </o:service>.. <o:service o:name="ORedirSSL">.. <o:url>https://o15.officeredir.microsoft.com/r</o:url>.. </o:service>.. <o:service o:name="ClViewClientHelpId" o:authentication="1">.. <o:url>https://[MAX.BaseHost]/client/results</o:url>.. <o:ticket o:policy="MBI_SSL_SHORT" o:idprovider="1" o:target="[MAX.AuthHost]" o:headerValue="Passport1.4 from-PP='{}&amp;p='" />.. <o:ticket o:idprovider="3" o:headerValue="Bearer {}" o:resourceId="[
                            Process:C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exe
                            File Type:data
                            Category:dropped
                            Size (bytes):65536
                            Entropy (8bit):0.1257123631231998
                            Encrypted:false
                            SSDEEP:12:D+XPqF69Fq5T/xK8CeQ1UMCl2M+aqc2EfK8C7aP:DU1EKf/SMClCaoEfKf+
                            MD5:AAC97B54E02FED256A5C533429C71EA9
                            SHA1:554CBD79510CC89802DB66DC2BC1E605627D45FB
                            SHA-256:B622FD8B9D641BCD0782EB522A140FF1DD03AE04CC21F895A843AE79F5E7017C
                            SHA-512:447FFDE2DAF674457A8F75D40A194A24A9008C305CBF6155577C31A8C79FC883A4F2B8607DD09759B391DC618F99D3E12AFEE5EBB973158CC4F963B650EF6ABD
                            Malicious:false
                            Preview:............................................................................d.......X......4....................eJ..............Zb..............................................,...@.t.z.r.e.s...d.l.l.,.-.1.1.2.......................................................@.t.z.r.e.s...d.l.l.,.-.1.1.1........................................................... .Y..Y..............R&..........H.x.A.c.c.o.u.n.t.s.A.l.w.a.y.s.O.n.L.o.g.g.e.r...C.:.\.U.s.e.r.s.\.n.o.r.d.i.\.A.p.p.D.a.t.a.\.L.o.c.a.l.\.P.a.c.k.a.g.e.s.\.m.i.c.r.o.s.o.f.t...w.i.n.d.o.w.s.c.o.m.m.u.n.i.c.a.t.i.o.n.s.a.p.p.s._.8.w.e.k.y.b.3.d.8.b.b.w.e.\.L.o.c.a.l.S.t.a.t.e.\.H.x.A.c.c.o.u.n.t.s.A.l.w.a.y.s.O.n.L.o.g...e.t.l...........P.P.....X...+..4....................................................................................................................................................................................................................................................................................................
                            Process:C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exe
                            File Type:data
                            Category:dropped
                            Size (bytes):65536
                            Entropy (8bit):0.12075136256888248
                            Encrypted:false
                            SSDEEP:12:eTXPqF69Fq5T78C2Q1UMCl2M+aqc2EOC0iv:K1if3SMClCaoEF0y
                            MD5:956CB54B0F47A06F2051FC01589736F2
                            SHA1:CA0A59120DD02757F70D700BB4E8930002F5E2B0
                            SHA-256:2C8DD2156EF665C15D2D88E7D1B1E8C73BE7C25392130A1E5E07152F5541F294
                            SHA-512:EDD94D78971EB3F71AC1012967FC0537F2F59EB466B59E19E2443600AB0595EB11DA400B5900B0DF5F9BBFB4FB4FCFBAE645186669B8189DA5F2B0E48ADE81FF
                            Malicious:false
                            Preview:............................................................................B...........o5.1....................eJ..............Zb..............................................,...@.t.z.r.e.s...d.l.l.,.-.1.1.2.......................................................@.t.z.r.e.s...d.l.l.,.-.1.1.1........................................................... .Y..Y...........^W.R&..........H.x.M.A.l.w.a.y.s.O.n.L.o.g...C.:.\.U.s.e.r.s.\.n.o.r.d.i.\.A.p.p.D.a.t.a.\.L.o.c.a.l.\.P.a.c.k.a.g.e.s.\.m.i.c.r.o.s.o.f.t...w.i.n.d.o.w.s.c.o.m.m.u.n.i.c.a.t.i.o.n.s.a.p.p.s._.8.w.e.k.y.b.3.d.8.b.b.w.e.\.L.o.c.a.l.S.t.a.t.e.\.H.x.m.A.l.w.a.y.s.O.n.L.o.g...e.t.l.............P.P.........d..1....................................................................................................................................................................................................................................................................................................................................
                            Process:C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exe
                            File Type:MS Windows registry file, NT/2000 or above
                            Category:dropped
                            Size (bytes):524288
                            Entropy (8bit):2.5881757374425867
                            Encrypted:false
                            SSDEEP:3072:PANVM/E7Tc6ktCg8vNKuLwgBEjgOzC1UoLWwPAtn6x1QWAEFRbZqO/q7gEtbNglv:DJsp6QG7y4
                            MD5:B209D0854714AD41691CF960DD7C985B
                            SHA1:D11E99C3A85BDD688D7B58D5B5AFE7F61A285A07
                            SHA-256:948201521922858D5A7480BA1DFC72527B37C3886340BA3E8BFCD0963EFC0033
                            SHA-512:0D463AE8E9E6C105066DE30E4E99667138201E0BF32E82B7A56BED624AB496C184F145ADE23E0FC8823FC908AF1B92DCC8CA70B18C866E9F4ACC8FBBD0846D26
                            Malicious:false
                            Preview:regf........b.Q.7.................. ....P......y.b.3.d.8.b.b.w.e.\.S.e.t.t.i.n.g.s.\.s.e.t.t.i.n.g.s...d.a.t...y..j.....J.....y..j.....J.........z..j.....J.....rmtm....R&..............................................................................................................................................................................................................................................................................................................................................W".L........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                            Process:C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exe
                            File Type:MS Windows registry file, NT/2000 or above
                            Category:dropped
                            Size (bytes):286720
                            Entropy (8bit):4.072844821080531
                            Encrypted:false
                            SSDEEP:3072:bANVM/E7Tc6ktCg8vNKuLwgBEjgOzC1UoLWwPAtn6x1QWAEFRbZqO/q7gEtbNglv:/Jsp6QG7y4
                            MD5:5B58A5756967D67C2561301A381333E9
                            SHA1:BC4588975431F0D78B802D32FC6F3D4F81F63DA0
                            SHA-256:59A8A2E955479F517BDC7B40E999E24710F1CAA0569A4DD891E30A364B3990E1
                            SHA-512:52D36F78DE2607D3F15CF024EE8770C6B297C8B4579DB02F8BACC7F5887CE484B9007A2993084C699CEB6CC7F4AA7E8478CCF13E5CE5DDCFF45BF9112268CA09
                            Malicious:false
                            Preview:regf........b.Q.7.................. ....P......y.b.3.d.8.b.b.w.e.\.S.e.t.t.i.n.g.s.\.s.e.t.t.i.n.g.s...d.a.t...y..j.....J.....y..j.....J.........z..j.....J.....rmtm....R&..............................................................................................................................................................................................................................................................................................................................................P".LHvLE.^...........P........T.q..O.|.%.4......P..hbin................b.Q.7..........nk,.T...7...... ...........................x...............................Test....p...sk..h...h.......t.......H...X.............4.........?.......................?....................... ... ...............YQ..fr]%dc;.............nk .....R&..................................h...............8...Z...........ConfigSettings..p...sk..x...x...F...t.......H...X.............4.........?.......................
                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                            File Type:data
                            Category:dropped
                            Size (bytes):20971520
                            Entropy (8bit):0.008687196473608242
                            Encrypted:false
                            SSDEEP:192:PUqoKMQNKTCq85umcfVLOBhrJhj2jKIsQ5uYYmp4NChLBr:sqRwTCq85cVLwXj2mI/5lYmpaChLBr
                            MD5:9B97412B2D12AE55CBAC622D7A6FA932
                            SHA1:15C5F8D50EA55FEEA1A2D042474D3434ADD93990
                            SHA-256:3B2A3DA28A79943E25B06B641460F69CCAD04C0A4B69AE0A9E615778E5A8EAB7
                            SHA-512:771ACBED61A803344266729E59DFA0AFD6D512F90158CCA5C9C89473EAD9D472D8B9F32CDF886AEBA6ED3071BE88C700271DA71C677AFDAA183D55AC19A47814
                            Malicious:false
                            Preview:Timestamp.Process.TID.Area.Category.EventID.Level.Message.Correlation..10/24/2024 20:25:42.908.OUTLOOK (0x193C).0x11BC.Microsoft Outlook.Telemetry Event.b7vzq.Medium.SendEvent {"EventName":"Office.System.GracefulExit.GracefulAppExitDesktop","Flags":33777014402039809,"InternalSequenceNumber":21,"Time":"2024-10-24T20:25:42.908Z","Data.PreviousAppMajor":16,"Data.PreviousAppMinor":0,"Data.PreviousAppBuild":16827,"Data.PreviousAppRevision":20130,"Data.PreviousSessionId":"DD3FB93D-A1A9-414C-827C-3E388FCBC0E2","Data.PreviousSessionInitTime":"2024-10-24T20:25:27.445Z","Data.PreviousSessionUninitTime":"2024-10-24T20:25:30.445Z","Data.SessionFlags":2147483652,"Data.InstallMethod":0,"Data.OfficeUILang":1033,"Data.PreviousBuild":"Unknown","Data.EcsETag":"\"\"","Data.ProcessorArchitecture":"x64"}...10/24/2024 20:25:42.924.OUTLOOK (0x193C).0x178C.Microsoft Outlook.Telemetry Event.b7vzq.Medium.SendEvent {"EventName":"Office.Telemetry.LoadXmlRules","Flags":33777014401990913,"InternalSequenceNumber":28
                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                            File Type:data
                            Category:dropped
                            Size (bytes):20971520
                            Entropy (8bit):0.0
                            Encrypted:false
                            SSDEEP:3::
                            MD5:8F4E33F3DC3E414FF94E5FB6905CBA8C
                            SHA1:9674344C90C2F0646F0B78026E127C9B86E3AD77
                            SHA-256:CD52D81E25F372E6FA4DB2C0DFCEB59862C1969CAB17096DA352B34950C973CC
                            SHA-512:7FB91E868F3923BBD043725818EF3A5D8D08EBF1059A18AC0FE07040D32EEBA517DA11515E6A4AFAEB29BCC5E0F1543BA2C595B0FE8E6167DDC5E6793EDEF5BB
                            Malicious:false
                            Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                            File Type:data
                            Category:dropped
                            Size (bytes):114688
                            Entropy (8bit):4.6438157998722245
                            Encrypted:false
                            SSDEEP:768:PmWOMoVXUBX5oRKk0XqfVx8zv2yVVypqRKJHyVfy/H/9iUOoulicGioJiTidiGao:AVNH/9iUOoqM4MnXA9yxGAXchTE
                            MD5:8EBE577DA3871AF273AB37AF36CFDC03
                            SHA1:1279368EE3C52E6B2CBCDED0FFA6253EE92380D9
                            SHA-256:684F57F2243DD8D55047B60DC2166BF41C6CB6A37A3C8709A90062BF35996E23
                            SHA-512:190F410AB86E99E35AB0C1C5D76AF3EAA0094DE80863CA8E7A76D4907AA02C4A9E7A65FCED78DABB33D2C0D54CB533BBF4B20FA12619C92ED9158C4460452BDB
                            Malicious:false
                            Preview:............................................................................b.......<....7..R&..................eJ..............Zb..2...................................,...@.t.z.r.e.s...d.l.l.,.-.1.1.2.......................................................@.t.z.r.e.s...d.l.l.,.-.1.1.1........................................................... .Y..Y...........7..R&..........v.2._.O.U.T.L.O.O.K.:.1.9.3.c.:.2.7.c.e.9.2.2.3.9.a.6.8.4.d.1.2.b.3.b.3.8.4.a.d.c.d.0.a.5.2.5.a...C.:.\.U.s.e.r.s.\.n.o.r.d.i.\.A.p.p.D.a.t.a.\.L.o.c.a.l.\.T.e.m.p.\.O.u.t.l.o.o.k. .L.o.g.g.i.n.g.\.O.U.T.L.O.O.K._.1.6._.0._.1.6.8.2.7._.2.0.1.3.0.-.2.0.2.4.1.0.2.4.T.1.6.2.5.4.2.0.6.6.8.-.6.4.6.0...e.t.l.............P.P.....<....7..R&..................................................................................................................................................................................................................................................................................................
                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                            File Type:data
                            Category:dropped
                            Size (bytes):30
                            Entropy (8bit):1.2389205950315936
                            Encrypted:false
                            SSDEEP:3:OQ:O
                            MD5:77D53E107D42C82D343888402A424EFB
                            SHA1:9DEA55D8BD63D3FE136EFC02B6F8612B4ED1DDC8
                            SHA-256:ED37552EAE82C050D811B425D6B93A61B9BE6E1DBED66CE184C9B391D3C43421
                            SHA-512:3987CDB62A2C1C1802BD7D440C6089D6D1D3D766954914EF9E0043B0D132AA3FD2E79883AEF6B4819E9A0B2F27AFB868673FCE07D13A35428F43E9624B81C3AE
                            Malicious:false
                            Preview:....9.........................
                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                            File Type:Composite Document File V2 Document, Cannot read section info
                            Category:dropped
                            Size (bytes):16384
                            Entropy (8bit):0.6696621917325685
                            Encrypted:false
                            SSDEEP:12:rl3baFYVqLKeTy2MyheC8T23BMyhe+S7wzQP9zNMyhe+S7xMyheC0+X:r10mnq1Py9610+X
                            MD5:FCFAB2CF46F62D5216456299572C7CF6
                            SHA1:5C81C0463EEC40AAF63B89A14E5CFB5781A41BE8
                            SHA-256:5833525D76440F22712D3CAF2BF163046D1198E0295F4842E647E34E49E3518C
                            SHA-512:E94DE567B466251CE6B0F3A1DEC3EB74D3CC4A3EF37EBA6FE079F370253E5CA3C509F85FBC8E18B875F3156BB7A4D9B72C8201A34072CFA7C1A2DE6C42395FCB
                            Malicious:true
                            Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                            File Type:Microsoft Outlook email folder (>=2003)
                            Category:dropped
                            Size (bytes):271360
                            Entropy (8bit):2.385151236441641
                            Encrypted:false
                            SSDEEP:1536:y1DDObZai1uYmSd/eZYtisA7b73H6W53jEpEHPVQ10BAwrAikOW53jEpEHPVQ10f:YnOcJPIpjJOpj
                            MD5:49724DF36E2F89E360FE4E2BEBF2C5B4
                            SHA1:5D4990D0B7BFD730F2DF30E28393C232362FB6C1
                            SHA-256:674BE1D565E33B9A33C0C76D49A140CF91663A858BDE097B7B9A6585FF67DE57
                            SHA-512:AB7E9EAB6C688D277FAD1EE3E1D6E6FC67E0B1B4225624DF3F76D102FB32EC6ED91035E4D2CF76566E5A36D09E9AF6A43FC543D5787BE334BE44FDE29434EEC6
                            Malicious:true
                            Preview:!BDNn.-pSM......\...&....N......T......._................@...........@...@...................................@...........................................................................$.......D......................P...............S...................................................................................................................................................................................................................................................................................................2."['[F.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                            Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                            File Type:data
                            Category:dropped
                            Size (bytes):131072
                            Entropy (8bit):2.567351788359318
                            Encrypted:false
                            SSDEEP:768:w+tckYbbuVUd75JirBW53amEpAHRHPVQ10BAwrav5zfSBfQYbb2tG7twG5:Vy/d7nitW53jEpEHPVQ10BAwrMZcVz5
                            MD5:6629D8A1BC81EC030867198027D76DDC
                            SHA1:AF6D8C87D83EE7EB414550C99E14C16C7DF7CAD3
                            SHA-256:B57B4119CF23714904FB00657EC7EED058339650040F0CD07A9228C07EACF13A
                            SHA-512:513FC6E1A5F1345556F0D4D59EE84E847463E7877A5BA32AE185716C4F672DCC5902D94080C60BF31348EE9FC04784EAA807994D8BAF36D36DDBB1255AA9529A
                            Malicious:true
                            Preview:5R,.0...`.......<...W...R&.......D............#....................l....................................................................................................................?..................?............................................................................................................................................................................................................................................................................................................................................................D.......+;r0...a.......<...W...R&.......B............#.........................................................................................................................................................................................................................................................................................................................................................................................................
                            File type:RFC 822 mail, ASCII text, with CRLF line terminators
                            Entropy (8bit):5.957411526186627
                            TrID:
                            • E-Mail message (Var. 5) (54515/1) 100.00%
                            File name:(No subject) (91).eml
                            File size:8'645 bytes
                            MD5:efb174e1f0f5b73ab950ab361960ea50
                            SHA1:6757a77fad6b662c487a08654862f804a7304f04
                            SHA256:2e1c79b2e09a2c9f1cd2df545a2a4b1ae62939c34db1fc0bea633c5e0cfca773
                            SHA512:4e15be39a4004c964e66a6fa4f526d6621037ccd9e7441593fa21e9eb9dadd7f22748b0262bd17e77bac688f750f912170f493b7da9583e2dc31f9b139ffa78e
                            SSDEEP:192:323y15wr/hvg5kZGC0Im7ul/CTkHv7yZM8ra0Fuj4r94THi:miEbd0R0AWKM8uiuEJt
                            TLSH:7402F84E4EF9843649D022CD1D60FE0751931AAAE677E4E23EBCC267120B8EE5F4954B
                            File Content Preview:Received: from MW4PR09MB9172.namprd09.prod.outlook.com (2603:10b6:303:1e6::9).. by SJ0PR09MB11062.namprd09.prod.outlook.com with HTTPS; Thu, 24 Oct 2024.. 17:34:16 +0000..Received: from CY5PR09CA0027.namprd09.prod.outlook.com (2603:10b6:930:1::29).. by MW
                            Subject:DD Option
                            From:Elycia Thomas Knight <aviso@cromex.net>
                            To:nnader@santaclaraca.gov
                            Cc:
                            BCC:
                            Date:Thu, 24 Oct 2024 12:34:12 -0500
                            Communications:
                            • [You don't often get email from aviso@cromex.net. Learn why this is important at https://aka.ms/LearnAboutSenderIdentification ] Hi Nadine, I need to fill in my new checking deposit details before the upcoming payroll. What specifics do you require? Best Regards, Elycia Thomas Knight Project Manager, Priority, Related (Santa Clara) City of Santa Clara CA
                            Attachments:
                              Key Value
                              Receivedfrom [::1] (port=39864 helo=ramsesmailserver.ramsesdns.com) by ramsesmailserver.ramsesdns.com with esmtpa (Exim 4.98) (envelope-from <aviso@cromex.net>) id 1t41iu-00000004lcy-48LJ for nnader@santaclaraca.gov; Thu, 24 Oct 2024 12:34:13 -0500
                              Authentication-Resultsspf=pass (sender IP is 135.148.226.108) smtp.mailfrom=cromex.net; dkim=pass (signature was verified) header.d=cromex.net;dmarc=bestguesspass action=none header.from=cromex.net;compauth=pass reason=109
                              Received-SPFPass (protection.outlook.com: domain of cromex.net designates 135.148.226.108 as permitted sender) receiver=protection.outlook.com; client-ip=135.148.226.108; helo=ramsesmailserver.ramsesdns.com; pr=C
                              DKIM-Signaturev=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=cromex.net; s=default; h=Content-Transfer-Encoding:Content-Type:Message-ID:Subject:To: From:Date:MIME-Version:Sender:Reply-To:Cc:Content-ID:Content-Description: Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID: In-Reply-To:References:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=ICjmEt6FhtWfvF4WWBECjMaBOdRt8dO2Xq4YeCokiuA=; b=OqPrTF5+GEba4hz5cgX+dus/Pp nqEAipLFr3n00TSY2JSWIGU3ySwVNXqQ4lOUIl2mBULlWf0AghNK/yeDilYLYmMLOx2VCTPlcKmp+ zXX4rbK+xL5L88v8ZlTN689DbhVBKejnxGX+RUKZDHKrFeZJbvjZTmjKE72cyZQ3WDEMtSZp6eeXj DS1LMho1InMfkPaAby4e9j14YDPyYHTEZtnaM9ub+OL9iMluGIMp68e39ANXNgZNbYqhc1cEnPTH3 AZHgaSpbfD9+cHFB9v0n6THosw6a9pzZR4oLkxyQIoTaY/otpudlopbBicQRd/pE8+1YVgOj8F9Ro g/oMrKqA==;
                              DateThu, 24 Oct 2024 12:34:12 -0500
                              FromElycia Thomas Knight <aviso@cromex.net>
                              Tonnader@santaclaraca.gov
                              SubjectDD Option
                              User-AgentRoundcube Webmail/1.6.9
                              Message-ID<5f4883de71f1c05ae5a085677347be65@cromex.net>
                              X-Senderaviso@cromex.net
                              Content-Typetext/plain; charset="US-ASCII"; format="flowed"
                              Content-Transfer-Encodingquoted-printable
                              X-AntiAbuseSender Address Domain - cromex.net
                              X-Get-Message-Sender-Viaramsesmailserver.ramsesdns.com: authenticated_id: aviso@cromex.net
                              X-Authenticated-Senderramsesmailserver.ramsesdns.com: aviso@cromex.net
                              X-Source
                              X-Source-Args
                              X-Source-Dir
                              Return-Pathaviso@cromex.net
                              X-MS-Exchange-Organization-ExpirationStartTime24 Oct 2024 17:34:13.3224 (UTC)
                              X-MS-Exchange-Organization-ExpirationStartTimeReasonOriginalSubmit
                              X-MS-Exchange-Organization-ExpirationInterval1:00:00:00.0000000
                              X-MS-Exchange-Organization-ExpirationIntervalReasonOriginalSubmit
                              X-MS-Exchange-Organization-Network-Message-Id ee3cdd85-fdfd-4709-8ced-08dcf452139b
                              X-EOPAttributedMessage0
                              X-EOPTenantAttributedMessage28ea3548-1069-4e81-aa0b-6e4b3271a5cb:0
                              X-MS-Exchange-Organization-MessageDirectionalityIncoming
                              X-MS-PublicTrafficTypeEmail
                              X-MS-TrafficTypeDiagnostic BL02EPF0001B418:EE_|MW4PR09MB9172:EE_|SJ0PR09MB11062:EE_
                              X-MS-Exchange-Organization-AuthSource BL02EPF0001B418.namprd09.prod.outlook.com
                              X-MS-Exchange-Organization-AuthAsAnonymous
                              X-MS-Office365-Filtering-Correlation-Idee3cdd85-fdfd-4709-8ced-08dcf452139b
                              X-MS-Exchange-AtpMessagePropertiesSA|SL
                              X-MS-Exchange-Organization-SCL1
                              X-Microsoft-AntispamBCL:0;ARA:13230040|43540500003;
                              X-Forefront-Antispam-Report CIP:135.148.226.108;CTRY:US;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:ramsesmailserver.ramsesdns.com;PTR:ip108.ip-135-148-226.us;CAT:NONE;SFTY:9.25;SFS:(13230040)(43540500003);DIR:INB;SFTY:9.25;
                              X-MS-Exchange-CrossTenant-OriginalArrivalTime24 Oct 2024 17:34:13.2755 (UTC)
                              X-MS-Exchange-CrossTenant-Network-Message-Idee3cdd85-fdfd-4709-8ced-08dcf452139b
                              X-MS-Exchange-CrossTenant-Id28ea3548-1069-4e81-aa0b-6e4b3271a5cb
                              X-MS-Exchange-CrossTenant-AuthSource BL02EPF0001B418.namprd09.prod.outlook.com
                              X-MS-Exchange-CrossTenant-AuthAsAnonymous
                              X-MS-Exchange-CrossTenant-FromEntityHeaderInternet
                              X-MS-Exchange-Transport-CrossTenantHeadersStampedMW4PR09MB9172
                              X-MS-Exchange-Transport-EndToEndLatency00:00:03.5325205
                              X-MS-Exchange-Processed-By-BccFoldering15.20.8093.014
                              X-Microsoft-Antispam-Mailbox-Delivery ucf:0;jmr:0;auth:0;dest:I;ENG:(910001)(944506478)(944626604)(920097)(930097)(140003)(1420198);
                              X-Microsoft-Antispam-Message-Info pvKguFaIbsnhB29a85zZBvOrOc1TRTYKVPaAN8zz77AYAYlXkYYugSXNSD7twmDbbbZMjwcnQag5szGCiCqiau6Tn4+tqYdb6w6AdonwqlLRbRhIOEXxxquZLN0B4Ml7gKyl43ckwYdom+0BkOSnG6wE66k2oEzDtOX3hHum7IE1ExPSOXFMFI9uNbYUIo/Y+5XVvwQILP5Ax8QLMusvK2Vax9zSLQTb+R5TI3EfXBLZHlGs8XnGHU0CV6Duu2J0u/3tsF2RTaUXh67uy1YEdbkpDvIoK2hhPNoJFEtAeWo1TkvSqeKC/lLkqyn6htXHDCH0q9cmMA6XozlkuK9UI9cgVZY3BdVc8GDLj/0VP+r8SfI70KAPb6p4KSs1bqwOT574Mv3ApVqg+Y9odonfaA9g8vADOqhseW/5O87vc029IdZ7tpwJFn9J93xrAA0vZNTU8gHKsVDch6yNa8/b85nG6I4PycFDhYEmVsR0rpLpHJOQ6KPbmd9ErKWhA+aXXIqLe49TQUg2DkzBD23uukLa/hK9bTo1pPQaF2ou+E0wDkudAsIJ5AHGGV4eMVraPNdZVL7MQPZlfMoTuAWX31f/3XvmQ3+Ch1igU8XabPegmPInZ3uladRhsf6DW/a68sF7NCChNBrsJd5MLYJUZ9t2iE+TgTZHgiW5FnebiwZzfX4QbYZXqLGx8VO342U9HI1hM5SUu0rYaJca6XzeyhBaPS2uqf6hrQgqS0JQUwEd6qrVW22cHSwtEZU+pI7GRjAzaROoU0oziESKd9nN+4JdkGP1u8uWv7+AON3GM2qX9B3MBFF9sIj8rzSGZzhZ43jX961mMlajz9YHp2YPSbqDHUa8lVYPpt9jVKWcQi3jvs91oORHML4U0P1WVvJt91by73dUfDBw8GAb1GeSjPf7l4+DAGc3miZB33K/0Ws/iwHDLOpfBgvJWBWEGm3/1IDvetY1EVaCqj7Qtgm+CfmO6VCDwf1ZdXW6TNcwQBFuB6xJL8Pw7O8JQO8A4VnSp7vPYRi46uYGXzAGRvRBcK8XZyXGMl8EJZysR6K+NJ+wRK5W2hukjDcTo7mMbqu1gKC7YY4lrjGRsGRj+OEfQksAwBTZbs6lWFiyrMqdUp8vRfvutEv+YYEILJcxErZHOmXOa035Hjvt4OTDCQOzvkYKCXqKP4dv30td8CAXgpolVwdCRZFf94f4Hn86htX/ZxGyAPU9CZf85DZn28LSDe2WWvBuakniw37NoAvvLCcErM7vrHtz5C/TweED6Mu5nkxRHHiImx73qv6KvNAT3lcDMub0fRtA21hHeoNb8JHgg31vUfP4afZ8hf/zIfSo429vPkXLw8tes6e+sI8F1412GzDmTrATifKqfZLTf9vhWCF8H/Pzst1bXHXXFBim0ewMDo+5MwSzF1gedCPtFeFTdtEWkSZHcJEEYQmNeue+YImGmW7yTYsilPI+jtRKm8+D67Q+AtmzMfbz1MV0+KjzyoDAVyaiM8WDfuV4DSnss6LTy7Oby+seAxxPpAc53xaw0VKnUCZkkAVYY1OXdkxQMUWbspV77GOMJrgZzbelnrwTCfOj/2yapD8ELn003ea7y9OYfurQTZsVBokx1/kf+S4FbpgAj//ocCr17kVsXTzLtvHfVrM9YcD4c5rQgFzOdi0u+ROx/8oEBgfLD2BNX6kM+Ptz7mRtM2pswj7nGbYLcCku8sAXBRovXcQA07IDJukbp6rTQVc8cgCVIAQFFQ6CwU4y+uUsC8DzeRHwptu+xEb4TGERZywRtix7Sq1ZR1hEMpSvIVYJ9Cv4viedMmIE+qqv6783BcVjoGyDMnn8jdyn3FjJ8xd5sK9CUYp5layC1UrJBWnadVDV+djmWCaKVs4EWwjx0m7etU0ShzvgJRGnZtUdYObUMTudoYHl2YF06NA1utRIMJC++tWbCnFtuhRvmFBkz4FvvO70Cem++6OreasubirVhojQ8e33xX8wk3W0mONlcvBR9D1TgNpaPTFyk7uldD7U1WkBBviTYsk4AlcT8Maj0c6xVvfr+TjAV4/rnUbBjWky5QtG/4g0VnZEpByQFvN+P6g=
                              MIME-Version1.0

                              Icon Hash:46070c0a8e0c67d6
                              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                              Oct 24, 2024 22:25:46.314234018 CEST1.1.1.1192.168.2.180x8fd6No error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
                              Oct 24, 2024 22:25:46.314234018 CEST1.1.1.1192.168.2.180x8fd6No error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false

                              Click to jump to process

                              Click to jump to process

                              Click to dive into process behavior distribution

                              Click to jump to process

                              Target ID:0
                              Start time:16:25:42
                              Start date:24/10/2024
                              Path:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                              Wow64 process (32bit):true
                              Commandline:"C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" /eml "C:\Users\user\Desktop\(No subject) (91).eml"
                              Imagebase:0x5a0000
                              File size:34'446'744 bytes
                              MD5 hash:91A5292942864110ED734005B7E005C0
                              Has elevated privileges:true
                              Has administrator privileges:true
                              Programmed in:C, C++ or other language
                              Reputation:high
                              Has exited:false

                              Target ID:2
                              Start time:16:25:43
                              Start date:24/10/2024
                              Path:C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe
                              Wow64 process (32bit):false
                              Commandline:"C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe" "C8D29D07-5E0B-4309-9B21-2D2C223BD71C" "F9248E8B-C36B-4A38-B94D-97D9F1873580" "6460" "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" "WordCombinedFloatieLreOnline.onnx"
                              Imagebase:0x7ff7d3b10000
                              File size:710'048 bytes
                              MD5 hash:EC652BEDD90E089D9406AFED89A8A8BD
                              Has elevated privileges:true
                              Has administrator privileges:true
                              Programmed in:C, C++ or other language
                              Reputation:high
                              Has exited:false

                              Target ID:4
                              Start time:16:25:53
                              Start date:24/10/2024
                              Path:C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exe
                              Wow64 process (32bit):false
                              Commandline:"C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxOutlook.exe" -ServerName:microsoft.windowslive.mail.AppXfbjsbkxvprcgqg6q4c9jfr0pn3kv9x5s.mca
                              Imagebase:0x7ff6cbeb0000
                              File size:2'486'784 bytes
                              MD5 hash:6F8EAC2C377C8F16D91CB5AC8B8DBF5F
                              Has elevated privileges:false
                              Has administrator privileges:false
                              Programmed in:C, C++ or other language
                              Reputation:moderate
                              Has exited:false

                              Target ID:11
                              Start time:16:25:58
                              Start date:24/10/2024
                              Path:C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exe
                              Wow64 process (32bit):false
                              Commandline:"C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe\HxAccounts.exe" -ServerName:microsoft.windowslive.manageaccounts.AppXdbf3yp5apt3t7q877db3gnz5zqpf71zj.mca
                              Imagebase:0x7ff7d27f0000
                              File size:274'432 bytes
                              MD5 hash:6FEB00C9A2C3FF66230658B3012BAB6A
                              Has elevated privileges:false
                              Has administrator privileges:false
                              Programmed in:C, C++ or other language
                              Reputation:moderate
                              Has exited:false

                              No disassembly