Windows
Analysis Report
01142025.eml
Overview
General Information
Detection
Score: | 48 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64_ra
- OUTLOOK.EXE (PID: 6984 cmdline:
"C:\Progra m Files (x 86)\Micros oft Office \Root\Offi ce16\OUTLO OK.EXE" /e ml "C:\Use rs\user\De sktop\0114 2025.eml" MD5: 91A5292942864110ED734005B7E005C0) - ai.exe (PID: 676 cmdline:
"C:\Progra m Files (x 86)\Micros oft Office \root\vfs\ ProgramFil esCommonX6 4\Microsof t Shared\O ffice16\ai .exe" "389 7298D-BECE -4E36-9F78 -37EEEE9A5 103" "313C C496-2204- 41E5-BDD1- A0DE29FC69 9F" "6984" "C:\Progr am Files ( x86)\Micro soft Offic e\Root\Off ice16\OUTL OOK.EXE" " WordCombin edFloatieL reOnline.o nnx" MD5: EC652BEDD90E089D9406AFED89A8A8BD)
- cleanup
Source: | Author: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): |
Click to jump to signature section
Phishing |
---|
Source: | Joe Sandbox AI: |
Source: | Joe Sandbox AI: |
Source: | Classification: |
Source: | Classification label: |
Source: | File created: |
Source: | File created: |
Source: | File read: |
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: |
Source: | Section loaded: | ||
Source: | Section loaded: | ||
Source: | Section loaded: | ||
Source: | Section loaded: | ||
Source: | Section loaded: | ||
Source: | Section loaded: | ||
Source: | Section loaded: | ||
Source: | Section loaded: | ||
Source: | Section loaded: |
Source: | Key value queried: |
Source: | Window found: |
Source: | Window detected: |
Source: | Key opened: |
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: |
Source: | Process information queried: |
Source: | Queries volume information: |
Source: | Key value queried: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 11 Browser Extensions | 1 Process Injection | 1 Masquerading | OS Credential Dumping | 1 Process Discovery | Remote Services | Data from Local System | Data Obfuscation | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | 1 DLL Side-Loading | 1 DLL Side-Loading | 1 Process Injection | LSASS Memory | 1 File and Directory Discovery | Remote Desktop Protocol | Data from Removable Media | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 1 DLL Side-Loading | Security Account Manager | 12 System Information Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
52.113.194.132 | unknown | United States | 8068 | MICROSOFT-CORP-MSN-AS-BLOCKUS | false | |
2.16.168.119 | unknown | European Union | 20940 | AKAMAI-ASN1EU | false | |
52.109.32.97 | unknown | United States | 8075 | MICROSOFT-CORP-MSN-AS-BLOCKUS | false | |
20.189.173.10 | unknown | United States | 8075 | MICROSOFT-CORP-MSN-AS-BLOCKUS | false |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1590928 |
Start date and time: | 2025-01-14 15:39:56 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowsinteractivecookbook.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 9 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | stream |
Analysis stop reason: | Timeout |
Sample name: | 01142025.eml |
Detection: | MAL |
Classification: | mal48.winEML@3/5@0/40 |
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, SIHClient.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 52.109.32.97, 52.113.194.132, 2.16.168.119, 2.16.168.101, 20.189.173.10
- Excluded domains from analysis (whitelisted): ecs.office.com, omex.cdn.office.net, slscr.update.microsoft.com, prod.configsvc1.live.com.akadns.net, s-0005-office.config.skype.com, mobile.events.data.microsoft.com, fe3cr.delivery.mp.microsoft.com, ecs-office.s-0005.s-msedge.net, login.live.com, s-0005.s-msedge.net, config.officeapps.live.com, onedscolprdwus09.westus.cloudapp.azure.com, officeclient.microsoft.com, ecs.office.trafficmanager.net, ukw-azsc-config.officeapps.live.com, omex.cdn.office.net.akamaized.net, europe.configsvc1.live.com.akadns.net, mobile.events.data.trafficmanager.net, a1864.dscd.akamai.net
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtQueryAttributesFile calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- Report size getting too big, too many NtReadVirtualMemory calls found.
C:\Users\user\AppData\Local\Temp\Outlook Logging\OUTLOOK_16_0_16827_20130-20250114T0941270164-6984.etl
Download File
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | modified |
Size (bytes): | 102400 |
Entropy (8bit): | 4.474543119627498 |
Encrypted: | false |
SSDEEP: | |
MD5: | 0376BAC14295AE8FAD57130E9A5E4212 |
SHA1: | 4A375F7A773FBA3CD5776A619AC4B7D4D8A1986B |
SHA-256: | ED6DDA3676F2F42F52A5B9F7B330C862FD211E7B2B1C4778C9A158A96F99C20C |
SHA-512: | 8E292BDA4BBF79C2484F8C668AFA9284BF1CDF8915E189927B36C9FAA1401A133B697616F3641E7BEB0E5AFE5298946235E28A29EAEA1F06EAE0E1175166A9C3 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 663 |
Entropy (8bit): | 5.949125862393289 |
Encrypted: | false |
SSDEEP: | |
MD5: | ED3C1C40B68BA4F40DB15529D5443DEC |
SHA1: | 831AF99BB64A04617E0A42EA898756F9E0E0BCCA |
SHA-256: | 039FE79B74E6D3D561E32D4AF570E6CA70DB6BB3718395BE2BF278B9E601279A |
SHA-512: | C7B765B9AFBB9810B6674DBC5C5064ED96A2682E78D5DFFAB384D81EDBC77D01E0004F230D4207F2B7D89CEE9008D79D5FBADC5CB486DA4BC43293B7AA878041 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 70400 |
Entropy (8bit): | 7.963823708028205 |
Encrypted: | false |
SSDEEP: | |
MD5: | 5088205E55AB9BA9DAA872AEBC504ECF |
SHA1: | C52E25F383F278629BF83D660FED7FC6EE4F459F |
SHA-256: | 28C02EF9A101A270C2FA6EB36840AD98B41097F1DD0CC524E25DA7B063B17C3B |
SHA-512: | 8D81F0B081A16AFD3A60220B97F1D70E4C84ABA5DBBB8D80125D73FE3099093C10A3F945E6C1CAF89B6C2217041F0BE99C669B4E37A7833E786D01E023728E4E |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 2302976 |
Entropy (8bit): | 1.798211981592883 |
Encrypted: | false |
SSDEEP: | |
MD5: | 6A965E041866E75B622F36312DB9CE91 |
SHA1: | C3B73210DED6838E8A87059902DA02ACD439B414 |
SHA-256: | EF8FA0A4BB89968A25DD0B4828B784A5B6DBC576CABF8B29DF0A368A3FD5581D |
SHA-512: | D595640800DA2D8529B176828CE57F218C562227FCF645C958FCE61251856715E3E6D6A9C465130FBB3FC991069A63A3F6076C9E126E52EEC6CDFB52F6560B72 |
Malicious: | true |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 393216 |
Entropy (8bit): | 6.806545859888669 |
Encrypted: | false |
SSDEEP: | |
MD5: | 40F35A2FD5874D9025C2CB8E2AE1BED9 |
SHA1: | 9D3422E1A35830DC959B8BF103F0DB9311DB6ABA |
SHA-256: | EBBA5447C7AE2E6C9863CB67644809AE394117D1C1A286B310500473A20CD0EC |
SHA-512: | 29DBA563FF96CD993815F1384D2652044111C611EC05B2372F615DF77F949480BEA881F6804135CB73601DC62DC4B30A7C06D7BE415F2DDE1DFBCB02E3AECCD7 |
Malicious: | true |
Reputation: | unknown |
Preview: |
File type: | |
Entropy (8bit): | 6.116662286865496 |
TrID: |
|
File name: | 01142025.eml |
File size: | 347'327 bytes |
MD5: | c3e7562e7a87b9edcdd3701b2afcdae1 |
SHA1: | e23462bbdcbad654e46c3ed2e0f65deabd93c5a9 |
SHA256: | 581c5e135c25f9134341fcefc702f3d253be62a1d62084202ae04dc69f842e0d |
SHA512: | 8a786ff4f46782e6b7176f1dbb95dfff628ff3b9de7d6728a96af68b37443d002ef482e1855199743713e089c7948a36dde77349c44d3ec0d77df203c85abe13 |
SSDEEP: | 6144:RV/4I6jdRF2baUh+3vypIs5pbEEyki5sPUsm1LSnb4lGPAmwoa5UzoKhH:RV/4I692jM3Hs55EEdYsPUsISnP5yUzp |
TLSH: | 44740230B445335BCE2363DED2297E01A29476CAC6C364B12FFCCE953556A249B7067E |
File Content Preview: | Received: from SJ0PR11MB4847.namprd11.prod.outlook.com (::1) by.. MW4PR11MB6785.namprd11.prod.outlook.com with HTTPS; Fri, 10 Jan 2025.. 18:32:50 +0000..Received: from BYAPR07CA0027.namprd07.prod.outlook.com.. (2603:10b6:a02:bc::40) by SJ0PR11MB4847.nampr |
Subject: | FW: United Health Care Medicare Kit #y572e#qn8an |
From: | United Health Care #y572e#a8sw5 <JANISBROWN.493@oxvrim.sambuh.com> |
To: | !Imagicomm - TUL Tulsa TV PhotoTeam <phototeam@fox23.com> |
Cc: | !Imagicomm - TUL Tulsa TV PhotoTeam <phototeam@fox23.com> |
BCC: | !Imagicomm - TUL Tulsa TV PhotoTeam <phototeam@fox23.com> |
Date: | Fri, 10 Jan 2025 18:32:06 +0000 |
Communications: |
|
Attachments: |
|
Key | Value |
---|---|
Received | from CH2PR02MB6967.namprd02.prod.outlook.com ([fe80::f319:3b55:a859:f5f7]) by CH2PR02MB6967.namprd02.prod.outlook.com ([fe80::f319:3b55:a859:f5f7%4]) with mapi id 15.20.8335.011; Fri, 10 Jan 2025 13:18:55 +0000 |
Authentication-Results | spf=pass (sender IP is 40.107.215.67) smtp.mailfrom=oxvrim.sambuh.com; dkim=fail (signature did not verify) header.d=wakemed.org;dmarc=permerror action=none header.from=oxvrim.sambuh.com;compauth=pass reason=111 |
Received-Spf | Pass (protection.outlook.com: domain of wakemed.org designates 205.220.177.47 as permitted sender) receiver=protection.outlook.com; client-ip=205.220.177.47; helo=mx0b-00589901.pphosted.com; pr=C |
Arc-Seal | i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=YL5DJOVMl4CCgvE9fj+/tSYLUkhVWWoeTeeBjqYcvOK82EQigdpkR1YdvcNQv1nQ3i3vtxrxEhh3Guum+pxHognLyiej6lytKQKLBQxdw3XEQbcxH7xDqhnSPrS43aWfFr6myJ/9L+DC011K7yUrMPHNfDxJ4nA/6imSHFNs90SRS1tPKpqAVRBAS0mQbdndzX8QtlRbM43tG9lzlw6Supl4HF44PWnoK2++KtzwIc9GcmkSXZy6qzZYzHtwOfNkzymZhMUdvwxIaA4Uxlqggmjle6Kt5/CYqGZhC9ARYnX6G3D4BmsXNie5JgZsrc56D2inBY8Xp/IzqzrytwldbA== |
Arc-Message-Signature | i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=8aUNYqzIpUh/mLxJUPmQ2KjGnHTPM7Y2a5JrOzB5wOs=; b=snZKx08X1ebAJaghEcygjgYHxJxuecTeq/iIwHqJoX99s1xjy4mUhqOvcQ8FTJM6mfSKHjWzvpH72h6y2GZY/IWB0PeVMS1zAQUjXrtgiTsNTwK3RxdXABA4Tzjs58P3OIJNfFm5/L1YFxmyZZlLpJqVmgf8qpLCluW2bkwGys4oSroLGsF8sKOYu/L6CCVrW9tMRj/T5ZgpO3GaaTMjBbXvt7jG9HsALxpkTtCvMdXKRTrXN9saKUstwRbsL8ahCDwE22mVjK+WL5ewWj4jDveV64waPnuwWLYe6VbaPt6Vze58poUSnTf5cAyMppLqXWDAv1Bix0NhsILFfylAxQ== |
Arc-Authentication-Results | i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=wakemed.org; dmarc=pass action=none header.from=wakemed.org; dkim=pass header.d=wakemed.org; arc=none |
X-Ms-Exchange-Authentication-Results | spf=fail (sender IP is 185.246.85.91) smtp.mailfrom=oxvrim.sambuh.com; dkim=fail (signature did not verify) header.d=wakemed.org;dmarc=permerror action=none header.from=oxvrim.sambuh.com; |
X-Mozilla-Status | 0001 |
X-Mozilla-Status2 | 00000000 |
Authentication-Results-Original | spf=pass (sender IP is 205.220.177.47) smtp.mailfrom=wakemed.org; dkim=pass (signature was verified) header.d=wakemed.org;dmarc=pass action=none header.from=wakemed.org;compauth=pass reason=100 |
Dkim-Signature | v=1; a=rsa-sha256; c=relaxed/relaxed; d=wakemed.org; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=8aUNYqzIpUh/mLxJUPmQ2KjGnHTPM7Y2a5JrOzB5wOs=; b=4naW+TsZLIhXgxwlLaM2ooHa4Zp4Uf+EStdR/9L7PanmFciaR6gkGmXbaYarGRAUrXlAJwRNyyh+1T0omKCS5lhfAre9K1V+sQbSgySsVGA2nohVA812qgITuxU9bkhxOFhj2ftc8d52CB0iBJ6AgoBpbpkI09wvn2sWtyFIsq4= |
From | United Health Care #y572e#a8sw5 <JANISBROWN.493@oxvrim.sambuh.com> |
To | !Imagicomm - TUL Tulsa TV PhotoTeam <phototeam@fox23.com> |
Cc | !Imagicomm - TUL Tulsa TV PhotoTeam <phototeam@fox23.com> |
Subject | FW: United Health Care Medicare Kit #y572e#qn8an |
Thread-Topic | CapRAC Coalition updates: NWS Briefing 8AM, SEOC, CapRAC on-call # |
Thread-Index | AQHbY2IyOSM6GeZwQUuQ7g0nFDTsKg== |
Date | Fri, 10 Jan 2025 18:32:06 +0000 |
Message-Id | <CH2PR02MB69676FC3A7524rpeysxp4nez92E0917A02C5BC31C2@CH2PR02MB6967.namprd02.prod.outlook.com> |
References | <678119d1.tw0ZF4fBSopq7K84%nws.raleigh@noaa.gov> |
In-Reply-To | <678119d1.tw0ZF4fBSopq7K84%nws.raleigh@noaa.gov> |
Accept-Language | en-US |
Content-Language | en-US |
X-Ms-Has-Attach | yes |
X-Ms-Traffictypediagnostic | CH2PR02MB6967:EE_|CYYPR02MB9888:EE_|BL6PEPF0001AB55:EE_|CO6P221MB0808:EE_|BN0P221MB0573:EE_|HK2PEPF00006FB5:EE_|TYZPR04MB7507:EE_|SJ5PEPF000001D4:EE_|SJ0PR11MB4847:EE_|MW4PR11MB6785:EE_ |
X-Ms-Office365-Filtering-Correlation-Id | 6777ff48-58c1-4601-223a-08dd31a51b95 |
X-Ld-Processed | 4045d223-8b31-4c15-b863-ee20f3303bb8,ExtAddr |
X-Ms-Exchange-Senderadcheck | 1 |
X-Ms-Exchange-Antispam-Relay | 0 |
X-Microsoft-Antispam-Untrusted | BCL:0;ARA:13230040|82310400026|61400799027|41320700013|35042699022|34070700014|36860700013|6140799039|376014|8096899003|8135299006|4076899003; |
X-Microsoft-Antispam-Message-Info-Original | kV5XtJCJuig2Fx5HD6nVLCAmJyOGp7r4RM2pmoYPpcck+F9gycAyGfjqemVAWkoGaf0QQBDEjiwLDz6ufjJea3kn2Mcka659oRqfOQ+Bozkq2t9n/kOvLQWaIXqxFAInpQawyb0pQWGmapu4JkpsZgpCyivlAf0teEYgZJTU9JUk8fYxAAdhDWSd0OvlLih3f5EBAW8b+60veMJryQL7GHcFctTsuCj/UoXWxKsWgMEAioHULXwzJ166+0BiJhQ+dUMPo7c4AwcvufqEVWg2Bjbl/BkuCbLValrxjGEA6wx32wkTbapPC+ZMBlJorQznutCrHbV5nMxQHI/3Z1tGhcBnDEiW6ckm6102myZtaA4qmtxl3eVZQx5VzDhqGpqD0QbVev0+HnOBBXrXcmJkVq2I895Zcha5s7k/ib9fwgqUKU1M6VHyaTbcXb9Ch0W8Tgn3mxPuOTzjMCokJOPf4cIqClvGdzzxTTzG2Eh7cSn28LKlzmy851TGIxh8CKaLG7EERX8ag5HTrizx388upVB80xzTh2NzvR+5u941C1wdOlqQqF2fXOZQ/neHM+m+RxDodjZiGtS43hguB2+2gOQhyKWzVLTfUobWUGvudcpgS+HZ5dM9gCBBvT2dimRS9m8LsWQzj4LZuPTiuml5hLwzUhhK7BDwyVDHWXnDkE0H2HxCyEMa2Yyu3VQxj+rTPwWTt2rD5Zf0s41g/gJIDMs0LabC7SvWYvnRF1CBGw1K8FEtcsAblPkllexF0tDu8L9h4obWam1ed7wgOmAiEVrCqHs/WNg/Pr736grzruc+JTzbBkQirt6TAkfSxITZMv77c0fv5cd5UXeQ3wv1LKDBzcXbyR5Jf7NVb/srOgYqEts5UCXSj1PfdBOmifXvxkS4lB6p5xksBPzBXH4QOaHwBssh0iRI8L9A93lUcEVRqSPiPwfvrneOtcq4yjHBvACMfr3stjBZACm/xQtwWyTmA8IyplGYT9C2vheU/zlYZqrg7DHEqe0312gmt17w19rdrbiEPX4OAs9DG0Rr0nUgdhS/g8vSc2WQS5lf7nxNDKHdMoUhAT26YtwNrH7YagfcEHOBAlSu6l634rAHRsVtj1XmVmD0bTgXg2tlQjSsX/mI7ElHv89d0wwXNBY4llO5/Tbpm98xWvnSdCGTDqhWsIOcs1I17yQoJc3Yu6kHgwAMXspK3U7u91g80F0oR4nzLp8oC4d//+PNDjyECZ0oL0Dp0RgpVyRIIAoWBC5Iine19ZHGDy+ZInTqT6sN0NwHyHJ4n+BGGhTptdBG1W+wpLk7LbZWWx1HKEWtTiqpLW/sJyS9PonGSIkKe6e6wTqO0CMxVwNAMwuOjTY8rcwt5vw8cbCbdmInIBChLrr/Qz3EFY5Jj6sLUvzhK9OzxCOqIIXRT8Oen7l8tqROVA== |
X-Forefront-Antispam-Report-Untrusted | CIP:185.246.85.91;CTRY:FR;LANG:en;SCL:1;SRV:;IPV:CAL;SFV:NSPM;H:miroza.it;PTR:api.andywhitemosaics.click;CAT:NONE;SFS:(13230040)(82310400026)(61400799027)(41320700013)(35042699022)(34070700014)(36860700013)(6140799039)(376014)(8096899003)(8135299006)(4076899003);DIR:OUT;SFP:1101; |
X-Ms-Exchange-Antispam-Messagedata-Original-Chunkcount | 1 |
X-Ms-Exchange-Antispam-Messagedata-Original-0 | MGxlRXDWu6JoUX3CqawZEIbFvLrwvsgYj1IlqBW2j2D+My8uxN/PdMQpmeJpbl9oTxZsHOWl/ZamPIMLyZi+KoA+4vcWaMOpnfAu0y1Z2SpZDDNjaWaJE4Dvu14I318DnDqyZckwrQtUh9Oz8KlQR8JZuMHiMCR+h20FdMgDtE7dPrZcqQ/V0Anw4DLTE7/D9IRiA47YoKWpKhhDyuMlioQFpB6Xk5Dfgagy60o6NxsYX7sUSRSD3q76UrlpE73RMgGyCyUNzbWMEQe6LfYdiWuBT1vPX9WqAmKBjmedmmyI7WPV37Ou3HMX7eQjbNZ6C9RsWQSV7iOD5Nu3TRjUicJkBCOR30DntDkCxHnBd3d1pcN/2vjCiId2bbFR6Zr37y13LMQ9uzmu05MJBiWrAR8EYfRlzEdAJIdq6lLcuPM0H7KfIQag10ldIlLh7H0RUUdX/RCH5sIozr/WERzyc8gZ6J8veFvTWA8lw62SQO4bN0mpgL28Qn1nJze7r7RgKt8zeqBXngSi+u0V3+49cdKvhu66yDhjTFO5B4KtA46FE90fHMuKokcMiY7rvCAHnmLHEXwoIzyyScy5pJ1/JPNtS0AGybe8Q05n9rCk0YzKtxvm56eXKrJVgqwd0Ch9l9OSh3owPyF1mNpRKK5fBxqpq9n7HQHrRdCbfah6LeqqGqjvfECVyhr3Tgxu9V8DliTluYDPSbjWxVVStjUwlT66pQwMwg24hIZCMqOhmJvKeANKSM1uO2GxgEcoY6Gfj068iWkohzy23AAWBRBVtQIh3hZ0KHvS701R5ZxWW1KCRwMvAC6L6eX6TTrIbDRvJ0xBP7A2cw2dhpejWXNsg1qRMkysxVouqlUE+83r/8glPJ1b9j+zOIE1+AN1SeR/dHMrBNJdJCT0lmt0D+JJFAQvtEOpDD2NChoL7QjfKFAlhepjDE5tSvuZnxwIFnp8T1plN8Efuiy3h+E5JF6KS8XNNRhf54XvKpK3TUUozGL2IZ3PYfqLiIiAHo4uw0+d0vZ+k3LG+2Nv8aUwkyQGniVxhMNFdu5YVycg2DGuItCq5jnscXDbi2+TlnzVHZ39vkAMlKPSYKWtpkV5766drQATzNcCDal0HpWKFvqseAbXE0opSN6qSE9MsmH7TXceAoLRopOuW5zSYZBPx9dOmVjqgv/BWVAPOXFMHgfz+xgpfLsi1zanoRM0aE3m5rxyBwQqj6ee8O9uyTZ5KePg63VjDatpiMbzyUieEA1uba9+o3utgHsGjHdhuypgoHL+jwIFTlnvRHKqgMkaSA4pxFOWt8htx40l5hnbu/1k9BncHLoQdDhlW4x7MPrVAZOaDc9sq/zq3S3pVUByXIuLZzUjaNdaLsF+jrZahi/LxVSuIxp/65SOhAMSDVpu2sOYwPLvweMgEBrl23YhvEqkB1fdU0+QoTeS/IbHQzZVwDHD9N2tanJ5m5eOQC1mqS0hij+/HXdBwFWLYcbgcr8y6IHKlm7y1WyJjp15v/DWXqcrvEKEHJXWFykdOz+sdAM6Fs20ZveupagxG959JRFeVEq+fvqknvG+KBOvKsfm7V7SocO6cetXmZ6qozJq+DH9 |
Content-Type | multipart/mixed; boundary="----sinikael-?=_1-17365401903820.9719856144485943" |
X-Ms-Exchange-Transport-Crosstenantheadersstamped | SJ0PR11MB4847 |
X-Proofpoint-Orig-Guid | 71vMt_vxniOoo8GsmlQtjTCJsS51YRa_ |
X-Proofpoint-Guid | TIUIJpZ8R10R_khseDlMxhjaF4USMNzh |
X-Proofpoint-Virus-Version | vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1039,Hydra:6.0.680,FMLib:17.12.60.29 definitions=2024-09-06_09,2024-09-06_01,2024-09-02_01 |
X-Proofpoint-Spam-Details | rule=outbound_notspam policy=outbound score=0 mlxscore=0 phishscore=0 lowpriorityscore=0 impostorscore=0 mlxlogscore=999 priorityscore=1501 adultscore=0 spamscore=0 bulkscore=0 clxscore=1015 malwarescore=0 suspectscore=0 classifier=scan_limit adjust=0 reason=mlx scancount=1 engine=8.19.0-2411120000 definitions=main-2501100104 |
Return-Path | Conin.260@oxvrim.sambuh.com |
X-Eopattributedmessage | 2 |
X-Ms-Exchange-Transport-Crosstenantheadersstripped | SJ5PEPF000001D4.namprd05.prod.outlook.com |
X-Ms-Office365-Filtering-Correlation-Id-Prvs | 7469c462-e56b-4af0-4281-08dd31a516c5 |
X-Ms-Exchange-Transport-Endtoendlatency | 00:00:34.9026684 |
X-Ms-Exchange-Processed-By-Bccfoldering | 15.20.8335.010 |
X-Microsoft-Antispam-Mailbox-Delivery | ucf:0;jmr:0;auth:0;dest:I;ENG:(910001)(944506478)(944626604)(920097)(930097)(140003); |
MIME-Version | 1.0 |
X-Ms-Exchange-Organization-Expirationstarttime | 10 Jan 2025 18:32:15.8601 (UTC) |
X-Ms-Exchange-Organization-Expirationstarttimereason | OriginalSubmit |
X-Ms-Exchange-Organization-Expirationinterval | 1:00:00:00.0000000 |
X-Ms-Exchange-Organization-Expirationintervalreason | OriginalSubmit |
X-Ms-Exchange-Organization-Network-Message-Id | 6777ff48-58c1-4601-223a-08dd31a51b95 |
X-Eoptenantattributedmessage | 3da2778b-8fac-4742-832d-d1d32c7936f0:0 |
X-Ms-Exchange-Organization-Messagedirectionality | Incoming |
X-Ms-Exchange-Transport-Crosstenantheaderspromoted | SJ5PEPF000001D4.namprd05.prod.outlook.com |
X-Ms-Publictraffictype | |
X-Ms-Exchange-Organization-Authsource | SJ5PEPF000001D4.namprd05.prod.outlook.com |
X-Ms-Exchange-Organization-Authas | Anonymous |
X-Ms-Exchange-Atpmessageproperties | SA|SL |
X-Ms-Exchange-Organization-Scl | 1 |
X-Microsoft-Antispam | BCL:0;ARA:13230040|4073199012|5073199012|35042699022|4076899003|8096899003; |
X-Forefront-Antispam-Report | CIP:40.107.215.67;CTRY:SG;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:APC01-SG2-obe.outbound.protection.outlook.com;PTR:mail-sg2apc01on2067.outbound.protection.outlook.com;CAT:NONE;SFS:(13230040)(4073199012)(5073199012)(35042699022)(4076899003)(8096899003);DIR:INB; |
X-Auto-Response-Suppress | DR, RN, NRN, OOF, AutoReply |
X-Ms-Exchange-Crosstenant-Originalarrivaltime | 10 Jan 2025 18:32:15.2664 (UTC) |
X-Ms-Exchange-Crosstenant-Network-Message-Id | 6777ff48-58c1-4601-223a-08dd31a51b95 |
X-Ms-Exchange-Crosstenant-Id | 3da2778b-8fac-4742-832d-d1d32c7936f0 |
X-Ms-Exchange-Crosstenant-Originalattributedtenantconnectingip | TenantId=834fab4d-d063-416f-be32-2c02cf73e520;Ip=[185.246.85.91];Helo=[miroza.it] |
X-Ms-Exchange-Crosstenant-Authsource | SJ5PEPF000001D4.namprd05.prod.outlook.com |
X-Ms-Exchange-Crosstenant-Authas | Anonymous |
X-Ms-Exchange-Crosstenant-Fromentityheader | Internet |
X-Microsoft-Antispam-Message-Info | sT8yr6VtZhH1jEUMitpNKJzMEZyjc9UM87FMa9hkRE2yJZ8RDi8EMdR0fKwwy3EFfTky+ta0isiN6MK2k8Ku0RNxmB+XqPsYPXzA0K6X74Gq74bDz+gZvo9/UKA5KkSs7lfcoZbDXFijAWgrRrQZsZMqcBbLxxA/7QRjs6AWozPYfdl99JvNOyJww1jdIVOTJFeOG40kTVDGN3cQExtGgcFHPTJAdSwuypKKrrCbAoJvAEzUx1pEhvgAONgWFp1b6iSCOq4x4sr903dZGmbsiTMjgtGNqmuuszcl2RO01sWZx3vRZdmRUnXIENXY3ZkCrZbfj/B2Ri3wUkLLPetQsvg0MQR1TQYuoD3+tGpZugcsxpluEM4GIiahYBwnlq6EaXyHHYrwCwl+6vPDBRmGtoJxPqAcKHuA4XWKtweynGReidV35hNIeY9bHMDKo/2aaShOxeq9HRYud7oGJJ4lhJ6MEzSaJjYSh6RWM9oSNt8ZEgMRCxB8TGaiHvXAll6BmaJYJVDjdNGtw68sf55lH/l/ohkMoKqyUTKBHkm2OLrFQP/uqibC0cUDWLLcNlfQFaXDQwfaszPfSCQV4cg0lGTkMWss7lW+cA9PMPeAC6DirELLArgAA7npYqtg+AwcAnlMlJ66oRAE6vS7fkk6US0QpZpe3gymYc5nv0RUnU1S6nx/vGM8E2vDtp0XhodqyyQgc+YgXH+PshHohHPAHJVYxxWPjFI069+5d+sDAuvddZTMIi8OlG7qkX5a/Iz0+Iz9mYWBmeCNFmj7De2NuY/xqwv8Cx3de7yD15W708V/NdC1PfvqWiub8v8lQ/7P9OCTMVIygvgv4/hDqouKP/8BAuso/aOqnjEoAaOFPhgbA6VLN3VY1xRq6mUbPbNfiIbqq5nR6HDXc2G+/+QgYnMAo3xbO7HdyuQW6hAYDTDrfJNIYWnp7GpshTROmU4xKfrmFmcVWq23wEQIEh3JXuUpOYpvgbAWQBPZXSqVlOf/IZgLEQJ3TlCWl43L4r6rT4YypwKNp00RWqvvC2OouZlK2sNEltQtPXD/3YatWTUJoIFvgh9kXL8fvbGObiBkM5eyXBhk4XX/S0Bl7EUQSAZO7GxdEU26F9HgSfemqWFGXyyXD8uLI2ep+5QbEm9TwqqwqJskQoZXXp/pZq7qISgw62/SWoYe/mIAVlb5Ns3h2pHoEENhltsEOpRxgLmqu5Eo5vm4EmFKBG8+5IdBE40ArXaAffD3tw0hsTVLCjKmaquc98+9LFVTJerLan2cfGXDnHktC/6vLpmzwDIGR6nxo9IeyppcmMTRLpi6ClddbHXe4rsKYZTscWQ6OydRzsSrhoNowYG8G9wf83c+8QJPL4xM51m5qk52mL5/PliCSAw7XKpP5Jn7+S3MaebRIG9ewTiM8GWQYGNpGIVbGhkWMXv55YvV5fUS/jlmfc877j+z/H3H0U64MdKtqKTqyGUif5Rp9moxlOPP088pu58EaJJESe1Ld8yMESsBUk47nhqWoqDWmQFJIi5GWdo0Wlp2CCY2fIAkhP9oGofhtvb5QK2UJy1z1vVcToCeYz15a0ij5tH4E1siV2ae1Fiiku77Yw0P7Ui8jrf2dGfh7SUcs7+2POuTjN7UWmwAXSWUmRUg86x4JuR8pzCVM6vunOIOJdBSBruw+iRZjAjwma1M/jhdG8vPDqAzvaXvyBBDN95YuVZ1zV+O8+PKsYTugS4QbVoscz5DxovOt1Un8QloStU+9JgXZikBj8uCpx2osvgb37P0pL9/U4qqvgQxEG64gOJodIdsp610fx+iyOQXTHbJXGdJmrm/MmVzy+feiuBVJn1BItw44VMWlrsaB1Hgv9GZPNUf/edeODMGct3UATTaDjl6+vLymsSv8r1RUlZ+An0KTcuZPhU21EeM8DPkWAZaWJQwQYAOnfAlG30zM7Q+7gJTB659lJcf6zi3Y3dY/89DhGtVrY4QxlHgeJy5p73EnauywiRwD+MrHznfQE/oUr9tFPhtTpSfmqLg839rfNc6EZLpEnqggs+eIuAAF/cVXZ6wl4euIRV4QO15873XfV5knJ7px5pkillPuAfZ1fZdFpRzkv1weaRD3U42zdd0oFvvG0W57H0reTEus/IxBuL1YONADx2AVvI= |
Content-Transfer-Encoding | 7bit |
Icon Hash: | 46070c0a8e0c67d6 |