Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
01142025.eml

Overview

General Information

Sample name:01142025.eml
Analysis ID:1590928
MD5:c3e7562e7a87b9edcdd3701b2afcdae1
SHA1:e23462bbdcbad654e46c3ed2e0f65deabd93c5a9
SHA256:581c5e135c25f9134341fcefc702f3d253be62a1d62084202ae04dc69f842e0d
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

AI detected suspicious elements in Email content
AI detected suspicious elements in Email header
Queries the volume information (name, serial number etc) of a device
Sigma detected: Office Autorun Keys Modification

Classification

  • System is w10x64_ra
  • OUTLOOK.EXE (PID: 6984 cmdline: "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" /eml "C:\Users\user\Desktop\01142025.eml" MD5: 91A5292942864110ED734005B7E005C0)
    • ai.exe (PID: 676 cmdline: "C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe" "3897298D-BECE-4E36-9F78-37EEEE9A5103" "313CC496-2204-41E5-BDD1-A0DE29FC699F" "6984" "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" "WordCombinedFloatieLreOnline.onnx" MD5: EC652BEDD90E089D9406AFED89A8A8BD)
  • cleanup
No yara matches
Source: Registry Key setAuthor: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): Data: Details: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 , EventID: 13, EventType: SetValue, Image: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE, ProcessId: 6984, TargetObject: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Outlook\Addins\OneNote.OutlookAddin\1
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

Phishing

barindex
Source: EmailJoe Sandbox AI: Detected potential phishing email: The email contains suspicious sender domain 'oxvrim.sambuh.com' that doesn't match the claimed United Health Care sender. The subject line and body contain random character strings (#y572e#qn8an) typical of spam/phishing. The email contains suspicious URLs with domain 'goyangterus.store' and appears to be injecting unrelated weather alert content to appear legitimate
Source: EmailJoe Sandbox AI: Detected suspicious elements in Email header: Return-path domain (oxvrim.sambuh.com) doesn't match the DKIM signing domain (wakemed.org). DKIM authentication failed according to authentication results. Suspicious return-path domain appears to be randomly generated (oxvrim.sambuh.com). Mismatch between SPF pass for wakemed.org but email actually from oxvrim.sambuh.com. Presence of extensive Microsoft Antispam headers suggests this email triggered security checks. Suspicious boundary string format in content-type header. Authentication results show DMARC permerror, indicating potential spoofing attempt. Multiple authentication inconsistencies suggest a sophisticated spoofing attempt
Source: EmailClassification: Credential Stealer
Source: classification engineClassification label: mal48.winEML@3/5@0/40
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEFile created: C:\Users\user\Documents\Outlook Files\~Outlook Data File - NoEmail.pst.tmp
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEFile created: C:\Users\user\AppData\Local\Temp\Outlook Logging\OUTLOOK_16_0_16827_20130-20250114T0941270164-6984.etl
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEFile read: C:\Users\desktop.ini
Source: unknownProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" /eml "C:\Users\user\Desktop\01142025.eml"
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe "C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe" "3897298D-BECE-4E36-9F78-37EEEE9A5103" "313CC496-2204-41E5-BDD1-A0DE29FC699F" "6984" "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" "WordCombinedFloatieLreOnline.onnx"
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe "C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe" "3897298D-BECE-4E36-9F78-37EEEE9A5103" "313CC496-2204-41E5-BDD1-A0DE29FC699F" "6984" "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" "WordCombinedFloatieLreOnline.onnx"
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: apphelp.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: c2r64.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: userenv.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: msasn1.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: kernel.appcore.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: cryptsp.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: rsaenh.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: cryptbase.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: gpapi.dll
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}\InprocServer32
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEWindow found: window name: SysTabControl32
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Common
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information queried: ProcessInformation
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeQueries volume information: C:\Program Files (x86)\Microsoft Office\root\Office16\AI\WordCombinedFloatieLreOnline.onnx VolumeInformation
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation11
Browser Extensions
1
Process Injection
1
Masquerading
OS Credential Dumping1
Process Discovery
Remote ServicesData from Local SystemData ObfuscationExfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/Job1
DLL Side-Loading
1
DLL Side-Loading
1
Process Injection
LSASS Memory1
File and Directory Discovery
Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
DLL Side-Loading
Security Account Manager12
System Information Discovery
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs
IPDomainCountryFlagASNASN NameMalicious
52.113.194.132
unknownUnited States
8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
2.16.168.119
unknownEuropean Union
20940AKAMAI-ASN1EUfalse
52.109.32.97
unknownUnited States
8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
20.189.173.10
unknownUnited States
8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1590928
Start date and time:2025-01-14 15:39:56 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultwindowsinteractivecookbook.jbs
Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Number of analysed new started processes analysed:9
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
Technologies:
  • EGA enabled
Analysis Mode:stream
Analysis stop reason:Timeout
Sample name:01142025.eml
Detection:MAL
Classification:mal48.winEML@3/5@0/40
Cookbook Comments:
  • Found application associated with file extension: .eml
  • Exclude process from analysis (whitelisted): dllhost.exe, SIHClient.exe, svchost.exe
  • Excluded IPs from analysis (whitelisted): 52.109.32.97, 52.113.194.132, 2.16.168.119, 2.16.168.101, 20.189.173.10
  • Excluded domains from analysis (whitelisted): ecs.office.com, omex.cdn.office.net, slscr.update.microsoft.com, prod.configsvc1.live.com.akadns.net, s-0005-office.config.skype.com, mobile.events.data.microsoft.com, fe3cr.delivery.mp.microsoft.com, ecs-office.s-0005.s-msedge.net, login.live.com, s-0005.s-msedge.net, config.officeapps.live.com, onedscolprdwus09.westus.cloudapp.azure.com, officeclient.microsoft.com, ecs.office.trafficmanager.net, ukw-azsc-config.officeapps.live.com, omex.cdn.office.net.akamaized.net, europe.configsvc1.live.com.akadns.net, mobile.events.data.trafficmanager.net, a1864.dscd.akamai.net
  • Not all processes where analyzed, report is missing behavior information
  • Report size getting too big, too many NtQueryAttributesFile calls found.
  • Report size getting too big, too many NtQueryValueKey calls found.
  • Report size getting too big, too many NtReadVirtualMemory calls found.
Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
File Type:data
Category:modified
Size (bytes):102400
Entropy (8bit):4.474543119627498
Encrypted:false
SSDEEP:
MD5:0376BAC14295AE8FAD57130E9A5E4212
SHA1:4A375F7A773FBA3CD5776A619AC4B7D4D8A1986B
SHA-256:ED6DDA3676F2F42F52A5B9F7B330C862FD211E7B2B1C4778C9A158A96F99C20C
SHA-512:8E292BDA4BBF79C2484F8C668AFA9284BF1CDF8915E189927B36C9FAA1401A133B697616F3641E7BEB0E5AFE5298946235E28A29EAEA1F06EAE0E1175166A9C3
Malicious:false
Reputation:unknown
Preview:............................................................................`...L...H.....Md.f..................eJ..............Zb..2...................................,...@.t.z.r.e.s...d.l.l.,.-.1.1.2.......................................................@.t.z.r.e.s...d.l.l.,.-.1.1.1...........................................................`..7.Y............Md.f..........v.2._.O.U.T.L.O.O.K.:.1.b.4.8.:.e.9.0.8.5.4.0.e.4.c.d.9.4.6.1.7.a.3.3.1.d.8.a.2.9.e.7.9.6.c.e.8...C.:.\.U.s.e.r.s.\.c.a.l.i.\.A.p.p.D.a.t.a.\.L.o.c.a.l.\.T.e.m.p.\.O.u.t.l.o.o.k. .L.o.g.g.i.n.g.\.O.U.T.L.O.O.K._.1.6._.0._.1.6.8.2.7._.2.0.1.3.0.-.2.0.2.5.0.1.1.4.T.0.9.4.1.2.7.0.1.6.4.-.6.9.8.4...e.t.l.......P.P.L...H.....Md.f..........................................................................................................................................................................................................................................................................................................
Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
File Type:GIF image data, version 89a, 15 x 15
Category:dropped
Size (bytes):663
Entropy (8bit):5.949125862393289
Encrypted:false
SSDEEP:
MD5:ED3C1C40B68BA4F40DB15529D5443DEC
SHA1:831AF99BB64A04617E0A42EA898756F9E0E0BCCA
SHA-256:039FE79B74E6D3D561E32D4AF570E6CA70DB6BB3718395BE2BF278B9E601279A
SHA-512:C7B765B9AFBB9810B6674DBC5C5064ED96A2682E78D5DFFAB384D81EDBC77D01E0004F230D4207F2B7D89CEE9008D79D5FBADC5CB486DA4BC43293B7AA878041
Malicious:false
Reputation:unknown
Preview:GIF89a....w..!..MSOFFICE9.0.....sRGB......!..MSOFFICE9.0.....msOPMSOFFICE9.0Dn&P3.!..MSOFFICE9.0.....cmPPJCmp0712.........!.......,....................'..;..b...RQ.xx..................,+................................yy..;..b.........................qp.bb..........uv.ZZ.LL.......xw.jj.NN.A@....zz.mm.^_.........yw........yx.xw.RR.,*.++............................................................................................................................................................................................................8....>.......................4567...=..../0123.....<9:.()*+,-.B.@...."#$%&'....... !............C.?....A;<...HT(..;
Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
File Type:data
Category:dropped
Size (bytes):70400
Entropy (8bit):7.963823708028205
Encrypted:false
SSDEEP:
MD5:5088205E55AB9BA9DAA872AEBC504ECF
SHA1:C52E25F383F278629BF83D660FED7FC6EE4F459F
SHA-256:28C02EF9A101A270C2FA6EB36840AD98B41097F1DD0CC524E25DA7B063B17C3B
SHA-512:8D81F0B081A16AFD3A60220B97F1D70E4C84ABA5DBBB8D80125D73FE3099093C10A3F945E6C1CAF89B6C2217041F0BE99C669B4E37A7833E786D01E023728E4E
Malicious:false
Reputation:unknown
Preview:...4}.9}]Jdy...y.!., ..r../.q......\.`...g/.X.].8.Ki..g......=P....GF...d.sYS....]....2u<.l.B7................d4..'..7i...$..1...Z.G.p..%..C\.......5A~?(....DFI:..b..RK......s36.H.nt.oVUu.)5..J..]p.2..Y...d.$.J.u...8Q..b.....Y.3..O...]@.h..la|..%.u....6.".YH.b.^.x.0{.U....^.ZeZ.+..B.JEY..4".Q....RB7...6Q.../;-.^@.XID6....|..W.F.K.J....._ar.5<td.5....*.7..\.G\G...z.....}a..J.%.......n.c......G&..I..o.<.)......`.Z..=c..i...:q.`:..?....FE.Z.W....*.\. ..)..n..wq...@.V...z.e.f....|....[..2w..v[...97....l.H.+..YI0].".".SPvU...n..r.q.|.v..Yd..d.%L.*..r58...".";hoKK$..a<.u..w$....'/".I....G^.?..u...>:.dl. ..2..2..,...B...._..8....*.H..k..-M.):...J..55q.,iI.....xj.[.;...`m.$...D.V.B.0.M.O...I.g?.0.z>a.......A..U.........U(..R.........~..lOl.,{.._..9}.ws.X.q..>2.P..]..j`{S..E7.@......^..L.[I,e.:..Q,G.iY-Z.8..'.M.....v1..r._3]kL. .MA.....FY..1..pN..=.oO,oo,5..Y...h*us...,../...wRAd..l.U..C.cTv..(;..w.\..[....+.U\b............|O....b..f.`.
Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
File Type:Microsoft Outlook email folder (>=2003)
Category:dropped
Size (bytes):2302976
Entropy (8bit):1.798211981592883
Encrypted:false
SSDEEP:
MD5:6A965E041866E75B622F36312DB9CE91
SHA1:C3B73210DED6838E8A87059902DA02ACD439B414
SHA-256:EF8FA0A4BB89968A25DD0B4828B784A5B6DBC576CABF8B29DF0A368A3FD5581D
SHA-512:D595640800DA2D8529B176828CE57F218C562227FCF645C958FCE61251856715E3E6D6A9C465130FBB3FC991069A63A3F6076C9E126E52EEC6CDFB52F6560B72
Malicious:true
Reputation:unknown
Preview:!BDN..O.SM......\....3..................h................@...........@...@...................................@...........................................................................$#......D......@\....................................................................................................................................................................................................................................................................................................................................Q...F.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
File Type:OpenPGP Secret Key
Category:dropped
Size (bytes):393216
Entropy (8bit):6.806545859888669
Encrypted:false
SSDEEP:
MD5:40F35A2FD5874D9025C2CB8E2AE1BED9
SHA1:9D3422E1A35830DC959B8BF103F0DB9311DB6ABA
SHA-256:EBBA5447C7AE2E6C9863CB67644809AE394117D1C1A286B310500473A20CD0EC
SHA-512:29DBA563FF96CD993815F1384D2652044111C611EC05B2372F615DF77F949480BEA881F6804135CB73601DC62DC4B30A7C06D7BE415F2DDE1DFBCB02E3AECCD7
Malicious:true
Reputation:unknown
Preview:.Y..C...........H...o^.d.f....................#.!BDN..O.SM......\....3..................h................@...........@...@...................................@...........................................................................$#......D......@\....................................................................................................................................................................................................................................................................................................................................Q...F.o^.d.f.......B............#........................................#................................................................................................................................................................................................................................................................................................................................................................
File type:RFC 822 mail, ASCII text, with very long lines (2157), with CRLF line terminators
Entropy (8bit):6.116662286865496
TrID:
  • E-Mail message (Var. 5) (54515/1) 100.00%
File name:01142025.eml
File size:347'327 bytes
MD5:c3e7562e7a87b9edcdd3701b2afcdae1
SHA1:e23462bbdcbad654e46c3ed2e0f65deabd93c5a9
SHA256:581c5e135c25f9134341fcefc702f3d253be62a1d62084202ae04dc69f842e0d
SHA512:8a786ff4f46782e6b7176f1dbb95dfff628ff3b9de7d6728a96af68b37443d002ef482e1855199743713e089c7948a36dde77349c44d3ec0d77df203c85abe13
SSDEEP:6144:RV/4I6jdRF2baUh+3vypIs5pbEEyki5sPUsm1LSnb4lGPAmwoa5UzoKhH:RV/4I692jM3Hs55EEdYsPUsISnP5yUzp
TLSH:44740230B445335BCE2363DED2297E01A29476CAC6C364B12FFCCE953556A249B7067E
File Content Preview:Received: from SJ0PR11MB4847.namprd11.prod.outlook.com (::1) by.. MW4PR11MB6785.namprd11.prod.outlook.com with HTTPS; Fri, 10 Jan 2025.. 18:32:50 +0000..Received: from BYAPR07CA0027.namprd07.prod.outlook.com.. (2603:10b6:a02:bc::40) by SJ0PR11MB4847.nampr
Subject:FW: United Health Care Medicare Kit #y572e#qn8an
From:United Health Care #y572e#a8sw5 <JANISBROWN.493@oxvrim.sambuh.com>
To:!Imagicomm - TUL Tulsa TV PhotoTeam <phototeam@fox23.com>
Cc:!Imagicomm - TUL Tulsa TV PhotoTeam <phototeam@fox23.com>
BCC:!Imagicomm - TUL Tulsa TV PhotoTeam <phototeam@fox23.com>
Date:Fri, 10 Jan 2025 18:32:06 +0000
Communications:
  • CONGRATS....Medicare Kit Reward Has Arrived...Good morning, Please see several updates below. If anyone has identified any concerns as their preparedness activities have progressed and the forecast has changed to more ice, please reach out directly to us. We will not hold a coordination call today as many of you will be on internal and external calls with various groups. The AM weather briefing is attached. Increase to snow/ice amounts with potential of ice accumulations in excess of 0.25 possible.The State Emergency Operations Center (SEOC) will be Activated from 0700 on 10 January 2025 through 1900 on January 12, 2025.CapRAC On-Call 919-350-7887 Key Messages from weather briefing:1.Light to moderate snow will move into central NC from SW to NE between 3 PM and 8 PMFriday. Triad: 3 4 PM, Triangle/Fayetteville: 5 7 PM, Rocky Mount: 7 9 PM. Some very lightsnow accumulations may be possible as early as 12 1PM in the Triad.2.Dont focus so much on the exact snow and ice amounts that are forecast, but rather focuson the hazards and impacts. To that point, there will be enough snow and iceaccumulations to result in hazardous travel conditions beginning Friday afternoon andlasting into Saturday.3.Due to very cold ground temperatures, the snow/ice is highly likely to stick and freezeimmediately and enable rapid accumulation. Black ice will be a subsequent concern Sundaymorning and Monday morning.4.There is still a large amount of uncertainty on location and amounts of greatest iceaccumulations. Large changes in the forecast will be possible over the next 12 hours.Residents of central NC should have preparations complete by this afternoon and plan toavoid/delay travel Friday night into early Saturday morning. Thank you,Janis-----Janis Cox Brown, MPASupervisor, CapRAC Healthcare Preparedness CoalitionWakeMed Health & Hospitals919.350.6265 (o)919.630.6764 (m) -----Original Message-----From: nws.raleigh@noaa.gov <nws.raleigh@noaa.gov> Sent: Friday, January 10, 2025 8:00 AMTo: nws.raleigh@noaa.govSubject: NWS Raleigh - Weather Briefing Update January 10 08:00:01 AM WARNING: This email originated from outside WakeMed Health & Hospitals. Do not click on links or open attachments unless you are sure you recognize the sender and you know the contents are safe. The Original Sender of this email is nws.er.rah.partners+bncbcypzihbxebrbw5tqs6amgqefcyhtaa@noaa.gov A new briefing that addresses Central North Carolina Weather has been issued. To view this briefing see the attached file, or please click this link: https://urldefense.com/v3/__http://www.weather.gov/media/rah/briefing/NWSRaleighLatestBriefing.pdf__;!!JN6lrkDE!zU-2sufqsekJkKqEbMHeGQ8f1fTLqUFLu9biExXf4G_sPobG8LPHl4qq9p5xlli_M_NIVICOk-f4ivWgognCbC3M5g$ As always, if you have any questions, don't hesitate to call us. Useful links:NWS Raleigh web page: https://urldefense.com/v3/__http://weather.gov/Raleigh__;!!JN6lrkDE!zU-2sufqsekJkKqEbMHeGQ8f1fTLqUFLu9biExXf4G_sPobG8LPHl4qq9p5xlli_M_NIVICOk-f4ivWgogmH7ibqyw$ NWS Raleigh on Facebook: https://urldefense.com/v3/__https://www.facebook.com/NWSRaleigh__;!!JN6lrkDE!zU-2sufqsekJkKqEbMHeGQ8f1fTLqUFLu9biExXf4G_sPobG8LPHl4qq9p5xlli_M_NIVICOk-f4ivWgogkyLxLE2Q$ NWS Raleigh on Twitter: https://urldefense.com/v3/__https://twitter.com/nwsraleigh__;!!JN6lrkDE!zU-2sufqsekJkKqEbMHeGQ8f1fTLqUFLu9biExXf4G_sPobG8LPHl4qq9p5xlli_M_NIVICOk-f4ivWgogmta6sqOg$ NWS Raleigh on YouTube: https://urldefense.com/v3/__https://www.youtube.com/user/NWSRaleigh__;!!JN6lrkDE!zU-2sufqsekJkKqEbMHeGQ8f1fTLqUFLu9biExXf4G_sPobG8LPHl4qq9p5xlli_M_NIVICOk-f4ivWgognrAEZ8dA$ CONGRATS....Medicare Kit Reward Has Arrived...Good morning, Please see several updates below. If anyone has identified any concerns as their preparedness activities have progressed and the forecast has changed to more ice, please reach out directly to us. We will not hold a coordination call today as many of you will be on internal and external calls with various groups. The AM weather briefing is attached. Increase to snow/ice amounts with potential of ice accumulations in excess of 0.25 possible.The State Emergency Operations Center (SEOC) will be Activated from 0700 on 10 January 2025 through 1900 on January 12, 2025.CapRAC On-Call 919-350-7887 Key Messages from weather briefing:1.Light to moderate snow will move into central NC from SW to NE between 3 PM and 8 PMFriday. Triad: 3 4 PM, Triangle/Fayetteville: 5 7 PM, Rocky Mount: 7 9 PM. Some very lightsnow accumulations may be possible as early as 12 1PM in the Triad.2.Dont focus so much on the exact snow and ice amounts that are forecast, but rather focuson the hazards and impacts. To that point, there will be enough snow and iceaccumulations to result in hazardous travel conditions beginning Friday afternoon andlasting into Saturday.3.Due to very cold ground temperatures, the snow/ice is highly likely to stick and freezeimmediately and enable rapid accumulation. Black ice will be a subsequent concern Sundaymorning and Monday morning.4.There is still a large amount of uncertainty on location and amounts of greatest iceaccumulations. Large changes in the forecast will be possible over the next 12 hours.Residents of central NC should have preparations complete by this afternoon and plan toavoid/delay travel Friday night into early Saturday morning. Thank you,Janis-----Janis Cox Brown, MPASupervisor, CapRAC Healthcare Preparedness CoalitionWakeMed Health & Hospitals919.350.6265 (o)919.630.6764 (m) -----Original Message-----From: nws.raleigh@noaa.gov <nws.raleigh@noaa.gov> Sent: Friday, January 10, 2025 8:00 AMTo: nws.raleigh@noaa.govSubject: NWS Raleigh - Weather Briefing Update January 10 08:00:01 AM WARNING: This email originated from outside WakeMed Health & Hospitals. Do not click on links or open attachments unless you are sure you recognize the sender and you know the contents are safe. The Original Sender of this email is nws.er.rah.partners+bncbcypzihbxebrbw5tqs6amgqefcyhtaa@noaa.gov A new briefing that addresses Central North Carolina Weather has been issued. To view this briefing see the attached file, or please click this link: https://urldefense.com/v3/__http://www.weather.gov/media/rah/briefing/NWSRaleighLatestBriefing.pdf__;!!JN6lrkDE!zU-2sufqsekJkKqEbMHeGQ8f1fTLqUFLu9biExXf4G_sPobG8LPHl4qq9p5xlli_M_NIVICOk-f4ivWgognCbC3M5g$ As always, if you have any questions, don't hesitate to call us. Useful links:NWS Raleigh web page: https://urldefense.com/v3/__http://weather.gov/Raleigh__;!!JN6lrkDE!zU-2sufqsekJkKqEbMHeGQ8f1fTLqUFLu9biExXf4G_sPobG8LPHl4qq9p5xlli_M_NIVICOk-f4ivWgogmH7ibqyw$ NWS Raleigh on Facebook: https://urldefense.com/v3/__https://www.facebook.com/NWSRaleigh__;!!JN6lrkDE!zU-2sufqsekJkKqEbMHeGQ8f1fTLqUFLu9biExXf4G_sPobG8LPHl4qq9p5xlli_M_NIVICOk-f4ivWgogkyLxLE2Q$ NWS Raleigh on Twitter: https://urldefense.com/v3/__https://twitter.com/nwsraleigh__;!!JN6lrkDE!zU-2sufqsekJkKqEbMHeGQ8f1fTLqUFLu9biExXf4G_sPobG8LPHl4qq9p5xlli_M_NIVICOk-f4ivWgogmta6sqOg$ NWS Raleigh on YouTube: https://urldefense.com/v3/__https://www.youtube.com/user/NWSRaleigh__;!!JN6lrkDE!zU-2sufqsekJkKqEbMHeGQ8f1fTLqUFLu9biExXf4G_sPobG8LPHl4qq9p5xlli_M_NIVICOk-f4ivWgognrAEZ8dA$ CONGRATS....Medicare Kit Reward Has Arrived...Good morning, Please see several updates below. If anyone has identified any concerns as their preparedness activities have progressed and the forecast has changed to more ice, please reach out directly to us. We will not hold a coordination call today as many of you will be on internal and external calls with various groups. The AM weather briefing is attached. Increase to snow/ice amounts with potential of ice accumulations in excess of 0.25 possible.The State Emergency Operations Center (SEOC) will be Activated from 0700 on 10 January 2025 through 1900 on January 12, 2025.CapRAC On-Call 919-350-7887 Key Messages from weather briefing:1.Light to moderate snow will move into central NC from SW to NE between 3 PM and 8 PMFriday. Triad: 3 4 PM, Triangle/Fayetteville: 5 7 PM, Rocky Mount: 7 9 PM. Some very lightsnow accumulations may be possible as early as 12 1PM in the Triad.2.Dont focus so much on the exact snow and ice amounts that are forecast, but rather focuson the hazards and impacts. To that point, there will be enough snow and iceaccumulations to result in hazardous travel conditions beginning Friday afternoon andlasting into Saturday.3.Due to very cold ground temperatures, the snow/ice is highly likely to stick and freezeimmediately and enable rapid accumulation. Black ice will be a subsequent concern Sundaymorning and Monday morning.4.There is still a large amount of uncertainty on location and amounts of greatest iceaccumulations. Large changes in the forecast will be possible over the next 12 hours.Residents of central NC should have preparations complete by this afternoon and plan toavoid/delay travel Friday night into early Saturday morning. Thank you,Janis-----Janis Cox Brown, MPASupervisor, CapRAC Healthcare Preparedness CoalitionWakeMed Health & Hospitals919.350.6265 (o)919.630.6764 (m) -----Original Message-----From: nws.raleigh@noaa.gov <nws.raleigh@noaa.gov> Sent: Friday, January 10, 2025 8:00 AMTo: nws.raleigh@noaa.govSubject: NWS Raleigh - Weather Briefing Update January 10 08:00:01 AM WARNING: This email originated from outside WakeMed Health & Hospitals. Do not click on links or open attachments unless you are sure you recognize the sender and you know the contents are safe. The Original Sender of this email is nws.er.rah.partners+bncbcypzihbxebrbw5tqs6amgqefcyhtaa@noaa.gov A new briefing that addresses Central North Carolina Weather has been issued. To view this briefing see the attached file, or please click this link: https://urldefense.com/v3/__http://www.weather.gov/media/rah/briefing/NWSRaleighLatestBriefing.pdf__;!!JN6lrkDE!zU-2sufqsekJkKqEbMHeGQ8f1fTLqUFLu9biExXf4G_sPobG8LPHl4qq9p5xlli_M_NIVICOk-f4ivWgognCbC3M5g$ As always, if you have any questions, don't hesitate to call us. Useful links:NWS Raleigh web page: https://urldefense.com/v3/__http://weather.gov/Raleigh__;!!JN6lrkDE!zU-2sufqsekJkKqEbMHeGQ8f1fTLqUFLu9biExXf4G_sPobG8LPHl4qq9p5xlli_M_NIVICOk-f4ivWgogmH7ibqyw$ NWS Raleigh on Facebook: https://urldefense.com/v3/__https://www.facebook.com/NWSRaleigh__;!!JN6lrkDE!zU-2sufqsekJkKqEbMHeGQ8f1fTLqUFLu9biExXf4G_sPobG8LPHl4qq9p5xlli_M_NIVICOk-f4ivWgogkyLxLE2Q$ NWS Raleigh on Twitter: https://urldefense.com/v3/__https://twitter.com/nwsraleigh__;!!JN6lrkDE!zU-2sufqsekJkKqEbMHeGQ8f1fTLqUFLu9biExXf4G_sPobG8LPHl4qq9p5xlli_M_NIVICOk-f4ivWgogmta6sqOg$ NWS Raleigh on YouTube: https://urldefense.com/v3/__https://www.youtube.com/user/NWSRaleigh__;!!JN6lrkDE!zU-2sufqsekJkKqEbMHeGQ8f1fTLqUFLu9biExXf4G_sPobG8LPHl4qq9p5xlli_M_NIVICOk-f4ivWgognrAEZ8dA$ CONGRATS....Medicare Kit Reward Has Arrived... http://.y572e.goyangterus.store/4TSOlP3644SAFm324xzrydobulw260SYTMRVMWDLYVDGS52958EPJO15865N17 http://.y572e.goyangterus.store/4RnAJB3644APmC324ubgjxeszbk260KOCTHTKZWJWVFBC52958FMZU15865n17 Good morning, Please see several updates below. If anyone has identified any concerns as their preparedness activities have progressed and the forecast has changed to more ice, please reach out directly to us. We will not hold a coordination call today as many of you will be on internal and external calls with various groups. The AM weather briefing is attached. Increase to snow/ice amounts with potential of ice accumulations in excess of 0.25 possible.The State Emergency Operations Center (SEOC) will be Activated from 0700 on 10 January 2025 through 1900 on January 12, 2025.CapRAC On-Call 919-350-7887 Key Messages from weather briefing:1.Light to moderate snow will move into central NC from SW to NE between 3 PM and 8 PMFriday. Triad: 3 4 PM, Triangle/Fayetteville: 5 7 PM, Rocky Mount: 7 9 PM. Some very lightsnow accumulations may be possible as early as 12 1PM in the Triad.2.Dont focus so much on the exact snow and ice amounts that are forecast, but rather focuson the hazards and impacts. To that point, there will be enough snow and iceaccumulations to result in hazardous travel conditions beginning Friday afternoon andlasting into Saturday.3.Due to very cold ground temperatures, the snow/ice is highly likely to stick and freezeimmediately and enable rapid accumulation. Black ice will be a subsequent concern Sundaymorning and Monday morning.4.There is still a large amount of uncertainty on location and amounts of greatest iceaccumulations. Large changes in the forecast will be possible over the next 12 hours.Residents of central NC should have preparations complete by this afternoon and plan toavoid/delay travel Friday night into early Saturday morning. Thank you,Janis-----Janis Cox Brown, MPASupervisor, CapRAC Healthcare Preparedness CoalitionWakeMed Health & Hospitals919.350.6265 (o)919.630.6764 (m) -----Original Message-----From: nws.raleigh@noaa.gov <nws.raleigh@noaa.gov> Sent: Friday, January 10, 2025 8:00 AMTo: nws.raleigh@noaa.govSubject: NWS Raleigh - Weather Briefing Update January 10 08:00:01 AM WARNING: This email originated from outside WakeMed Health & Hospitals. Do not click on links or open attachments unless you are sure you recognize the sender and you know the contents are safe. The Original Sender of this email is nws.er.rah.partners+bncbcypzihbxebrbw5tqs6amgqefcyhtaa@noaa.gov A new briefing that addresses Central North Carolina Weather has been issued. To view this briefing see the attached file, or please click this link: https://urldefense.com/v3/__http://www.weather.gov/media/rah/briefing/NWSRaleighLatestBriefing.pdf__;!!JN6lrkDE!zU-2sufqsekJkKqEbMHeGQ8f1fTLqUFLu9biExXf4G_sPobG8LPHl4qq9p5xlli_M_NIVICOk-f4ivWgognCbC3M5g$ As always, if you have any questions, don't hesitate to call us. Useful links:NWS Raleigh web page: https://urldefense.com/v3/__http://weather.gov/Raleigh__;!!JN6lrkDE!zU-2sufqsekJkKqEbMHeGQ8f1fTLqUFLu9biExXf4G_sPobG8LPHl4qq9p5xlli_M_NIVICOk-f4ivWgogmH7ibqyw$ NWS Raleigh on Facebook: https://urldefense.com/v3/__https://www.facebook.com/NWSRaleigh__;!!JN6lrkDE!zU-2sufqsekJkKqEbMHeGQ8f1fTLqUFLu9biExXf4G_sPobG8LPHl4qq9p5xlli_M_NIVICOk-f4ivWgogkyLxLE2Q$ NWS Raleigh on Twitter: https://urldefense.com/v3/__https://twitter.com/nwsraleigh__;!!JN6lrkDE!zU-2sufqsekJkKqEbMHeGQ8f1fTLqUFLu9biExXf4G_sPobG8LPHl4qq9p5xlli_M_NIVICOk-f4ivWgogmta6sqOg$ NWS Raleigh on YouTube: https://urldefense.com/v3/__https://www.youtube.com/user/NWSRaleigh__;!!JN6lrkDE!zU-2sufqsekJkKqEbMHeGQ8f1fTLqUFLu9biExXf4G_sPobG8LPHl4qq9p5xlli_M_NIVICOk-f4ivWgognrAEZ8dA$ <!-- /* Font Definitions */ @font-face {font-family:Wingdings; panose-1:5 0 0 0 0 0 0 0 0 0;} @font-face {font-family:"Cambria Math"; panose-1:2 4 5 3 5 4 6 3 2 4;} @font-face {font-family:Calibri; panose-1:2 15 5 2 2 2 4 3 2 4;} /* Style Definitions */ p.MsoNormal, li.MsoNormal, div.MsoNormal {margin:0in; font-size:11.0pt; font-family:"Calibri",sans-serif; mso-ligatures:standardcontextual;} p.MsoPlainText, li.MsoPlainText, div.MsoPlainText {mso-style-priority:99; mso-style-link:"Plain Text Char"; margin:0in; font-size:11.0pt; font-family:"Calibri",sans-serif; mso-ligatures:standardcontextual;} span.PlainTextChar {mso-style-name:"Plain Text Char"; mso-style-priority:99; mso-style-link:"Plain Text"; font-family:"Calibri",sans-serif;} .MsoChpDefault {mso-style-type:export-only;} @page WordSection1 {size:8.5in 11.0in; margin:1.0in 1.0in 1.0in 1.0in;} div.WordSection1 {page:WordSection1;} /* List Definitions */ @list l0 {mso-list-id:2131775933; mso-list-type:hybrid; mso-list-template-ids:187725676 67698689 67698691 67698693 67698689 67698691 67698693 67698689 67698691 67698693;} @list l0:level1 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-.25in; font-family:Symbol;} @list l0:level2 {mso-level-number-format:bullet; mso-level-text:o; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-.25in; font-family:"Courier New";} @list l0:level3 {mso-level-number-format:bullet; mso-level-text:\F0A7; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-.25in; font-family:Wingdings;} @list l0:level4 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-.25in; font-family:Symbol;} @list l0:level5 {mso-level-number-format:bullet; mso-level-text:o; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-.25in; font-family:"Courier New";} @list l0:level6 {mso-level-number-format:bullet; mso-level-text:\F0A7; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-.25in; font-family:Wingdings;} @list l0:level7 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-.25in; font-family:Symbol;} @list l0:level8 {mso-level-number-format:bullet; mso-level-text:o; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-.25in; font-family:"Courier New";} @list l0:level9 {mso-level-number-format:bullet; mso-level-text:\F0A7; mso-level-tab-stop:none; mso-level-number-position:left; text-indent:-.25in; font-family:Wingdings;} ol {margin-bottom:0in;} ul {margin-bottom:0in;} --> Good morning, Please see several updates below. If anyone has identified any concerns as their preparedness activities have progressed and the forecast has changed to more ice, please reach out directly to us. We will not hold a coordination call today as many of you will be on internal and external calls with various groups. The AM weather briefing is attached. Increase to snow/ice amounts with potential of ice accumulations in excess of 0.25 possible.The State Emergency Operations Center (SEOC) will be Activated from 0700 on 10 January 2025 through 1900 on January 12, 2025.CapRAC On-Call 919-350-7887 Key Messages from weather briefing:1.Light to moderate snow will move into central NC from SW to NE between 3 PM and 8 PMFriday. Triad: 3 4 PM, Triangle/Fayetteville: 5 7 PM, Rocky Mount: 7 9 PM. Some very lightsnow accumulations may be possible as early as 12 1PM in the Triad.2.Dont focus so much on the exact snow and ice amounts that are forecast, but rather focuson the hazards and impacts. To that point, there will be enough snow and iceaccumulations to result in hazardous travel conditions beginning Friday afternoon andlasting into Saturday.3.Due to very cold ground temperatures, the snow/ice is highly likely to stick and freezeimmediately and enable rapid accumulation. Black ice will be a subsequent concern Sundaymorning and Monday morning.4.There is still a large amount of uncertainty on location and amounts of greatest iceaccumulations. Large changes in the forecast will be possible over the next 12 hours.Residents of central NC should have preparations complete by this afternoon and plan toavoid/delay travel Friday night into early Saturday morning. Thank you,Janis-----Janis Cox Brown, MPASupervisor, CapRAC Healthcare Preparedness CoalitionWakeMed Health & Hospitals919.350.6265 (o)919.630.6764 (m) -----Original Message-----From: nws.raleigh@noaa.gov <nws.raleigh@noaa.gov> Sent: Friday, January 10, 2025 8:00 AMTo: nws.raleigh@noaa.govSubject: NWS Raleigh - Weather Briefing Update January 10 08:00:01 AM WARNING: This email originated from outside WakeMed Health & Hospitals. Do not click on links or open attachments unless you are sure you recognize the sender and you know the contents are safe. The Original Sender of this email is nws.er.rah.partners+bncbcypzihbxebrbw5tqs6amgqefcyhtaa@noaa.gov A new briefing that addresses Central North Carolina Weather has been issued. To view this briefing see the attached file, or please click this link: https://urldefense.com/v3/__http://www.weather.gov/media/rah/briefing/NWSRaleighLatestBriefing.pdf__;!!JN6lrkDE!zU-2sufqsekJkKqEbMHeGQ8f1fTLqUFLu9biExXf4G_sPobG8LPHl4qq9p5xlli_M_NIVICOk-f4ivWgognCbC3M5g$ As always, if you have any questions, don't hesitate to call us. Useful links:NWS Raleigh web page: https://urldefense.com/v3/__http://weather.gov/Raleigh__;!!JN6lrkDE!zU-2sufqsekJkKqEbMHeGQ8f1fTLqUFLu9biExXf4G_sPobG8LPHl4qq9p5xlli_M_NIVICOk-f4ivWgogmH7ibqyw$ NWS Raleigh on Facebook: https://urldefense.com/v3/__https://www.facebook.com/NWSRaleigh__;!!JN6lrkDE!zU-2sufqsekJkKqEbMHeGQ8f1fTLqUFLu9biExXf4G_sPobG8LPHl4qq9p5xlli_M_NIVICOk-f4ivWgogkyLxLE2Q$ NWS Raleigh on Twitter: https://urldefense.com/v3/__https://twitter.com/nwsraleigh__;!!JN6lrkDE!zU-2sufqsekJkKqEbMHeGQ8f1fTLqUFLu9biExXf4G_sPobG8LPHl4qq9p5xlli_M_NIVICOk-f4ivWgogmta6sqOg$ NWS Raleigh on YouTube: https://urldefense.com/v3/__https://www.youtube.com/user/NWSRaleigh__;!!JN6lrkDE!zU-2sufqsekJkKqEbMHeGQ8f1fTLqUFLu9biExXf4G_sPobG8LPHl4qq9p5xlli_M_NIVICOk-f4ivWgognrAEZ8dA$ Good morning, Please see several updates below. If anyone has identified any concerns as their preparedness activities have progressed and the forecast has changed to more ice, please reach out directly to us. We will not hold a coordination call today as many of you will be on internal and external calls with various groups. If anyone has identified any concerns as their preparedness activities have progressed and the forecast has changed to more ice, please reach out directly to us. If anyone has identified any concerns as their preparedness activities have progressed and the forecast has changed to more ice, please reach out directly to us. The AM weather briefing is attached. Increase to snow/ice amounts with potential of ice accumulations in excess of 0.25 possible.The State Emergency Operations Center (SEOC) will be Activated from 0700 on 10 January 2025 through 1900 on January 12, 2025.CapRAC On-Call 919-350-7887 The AM weather briefing is attached. Increase to snow/ice amounts with potential of ice accumulations in excess of 0.25 possible. The State Emergency Operations Center (SEOC) will be Activated from 0700 on 10 January 2025 through 1900 on January 12, 2025. The State Emergency Operations Center (SEOC) will be Activated from 0700 on 10 January 2025 through 1900 on January 12, 2025. CapRAC On-Call 919-350-7887 Key Messages from weather briefing: 1. Light to moderate snow will move into central NC from SW to NE between 3 PM and 8 PM Friday. Triad: 3 4 PM, Triangle/Fayetteville: 5 7 PM, Rocky Mount: 7 9 PM. Some very light snow accumulations may be possible as early as 12 1PM in the Triad. 2. Dont focus so much on the exact snow and ice amounts that are forecast, but rather focus on the hazards and impacts. To that point, there will be enough snow and ice accumulations to result in hazardous travel conditions beginning Friday afternoon and lasting into Saturday. 3. Due to very cold ground temperatures, the snow/ice is highly likely to stick and freeze immediately and enable rapid accumulation. Black ice will be a subsequent concern Sunday morning and Monday morning. 4. There is still a large amount of uncertainty on location and amounts of greatest ice accumulations. Large changes in the forecast will be possible over the next 12 hours. Residents of central NC should have preparations complete by this afternoon and plan to avoid/delay travel Friday night into early Saturday morning. Thank you, Janis ----- ----- ----- Janis Cox Brown, MPA Janis Cox Brown, MPA Janis Cox Brown, MPA Supervisor, CapRAC Healthcare Preparedness Coalition Supervisor, CapRAC Healthcare Preparedness Coalition WakeMed Health & Hospitals WakeMed Health & Hospitals WakeMed Health & Hospitals http://www.wakemed.org/ WakeMed Health & Hospitals 919.350.6265 (o) 919.350.6265 (o) 919.630.6764 (m) 919.630.6764 (m) -----Original Message-----From: nws.raleigh@noaa.gov <nws.raleigh@noaa.gov> Sent: Friday, January 10, 2025 8:00 AMTo: nws.raleigh@noaa.govSubject: NWS Raleigh - Weather Briefing Update January 10 08:00:01 AM WARNING: This email originated from outside WakeMed Health & Hospitals. Do not click on links or open attachments unless you are sure you recognize the sender and you know the contents are safe. The Original Sender of this email is nws.er.rah.partners+bncbcypzihbxebrbw5tqs6amgqefcyhtaa@noaa.gov nws.er.rah.partners+bncbcypzihbxebrbw5tqs6amgqefcyhtaa@noaa.gov mailto:nws.er.rah.partners+bncbcypzihbxebrbw5tqs6amgqefcyhtaa@noaa.gov nws.er.rah.partners+bncbcypzihbxebrbw5tqs6amgqefcyhtaa@noaa.gov A new briefing that addresses Central North Carolina Weather has been issued. To view this briefing see the attached file, or please click this link: https://urldefense.com/v3/__http://www.weather.gov/media/rah/briefing/NWSRaleighLatestBriefing.pdf__;!!JN6lrkDE!zU-2sufqsekJkKqEbMHeGQ8f1fTLqUFLu9biExXf4G_sPobG8LPHl4qq9p5xlli_M_NIVICOk-f4ivWgognCbC3M5g$ https://urldefense.com/v3/__http://www.weather.gov/media/rah/briefing/NWSRaleighLatestBriefing.pdf__;!!JN6lrkDE!zU-2sufqsekJkKqEbMHeGQ8f1fTLqUFLu9biExXf4G_sPobG8LPHl4qq9p5xlli_M_NIVICOk-f4ivWgognCbC3M5g$ https://urldefense.com/v3/__http:/www.weather.gov/media/rah/briefing/NWSRaleighLatestBriefing.pdf__;!!JN6lrkDE!zU-2sufqsekJkKqEbMHeGQ8f1fTLqUFLu9biExXf4G_sPobG8LPHl4qq9p5xlli_M_NIVICOk-f4ivWgognCbC3M5g$ https://urldefense.com/v3/__http://www.weather.gov/media/rah/briefing/NWSRaleighLatestBriefing.pdf__;!!JN6lrkDE!zU-2sufqsekJkKqEbMHeGQ8f1fTLqUFLu9biExXf4G_sPobG8LPHl4qq9p5xlli_M_NIVICOk-f4ivWgognCbC3M5g$ As always, if you have any questions, don't hesitate to call us. Useful links: NWS Raleigh web page: https://urldefense.com/v3/__http://weather.gov/Raleigh__;!!JN6lrkDE!zU-2sufqsekJkKqEbMHeGQ8f1fTLqUFLu9biExXf4G_sPobG8LPHl4qq9p5xlli_M_NIVICOk-f4ivWgogmH7ibqyw$ https://urldefense.com/v3/__http://weather.gov/Raleigh__;!!JN6lrkDE!zU-2sufqsekJkKqEbMHeGQ8f1fTLqUFLu9biExXf4G_sPobG8LPHl4qq9p5xlli_M_NIVICOk-f4ivWgogmH7ibqyw$ https://urldefense.com/v3/__http:/weather.gov/Raleigh__;!!JN6lrkDE!zU-2sufqsekJkKqEbMHeGQ8f1fTLqUFLu9biExXf4G_sPobG8LPHl4qq9p5xlli_M_NIVICOk-f4ivWgogmH7ibqyw$ https://urldefense.com/v3/__http://weather.gov/Raleigh__;!!JN6lrkDE!zU-2sufqsekJkKqEbMHeGQ8f1fTLqUFLu9biExXf4G_sPobG8LPHl4qq9p5xlli_M_NIVICOk-f4ivWgogmH7ibqyw$ NWS Raleigh on Facebook: https://urldefense.com/v3/__https://www.facebook.com/NWSRaleigh__;!!JN6lrkDE!zU-2sufqsekJkKqEbMHeGQ8f1fTLqUFLu9biExXf4G_sPobG8LPHl4qq9p5xlli_M_NIVICOk-f4ivWgogkyLxLE2Q$ https://urldefense.com/v3/__https://www.facebook.com/NWSRaleigh__;!!JN6lrkDE!zU-2sufqsekJkKqEbMHeGQ8f1fTLqUFLu9biExXf4G_sPobG8LPHl4qq9p5xlli_M_NIVICOk-f4ivWgogkyLxLE2Q$ https://urldefense.com/v3/__https:/www.facebook.com/NWSRaleigh__;!!JN6lrkDE!zU-2sufqsekJkKqEbMHeGQ8f1fTLqUFLu9biExXf4G_sPobG8LPHl4qq9p5xlli_M_NIVICOk-f4ivWgogkyLxLE2Q$ https://urldefense.com/v3/__https://www.facebook.com/NWSRaleigh__;!!JN6lrkDE!zU-2sufqsekJkKqEbMHeGQ8f1fTLqUFLu9biExXf4G_sPobG8LPHl4qq9p5xlli_M_NIVICOk-f4ivWgogkyLxLE2Q$ NWS Raleigh on Twitter: https://urldefense.com/v3/__https://twitter.com/nwsraleigh__;!!JN6lrkDE!zU-2sufqsekJkKqEbMHeGQ8f1fTLqUFLu9biExXf4G_sPobG8LPHl4qq9p5xlli_M_NIVICOk-f4ivWgogmta6sqOg$ https://urldefense.com/v3/__https://twitter.com/nwsraleigh__;!!JN6lrkDE!zU-2sufqsekJkKqEbMHeGQ8f1fTLqUFLu9biExXf4G_sPobG8LPHl4qq9p5xlli_M_NIVICOk-f4ivWgogmta6sqOg$ https://urldefense.com/v3/__https:/twitter.com/nwsraleigh__;!!JN6lrkDE!zU-2sufqsekJkKqEbMHeGQ8f1fTLqUFLu9biExXf4G_sPobG8LPHl4qq9p5xlli_M_NIVICOk-f4ivWgogmta6sqOg$ https://urldefense.com/v3/__https://twitter.com/nwsraleigh__;!!JN6lrkDE!zU-2sufqsekJkKqEbMHeGQ8f1fTLqUFLu9biExXf4G_sPobG8LPHl4qq9p5xlli_M_NIVICOk-f4ivWgogmta6sqOg$ NWS Raleigh on YouTube: https://urldefense.com/v3/__https://www.youtube.com/user/NWSRaleigh__;!!JN6lrkDE!zU-2sufqsekJkKqEbMHeGQ8f1fTLqUFLu9biExXf4G_sPobG8LPHl4qq9p5xlli_M_NIVICOk-f4ivWgognrAEZ8dA$ https://urldefense.com/v3/__https://www.youtube.com/user/NWSRaleigh__;!!JN6lrkDE!zU-2sufqsekJkKqEbMHeGQ8f1fTLqUFLu9biExXf4G_sPobG8LPHl4qq9p5xlli_M_NIVICOk-f4ivWgognrAEZ8dA$ https://urldefense.com/v3/__https:/www.youtube.com/user/NWSRaleigh__;!!JN6lrkDE!zU-2sufqsekJkKqEbMHeGQ8f1fTLqUFLu9biExXf4G_sPobG8LPHl4qq9p5xlli_M_NIVICOk-f4ivWgognrAEZ8dA$ https://urldefense.com/v3/__https://www.youtube.com/user/NWSRaleigh__;!!JN6lrkDE!zU-2sufqsekJkKqEbMHeGQ8f1fTLqUFLu9biExXf4G_sPobG8LPHl4qq9p5xlli_M_NIVICOk-f4ivWgognrAEZ8dA$
Attachments:
  • Outlook-n41gului.png
  • United Health Care Medicare Kit.pdf
Key Value
Receivedfrom CH2PR02MB6967.namprd02.prod.outlook.com ([fe80::f319:3b55:a859:f5f7]) by CH2PR02MB6967.namprd02.prod.outlook.com ([fe80::f319:3b55:a859:f5f7%4]) with mapi id 15.20.8335.011; Fri, 10 Jan 2025 13:18:55 +0000
Authentication-Resultsspf=pass (sender IP is 40.107.215.67) smtp.mailfrom=oxvrim.sambuh.com; dkim=fail (signature did not verify) header.d=wakemed.org;dmarc=permerror action=none header.from=oxvrim.sambuh.com;compauth=pass reason=111
Received-SpfPass (protection.outlook.com: domain of wakemed.org designates 205.220.177.47 as permitted sender) receiver=protection.outlook.com; client-ip=205.220.177.47; helo=mx0b-00589901.pphosted.com; pr=C
Arc-Seali=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=YL5DJOVMl4CCgvE9fj+/tSYLUkhVWWoeTeeBjqYcvOK82EQigdpkR1YdvcNQv1nQ3i3vtxrxEhh3Guum+pxHognLyiej6lytKQKLBQxdw3XEQbcxH7xDqhnSPrS43aWfFr6myJ/9L+DC011K7yUrMPHNfDxJ4nA/6imSHFNs90SRS1tPKpqAVRBAS0mQbdndzX8QtlRbM43tG9lzlw6Supl4HF44PWnoK2++KtzwIc9GcmkSXZy6qzZYzHtwOfNkzymZhMUdvwxIaA4Uxlqggmjle6Kt5/CYqGZhC9ARYnX6G3D4BmsXNie5JgZsrc56D2inBY8Xp/IzqzrytwldbA==
Arc-Message-Signaturei=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=8aUNYqzIpUh/mLxJUPmQ2KjGnHTPM7Y2a5JrOzB5wOs=; b=snZKx08X1ebAJaghEcygjgYHxJxuecTeq/iIwHqJoX99s1xjy4mUhqOvcQ8FTJM6mfSKHjWzvpH72h6y2GZY/IWB0PeVMS1zAQUjXrtgiTsNTwK3RxdXABA4Tzjs58P3OIJNfFm5/L1YFxmyZZlLpJqVmgf8qpLCluW2bkwGys4oSroLGsF8sKOYu/L6CCVrW9tMRj/T5ZgpO3GaaTMjBbXvt7jG9HsALxpkTtCvMdXKRTrXN9saKUstwRbsL8ahCDwE22mVjK+WL5ewWj4jDveV64waPnuwWLYe6VbaPt6Vze58poUSnTf5cAyMppLqXWDAv1Bix0NhsILFfylAxQ==
Arc-Authentication-Resultsi=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=wakemed.org; dmarc=pass action=none header.from=wakemed.org; dkim=pass header.d=wakemed.org; arc=none
X-Ms-Exchange-Authentication-Resultsspf=fail (sender IP is 185.246.85.91) smtp.mailfrom=oxvrim.sambuh.com; dkim=fail (signature did not verify) header.d=wakemed.org;dmarc=permerror action=none header.from=oxvrim.sambuh.com;
X-Mozilla-Status0001
X-Mozilla-Status200000000
Authentication-Results-Originalspf=pass (sender IP is 205.220.177.47) smtp.mailfrom=wakemed.org; dkim=pass (signature was verified) header.d=wakemed.org;dmarc=pass action=none header.from=wakemed.org;compauth=pass reason=100
Dkim-Signaturev=1; a=rsa-sha256; c=relaxed/relaxed; d=wakemed.org; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=8aUNYqzIpUh/mLxJUPmQ2KjGnHTPM7Y2a5JrOzB5wOs=; b=4naW+TsZLIhXgxwlLaM2ooHa4Zp4Uf+EStdR/9L7PanmFciaR6gkGmXbaYarGRAUrXlAJwRNyyh+1T0omKCS5lhfAre9K1V+sQbSgySsVGA2nohVA812qgITuxU9bkhxOFhj2ftc8d52CB0iBJ6AgoBpbpkI09wvn2sWtyFIsq4=
FromUnited Health Care #y572e#a8sw5 <JANISBROWN.493@oxvrim.sambuh.com>
To!Imagicomm - TUL Tulsa TV PhotoTeam <phototeam@fox23.com>
Cc!Imagicomm - TUL Tulsa TV PhotoTeam <phototeam@fox23.com>
SubjectFW: United Health Care Medicare Kit #y572e#qn8an
Thread-TopicCapRAC Coalition updates: NWS Briefing 8AM, SEOC, CapRAC on-call #
Thread-IndexAQHbY2IyOSM6GeZwQUuQ7g0nFDTsKg==
DateFri, 10 Jan 2025 18:32:06 +0000
Message-Id <CH2PR02MB69676FC3A7524rpeysxp4nez92E0917A02C5BC31C2@CH2PR02MB6967.namprd02.prod.outlook.com>
References<678119d1.tw0ZF4fBSopq7K84%nws.raleigh@noaa.gov>
In-Reply-To<678119d1.tw0ZF4fBSopq7K84%nws.raleigh@noaa.gov>
Accept-Languageen-US
Content-Languageen-US
X-Ms-Has-Attachyes
X-Ms-Traffictypediagnostic CH2PR02MB6967:EE_|CYYPR02MB9888:EE_|BL6PEPF0001AB55:EE_|CO6P221MB0808:EE_|BN0P221MB0573:EE_|HK2PEPF00006FB5:EE_|TYZPR04MB7507:EE_|SJ5PEPF000001D4:EE_|SJ0PR11MB4847:EE_|MW4PR11MB6785:EE_
X-Ms-Office365-Filtering-Correlation-Id 6777ff48-58c1-4601-223a-08dd31a51b95
X-Ld-Processed4045d223-8b31-4c15-b863-ee20f3303bb8,ExtAddr
X-Ms-Exchange-Senderadcheck1
X-Ms-Exchange-Antispam-Relay0
X-Microsoft-Antispam-Untrusted BCL:0;ARA:13230040|82310400026|61400799027|41320700013|35042699022|34070700014|36860700013|6140799039|376014|8096899003|8135299006|4076899003;
X-Microsoft-Antispam-Message-Info-Original kV5XtJCJuig2Fx5HD6nVLCAmJyOGp7r4RM2pmoYPpcck+F9gycAyGfjqemVAWkoGaf0QQBDEjiwLDz6ufjJea3kn2Mcka659oRqfOQ+Bozkq2t9n/kOvLQWaIXqxFAInpQawyb0pQWGmapu4JkpsZgpCyivlAf0teEYgZJTU9JUk8fYxAAdhDWSd0OvlLih3f5EBAW8b+60veMJryQL7GHcFctTsuCj/UoXWxKsWgMEAioHULXwzJ166+0BiJhQ+dUMPo7c4AwcvufqEVWg2Bjbl/BkuCbLValrxjGEA6wx32wkTbapPC+ZMBlJorQznutCrHbV5nMxQHI/3Z1tGhcBnDEiW6ckm6102myZtaA4qmtxl3eVZQx5VzDhqGpqD0QbVev0+HnOBBXrXcmJkVq2I895Zcha5s7k/ib9fwgqUKU1M6VHyaTbcXb9Ch0W8Tgn3mxPuOTzjMCokJOPf4cIqClvGdzzxTTzG2Eh7cSn28LKlzmy851TGIxh8CKaLG7EERX8ag5HTrizx388upVB80xzTh2NzvR+5u941C1wdOlqQqF2fXOZQ/neHM+m+RxDodjZiGtS43hguB2+2gOQhyKWzVLTfUobWUGvudcpgS+HZ5dM9gCBBvT2dimRS9m8LsWQzj4LZuPTiuml5hLwzUhhK7BDwyVDHWXnDkE0H2HxCyEMa2Yyu3VQxj+rTPwWTt2rD5Zf0s41g/gJIDMs0LabC7SvWYvnRF1CBGw1K8FEtcsAblPkllexF0tDu8L9h4obWam1ed7wgOmAiEVrCqHs/WNg/Pr736grzruc+JTzbBkQirt6TAkfSxITZMv77c0fv5cd5UXeQ3wv1LKDBzcXbyR5Jf7NVb/srOgYqEts5UCXSj1PfdBOmifXvxkS4lB6p5xksBPzBXH4QOaHwBssh0iRI8L9A93lUcEVRqSPiPwfvrneOtcq4yjHBvACMfr3stjBZACm/xQtwWyTmA8IyplGYT9C2vheU/zlYZqrg7DHEqe0312gmt17w19rdrbiEPX4OAs9DG0Rr0nUgdhS/g8vSc2WQS5lf7nxNDKHdMoUhAT26YtwNrH7YagfcEHOBAlSu6l634rAHRsVtj1XmVmD0bTgXg2tlQjSsX/mI7ElHv89d0wwXNBY4llO5/Tbpm98xWvnSdCGTDqhWsIOcs1I17yQoJc3Yu6kHgwAMXspK3U7u91g80F0oR4nzLp8oC4d//+PNDjyECZ0oL0Dp0RgpVyRIIAoWBC5Iine19ZHGDy+ZInTqT6sN0NwHyHJ4n+BGGhTptdBG1W+wpLk7LbZWWx1HKEWtTiqpLW/sJyS9PonGSIkKe6e6wTqO0CMxVwNAMwuOjTY8rcwt5vw8cbCbdmInIBChLrr/Qz3EFY5Jj6sLUvzhK9OzxCOqIIXRT8Oen7l8tqROVA==
X-Forefront-Antispam-Report-Untrusted CIP:185.246.85.91;CTRY:FR;LANG:en;SCL:1;SRV:;IPV:CAL;SFV:NSPM;H:miroza.it;PTR:api.andywhitemosaics.click;CAT:NONE;SFS:(13230040)(82310400026)(61400799027)(41320700013)(35042699022)(34070700014)(36860700013)(6140799039)(376014)(8096899003)(8135299006)(4076899003);DIR:OUT;SFP:1101;
X-Ms-Exchange-Antispam-Messagedata-Original-Chunkcount1
X-Ms-Exchange-Antispam-Messagedata-Original-0 MGxlRXDWu6JoUX3CqawZEIbFvLrwvsgYj1IlqBW2j2D+My8uxN/PdMQpmeJpbl9oTxZsHOWl/ZamPIMLyZi+KoA+4vcWaMOpnfAu0y1Z2SpZDDNjaWaJE4Dvu14I318DnDqyZckwrQtUh9Oz8KlQR8JZuMHiMCR+h20FdMgDtE7dPrZcqQ/V0Anw4DLTE7/D9IRiA47YoKWpKhhDyuMlioQFpB6Xk5Dfgagy60o6NxsYX7sUSRSD3q76UrlpE73RMgGyCyUNzbWMEQe6LfYdiWuBT1vPX9WqAmKBjmedmmyI7WPV37Ou3HMX7eQjbNZ6C9RsWQSV7iOD5Nu3TRjUicJkBCOR30DntDkCxHnBd3d1pcN/2vjCiId2bbFR6Zr37y13LMQ9uzmu05MJBiWrAR8EYfRlzEdAJIdq6lLcuPM0H7KfIQag10ldIlLh7H0RUUdX/RCH5sIozr/WERzyc8gZ6J8veFvTWA8lw62SQO4bN0mpgL28Qn1nJze7r7RgKt8zeqBXngSi+u0V3+49cdKvhu66yDhjTFO5B4KtA46FE90fHMuKokcMiY7rvCAHnmLHEXwoIzyyScy5pJ1/JPNtS0AGybe8Q05n9rCk0YzKtxvm56eXKrJVgqwd0Ch9l9OSh3owPyF1mNpRKK5fBxqpq9n7HQHrRdCbfah6LeqqGqjvfECVyhr3Tgxu9V8DliTluYDPSbjWxVVStjUwlT66pQwMwg24hIZCMqOhmJvKeANKSM1uO2GxgEcoY6Gfj068iWkohzy23AAWBRBVtQIh3hZ0KHvS701R5ZxWW1KCRwMvAC6L6eX6TTrIbDRvJ0xBP7A2cw2dhpejWXNsg1qRMkysxVouqlUE+83r/8glPJ1b9j+zOIE1+AN1SeR/dHMrBNJdJCT0lmt0D+JJFAQvtEOpDD2NChoL7QjfKFAlhepjDE5tSvuZnxwIFnp8T1plN8Efuiy3h+E5JF6KS8XNNRhf54XvKpK3TUUozGL2IZ3PYfqLiIiAHo4uw0+d0vZ+k3LG+2Nv8aUwkyQGniVxhMNFdu5YVycg2DGuItCq5jnscXDbi2+TlnzVHZ39vkAMlKPSYKWtpkV5766drQATzNcCDal0HpWKFvqseAbXE0opSN6qSE9MsmH7TXceAoLRopOuW5zSYZBPx9dOmVjqgv/BWVAPOXFMHgfz+xgpfLsi1zanoRM0aE3m5rxyBwQqj6ee8O9uyTZ5KePg63VjDatpiMbzyUieEA1uba9+o3utgHsGjHdhuypgoHL+jwIFTlnvRHKqgMkaSA4pxFOWt8htx40l5hnbu/1k9BncHLoQdDhlW4x7MPrVAZOaDc9sq/zq3S3pVUByXIuLZzUjaNdaLsF+jrZahi/LxVSuIxp/65SOhAMSDVpu2sOYwPLvweMgEBrl23YhvEqkB1fdU0+QoTeS/IbHQzZVwDHD9N2tanJ5m5eOQC1mqS0hij+/HXdBwFWLYcbgcr8y6IHKlm7y1WyJjp15v/DWXqcrvEKEHJXWFykdOz+sdAM6Fs20ZveupagxG959JRFeVEq+fvqknvG+KBOvKsfm7V7SocO6cetXmZ6qozJq+DH9
Content-Typemultipart/mixed; boundary="----sinikael-?=_1-17365401903820.9719856144485943"
X-Ms-Exchange-Transport-CrosstenantheadersstampedSJ0PR11MB4847
X-Proofpoint-Orig-Guid71vMt_vxniOoo8GsmlQtjTCJsS51YRa_
X-Proofpoint-GuidTIUIJpZ8R10R_khseDlMxhjaF4USMNzh
X-Proofpoint-Virus-Versionvendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1039,Hydra:6.0.680,FMLib:17.12.60.29 definitions=2024-09-06_09,2024-09-06_01,2024-09-02_01
X-Proofpoint-Spam-Detailsrule=outbound_notspam policy=outbound score=0 mlxscore=0 phishscore=0 lowpriorityscore=0 impostorscore=0 mlxlogscore=999 priorityscore=1501 adultscore=0 spamscore=0 bulkscore=0 clxscore=1015 malwarescore=0 suspectscore=0 classifier=scan_limit adjust=0 reason=mlx scancount=1 engine=8.19.0-2411120000 definitions=main-2501100104
Return-PathConin.260@oxvrim.sambuh.com
X-Eopattributedmessage2
X-Ms-Exchange-Transport-Crosstenantheadersstripped SJ5PEPF000001D4.namprd05.prod.outlook.com
X-Ms-Office365-Filtering-Correlation-Id-Prvs 7469c462-e56b-4af0-4281-08dd31a516c5
X-Ms-Exchange-Transport-Endtoendlatency00:00:34.9026684
X-Ms-Exchange-Processed-By-Bccfoldering15.20.8335.010
X-Microsoft-Antispam-Mailbox-Delivery ucf:0;jmr:0;auth:0;dest:I;ENG:(910001)(944506478)(944626604)(920097)(930097)(140003);
MIME-Version1.0
X-Ms-Exchange-Organization-Expirationstarttime10 Jan 2025 18:32:15.8601 (UTC)
X-Ms-Exchange-Organization-ExpirationstarttimereasonOriginalSubmit
X-Ms-Exchange-Organization-Expirationinterval1:00:00:00.0000000
X-Ms-Exchange-Organization-ExpirationintervalreasonOriginalSubmit
X-Ms-Exchange-Organization-Network-Message-Id 6777ff48-58c1-4601-223a-08dd31a51b95
X-Eoptenantattributedmessage3da2778b-8fac-4742-832d-d1d32c7936f0:0
X-Ms-Exchange-Organization-MessagedirectionalityIncoming
X-Ms-Exchange-Transport-Crosstenantheaderspromoted SJ5PEPF000001D4.namprd05.prod.outlook.com
X-Ms-PublictraffictypeEmail
X-Ms-Exchange-Organization-Authsource SJ5PEPF000001D4.namprd05.prod.outlook.com
X-Ms-Exchange-Organization-AuthasAnonymous
X-Ms-Exchange-AtpmessagepropertiesSA|SL
X-Ms-Exchange-Organization-Scl1
X-Microsoft-Antispam BCL:0;ARA:13230040|4073199012|5073199012|35042699022|4076899003|8096899003;
X-Forefront-Antispam-Report CIP:40.107.215.67;CTRY:SG;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:APC01-SG2-obe.outbound.protection.outlook.com;PTR:mail-sg2apc01on2067.outbound.protection.outlook.com;CAT:NONE;SFS:(13230040)(4073199012)(5073199012)(35042699022)(4076899003)(8096899003);DIR:INB;
X-Auto-Response-SuppressDR, RN, NRN, OOF, AutoReply
X-Ms-Exchange-Crosstenant-Originalarrivaltime10 Jan 2025 18:32:15.2664 (UTC)
X-Ms-Exchange-Crosstenant-Network-Message-Id 6777ff48-58c1-4601-223a-08dd31a51b95
X-Ms-Exchange-Crosstenant-Id3da2778b-8fac-4742-832d-d1d32c7936f0
X-Ms-Exchange-Crosstenant-Originalattributedtenantconnectingip TenantId=834fab4d-d063-416f-be32-2c02cf73e520;Ip=[185.246.85.91];Helo=[miroza.it]
X-Ms-Exchange-Crosstenant-Authsource SJ5PEPF000001D4.namprd05.prod.outlook.com
X-Ms-Exchange-Crosstenant-AuthasAnonymous
X-Ms-Exchange-Crosstenant-FromentityheaderInternet
X-Microsoft-Antispam-Message-Info sT8yr6VtZhH1jEUMitpNKJzMEZyjc9UM87FMa9hkRE2yJZ8RDi8EMdR0fKwwy3EFfTky+ta0isiN6MK2k8Ku0RNxmB+XqPsYPXzA0K6X74Gq74bDz+gZvo9/UKA5KkSs7lfcoZbDXFijAWgrRrQZsZMqcBbLxxA/7QRjs6AWozPYfdl99JvNOyJww1jdIVOTJFeOG40kTVDGN3cQExtGgcFHPTJAdSwuypKKrrCbAoJvAEzUx1pEhvgAONgWFp1b6iSCOq4x4sr903dZGmbsiTMjgtGNqmuuszcl2RO01sWZx3vRZdmRUnXIENXY3ZkCrZbfj/B2Ri3wUkLLPetQsvg0MQR1TQYuoD3+tGpZugcsxpluEM4GIiahYBwnlq6EaXyHHYrwCwl+6vPDBRmGtoJxPqAcKHuA4XWKtweynGReidV35hNIeY9bHMDKo/2aaShOxeq9HRYud7oGJJ4lhJ6MEzSaJjYSh6RWM9oSNt8ZEgMRCxB8TGaiHvXAll6BmaJYJVDjdNGtw68sf55lH/l/ohkMoKqyUTKBHkm2OLrFQP/uqibC0cUDWLLcNlfQFaXDQwfaszPfSCQV4cg0lGTkMWss7lW+cA9PMPeAC6DirELLArgAA7npYqtg+AwcAnlMlJ66oRAE6vS7fkk6US0QpZpe3gymYc5nv0RUnU1S6nx/vGM8E2vDtp0XhodqyyQgc+YgXH+PshHohHPAHJVYxxWPjFI069+5d+sDAuvddZTMIi8OlG7qkX5a/Iz0+Iz9mYWBmeCNFmj7De2NuY/xqwv8Cx3de7yD15W708V/NdC1PfvqWiub8v8lQ/7P9OCTMVIygvgv4/hDqouKP/8BAuso/aOqnjEoAaOFPhgbA6VLN3VY1xRq6mUbPbNfiIbqq5nR6HDXc2G+/+QgYnMAo3xbO7HdyuQW6hAYDTDrfJNIYWnp7GpshTROmU4xKfrmFmcVWq23wEQIEh3JXuUpOYpvgbAWQBPZXSqVlOf/IZgLEQJ3TlCWl43L4r6rT4YypwKNp00RWqvvC2OouZlK2sNEltQtPXD/3YatWTUJoIFvgh9kXL8fvbGObiBkM5eyXBhk4XX/S0Bl7EUQSAZO7GxdEU26F9HgSfemqWFGXyyXD8uLI2ep+5QbEm9TwqqwqJskQoZXXp/pZq7qISgw62/SWoYe/mIAVlb5Ns3h2pHoEENhltsEOpRxgLmqu5Eo5vm4EmFKBG8+5IdBE40ArXaAffD3tw0hsTVLCjKmaquc98+9LFVTJerLan2cfGXDnHktC/6vLpmzwDIGR6nxo9IeyppcmMTRLpi6ClddbHXe4rsKYZTscWQ6OydRzsSrhoNowYG8G9wf83c+8QJPL4xM51m5qk52mL5/PliCSAw7XKpP5Jn7+S3MaebRIG9ewTiM8GWQYGNpGIVbGhkWMXv55YvV5fUS/jlmfc877j+z/H3H0U64MdKtqKTqyGUif5Rp9moxlOPP088pu58EaJJESe1Ld8yMESsBUk47nhqWoqDWmQFJIi5GWdo0Wlp2CCY2fIAkhP9oGofhtvb5QK2UJy1z1vVcToCeYz15a0ij5tH4E1siV2ae1Fiiku77Yw0P7Ui8jrf2dGfh7SUcs7+2POuTjN7UWmwAXSWUmRUg86x4JuR8pzCVM6vunOIOJdBSBruw+iRZjAjwma1M/jhdG8vPDqAzvaXvyBBDN95YuVZ1zV+O8+PKsYTugS4QbVoscz5DxovOt1Un8QloStU+9JgXZikBj8uCpx2osvgb37P0pL9/U4qqvgQxEG64gOJodIdsp610fx+iyOQXTHbJXGdJmrm/MmVzy+feiuBVJn1BItw44VMWlrsaB1Hgv9GZPNUf/edeODMGct3UATTaDjl6+vLymsSv8r1RUlZ+An0KTcuZPhU21EeM8DPkWAZaWJQwQYAOnfAlG30zM7Q+7gJTB659lJcf6zi3Y3dY/89DhGtVrY4QxlHgeJy5p73EnauywiRwD+MrHznfQE/oUr9tFPhtTpSfmqLg839rfNc6EZLpEnqggs+eIuAAF/cVXZ6wl4euIRV4QO15873XfV5knJ7px5pkillPuAfZ1fZdFpRzkv1weaRD3U42zdd0oFvvG0W57H0reTEus/IxBuL1YONADx2AVvI=
Content-Transfer-Encoding7bit

Icon Hash:46070c0a8e0c67d6