Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
Read_ Statement.eml

Overview

General Information

Sample name:Read_ Statement.eml
Analysis ID:1520613
MD5:d913c22b4dce731e1cd11b9845086244
SHA1:f13468f3f2d34e34636aa11ff37ffd6e8fa38225
SHA256:18e76a6e3004e92dec27187b944ea5302368a1756e1812926b4bdebb09fde1e6
Infos:

Detection

Score:3
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Creates a window with clipboard capturing capabilities
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
Queries the volume information (name, serial number etc) of a device
Sigma detected: Office Autorun Keys Modification
Sigma detected: Office Macro File Download
Sigma detected: Suspicious Office Outbound Connections

Classification

  • System is w10x64_ra
  • OUTLOOK.EXE (PID: 6908 cmdline: "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" /eml "C:\Users\user\Desktop\Read_ Statement.eml" MD5: 91A5292942864110ED734005B7E005C0)
    • ai.exe (PID: 6276 cmdline: "C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe" "9FED77D2-8569-46B4-A9E6-C030199CA153" "753032D4-7DA5-4A69-AB42-A122198C7FE5" "6908" "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" "WordCombinedFloatieLreOnline.onnx" MD5: EC652BEDD90E089D9406AFED89A8A8BD)
  • OUTLOOK.EXE (PID: 3284 cmdline: "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" /eml "C:\Users\user\Desktop\RE_ Overdue Invoice ___IMPORTANT___.eml" MD5: 91A5292942864110ED734005B7E005C0)
    • ai.exe (PID: 1904 cmdline: "C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe" "6BBBA20A-876A-4E8A-8AD8-D424E4FB21D8" "DB3CCE73-E394-4AB6-9B07-DCD2D719738B" "3284" "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" "WordCombinedFloatieLreOnline.onnx" MD5: EC652BEDD90E089D9406AFED89A8A8BD)
  • cleanup
No configs have been found
No yara matches
Source: Registry Key setAuthor: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): Data: Details: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 , EventID: 13, EventType: SetValue, Image: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE, ProcessId: 6908, TargetObject: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Outlook\Addins\OneNote.OutlookAddin\1
Source: File createdAuthor: Nasreddine Bencherchali (Nextron Systems): Data: EventID: 11, Image: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE, ProcessId: 6908, TargetFilename: C:\Users\user\AppData\Roaming\Microsoft\Templates\~$rmalEmail.dotm
Source: Network ConnectionAuthor: X__Junior (Nextron Systems): Data: DestinationIp: 192.168.2.16, DestinationIsIpv6: false, DestinationPort: 49715, EventID: 3, Image: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE, Initiated: true, ProcessId: 3284, Protocol: tcp, SourceIp: 13.107.246.60, SourceIsIpv6: false, SourcePort: 443
Source: File createdAuthor: Nasreddine Bencherchali (Nextron Systems): Data: EventID: 11, Image: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE, ProcessId: 6908, TargetFilename: C:\Users\user\AppData\Roaming\Microsoft\Templates\~$rmalEmail.dotm
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 13.107.246.60:443 -> 192.168.2.16:49715 version: TLS 1.2
Source: Joe Sandbox ViewIP Address: 13.107.246.60 13.107.246.60
Source: Joe Sandbox ViewJA3 fingerprint: a0e9f5d64349fb13191bc781f81f42e1
Source: global trafficHTTP traffic detected: GET /rules/outlook.exe-Production-v19.bundle HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; Microsoft Outlook 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: global trafficHTTP traffic detected: GET /rules/rule120603v8s19.xml HTTP/1.1Connection: Keep-AliveAccept-Encoding: gzipUser-Agent: Microsoft Office/16.0 (Windows NT 10.0; Microsoft Outlook 16.0.16827; Pro)Host: otelrules.azureedge.net
Source: ~WRS{D93139DE-93B2-45DC-9CC9-9939C08D31C6}.tmp.13.drString found in binary or memory: HYPERLINK "https://protect.checkpoint.com/v2/___https:/www.youtube.com/user/combilift/videos___.YzJlOmNvbWJpbGlmdDpjOm86MTFiNjkzMzAzODZjMmE2ZDhkNTg5MzNjM2FiNjRkZTM6Njo1OTBiOmY2OTE0OTdkZGJlMDA1Nzk5MDA0ZGVmMjk0ODRiYTRjZjU4NzEzNWZiMTFmOGVlMWFhZDkzNjUxZGQ3NjRkN2U6aDpUOk4" \o "Protected by Check Point: https://www.youtube.com/user/combilift/videos" \t "_blank" equals www.youtube.com (Youtube)
Source: ~WRS{D93139DE-93B2-45DC-9CC9-9939C08D31C6}.tmp.13.drString found in binary or memory: HYPERLINK "https://protect.checkpoint.com/v2/___www.linkedin.com/company/combilift-ltd___.YzJlOmNvbWJpbGlmdDpjOm86MTFiNjkzMzAzODZjMmE2ZDhkNTg5MzNjM2FiNjRkZTM6Njo3ODE1OmFlZWU1NjkyZTczMmY3ZDRjM2IzY2MzYjEwNDEwMjkxZjI1NTY4NzA3MWFhMTE2OGYyMTYxNzNmZDY4Y2MwYjU6aDpUOk4" \o "Protected by Check Point: www.linkedin.com/company/combilift-ltd" \t "_blank" equals www.linkedin.com (Linkedin)
Source: ~WRS{D93139DE-93B2-45DC-9CC9-9939C08D31C6}.tmp.13.drString found in binary or memory: HYPERLINK "https://www.youtube.com/user/combilift/videos" \t "_blank" equals www.youtube.com (Youtube)
Source: ~WRS{D93139DE-93B2-45DC-9CC9-9939C08D31C6}.tmp.13.drString found in binary or memory: HYPERLINK "www.linkedin.com/company/combilift-ltd" \t "_blank" equals www.linkedin.com (Linkedin)
Source: ~WRS{D93139DE-93B2-45DC-9CC9-9939C08D31C6}.tmp.13.drString found in binary or memory: HYPERLINK "https://protect.checkpoint.com/v2/___https:/www.facebook.com/CombiliftOfficial___.YzJlOmNvbWJpbGlmdDpjOm86MTFiNjkzMzAzODZjMmE2ZDhkNTg5MzNjM2FiNjRkZTM6NjpjOGIxOjk0MTEwNGY1ZTQ5ZWI3ODA2NWViZGI1OWZmMzM4MjExMWM4ZTBlMWQ5ZTNmYWM3NzMwMTE1ZWFhMzJjNmQ2YjA6aDpUOk4" \o "Protected by Check Point: https://www.facebook.com/CombiliftOfficial" \t "_blank" equals www.facebook.com (Facebook)
Source: ~WRS{D93139DE-93B2-45DC-9CC9-9939C08D31C6}.tmp.13.drString found in binary or memory: HYPERLINK "https://protect.checkpoint.com/v2/___https:/www.facebook.com/CombiliftOfficial___.YzJlOmNvbWJpbGlmdDpjOm86YTBjMTg0NzBjYWUwMGVhOWM1ZmRhNzExYTc5YmUxYmE6NjplNGRiOjg5ZmEzZjAzZDlkNzIxNTk0MjA2N2Q0Mjk5ZTY2MzVhMzcwYWVhNzc5MzQ5NjYxMGI0ODdlZTA5NjkwZDhjMmY6aDpUOk4" \o "Protected by Check Point: https://www.facebook.com/CombiliftOfficial" \t "_blank" equals www.facebook.com (Facebook)
Source: ~WRS{D93139DE-93B2-45DC-9CC9-9939C08D31C6}.tmp.13.drString found in binary or memory: HYPERLINK "https://protect.checkpoint.com/v2/___https:/www.youtube.com/user/combilift/videos___.YzJlOmNvbWJpbGlmdDpjOm86YTBjMTg0NzBjYWUwMGVhOWM1ZmRhNzExYTc5YmUxYmE6Njo4ZGFmOjNkNTkzZjY1NTBkYmVjYzRlMGY5ZDc1NWZmMDhjOTI3NmIwZDkzOGYyNzk3MzU4NTc2ODMwNDA0YmZhYzNjMmE6aDpUOk4" \o "Protected by Check Point: https://www.youtube.com/user/combilift/videos" \t "_blank" equals www.youtube.com (Youtube)
Source: ~WRS{D93139DE-93B2-45DC-9CC9-9939C08D31C6}.tmp.13.drString found in binary or memory: HYPERLINK "https://protect.checkpoint.com/v2/___www.linkedin.com/company/combilift-ltd___.YzJlOmNvbWJpbGlmdDpjOm86YTBjMTg0NzBjYWUwMGVhOWM1ZmRhNzExYTc5YmUxYmE6NjphMWIzOjY3ZGUzYWY4YmFiMTg1M2M4NGRjOGU4MjhiOWMzMTQzZTBlNWI0NmFkYzMwYjkzNDk0MDg1NmZjNTY2NTA0MWY6aDpUOk4" \o "Protected by Check Point: www.linkedin.com/company/combilift-ltd" \t "_blank" equals www.linkedin.com (Linkedin)
Source: ~WRS{D93139DE-93B2-45DC-9CC9-9939C08D31C6}.tmp.13.drString found in binary or memory: HYPERLINK "https://www.facebook.com/CombiliftOfficial" \t "_blank" equals www.facebook.com (Facebook)
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: http://b.c2r.ts.cdn.office.net/pr
Source: ~WRS{D93139DE-93B2-45DC-9CC9-9939C08D31C6}.tmp.13.drString found in binary or memory: http://combilift.net/emails2020/Facebook_Image.png
Source: ~WRS{D93139DE-93B2-45DC-9CC9-9939C08D31C6}.tmp.13.drString found in binary or memory: http://combilift.net/emails2020/ISO-AEO.png
Source: ~WRS{D93139DE-93B2-45DC-9CC9-9939C08D31C6}.tmp.13.drString found in binary or memory: http://combilift.net/emails2020/Instagram.jpg
Source: ~WRS{D93139DE-93B2-45DC-9CC9-9939C08D31C6}.tmp.13.drString found in binary or memory: http://combilift.net/emails2020/LinkedIn_Image.png
Source: ~WRS{D93139DE-93B2-45DC-9CC9-9939C08D31C6}.tmp.13.drString found in binary or memory: http://combilift.net/emails2020/YouTube.png
Source: ~WRS{D93139DE-93B2-45DC-9CC9-9939C08D31C6}.tmp.13.drString found in binary or memory: http://combilift.net/emails2020/twitter-icon.png
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: http://f.c2r.ts.cdn.office.net/pr
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: http://olkflt.edog.officeapps.live.com/olkflt/outlookflighting.svc/api/glides
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: http://weather.service.msn.com/data.aspx
Source: ~WRS{D93139DE-93B2-45DC-9CC9-9939C08D31C6}.tmp.13.drString found in binary or memory: http://www.cbequipment.com
Source: ~WRS{D93139DE-93B2-45DC-9CC9-9939C08D31C6}.tmp.13.drString found in binary or memory: http://www.combilift.com
Source: ~WRS{D93139DE-93B2-45DC-9CC9-9939C08D31C6}.tmp.13.drString found in binary or memory: http://www.combilift.com/
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://addinsinstallation.store.office.com/app/acquisitionlogging
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://addinsinstallation.store.office.com/app/download
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://addinsinstallation.store.office.com/appinstall/authenticated
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://addinsinstallation.store.office.com/appinstall/preinstalled
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://addinsinstallation.store.office.com/appinstall/unauthenticated
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://addinsinstallation.store.office.com/orgid/appinstall/authenticated
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://addinslicensing.store.office.com/apps/remove
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://addinslicensing.store.office.com/commerce/query
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://addinslicensing.store.office.com/entitlement/query
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://addinslicensing.store.office.com/orgid/apps/remove
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://addinslicensing.store.office.com/orgid/entitlement/query
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://analysis.windows.net/powerbi/api
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://apc.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://api.aadrm.com
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://api.aadrm.com/
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://api.addins.omex.office.net/api/addins/search
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://api.addins.omex.office.net/appinfo/query
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://api.addins.omex.office.net/appstate/query
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://api.addins.store.office.com/addinstemplate
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://api.addins.store.office.com/app/query
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://api.addins.store.officeppe.com/addinstemplate
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://api.cortana.ai
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://api.diagnostics.office.com
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://api.diagnosticssdf.office.com
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://api.diagnosticssdf.office.com/v2/feedback
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://api.diagnosticssdf.office.com/v2/file
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://api.microsoftstream.com
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://api.microsoftstream.com/api/
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://api.office.net
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://api.officescripts.microsoftusercontent.com/api
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://api.onedrive.com
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://api.powerbi.com/v1.0/myorg/datasets
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://api.powerbi.com/v1.0/myorg/groups
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://api.powerbi.com/v1.0/myorg/imports
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://api.scheduler.
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://apis.live.net/v5.0/
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://apis.mobile.m365.svc.cloud.microsoft
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://app.powerbi.com
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://arc.msn.com/v4/api/selection
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://asgsmsproxyapi.azurewebsites.net/
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://augloop.office.com
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://augloop.office.com/v2
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://augloop.office.com;https://augloop-int.officeppe.com;https://augloop-dogfood.officeppe.com;h
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://autodiscover-s.outlook.com/
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://autodiscover-s.outlook.com/autodiscover/autodiscover.xml
Source: outlook.exe_Rules.xml.13.drString found in binary or memory: https://autodiscover.com.br/Autodiscover/Autodiscover.xml
Source: outlook.exe_Rules.xml.13.drString found in binary or memory: https://autodiscover.com.br/autodiscover/autodiscover.xml
Source: outlook.exe_Rules.xml.13.drString found in binary or memory: https://autodiscover.com.cn/Autodiscover/Autodiscover.xml
Source: outlook.exe_Rules.xml.13.drString found in binary or memory: https://autodiscover.com.cn/autodiscover/autodiscover.xml
Source: outlook.exe_Rules.xml.13.drString found in binary or memory: https://autodiscover.com/Autodiscover/Autodiscover.xml
Source: outlook.exe_Rules.xml.13.drString found in binary or memory: https://autodiscover.com/autodiscover/autodiscover.xml
Source: outlook.exe_Rules.xml.13.drString found in binary or memory: https://autodiscover.es/Autodiscover/Autodiscover.xml
Source: outlook.exe_Rules.xml.13.drString found in binary or memory: https://autodiscover.es/autodiscover/autodiscover.xml
Source: outlook.exe_Rules.xml.13.drString found in binary or memory: https://autodiscover.fr/Autodiscover/Autodiscover.xml
Source: outlook.exe_Rules.xml.13.drString found in binary or memory: https://autodiscover.fr/autodiscover/autodiscover.xml
Source: outlook.exe_Rules.xml.13.drString found in binary or memory: https://autodiscover.in/Autodiscover/Autodiscover.xml
Source: outlook.exe_Rules.xml.13.drString found in binary or memory: https://autodiscover.in/autodiscover/autodiscover.xml
Source: outlook.exe_Rules.xml.13.drString found in binary or memory: https://autodiscover.it/Autodiscover/Autodiscover.xml
Source: outlook.exe_Rules.xml.13.drString found in binary or memory: https://autodiscover.it/autodiscover/autodiscover.xml
Source: outlook.exe_Rules.xml.13.drString found in binary or memory: https://autodiscover.online/Autodiscover/Autodiscover.xml
Source: outlook.exe_Rules.xml.13.drString found in binary or memory: https://autodiscover.online/autodiscover/autodiscover.xml
Source: outlook.exe_Rules.xml.13.drString found in binary or memory: https://autodiscover.sg/Autodiscover/Autodiscover.xml
Source: outlook.exe_Rules.xml.13.drString found in binary or memory: https://autodiscover.sg/autodiscover/autodiscover.xml
Source: outlook.exe_Rules.xml.13.drString found in binary or memory: https://autodiscover.uk/Autodiscover/Autodiscover.xml
Source: outlook.exe_Rules.xml.13.drString found in binary or memory: https://autodiscover.uk/autodiscover/autodiscover.xml
Source: outlook.exe_Rules.xml.13.drString found in binary or memory: https://autodiscover.xyz/Autodiscover/Autodiscover.xml
Source: outlook.exe_Rules.xml.13.drString found in binary or memory: https://autodiscover.xyz/autodiscover/autodiscover.xml
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://canary.designerapp.
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://cdn.designerapp.osi.office.net
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://cdn.designerapp.osi.office.net/designer-mobile
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://cdn.designerapp.osi.office.net/designerapp/fonts
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://cdn.designerapp.osi.office.net/designerapp/mobile-assets
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://cdn.designerapp.osi.office.net/designerapp/mobile-dynamic-strings
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://cdn.designerapp.osi.office.net/designerapp/mobile-home-screen
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://cdn.entity.
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://cdn.hubblecontent.osi.office.net/
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://cdn.int.designerapp.osi.office.net/fonts
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://client-office365-tas.msedge.net/ab
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://clients.config.office.net
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://clients.config.office.net/
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://clients.config.office.net/c2r/v1.0/DeltaAdvisory
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://clients.config.office.net/c2r/v1.0/InteractiveInstallation
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/android/policies
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/ios
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/mac
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://clients.config.office.net/user/v1.0/tenantassociationkey
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://cloudfiles.onenote.com/upload.aspx
Source: ~WRS{D93139DE-93B2-45DC-9CC9-9939C08D31C6}.tmp.13.drString found in binary or memory: https://combilift.com/
Source: ~WRS{D93139DE-93B2-45DC-9CC9-9939C08D31C6}.tmp.13.drString found in binary or memory: https://combilift.net/emails2020/Best_Managed_Companies_2023-E-signature.jpg
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://config.edge.skype.com/config/v1/Office
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://config.edge.skype.com/config/v2/Office
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://consent.config.office.com/consentcheckin/v1.0/consents
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://consent.config.office.com/consentweb/v1.0/consents
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://cortana.ai
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://cortana.ai/api
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://cr.office.com
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://d.docs.live.net
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://dataservice.o365filtering.com
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://dataservice.o365filtering.com/
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://dataservice.o365filtering.com/PolicySync/PolicySync.svc/SyncFile
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://dataservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPolicies
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://designerapp.azurewebsites.net
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://dev.cortana.ai
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://dev0-api.acompli.net/autodetect
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://devnull.onenote.com
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://directory.services.
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://ecs.office.com
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://ecs.office.com/config/v1/Designer
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://ecs.office.com/config/v2/Office
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://edge.skype.com/registrar/prod
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://edge.skype.com/rps
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://enrichment.osi.office.net/
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/Refresh/v1
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/Resolve/v1
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/Search/v1
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/StockHistory/v1
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/ipcheck/v1
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/v2.1601652342626
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/web/Metadata/
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/web/Metadata/metadata.json
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/web/view/desktop/main.cshtml
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://enrichment.osi.office.net/OfficeEnrichment/web/view/web/main.cshtml
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://entitlement.diagnostics.office.com
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://entitlement.diagnosticssdf.office.com
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://eur.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://excel.uservoice.com/forums/304936-excel-for-mobile-devices-tablets-phones-android
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://fpastorage.cdn.office.net/%s
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://fpastorage.cdn.office.net/firstpartyapp/addins.xml
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://globaldisco.crm.dynamics.com
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://graph.ppe.windows.net
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://graph.ppe.windows.net/
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://graph.windows.net
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://graph.windows.net/
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/api/pivots/
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/api/telemetry
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/browse?cp=remix3d
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/browse?secureurl=1
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=icons
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=stockimages
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsoftcontent?initpivot=stockvideos
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/microsofticon?
Source: ~WRS{D93139DE-93B2-45DC-9CC9-9939C08D31C6}.tmp.13.drString found in binary or memory: https://i.postimg.cc/ZYxtszyz/C-B-Operations-Registered-Logo-CMYK-Alt-Black.jpg
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://ic3.teams.office.com
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://incidents.diagnostics.office.com
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://incidents.diagnosticssdf.office.com
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://inclient.store.office.com/gyro/client
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://inclient.store.office.com/gyro/clientstore
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/hosted?host=office&adlt=strict&hostType=Immersive
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Bing
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=ClipArt
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Facebook
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Flickr
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=OneDrive
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://insertmedia.bing.office.net/odc/insertmedia
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://invites.office.com/
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://learningtools.onenote.com/learningtoolsapi/v2.0/GetFreeformSpeech
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://learningtools.onenote.com/learningtoolsapi/v2.0/Getvoices
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://lifecycle.office.com
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://login.microsoftonline.com
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://login.microsoftonline.com/
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://login.microsoftonline.com/organizations
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://login.windows-ppe.net/common/oauth2/authorize
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://login.windows.local
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://login.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/oauth2/authorize
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://login.windows.net/common/oauth2/authorize
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://loki.delve.office.com/api/v1/configuration/officewin32/
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://lookup.onenote.com/lookup/geolocation/v1
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://make.powerautomate.com
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://management.azure.com
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://management.azure.com/
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://messagebroker.mobile.m365.svc.cloud.microsoft
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://messaging.action.office.com/
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://messaging.action.office.com/setcampaignaction
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://messaging.action.office.com/setuseraction16
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://messaging.engagement.office.com/
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://messaging.engagement.office.com/campaignmetadataaggregator
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://messaging.lifecycle.office.com/
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://messaging.lifecycle.office.com/getcustommessage16
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://messaging.office.com/
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://metadata.templates.cdn.office.net/client/log
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://mss.office.com
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://my.microsoftpersonalcontent.com
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://ncus.contentsync.
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://ncus.pagecontentsync.
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://o365auditrealtimeingestion.manage.office.com/api/userauditrecord
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://ocos-office365-s2s.msedge.net/ab
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://odc.officeapps.live.com/odc/stat/images/OneDriveUpsell.png
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://odc.officeapps.live.com/odc/xml?resource=OneDriveSignUpUpsell
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://odc.officeapps.live.com/odc/xml?resource=OneDriveSyncClientUpsell
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://ods-diagnostics-ppe.trafficmanager.net
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://ofcrecsvcapi-int.azurewebsites.net/
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://officeapps.live.com
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://officeci.azurewebsites.net/api/
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://officemobile.uservoice.com/forums/929800-office-app-ios-and-ipad-asks
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://officepyservice.office.net/
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://officepyservice.office.net/service.functionality
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://officesetup.getmicrosoftkey.com
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://ogma.osi.office.net/TradukoApi/api/v1.0/
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officeentities
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officeentitiesupdated
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officesharedentities
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://omex.cdn.office.net/addinclassifier/officesharedentitiesupdated
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://onedrive.live.com
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://onedrive.live.com/about/download/?windows10SyncClientInstalled=false
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://onedrive.live.com/embed?
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://otelrules.azureedge.net
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://otelrules.svc.static.microsoft
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://outlook.office.com
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://outlook.office.com/
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://outlook.office.com/autosuggest/api/v1/init?cvid=
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://outlook.office365.com
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://outlook.office365.com/
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://outlook.office365.com/api/v1.0/me/Activities
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://outlook.office365.com/autodiscover/autodiscover.json
Source: outlook.exe_Rules.xml.13.dr, rule11730v0.xml.13.drString found in binary or memory: https://outlook.office365.com/autosuggest"
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://outlook.office365.com/connectors
Source: outlook.exe_Rules.xml.13.dr, rule11730v0.xml.13.drString found in binary or memory: https://outlook.office365.com/search"
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://ovisualuiapp.azurewebsites.net/pbiagave/
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://pages.store.office.com/appshome.aspx?productgroup=Outlook
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://pages.store.office.com/review/query
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://pages.store.office.com/webapplandingpage.aspx
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://partnerservices.getmicrosoftkey.com/PartnerProvisioning.svc/v1/subscriptions
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.json
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://pf.directory.live.com/profile/mine/WLX.Profiles.IC.json
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://portal.office.com/account/?ref=ClientMeControl
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://posarprodcssservice.accesscontrol.windows.net/v2/OAuth2-13
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://powerlift-frontdesk.acompli.net
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://powerlift.acompli.net
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://powerpoint.uservoice.com/forums/288952-powerpoint-for-ipad-iphone-ios
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://prod-global-autodetect.acompli.net/autodetect
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://prod.mds.office.com/mds/api/v1.0/clientmodeldirectory
Source: ~WRS{D93139DE-93B2-45DC-9CC9-9939C08D31C6}.tmp.13.drString found in binary or memory: https://protect.checkpoint.com/v2/___http:/www.cbequipment.com___.YzJlOmNvbWJpbGlmdDpjOm86YTBjMTg0Nz
Source: ~WRS{D93139DE-93B2-45DC-9CC9-9939C08D31C6}.tmp.13.drString found in binary or memory: https://protect.checkpoint.com/v2/___http:/www.combilift.com/___.YzJlOmNvbWJpbGlmdDpjOm86MTFiNjkzMzA
Source: ~WRS{D93139DE-93B2-45DC-9CC9-9939C08D31C6}.tmp.13.drString found in binary or memory: https://protect.checkpoint.com/v2/___http:/www.combilift.com___.YzJlOmNvbWJpbGlmdDpjOm86YTBjMTg0NzBj
Source: ~WRS{D93139DE-93B2-45DC-9CC9-9939C08D31C6}.tmp.13.drString found in binary or memory: https://protect.checkpoint.com/v2/___https:/combilift.com/___.YzJlOmNvbWJpbGlmdDpjOm86MTFiNjkzMzAzOD
Source: ~WRS{D93139DE-93B2-45DC-9CC9-9939C08D31C6}.tmp.13.drString found in binary or memory: https://protect.checkpoint.com/v2/___https:/combilift.com/___.YzJlOmNvbWJpbGlmdDpjOm86YTBjMTg0NzBjYW
Source: ~WRS{D93139DE-93B2-45DC-9CC9-9939C08D31C6}.tmp.13.drString found in binary or memory: https://protect.checkpoint.com/v2/___https:/twitter.com/Combilift___.YzJlOmNvbWJpbGlmdDpjOm86MTFiNjk
Source: ~WRS{D93139DE-93B2-45DC-9CC9-9939C08D31C6}.tmp.13.drString found in binary or memory: https://protect.checkpoint.com/v2/___https:/twitter.com/Combilift___.YzJlOmNvbWJpbGlmdDpjOm86YTBjMTg
Source: ~WRS{D93139DE-93B2-45DC-9CC9-9939C08D31C6}.tmp.13.drString found in binary or memory: https://protect.checkpoint.com/v2/___https:/www.cbequipment.com/___.YzJlOmNvbWJpbGlmdDpjOm86YTBjMTg0
Source: ~WRS{D93139DE-93B2-45DC-9CC9-9939C08D31C6}.tmp.13.drString found in binary or memory: https://protect.checkpoint.com/v2/___https:/www.instagram.com/combilift_official/___.YzJlOmNvbWJpbGl
Source: ~WRS{D93139DE-93B2-45DC-9CC9-9939C08D31C6}.tmp.13.drString found in binary or memory: https://protect.checkpoint.com/v2/___https:/www.youtube.com/user/combilift/videos___.YzJlOmNvbWJpbGl
Source: ~WRS{D93139DE-93B2-45DC-9CC9-9939C08D31C6}.tmp.13.drString found in binary or memory: https://protect.checkpoint.com/v2/___www.linkedin.com/company/combilift-ltd___.YzJlOmNvbWJpbGlmdDpjO
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://pushchannel.1drv.ms
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://r4.res.office365.com/footprintconfig/v1.7/scripts/fpconfig.json
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://res.cdn.office.net
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://res.cdn.office.net/mro1cdnstorage/fonts/prod/4.40
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://res.cdn.office.net/polymer/models
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://res.getmicrosoftkey.com/api/redemptionevents
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://rpsticket.partnerservices.getmicrosoftkey.com
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://safelinks.protection.outlook.com/api/GetPolicy
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://service.officepy.microsoftusercontent.com/
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://service.powerapps.com
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://settings.outlook.com
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://shell.suite.office.com:1443
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://skyapi.live.net/Activity/
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://sr.outlook.office.net/ws/speech/recognize/assistant/work
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://staging.cortana.ai
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://storage.live.com/clientlogs/uploadlocation
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://store.office.cn/addinstemplate
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://store.office.de/addinstemplate
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://substrate.office.com
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://substrate.office.com/Notes-Internal.ReadWrite
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://substrate.office.com/search/api/v1/SearchHistory
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://substrate.office.com/search/api/v2/init
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://tasks.office.com
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://templatesmetadata.office.net/
Source: ~WRS{D93139DE-93B2-45DC-9CC9-9939C08D31C6}.tmp.13.drString found in binary or memory: https://twitter.com/Combilift
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://uci.cdn.office.net/mirrored/smartlookup/current/
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://uci.officeapps.live.com/OfficeInsights/web/views/insights.desktop.html
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://uci.officeapps.live.com/OfficeInsights/web/views/insights.immersive.html
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://useraudit.o365auditrealtimeingestion.manage.office.com
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://visio.uservoice.com/forums/368202-visio-on-devices
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://web.microsoftstream.com/video/
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://webshell.suite.office.com
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://word-edit.officeapps.live.com/we/rrdiscovery.ashx
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://word.uservoice.com/forums/304948-word-for-ipad-iphone-ios
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://wus2.contentsync.
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://wus2.pagecontentsync.
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://www.bingapis.com/api/v7/urlpreview/search?appid=E93048236FE27D972F67C5AF722136866DF65FA2
Source: ~WRS{D93139DE-93B2-45DC-9CC9-9939C08D31C6}.tmp.13.drString found in binary or memory: https://www.cbequipment.com/
Source: ~WRS{D93139DE-93B2-45DC-9CC9-9939C08D31C6}.tmp.13.drString found in binary or memory: https://www.instagram.com/combilift_official/
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://www.odwebp.svc.ms
Source: 06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drString found in binary or memory: https://www.yammer.com
Source: ~WRS{D93139DE-93B2-45DC-9CC9-9939C08D31C6}.tmp.13.drString found in binary or memory: https://www.youtube.com/user/combilift/videos
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 443
Source: unknownHTTPS traffic detected: 13.107.246.60:443 -> 192.168.2.16:49715 version: TLS 1.2
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEWindow created: window name: CLIPBRDWNDCLASSJump to behavior
Source: classification engineClassification label: clean3.winEML@6/1049@0/1
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEFile created: C:\Users\user\Documents\Outlook Files\~Outlook Data File - NoEmail.pst.tmpJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEFile created: C:\Users\user\AppData\Local\Temp\Outlook Logging\OUTLOOK_16_0_16827_20130-20240927T1048440507-6908.etlJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEFile read: C:\Users\desktop.iniJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\CAJump to behavior
Source: unknownProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" /eml "C:\Users\user\Desktop\Read_ Statement.eml"
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe "C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe" "9FED77D2-8569-46B4-A9E6-C030199CA153" "753032D4-7DA5-4A69-AB42-A122198C7FE5" "6908" "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" "WordCombinedFloatieLreOnline.onnx"
Source: unknownProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" /eml "C:\Users\user\Desktop\RE_ Overdue Invoice ___IMPORTANT___.eml"
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe "C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe" "6BBBA20A-876A-4E8A-8AD8-D424E4FB21D8" "DB3CCE73-E394-4AB6-9B07-DCD2D719738B" "3284" "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" "WordCombinedFloatieLreOnline.onnx"
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe "C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe" "9FED77D2-8569-46B4-A9E6-C030199CA153" "753032D4-7DA5-4A69-AB42-A122198C7FE5" "6908" "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" "WordCombinedFloatieLreOnline.onnx"Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe "C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe" "6BBBA20A-876A-4E8A-8AD8-D424E4FB21D8" "DB3CCE73-E394-4AB6-9B07-DCD2D719738B" "3284" "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" "WordCombinedFloatieLreOnline.onnx"Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: c2r64.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: userenv.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: msasn1.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: cryptsp.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: rsaenh.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: cryptbase.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: gpapi.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: c2r64.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: userenv.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: msasn1.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: kernel.appcore.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: cryptsp.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: rsaenh.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: cryptbase.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: gpapi.dll
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{F959DBBB-3867-41F2-8E5F-3B8BEFAA81B3}\InprocServer32Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEWindow found: window name: SysTabControl32Jump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\CommonJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEFile Volume queried: C:\Windows\SysWOW64 FullSizeInformationJump to behavior
Source: outlook.exe_Rules.xml.13.drBinary or memory string: <V V="VMWare, Inc." T="W" />
Source: outlook.exe_Rules.xml.13.drBinary or memory string: <V V="QEMU" T="W" />
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information queried: ProcessInformationJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeQueries volume information: C:\Program Files (x86)\Microsoft Office\root\Office16\AI\WordCombinedFloatieLreOnline.onnx VolumeInformationJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeQueries volume information: C:\Program Files (x86)\Microsoft Office\root\Office16\AI\WordCombinedFloatieLreOnline.onnx VolumeInformation
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
DLL Side-Loading
1
Process Injection
1
Masquerading
OS Credential Dumping1
Security Software Discovery
Remote Services1
Clipboard Data
1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
DLL Side-Loading
1
Process Injection
LSASS Memory1
Process Discovery
Remote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
DLL Side-Loading
Security Account Manager1
File and Directory Discovery
SMB/Windows Admin SharesData from Network Shared Drive2
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDS14
System Information Discovery
Distributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 1520613 Sample: Read_ Statement.eml Startdate: 27/09/2024 Architecture: WINDOWS Score: 3 5 OUTLOOK.EXE 92 1004 2->5         started        8 OUTLOOK.EXE 96 132 2->8         started        dnsIp3 14 s-part-0032.t-0009.t-msedge.net 13.107.246.60, 443, 49715, 49718 MICROSOFT-CORP-MSN-AS-BLOCKUS United States 5->14 10 ai.exe 5->10         started        12 ai.exe 8->12         started        process4

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://shell.suite.office.com:14430%URL Reputationsafe
https://designerapp.azurewebsites.net0%URL Reputationsafe
https://autodiscover-s.outlook.com/0%URL Reputationsafe
https://useraudit.o365auditrealtimeingestion.manage.office.com0%URL Reputationsafe
https://outlook.office365.com/connectors0%URL Reputationsafe
https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Flickr0%URL Reputationsafe
https://cdn.entity.0%URL Reputationsafe
https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/0%URL Reputationsafe
https://rpsticket.partnerservices.getmicrosoftkey.com0%URL Reputationsafe
https://lookup.onenote.com/lookup/geolocation/v10%URL Reputationsafe
https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile0%URL Reputationsafe
https://api.aadrm.com/0%URL Reputationsafe
https://canary.designerapp.0%URL Reputationsafe
https://www.yammer.com0%URL Reputationsafe
https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPolicies0%URL Reputationsafe
https://insertmedia.bing.office.net/images/hosted?host=office&amp;adlt=strict&amp;hostType=Immersive0%URL Reputationsafe
https://cr.office.com0%URL Reputationsafe
https://messagebroker.mobile.m365.svc.cloud.microsoft0%URL Reputationsafe
https://edge.skype.com/registrar/prod0%URL Reputationsafe
https://res.getmicrosoftkey.com/api/redemptionevents0%URL Reputationsafe
https://tasks.office.com0%URL Reputationsafe
https://officeci.azurewebsites.net/api/0%URL Reputationsafe
https://store.office.cn/addinstemplate0%URL Reputationsafe
https://edge.skype.com/rps0%URL Reputationsafe
https://messaging.engagement.office.com/0%URL Reputationsafe
https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech0%URL Reputationsafe
https://www.odwebp.svc.ms0%URL Reputationsafe
https://api.powerbi.com/v1.0/myorg/groups0%URL Reputationsafe
https://web.microsoftstream.com/video/0%URL Reputationsafe
https://api.addins.store.officeppe.com/addinstemplate0%URL Reputationsafe
https://graph.windows.net0%URL Reputationsafe
https://consent.config.office.com/consentcheckin/v1.0/consents0%URL Reputationsafe
https://learningtools.onenote.com/learningtoolsapi/v2.0/Getvoices0%URL Reputationsafe
https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.json0%URL Reputationsafe
https://safelinks.protection.outlook.com/api/GetPolicy0%URL Reputationsafe
https://ncus.contentsync.0%URL Reputationsafe
https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/0%URL Reputationsafe
http://weather.service.msn.com/data.aspx0%URL Reputationsafe
https://word.uservoice.com/forums/304948-word-for-ipad-iphone-ios0%URL Reputationsafe
https://autodiscover-s.outlook.com/autodiscover/autodiscover.xml0%URL Reputationsafe
https://mss.office.com0%URL Reputationsafe
https://pushchannel.1drv.ms0%URL Reputationsafe
https://wus2.contentsync.0%URL Reputationsafe
https://clients.config.office.net/user/v1.0/ios0%URL Reputationsafe
https://api.addins.omex.office.net/api/addins/search0%URL Reputationsafe
https://outlook.office365.com/api/v1.0/me/Activities0%URL Reputationsafe
https://clients.config.office.net/user/v1.0/android/policies0%URL Reputationsafe
https://entitlement.diagnostics.office.com0%URL Reputationsafe
https://pf.directory.live.com/profile/mine/WLX.Profiles.IC.json0%URL Reputationsafe
https://login.microsoftonline.com0%URL Reputationsafe
https://substrate.office.com/search/api/v1/SearchHistory0%URL Reputationsafe
https://clients.config.office.net/c2r/v1.0/InteractiveInstallation0%URL Reputationsafe
https://graph.windows.net/0%URL Reputationsafe
https://devnull.onenote.com0%URL Reputationsafe
https://messaging.office.com/0%URL Reputationsafe
https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Bing0%URL Reputationsafe
https://skyapi.live.net/Activity/0%URL Reputationsafe
https://messaging.action.office.com/setcampaignaction0%URL Reputationsafe
https://visio.uservoice.com/forums/368202-visio-on-devices0%URL Reputationsafe
https://staging.cortana.ai0%URL Reputationsafe
https://augloop.office.com0%URL Reputationsafe
https://api.diagnosticssdf.office.com/v2/file0%URL Reputationsafe
https://prod.mds.office.com/mds/api/v1.0/clientmodeldirectory0%URL Reputationsafe
https://officepyservice.office.net/0%URL Reputationsafe
https://api.diagnostics.office.com0%URL Reputationsafe
https://store.office.de/addinstemplate0%URL Reputationsafe
https://wus2.pagecontentsync.0%URL Reputationsafe
https://api.powerbi.com/v1.0/myorg/datasets0%URL Reputationsafe
NameIPActiveMaliciousAntivirus DetectionReputation
s-part-0032.t-0009.t-msedge.net
13.107.246.60
truefalse
    unknown
    NameSourceMaliciousAntivirus DetectionReputation
    https://autodiscover.uk/Autodiscover/Autodiscover.xmloutlook.exe_Rules.xml.13.drfalse
      unknown
      https://shell.suite.office.com:144306C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
      • URL Reputation: safe
      unknown
      https://designerapp.azurewebsites.net06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
      • URL Reputation: safe
      unknown
      https://autodiscover-s.outlook.com/06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
      • URL Reputation: safe
      unknown
      https://useraudit.o365auditrealtimeingestion.manage.office.com06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
      • URL Reputation: safe
      unknown
      https://outlook.office365.com/connectors06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
      • URL Reputation: safe
      unknown
      https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Flickr06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
      • URL Reputation: safe
      unknown
      https://cdn.entity.06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
      • URL Reputation: safe
      unknown
      https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
      • URL Reputation: safe
      unknown
      https://rpsticket.partnerservices.getmicrosoftkey.com06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
      • URL Reputation: safe
      unknown
      https://lookup.onenote.com/lookup/geolocation/v106C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
      • URL Reputation: safe
      unknown
      http://combilift.net/emails2020/YouTube.png~WRS{D93139DE-93B2-45DC-9CC9-9939C08D31C6}.tmp.13.drfalse
        unknown
        https://twitter.com/Combilift~WRS{D93139DE-93B2-45DC-9CC9-9939C08D31C6}.tmp.13.drfalse
          unknown
          https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
          • URL Reputation: safe
          unknown
          https://www.youtube.com/user/combilift/videos~WRS{D93139DE-93B2-45DC-9CC9-9939C08D31C6}.tmp.13.drfalse
            unknown
            https://api.aadrm.com/06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
            • URL Reputation: safe
            unknown
            https://canary.designerapp.06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
            • URL Reputation: safe
            unknown
            https://autodiscover.in/Autodiscover/Autodiscover.xmloutlook.exe_Rules.xml.13.drfalse
              unknown
              https://www.yammer.com06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
              • URL Reputation: safe
              unknown
              https://autodiscover.it/Autodiscover/Autodiscover.xmloutlook.exe_Rules.xml.13.drfalse
                unknown
                https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPolicies06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
                • URL Reputation: safe
                unknown
                https://api.microsoftstream.com/api/06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
                  unknown
                  https://insertmedia.bing.office.net/images/hosted?host=office&amp;adlt=strict&amp;hostType=Immersive06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
                  • URL Reputation: safe
                  unknown
                  https://cr.office.com06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
                  • URL Reputation: safe
                  unknown
                  https://autodiscover.fr/Autodiscover/Autodiscover.xmloutlook.exe_Rules.xml.13.drfalse
                    unknown
                    https://messagebroker.mobile.m365.svc.cloud.microsoft06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
                    • URL Reputation: safe
                    unknown
                    https://otelrules.svc.static.microsoft06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
                      unknown
                      https://edge.skype.com/registrar/prod06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
                      • URL Reputation: safe
                      unknown
                      https://autodiscover.uk/autodiscover/autodiscover.xmloutlook.exe_Rules.xml.13.drfalse
                        unknown
                        https://res.getmicrosoftkey.com/api/redemptionevents06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
                        • URL Reputation: safe
                        unknown
                        https://tasks.office.com06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
                        • URL Reputation: safe
                        unknown
                        https://officeci.azurewebsites.net/api/06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
                        • URL Reputation: safe
                        unknown
                        https://my.microsoftpersonalcontent.com06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
                          unknown
                          https://protect.checkpoint.com/v2/___https:/www.youtube.com/user/combilift/videos___.YzJlOmNvbWJpbGl~WRS{D93139DE-93B2-45DC-9CC9-9939C08D31C6}.tmp.13.drfalse
                            unknown
                            https://store.office.cn/addinstemplate06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
                            • URL Reputation: safe
                            unknown
                            https://protect.checkpoint.com/v2/___https:/twitter.com/Combilift___.YzJlOmNvbWJpbGlmdDpjOm86MTFiNjk~WRS{D93139DE-93B2-45DC-9CC9-9939C08D31C6}.tmp.13.drfalse
                              unknown
                              http://www.cbequipment.com~WRS{D93139DE-93B2-45DC-9CC9-9939C08D31C6}.tmp.13.drfalse
                                unknown
                                https://edge.skype.com/rps06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
                                • URL Reputation: safe
                                unknown
                                https://messaging.engagement.office.com/06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
                                • URL Reputation: safe
                                unknown
                                https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
                                • URL Reputation: safe
                                unknown
                                https://www.odwebp.svc.ms06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
                                • URL Reputation: safe
                                unknown
                                https://api.powerbi.com/v1.0/myorg/groups06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
                                • URL Reputation: safe
                                unknown
                                https://web.microsoftstream.com/video/06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
                                • URL Reputation: safe
                                unknown
                                https://api.addins.store.officeppe.com/addinstemplate06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
                                • URL Reputation: safe
                                unknown
                                https://graph.windows.net06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
                                • URL Reputation: safe
                                unknown
                                https://autodiscover.in/autodiscover/autodiscover.xmloutlook.exe_Rules.xml.13.drfalse
                                  unknown
                                  https://consent.config.office.com/consentcheckin/v1.0/consents06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
                                  • URL Reputation: safe
                                  unknown
                                  https://learningtools.onenote.com/learningtoolsapi/v2.0/Getvoices06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
                                  • URL Reputation: safe
                                  unknown
                                  https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.json06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
                                  • URL Reputation: safe
                                  unknown
                                  http://www.combilift.com/~WRS{D93139DE-93B2-45DC-9CC9-9939C08D31C6}.tmp.13.drfalse
                                    unknown
                                    https://d.docs.live.net06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
                                      unknown
                                      https://safelinks.protection.outlook.com/api/GetPolicy06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
                                      • URL Reputation: safe
                                      unknown
                                      https://ncus.contentsync.06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
                                      • URL Reputation: safe
                                      unknown
                                      https://autodiscover.com.cn/Autodiscover/Autodiscover.xmloutlook.exe_Rules.xml.13.drfalse
                                        unknown
                                        https://autodiscover.it/autodiscover/autodiscover.xmloutlook.exe_Rules.xml.13.drfalse
                                          unknown
                                          https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
                                          • URL Reputation: safe
                                          unknown
                                          http://weather.service.msn.com/data.aspx06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
                                          • URL Reputation: safe
                                          unknown
                                          https://word.uservoice.com/forums/304948-word-for-ipad-iphone-ios06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
                                          • URL Reputation: safe
                                          unknown
                                          https://autodiscover-s.outlook.com/autodiscover/autodiscover.xml06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
                                          • URL Reputation: safe
                                          unknown
                                          https://mss.office.com06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
                                          • URL Reputation: safe
                                          unknown
                                          https://pushchannel.1drv.ms06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
                                          • URL Reputation: safe
                                          unknown
                                          https://autodiscover.com.br/Autodiscover/Autodiscover.xmloutlook.exe_Rules.xml.13.drfalse
                                            unknown
                                            https://wus2.contentsync.06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
                                            • URL Reputation: safe
                                            unknown
                                            https://clients.config.office.net/user/v1.0/ios06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
                                            • URL Reputation: safe
                                            unknown
                                            https://api.addins.omex.office.net/api/addins/search06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
                                            • URL Reputation: safe
                                            unknown
                                            https://outlook.office365.com/api/v1.0/me/Activities06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
                                            • URL Reputation: safe
                                            unknown
                                            http://www.combilift.com~WRS{D93139DE-93B2-45DC-9CC9-9939C08D31C6}.tmp.13.drfalse
                                              unknown
                                              https://clients.config.office.net/user/v1.0/android/policies06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
                                              • URL Reputation: safe
                                              unknown
                                              https://entitlement.diagnostics.office.com06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
                                              • URL Reputation: safe
                                              unknown
                                              https://pf.directory.live.com/profile/mine/WLX.Profiles.IC.json06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
                                              • URL Reputation: safe
                                              unknown
                                              https://outlook.office.com/06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
                                                unknown
                                                https://storage.live.com/clientlogs/uploadlocation06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
                                                  unknown
                                                  https://login.microsoftonline.com06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
                                                  • URL Reputation: safe
                                                  unknown
                                                  https://substrate.office.com/search/api/v1/SearchHistory06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
                                                  • URL Reputation: safe
                                                  unknown
                                                  https://clients.config.office.net/c2r/v1.0/InteractiveInstallation06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
                                                  • URL Reputation: safe
                                                  unknown
                                                  https://service.powerapps.com06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
                                                    unknown
                                                    https://graph.windows.net/06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
                                                    • URL Reputation: safe
                                                    unknown
                                                    https://devnull.onenote.com06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
                                                    • URL Reputation: safe
                                                    unknown
                                                    https://autodiscover.online/Autodiscover/Autodiscover.xmloutlook.exe_Rules.xml.13.drfalse
                                                      unknown
                                                      https://messaging.office.com/06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
                                                      • URL Reputation: safe
                                                      unknown
                                                      https://autodiscover.com.cn/autodiscover/autodiscover.xmloutlook.exe_Rules.xml.13.drfalse
                                                        unknown
                                                        https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Bing06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
                                                        • URL Reputation: safe
                                                        unknown
                                                        https://skyapi.live.net/Activity/06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
                                                        • URL Reputation: safe
                                                        unknown
                                                        https://combilift.com/~WRS{D93139DE-93B2-45DC-9CC9-9939C08D31C6}.tmp.13.drfalse
                                                          unknown
                                                          https://autodiscover.sg/Autodiscover/Autodiscover.xmloutlook.exe_Rules.xml.13.drfalse
                                                            unknown
                                                            https://api.cortana.ai06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
                                                              unknown
                                                              https://messaging.action.office.com/setcampaignaction06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
                                                              • URL Reputation: safe
                                                              unknown
                                                              https://visio.uservoice.com/forums/368202-visio-on-devices06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
                                                              • URL Reputation: safe
                                                              unknown
                                                              https://staging.cortana.ai06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
                                                              • URL Reputation: safe
                                                              unknown
                                                              https://protect.checkpoint.com/v2/___www.linkedin.com/company/combilift-ltd___.YzJlOmNvbWJpbGlmdDpjO~WRS{D93139DE-93B2-45DC-9CC9-9939C08D31C6}.tmp.13.drfalse
                                                                unknown
                                                                https://onedrive.live.com/embed?06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
                                                                  unknown
                                                                  https://protect.checkpoint.com/v2/___https:/www.cbequipment.com/___.YzJlOmNvbWJpbGlmdDpjOm86YTBjMTg0~WRS{D93139DE-93B2-45DC-9CC9-9939C08D31C6}.tmp.13.drfalse
                                                                    unknown
                                                                    https://augloop.office.com06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
                                                                    • URL Reputation: safe
                                                                    unknown
                                                                    https://api.diagnosticssdf.office.com/v2/file06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
                                                                    • URL Reputation: safe
                                                                    unknown
                                                                    https://prod.mds.office.com/mds/api/v1.0/clientmodeldirectory06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
                                                                    • URL Reputation: safe
                                                                    unknown
                                                                    https://officepyservice.office.net/06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
                                                                    • URL Reputation: safe
                                                                    unknown
                                                                    https://api.diagnostics.office.com06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
                                                                    • URL Reputation: safe
                                                                    unknown
                                                                    https://store.office.de/addinstemplate06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
                                                                    • URL Reputation: safe
                                                                    unknown
                                                                    https://wus2.pagecontentsync.06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
                                                                    • URL Reputation: safe
                                                                    unknown
                                                                    https://api.powerbi.com/v1.0/myorg/datasets06C4E34B-C2E7-48B7-BB4A-7B4332B2107F.0.drfalse
                                                                    • URL Reputation: safe
                                                                    unknown
                                                                    • No. of IPs < 25%
                                                                    • 25% < No. of IPs < 50%
                                                                    • 50% < No. of IPs < 75%
                                                                    • 75% < No. of IPs
                                                                    IPDomainCountryFlagASNASN NameMalicious
                                                                    13.107.246.60
                                                                    s-part-0032.t-0009.t-msedge.netUnited States
                                                                    8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                    Joe Sandbox version:41.0.0 Charoite
                                                                    Analysis ID:1520613
                                                                    Start date and time:2024-09-27 16:48:12 +02:00
                                                                    Joe Sandbox product:CloudBasic
                                                                    Overall analysis duration:0h 5m 57s
                                                                    Hypervisor based Inspection enabled:false
                                                                    Report type:full
                                                                    Cookbook file name:defaultwindowsinteractivecookbook.jbs
                                                                    Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                                                    Number of analysed new started processes analysed:18
                                                                    Number of new started drivers analysed:0
                                                                    Number of existing processes analysed:0
                                                                    Number of existing drivers analysed:0
                                                                    Number of injected processes analysed:0
                                                                    Technologies:
                                                                    • EGA enabled
                                                                    • AMSI enabled
                                                                    Analysis Mode:default
                                                                    Analysis stop reason:Timeout
                                                                    Sample name:Read_ Statement.eml
                                                                    Detection:CLEAN
                                                                    Classification:clean3.winEML@6/1049@0/1
                                                                    Cookbook Comments:
                                                                    • Found application associated with file extension: .eml
                                                                    • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, sppsvc.exe, SIHClient.exe, SgrmBroker.exe, conhost.exe, WmiPrvSE.exe, svchost.exe
                                                                    • Excluded IPs from analysis (whitelisted): 52.109.28.46, 52.109.28.47, 52.113.194.132, 2.19.126.151, 2.19.126.160, 51.104.15.253, 52.111.231.24, 52.111.231.23, 52.111.231.25, 52.111.231.26, 20.189.173.16
                                                                    • Excluded domains from analysis (whitelisted): omex.cdn.office.net, slscr.update.microsoft.com, otelrules.afd.azureedge.net, eur.roaming1.live.com.akadns.net, mobile.events.data.microsoft.com, ecs-office.s-0005.s-msedge.net, roaming.officeapps.live.com, login.live.com, officeclient.microsoft.com, a1864.dscd.akamai.net, ecs.office.com, fs.microsoft.com, otelrules.azureedge.net, prod.configsvc1.live.com.akadns.net, onedscolprduks04.uksouth.cloudapp.azure.com, ctldl.windowsupdate.com, prod.roaming1.live.com.akadns.net, osiprod-uks-buff-azsc-000.uksouth.cloudapp.azure.com, s-0005-office.config.skype.com, onedscolprdwus17.westus.cloudapp.azure.com, fe3cr.delivery.mp.microsoft.com, prod1.naturallanguageeditorservice.osi.office.net.akadns.net, uks-azsc-000.roaming.officeapps.live.com, nleditor.osi.office.net, prod-eu-resolver.naturallanguageeditorservice.osi.office.net.akadns.net, s-0005.s-msedge.net, config.officeapps.live.com, azureedge-t-prod.trafficmanager.net, ecs.office.trafficmanager.net, omex.cdn.office.net.a
                                                                    • Not all processes where analyzed, report is missing behavior information
                                                                    • Report size exceeded maximum capacity and may have missing behavior information.
                                                                    • Report size getting too big, too many NtCreateFile calls found.
                                                                    • Report size getting too big, too many NtQueryAttributesFile calls found.
                                                                    • Report size getting too big, too many NtQueryValueKey calls found.
                                                                    • Report size getting too big, too many NtQueryVolumeInformationFile calls found.
                                                                    • Report size getting too big, too many NtReadFile calls found.
                                                                    • Report size getting too big, too many NtReadVirtualMemory calls found.
                                                                    • Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                                                                    • VT rate limit hit for: Read_ Statement.eml
                                                                    No simulations
                                                                    InputOutput
                                                                    URL: Email Model: jbxai
                                                                    {
                                                                    "brand":[],
                                                                    "contains_trigger_text":false,
                                                                    "trigger_text":"",
                                                                    "prominent_buttonname":"unknown",
                                                                    "text_input_field_labels":"unknown",
                                                                    "pdf_icon_visible":false,
                                                                    "has_visible_captcha":false,
                                                                    "has_urgent_text":false,
                                                                    "has_visible_qrcode":false}
                                                                    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                    13.107.246.60https://protect-us.mimecast.com/s/wFHoCqxrAnt7V914iZaD1vGet hashmaliciousUnknownBrowse
                                                                    • www.mimecast.com/Customers/Support/Contact-support/
                                                                    http://wellsfargo.dealogic.com/clientportal/Conferences/Registration/Form/368?menuItemId=5Get hashmaliciousUnknownBrowse
                                                                    • wellsfargo.dealogic.com/clientportal/Conferences/Registration/Form/368?menuItemId=5
                                                                    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                    s-part-0032.t-0009.t-msedge.netDev_Project.xlsGet hashmaliciousUnknownBrowse
                                                                    • 13.107.246.60
                                                                    Purchase Inquiry-0012.xlsGet hashmaliciousUnknownBrowse
                                                                    • 13.107.246.60
                                                                    https://cnrsys.com/.jhg/#5kZtQ3bfand0TbubQ3b5kZtingQ3br07xhH05Q3brbigQ3brd0TR3wH05nZ1Get hashmaliciousHTMLPhisherBrowse
                                                                    • 13.107.246.60
                                                                    http://wellsfargo.alumni-stage.com/Get hashmaliciousUnknownBrowse
                                                                    • 13.107.246.60
                                                                    https://index-html.info/?rid=jhOgcp4Get hashmaliciousUnknownBrowse
                                                                    • 13.107.246.60
                                                                    https://phase-thief-0566.typedream.app/Get hashmaliciousUnknownBrowse
                                                                    • 13.107.246.60
                                                                    http://win2-z13-web-core-windows-net.pages.dev/Get hashmaliciousHTMLPhisher, TechSupportScamBrowse
                                                                    • 13.107.246.60
                                                                    http://m3ins.azurewebsites.net/Get hashmaliciousHTMLPhisherBrowse
                                                                    • 13.107.246.60
                                                                    https://docs.zoom.us/doc/c63Sae4RQ6OyTcxmh_zLzw?from=email&data=05%7C02%7CRyan.Deiter@americansignature.com%7Ce3b8b957491b4e36dfd108dcde65b619%7C5c02e89ab9684d4e960de62c7cd02766%7C0%7C0%7C638629775655136517%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0=%7C0%7C%7C%7C&sdata=RMvLQDF1y92hR5HKChbiO0e0aKONAOKzPjDkQ4i5MTY=&reserved=0Get hashmaliciousUnknownBrowse
                                                                    • 13.107.246.60
                                                                    CLQD.htmGet hashmaliciousHTMLPhisherBrowse
                                                                    • 13.107.246.60
                                                                    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                    MICROSOFT-CORP-MSN-AS-BLOCKUShttps://www.google.fr/url?q=38pQvvq6xRyj7Y00xDjnlx9kIHOSozurMOiaAkImPuQJnOIWtJjqJLi6stjtDz3yh&rct=tTPSrMOiaAkImPuQJnOIWtJjqJLi6stjtFX08pQvvq6xRyj7Y00xDjnlx9kIjusucT&sa=t&url=amp%2Fcasaderestauraciononline.com%2Fholy%2Findexsyn1.html%23cmltYS5hbWV1ckBjYXRhbGluYW1hcmtldGluZy5mcg==Get hashmaliciousHTMLPhisherBrowse
                                                                    • 150.171.28.10
                                                                    https://lkk6m.conownsup.com/tpgbE/Get hashmaliciousHTMLPhisherBrowse
                                                                    • 40.114.177.156
                                                                    https://kulodayplastomer-my.sharepoint.com/:f:/g/personal/exim_kpplindia_com/EpT6drgdzgdPk3kwQBUf2ZAB7JXXdY25CyMiKP-z5XBGWQ?e=8byFZYGet hashmaliciousHTMLPhisherBrowse
                                                                    • 40.101.65.146
                                                                    ATT71725.htmlGet hashmaliciousHTMLPhisherBrowse
                                                                    • 40.99.149.210
                                                                    Payment Notification.msgGet hashmaliciousUnknownBrowse
                                                                    • 52.109.76.144
                                                                    Microsoft-Office-Update 1.exeGet hashmaliciousUnknownBrowse
                                                                    • 20.74.35.75
                                                                    Aisha C. Yetman shared you a document..msgGet hashmaliciousUnknownBrowse
                                                                    • 13.107.6.163
                                                                    FACTORY NEW PURCHASE ORDER.docGet hashmaliciousUnknownBrowse
                                                                    • 52.123.243.76
                                                                    Dev_Project.xlsGet hashmaliciousUnknownBrowse
                                                                    • 13.107.246.60
                                                                    Purchase Inquiry-0012.xlsGet hashmaliciousUnknownBrowse
                                                                    • 13.107.246.60
                                                                    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                    a0e9f5d64349fb13191bc781f81f42e1FoS5cjKhd3.exeGet hashmaliciousLummaCBrowse
                                                                    • 13.107.246.60
                                                                    file.exeGet hashmaliciousLummaC, Amadey, CryptOne, LummaC Stealer, PureLog Stealer, RedLine, StealcBrowse
                                                                    • 13.107.246.60
                                                                    file.exeGet hashmaliciousLummaCBrowse
                                                                    • 13.107.246.60
                                                                    bfINGx7hvL.exeGet hashmaliciousLummaCBrowse
                                                                    • 13.107.246.60
                                                                    kewyIO69TI.exeGet hashmaliciousLummaCBrowse
                                                                    • 13.107.246.60
                                                                    bfINGx7hvL.exeGet hashmaliciousLummaCBrowse
                                                                    • 13.107.246.60
                                                                    gZzI6gTYn4.exeGet hashmaliciousLummaCBrowse
                                                                    • 13.107.246.60
                                                                    U6b3tLFqN5.exeGet hashmaliciousLummaCBrowse
                                                                    • 13.107.246.60
                                                                    FACTORY NEW PURCHASE ORDER.docGet hashmaliciousUnknownBrowse
                                                                    • 13.107.246.60
                                                                    Dev_Project.xlsGet hashmaliciousUnknownBrowse
                                                                    • 13.107.246.60
                                                                    No context
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:data
                                                                    Category:dropped
                                                                    Size (bytes):231348
                                                                    Entropy (8bit):4.386219794490838
                                                                    Encrypted:false
                                                                    SSDEEP:1536:nlIyYLZlM3gsblZouHKl0molMJYgsgwNcAz79ysQqt2QzNfqoQOCrcm0FvtfSyMy:KIgaCYgCmiGu2uqoQ7rt0FvvIl1rZ8tN
                                                                    MD5:77AB5915DB0C8099C287A0E76A4BAC40
                                                                    SHA1:5A41A6A38861034EBD7B10BB3ECA223CA089C792
                                                                    SHA-256:4D7C708E0718D3A107A9A9D2DD79ABC43A4A2A516441CF54E27200DDC2E7C8A3
                                                                    SHA-512:D23EF43376BFAF3EE975C25B368851DE8B6211BD35C2C5C814C424D0ED07E5F3F7AE9FFDD8C773842E5ED2108D5059BCAED43399C327A2E0944266B726727640
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:TH02...... ...GO........SM01X...,.....;O............IPM.Activity...........h...............h............H..h..........|...h.........a..H..h\cal ...pDat...hX...0..........h+..............h........_`Ok...h....@...I.lw...h....H...8.Tk...0....T...............d.........2h...............k..............!h.............. h*)(...........#h....8.........$h.a......8....."h..............'h..............1h+...<.........0h....4....Tk../h....h.....TkH..hH...p.........-h .......<.....+h............................ ..............F7..............FIPM.Activity....Form....Standard....Journal Entry...IPM.Microsoft.FolderDesign.FormsDescription................F.k..........1122110020000000....Microsoft...This form is used to create journal entries.........kf...... ..........&...........(.......(... ...@.....................................................................................................................fffffffff........wwwwwwww.p....pp..............p...............pw..............pw..DDDDO..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with very long lines (1869), with no line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1869
                                                                    Entropy (8bit):5.086262471256765
                                                                    Encrypted:false
                                                                    SSDEEP:48:cGIdyUdyjdSyrudnzyZSyrenzyMJdyBkSyrdnzyr1nzyvASy/dyO:gEUEjdbqd2Zb622Embx2R2vAb/EO
                                                                    MD5:FDF12739730DED4FDE9ACECC60F24661
                                                                    SHA1:C79452906A62D4E8ACF0BB8669499DA9B589E879
                                                                    SHA-256:011CA319ABDBA4DDB9367266AC180851254C0B135A9EE65FFE30DBBB24D145D0
                                                                    SHA-512:E99A28CB3A93ED5A713F3A7B9AAC8D7481E2E44C6E8060DD2096FEB51CE1D92196E9FCD63F8C3745AFEB5FB42625E75A7FC63371F962C051C5594E1D8C79C4C0
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:<?xml version="1.0" encoding="UTF-8" standalone="yes"?><root><version>1</version><Count>12</Count><Resource><Id>Aptos_26215680</Id><LAT>2024-09-27T14:50:38Z</LAT><key>29939506207.ttf</key><folder>Aptos</folder><type>4</type></Resource><Resource><Id>Aptos_45876480</Id><LAT>2023-10-06T09:25:29Z</LAT><key>27160079615.ttf</key><folder>Aptos</folder><type>4</type></Resource><Resource><Id>Aptos Narrow_26215424</Id><LAT>2023-10-06T09:25:29Z</LAT><key>31558910439.ttf</key><folder>Aptos Narrow</folder><type>4</type></Resource><Resource><Id>Aptos Display_26215680</Id><LAT>2023-10-06T09:25:29Z</LAT><key>23001069669.ttf</key><folder>Aptos Display</folder><type>4</type></Resource><Resource><Id>Aptos Narrow_45876224</Id><LAT>2023-10-06T09:25:29Z</LAT><key>24153076628.ttf</key><folder>Aptos Narrow</folder><type>4</type></Resource><Resource><Id>Aptos Display_45876480</Id><LAT>2023-10-06T09:25:29Z</LAT><key>30264859306.ttf</key><folder>Aptos Display</folder><type>4</type></Resource><Resource><Id>Aptos_
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:ASCII text, with very long lines (65536), with no line terminators
                                                                    Category:dropped
                                                                    Size (bytes):322260
                                                                    Entropy (8bit):4.000299760592446
                                                                    Encrypted:false
                                                                    SSDEEP:6144:dztCFLNyoAHq5Rv2SCtUTnRe4N2+A/3oKBL37GZbTSB+pMZIrh:HMLgvKz9CtgRemO3oUHi3SBSMZIl
                                                                    MD5:CC90D669144261B198DEAD45AA266572
                                                                    SHA1:EF164048A8BC8BD3A015CF63E78BDAC720071305
                                                                    SHA-256:89C701EEFF939A44F28921FD85365ECD87041935DCD0FE0BAF04957DA12C9899
                                                                    SHA-512:16F8A8A6DCBAEAEFB88C7CFF910BCCC71B76A723CF808B810F500E28E543112C2FAE2491D4D209569BD810490EDFF564A2B084709B02963BCAF6FDF1AEEC59AC
                                                                    Malicious:false
                                                                    Reputation:high, very likely benign file
                                                                    Preview:51253fe60063c31af0d295afb42228b0:v2:2:1:1590:2:8479:76bd602437550e98c9043d06a55186ab7d95dea5a0e935a599f73e62a8c9b158e0afcb19351f6c353940c06a38172b94d18c02cf92bb8a80184eccca0392b259ab3e71dae73e491c7941997cb36ad4a198661f622dad478d840f66d530a0dde78acea3367f91fff62fbb3dc18faff0c708ad30edef5bea8b22c5fd782b770d8993386eaa784fd19a3c3e1db3b537b1a94d3d4fbd46f8df8fddf6d16611969fe0a97c50e0f3ac24750c93257cf5c161184aa7385800c87d803b339632a3d8ec7fe17a0afd83ce9e9d0e3f7b8d579637928a811f1f7e6d1887df2ddc7d4f752c4d600235e426c92c7bf8a1362f95457998cc0e5d4261f0efa4fada0f866dbcefb407dacab7a2914e91c2f08200f38c2d9d621962145b1464b0f204b326118a53ecdcab22bff005fdd5257c99a6dc51ac0600a49f2ef782396987e78c08b846dad5db55e8ccefffc64863bc2c3e90b95a09d25d0814a848c98fe01a82d4e30e6682dd546e12c45ca0d280a45295ab4bd632dafb070edfdc3c9e38313d5aeb195972986f8011b66817028fd8c78b67a0ac7e780eecc3fb6a31f5a025b8a9a3db278a98c0696aeaac739b18688b0f9c7d751bba02cc5f4e41853fb119b3c0c915059aaa92971244a1989124f12881ca88e6410df70b793a2c3a736ff4
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:ASCII text, with no line terminators
                                                                    Category:dropped
                                                                    Size (bytes):10
                                                                    Entropy (8bit):2.4464393446710155
                                                                    Encrypted:false
                                                                    SSDEEP:3:LC3kS:Ob
                                                                    MD5:0616033C4F61D0A37D7AAAB2DAAFB9A4
                                                                    SHA1:1AEBFDF15012A4AF3FADD9465A0F6223AB4A421F
                                                                    SHA-256:3F0BEBBFE626023C2E2924AA1B6EDFB6CC277069BF461872615DFE80DC55EF9E
                                                                    SHA-512:9D340799773280106895737A674B49C32D5E92D124FAEA5F223724633F7E8E60DE632CA75C167931844DD9CA611E48D0EF1E5D525F88D323B8848615FFB948CB
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:1727448527
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:JSON data
                                                                    Category:dropped
                                                                    Size (bytes):1538
                                                                    Entropy (8bit):5.170046666246265
                                                                    Encrypted:false
                                                                    SSDEEP:48:YZVrmf/x1AUzXemmf/x14Uz6QA/x1prTyzx:xfp1AUzuZfp14UzFAp1prTyzx
                                                                    MD5:F903C4A051E8AA36E9E085B08D1BC55E
                                                                    SHA1:FF9AF9BBA28D4F3FF2238A64425CABE8123250AB
                                                                    SHA-256:59D97433D58543D3CAE4BFDF9AC0DC6990A99BFB10D118B0D62D32DA15D30968
                                                                    SHA-512:7B9A526C71B8DF94CF6556AB827C07E2265ACF6F81B4A12B3303ACCD6601C92735ECAA0F4AD5DC054FD1E7EA19B29FC220F41213822CD04E71DC27FDA8C9027B
                                                                    Malicious:false
                                                                    Reputation:moderate, very likely benign file
                                                                    Preview:{"CampaignStates":[{"CampaignId":"398f8b35-ef06-4a2b-a5dc-d85540d6fff3","LastNominationTimeUtc":"2023-10-06T09:25:18Z","LastNominationBuildNumber":"16.0.16827.20130","DeleteAfterSecondsWhenStale":31536000,"ForceCandidacy":false,"IsCandidate":true,"DidCandidateTriggerSurvey":false,"LastSurveyActivatedTimeUtc":"1601-01-01T00:00:00Z","LastSurveyId":"7e1f72bd-2c13-423b-93cf-2786588bccbb","LastSurveyStartTimeUtc":"2023-10-06T09:25:18Z","LastSurveyExpirationTimeUtc":"2024-10-05T09:25:18Z","LastCooldownEndTimeUtc":"1601-01-01T00:00:00Z"},{"CampaignId":"8a42827d-29d2-473e-998e-3217724c5b68","LastNominationTimeUtc":"2023-10-06T09:25:18Z","LastNominationBuildNumber":"16.0.16827.20130","DeleteAfterSecondsWhenStale":31536000,"ForceCandidacy":false,"IsCandidate":true,"DidCandidateTriggerSurvey":false,"LastSurveyActivatedTimeUtc":"1601-01-01T00:00:00Z","LastSurveyId":"0bb7f335-0b8a-4926-bb93-540e4e5b86c8","LastSurveyStartTimeUtc":"2023-10-06T09:25:18Z","LastSurveyExpirationTimeUtc":"2024-10-05T09:25
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:JSON data
                                                                    Category:dropped
                                                                    Size (bytes):740
                                                                    Entropy (8bit):4.578658879460996
                                                                    Encrypted:false
                                                                    SSDEEP:12:Ym6dnG20cYIyJG20c6IfG20c6IGG20cDIZG20cdI2ayG20cgaIbnG20cIQPIKG2X:YddnUcYIyJUc6IfUc6IGUcDIZUcdIFy0
                                                                    MD5:439A34DE8DA5C04AF25AADB84A2120D4
                                                                    SHA1:F12F9FF6E03A5762BD03061557029446680B1DAE
                                                                    SHA-256:32B560C75C25C6F56C0439F67A3FA7D4F271F07B435EE41575A3D82C6C612880
                                                                    SHA-512:BE704CD0DF8041945D16B8103135650B33D5E97D6F7C202E9C9499C3AE57E33855C2CC3A8F73B578DB482F47026C756F1FAA411A2CC58B5E53CE23CD24229834
                                                                    Malicious:false
                                                                    Preview:{"ChannelStates":[{"ChannelType":0,"CooldownStartTimeUtc":"1601-01-01T00:00:00Z","Cooldown":1209600},{"ChannelType":1,"CooldownStartTimeUtc":"1601-01-01T00:00:00Z","Cooldown":0},{"ChannelType":2,"CooldownStartTimeUtc":"1601-01-01T00:00:00Z","Cooldown":0},{"ChannelType":3,"CooldownStartTimeUtc":"1601-01-01T00:00:00Z","Cooldown":3600},{"ChannelType":4,"CooldownStartTimeUtc":"1601-01-01T00:00:00Z","Cooldown":10800},{"ChannelType":5,"CooldownStartTimeUtc":"1601-01-01T00:00:00Z","Cooldown":7776000},{"ChannelType":6,"CooldownStartTimeUtc":"1601-01-01T00:00:00Z","Cooldown":1800},{"ChannelType":7,"CooldownStartTimeUtc":"1601-01-01T00:00:00Z","Cooldown":0},{"ChannelType":8,"CooldownStartTimeUtc":"1601-01-01T00:00:00Z","Cooldown":1209600}]}
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:JSON data
                                                                    Category:dropped
                                                                    Size (bytes):87
                                                                    Entropy (8bit):4.576828956814449
                                                                    Encrypted:false
                                                                    SSDEEP:3:Y2NKbNCOAqui32B0fkWbSpgLGwHY:Y2YZOUU0ffogaw4
                                                                    MD5:E4E83F8123E9740B8AA3C3DFA77C1C04
                                                                    SHA1:5281EAE96EFDE7B0E16A1D977F005F0D3BD7AAD0
                                                                    SHA-256:6034F27B0823B2A6A76FE296E851939FD05324D0AF9D55F249C79AF118B0EB31
                                                                    SHA-512:BD6B33FD2BBCE4A46991BC0D877695D16F7E60B1959A0DEFC79B627E569E5C6CAC7B4AD4E3E1D8389A08584602A51CF84D44CF247F03BEB95F7D307FBBA12BB9
                                                                    Malicious:false
                                                                    Preview:{"ShouldFloodgateTakePrecedenceOverRateAndReview":false,"AreRatingSurveysEnabled":true}
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:JSON data
                                                                    Category:dropped
                                                                    Size (bytes):14
                                                                    Entropy (8bit):3.378783493486176
                                                                    Encrypted:false
                                                                    SSDEEP:3:Y2Qt6eYYn:Y2Qt6eYYn
                                                                    MD5:6CA4960355E4951C72AA5F6364E459D5
                                                                    SHA1:2FD90B4EC32804DFF7A41B6E63C8B0A40B592113
                                                                    SHA-256:88301F0B7E96132A2699A8BCE47D120855C7F0A37054540019E3204D6BCBABA3
                                                                    SHA-512:8544CD778717788B7484FAF2001F463320A357DB63CB72715C1395EF19D32EEC4278BAB07F15DE3F4FED6AF7E4F96C41908A0C45BE94D5CDD8121877ECCF310D
                                                                    Malicious:false
                                                                    Preview:{"Surveys":{}}
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:JSON data
                                                                    Category:dropped
                                                                    Size (bytes):14
                                                                    Entropy (8bit):3.378783493486176
                                                                    Encrypted:false
                                                                    SSDEEP:3:Y2Qt6eYYn:Y2Qt6eYYn
                                                                    MD5:6CA4960355E4951C72AA5F6364E459D5
                                                                    SHA1:2FD90B4EC32804DFF7A41B6E63C8B0A40B592113
                                                                    SHA-256:88301F0B7E96132A2699A8BCE47D120855C7F0A37054540019E3204D6BCBABA3
                                                                    SHA-512:8544CD778717788B7484FAF2001F463320A357DB63CB72715C1395EF19D32EEC4278BAB07F15DE3F4FED6AF7E4F96C41908A0C45BE94D5CDD8121877ECCF310D
                                                                    Malicious:false
                                                                    Preview:{"Surveys":{}}
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):177088
                                                                    Entropy (8bit):5.2867669788779725
                                                                    Encrypted:false
                                                                    SSDEEP:1536:si2XfRAqcbH41gwEwLe7HW8bM/o/NM5cAZl1p5ihs7EXXCEAD2OdaLI:pCe7HW8bM/o/9XPkiI
                                                                    MD5:863F1F817E1786D49D9B6FE33E2B245D
                                                                    SHA1:1FFD34F9B286FB035EBE39E8E8176A280D995C75
                                                                    SHA-256:A465950570EE61486C8B07F1B7BD341FF879C7B0A4AD1F2E364641DBD7262C90
                                                                    SHA-512:974D1029CCA21E10D47E4724AFF0C29D42E7B72ED09B2F01BF3CF6F808FD23EAD4D81F9AC5BF91B3E0DD9343B8633C0EC3AE80D4451335584F95346010F601F2
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<o:OfficeConfig xmlns:o="urn:schemas-microsoft-com:office:office">.. <o:services o:GenerationTime="2024-09-27T14:48:46">.. Build: 16.0.18112.40129-->.. <o:default>.. <o:ticket o:headerName="Authorization" o:headerValue="{}" />.. </o:default>.. <o:service o:name="Research">.. <o:url>https://word-edit.officeapps.live.com/we/rrdiscovery.ashx</o:url>.. </o:service>.. <o:service o:name="ORedir">.. <o:url>https://o15.officeredir.microsoft.com/r</o:url>.. </o:service>.. <o:service o:name="ORedirSSL">.. <o:url>https://o15.officeredir.microsoft.com/r</o:url>.. </o:service>.. <o:service o:name="ClViewClientHelpId" o:authentication="1">.. <o:url>https://[MAX.BaseHost]/client/results</o:url>.. <o:ticket o:policy="MBI_SSL_SHORT" o:idprovider="1" o:target="[MAX.AuthHost]" o:headerValue="Passport1.4 from-PP='{}&amp;p='" />.. <o:ticket o:idprovider="3" o:headerValue="Bearer {}" o:resourceId="[
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:ASCII text, with CRLF line terminators
                                                                    Category:modified
                                                                    Size (bytes):2092055
                                                                    Entropy (8bit):4.722676838636391
                                                                    Encrypted:false
                                                                    SSDEEP:12288:NUSVt4KOXXqV0N8x5thr291gess3TylunXF:NUSVt0
                                                                    MD5:2F438C2B963B8BC1D5EEFF6A77AB9870
                                                                    SHA1:4CF5E859AAD158E596DA114B22424A6D8A2BE39C
                                                                    SHA-256:44014B7CC0FA1728F9C93D67CB3D607533DA143EA5EA72CB0248EEEED461C12B
                                                                    SHA-512:95D2279B65B9B6EE741505626790FD91783AC65D355F9ECC4B15DF75384D2DDDD622BD2CF9A3524F5036E11AFF4D4C4FEDCB16322C6F04DD9479C537FA844CEF
                                                                    Malicious:false
                                                                    Preview:<Rules><R Id="170022" V="2" DC="SM" EN="Office.Graphics.GVisInkLoad" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" S="1" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="b8ipj" A="anui5" />.. <A T="2" E="TelemetryShutdown" />.. </S>.. <C T="B" I="0" O="false" N="ContainsInkStrokes">.. <O T="COALESCE">.. <L>.. <O T="EQ">.. <L>.. <U T="EqualsNull">.. <S T="1" F="TimeStamp100ns" />.. </U>.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </C>.. <T>.. <S T="1" />.. <S T="2" />.. </T>..</R><R Id="170012" V="12" DC="SM" EN="Office.Graphics.GVizInkStroke" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bgwr8" A="aqxmg" />.. <F T="2">.. <O T="EQ">..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):489
                                                                    Entropy (8bit):5.155248000155917
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdIGXyT9un8DWyZcAAwEerWzlVZ66yuzySNO2su:2dILvDb0wLrWzPr
                                                                    MD5:414277D4E3F104F55B935AB02A9BA9BF
                                                                    SHA1:B01DF5CDB8EFCE39DA23495581D18C4AA4B1EF84
                                                                    SHA-256:B8F1C0D81E44F9FEAB83DC2749B7807121F9BF8AB6AE82C01F8077FC05CA3FE1
                                                                    SHA-512:40E2853C1EB0D9D627932232617C2D76EFA999DB788E20F5C7945C708B925E8A62788ED7D0F3518E72E00072AD7910BB199E67C82EE3119ABBEB3F3BB5E651C2
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100042" V="2" DC="SM" EN="Office.UX.Desktop.OfficeTheme.App.Init" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="cm9y5" A="a24c8" />.. </S>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="1" F="TimeStamp100ns" />.. </C>.. <C T="U32" I="1" O="false" N="OfficeTheme">.. <S T="1" F="OfficeTheme" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):517
                                                                    Entropy (8bit):5.213185196410167
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdAXynO6un8DWyZcAApAQier0lVZ66yuzySNO2su:2dnlvDb0/r0Pr
                                                                    MD5:E03148FECDFEA3BFD90CA19AA52AC2C1
                                                                    SHA1:BB0D4CE260F8E7C2F28A5A4FECD4AFA8B653BE2F
                                                                    SHA-256:6BBCCD4AEA9494B1FD31DE86E19B2634F3AC6E6C72506BCBFD5A5C849C67829C
                                                                    SHA-512:4B784F62D17524D89C194A534EAA1EF5FE69D21E907C97BEFBAB5321591256EE3D6348C48963A9DD9E156352218A6A8126DD9F2E5B934C0BE0B77D5ECCC6498C
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100043" V="0" DC="SM" EN="Office.UX.Desktop.OfficeTheme.Changed.Through.UI" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="a24db" />.. </S>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="1" F="TimeStamp100ns" />.. </C>.. <C T="U32" I="1" O="false" N="OfficeTheme">.. <S T="1" F="OfficeTheme" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):457
                                                                    Entropy (8bit):5.134868815976784
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdlZun8DWyZcAAwEerqlVZ6d7SyFNrlNO2su:2dlZvDb0wLrqP0HFF
                                                                    MD5:B9B2CA56A048BDBFE74315BAC8FEFAF0
                                                                    SHA1:2061D5AA8AC1B3DC17C2839600F16C8975A58740
                                                                    SHA-256:3C4A4929450C661680E8B674867368D76A71AA0A5FE6B1541E0CAB2EAECC2F2D
                                                                    SHA-512:E6625F4A0B10DF7E3B966C40F5AD8FFB605592BC5AA0E250270DDDE78C539F376094CD95455DAC093B10B64FFBD2C3E4C17ED49AC39D8D5414731CBBC0F1B2EF
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100068" V="2" DC="SM" EN="Office.UX.WhatsNewCantOpen" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bbqss" />.. </S>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="1" F="TimeStamp100ns" />.. </C>.. <C T="W" I="1" O="false" N="Reasons">.. <S T="1" F="Reasons" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):802
                                                                    Entropy (8bit):4.792062686551037
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdW+un8DWyZcAApAQierAerVxlVZdv2pu+/WkmSP/k//nx2Nf/0//RthmMNOjz:2d3vDb0/rnrVxP2Y+7HSc
                                                                    MD5:8279DE7A54DC506ED68199AC880C2920
                                                                    SHA1:C81A8D12C2CB577FC2A89242C8F9E22D4F37C6FC
                                                                    SHA-256:40AD004C81F69364A2017FD3B758DC4C7834BC47A4A1340BED54594AF13F5B58
                                                                    SHA-512:312A10EC95F62BCC2C924BEB9EDB7979E0EB3F8BDF5352874EB9337D2E8ABC02F2CC852E1B9813300FC1E40BB73422F075F4B42839180F6D0D15A49F211AFA3E
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100069" V="1" DC="SM" EN="Office.UX.WhatsNewTimeOnScreen" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bbqsl" />.. <UTS T="2" Id="bbqsm" />.. </S>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="2" F="TimeStamp100ns" />.. </C>.. <C T="I64" I="1" O="false" N="WhatsNewOnScreenTimeSec">.. <O T="DIV">.. <L>.. <O T="SUB">.. <L>.. <S T="2" F="TimeStamp100ns" />.. </L>.. <R>.. <S T="1" F="TimeStamp100ns" />.. </R>.. </O>.. </L>.. <R>.. <V V="10000000" T="U64" />.. </R>.. </O>.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):410
                                                                    Entropy (8bit):5.2896270378885895
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdtr5oun8DWyZcAApAQierglVZ6NO2su:2dtmvDb0/rgPQ
                                                                    MD5:D6DAF9F991EB87EB13BE13E79B869750
                                                                    SHA1:D6611509E67BE22A205CBF308A08ACD150C99FAA
                                                                    SHA-256:4CD12BB7EED5FE69ACC9E7A1EE29515CAEE4C453AB088F765ACB304DC882227C
                                                                    SHA-512:686C1BCB148009D1D09EC6C1AE55EDB5CF454E46BBC39BE1536B45084CA09D4C7ADDD4C840E4AEC34500E2B4E92061D06863FDD35C6DB836B921557713E33682
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100070" V="0" DC="SM" EN="Office.UX.WhatsNewButtonClick" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bbqsq" />.. </S>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="1" F="TimeStamp100ns" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):416
                                                                    Entropy (8bit):5.295531666329221
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd3LqqNoun8DWyZcAApAQierplVZ6NO2su:2d3OqOvDb0/rpPQ
                                                                    MD5:3DF0BABC8132291994D448B40582DB90
                                                                    SHA1:3C346E6C4A0779268FE62A4F7DF16307AF1F73C1
                                                                    SHA-256:6FB9BDDDA6B632428391FAFE9CE78D58CD0986B6571D8BB4C9691496070F3F19
                                                                    SHA-512:B982FC0ABC579C69F542C8BBBA3F78592E81BBE32DAEDA2D54E7A0427B0406DF62C53D483118A818A47162C766DAD68A29C83893401897D4994B993990D40288
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100071" V="0" DC="SM" EN="Office.UX.WhatsNewOnlineButtonClick" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bbqsr" />.. </S>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="1" F="TimeStamp100ns" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):500
                                                                    Entropy (8bit):5.241422570005702
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdWCun8DWyZcAApAQierKNqlVZ6dLJsNO2su:2dPvDb0/rKqP0W
                                                                    MD5:B5F555AC798495BD8A6B4E254745EDA0
                                                                    SHA1:C559E92D8618CA2F10E8734B77AFAFF25388F3FC
                                                                    SHA-256:1C79426930C54765CB7B121361D58839DDDBCED8F37502FAB16903274414AB21
                                                                    SHA-512:BF28AA7562613A4ADB9435701D58438AF3B2378D1BAF06394F4DE5805CC52628706A53D5AE3BCD4AAD12DCB6BE76EE7C533A9237113993450B2F2D8E62A5DE8A
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100074" V="0" DC="SM" EN="Office.UX.WhatsNewItemHyperlinkClick" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bbqsp" />.. </S>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="1" F="TimeStamp100ns" />.. </C>.. <C T="W" I="1" O="true" N="FeatureTag">.. <S T="1" F="FeatureTag" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):586
                                                                    Entropy (8bit):5.184710233838763
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd/ndkTun8DWyZcAAwEerY3tOpv0t/G5yp7s/ZByNO2su:2d/dsvDb0wLrYUlcsBi
                                                                    MD5:6E76DCB19FB44EA1E65014E0CE218AB0
                                                                    SHA1:0313ABCCB6532B8749626F7BCB03ED0D730B8B6F
                                                                    SHA-256:735879C44400699786304B87916667E37F35A3B26331C41B2366FEA88033B070
                                                                    SHA-512:967A39E02654A0C6996C6DD9699C37E79007A8EFB7D315EBE23E77E5298A14B3AE80D8322C41FFFDE714CD0EA50F256A8C65A242450C163CAF5C70AF6E72C871
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100075" V="1" DC="SM" EN="Office.UX.TeachingCallout.TeachingCalloutShown" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bfhe2" />.. </S>.. <C T="W" I="0" O="false" N="TeachingCalloutId">.. <S T="1" F="TeachingCalloutId" />.. </C>.. <C T="U32" I="1" O="false" N="PreRegKeyVal">.. <S T="1" F="PreRegKeyVal" />.. </C>.. <C T="U32" I="2" O="false" N="PostRegKeyVal">.. <S T="1" F="PostRegKeyVal" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):729
                                                                    Entropy (8bit):5.049181212012891
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd7dkVeun8DWyZcAAwEerN3tOpvdmARdyEXqdUNIdnHD9rgL0NO2su:2dxhvDb0wLrNUD/IDR1
                                                                    MD5:A1C32A2040850EEC0D8769D73B81F8B3
                                                                    SHA1:6309C8B096063BA83039390BE9391E7FE6A91A29
                                                                    SHA-256:8EBC17CB904B635F64A26B18D6C3BBB95BBA210C348D386F15A0C302B752A478
                                                                    SHA-512:973A85A11BEC72BDC6A5E8FC50EABFA56CA04B6E659AA14854BD80ADF2DC98EB63BF1D4349979C44A32D81A42981327DD994C242EE4AEDDE96A68EDD0784D72B
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100076" V="2" DC="SM" EN="Office.UX.TeachingCallout.TeachingCalloutHidden" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="4qnub" />.. </S>.. <C T="W" I="0" O="false" N="TeachingCalloutId">.. <S T="1" F="TeachingCalloutId" />.. </C>.. <C T="W" I="1" O="false" N="AnchorId">.. <S T="1" F="AnchorId" />.. </C>.. <C T="W" I="2" O="false" N="Title">.. <S T="1" F="Title" />.. </C>.. <C T="W" I="3" O="false" N="Info">.. <S T="1" F="Info" />.. </C>.. <C T="B" I="4" O="false" N="CalloutAlwaysShow">.. <S T="1" F="CalloutAlwaysShow" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):586
                                                                    Entropy (8bit):5.158726096353292
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdLF6dkRoun8DWyZcAAwEerm3tOpvvfEFxppvFNvxNO2su:2dLCxvDb0wLrmU1QVvFR3
                                                                    MD5:2BA258B06C54DF790012A5098D0DB9F0
                                                                    SHA1:66AC50733B3D79D421AA3453C580B864830D8682
                                                                    SHA-256:BB448A91F4A1AAEE49D517B15512555AE43508FE3471708EDC8B1549575E4A30
                                                                    SHA-512:E31DD4A8FE41BD1431CAC663B0206F1517F84647DF0B0914E6EAD5CDC94367A6423C42B454F7FA11B4235ECE4C3F9A0796718916139C9EC332839486F7D4E11B
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100077" V="2" DC="SM" EN="Office.UX.TeachingCallout.TeachingCalloutButtonClick" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="4qnua" />.. </S>.. <C T="W" I="0" O="false" N="TeachingCalloutId">.. <S T="1" F="TeachingCalloutId" />.. </C>.. <C T="U32" I="1" O="false" N="ButtonType">.. <S T="1" F="ButtonType" />.. </C>.. <C T="U32" I="2" O="false" N="TotalButtons">.. <S T="1" F="TotalButtons" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):413
                                                                    Entropy (8bit):5.287984558638439
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdQdkV0un8DWyZcAAwEerEA3tOpvNO2su:2dWzvDb0wLrPU/
                                                                    MD5:F1CE09999B4B350E954C449DCD687080
                                                                    SHA1:2DE21A2FFB189374B50FAFC28E524018874AE0B2
                                                                    SHA-256:D708E23A5A1B7EEF562C29674913688C4C09F3BA6917988202F54A9B68EAD43E
                                                                    SHA-512:9F17CD24C78E0FE9B5609B841DCE49EF7BB899859D1F1D26FF50E1601EA8A9AE74E933313132FEB229594570DAAF581A2557D87674BAC928D01F1000F5B9EE3B
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100078" V="1" DC="SM" EN="Office.UX.TeachingCallout.TeachingCalloutHyperlinkClick" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bfhe5" />.. </S>.. <C T="W" I="0" O="false" N="TeachingCalloutId">.. <S T="1" F="TeachingCalloutId" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):412
                                                                    Entropy (8bit):5.267817827165894
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdCdkJEk3dun8DWyZcAAwEer43tOpvNO2su:2dQQEk3dvDb0wLr4U/
                                                                    MD5:3482F3A1659236D2232BA10912EF5CC6
                                                                    SHA1:0C7CD5F8BBF3996C825E099148A6AC934D87C7F0
                                                                    SHA-256:795F2F9F2683236ABE758C54944FCC1529B13DFA2F9CBC8FDFD5A6BE7B418922
                                                                    SHA-512:4198CE6BEFBC9C2955A50B25C34F972E5FCB4F4E464FD4331E00E8B300670BD760F7E22091211BEAC280A0778BD4E77059B9F75BEA4C72BF931D4EE334A5790F
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100079" V="2" DC="SM" EN="Office.UX.TeachingCallout.TeachingCalloutTappedOutside" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="4qnt8" />.. </S>.. <C T="W" I="0" O="false" N="TeachingCalloutId">.. <S T="1" F="TeachingCalloutId" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):681
                                                                    Entropy (8bit):5.231377942579125
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdYZHsHoun8DWyZcAAwEersJV4ciFIqtcifn+0H/Iqttdy9oEINO2su:2dYZGovDb0wLrs8cixcitHTvYg
                                                                    MD5:7B5BAC8525989E8899C3679731D98258
                                                                    SHA1:C0803639CEFF57C7066B8ED1C67EB50B00349403
                                                                    SHA-256:9A3292D9D11EE8CB27677F193ABE095831F9B7E4174D9E652F82803D328E5DE9
                                                                    SHA-512:91D981040EA5E09BE70950240F8867229617D00092D1E66D537313AF74EA1DF765BDE195C2626B965B75E67BF8C454E2738ADE3E34FB44BA8D9B3068CBF78B13
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100083" V="2" DC="SM" EN="Office.UX.HighContrastAccessibilitySystemSettingsWin32" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bhktg" A="bgkti" />.. </S>.. <C T="B" I="0" O="true" N="IsHighContrastFeatureAvailable">.. <S T="1" F="IsHighContrastFeatureAvailable" M="Ignore" />.. </C>.. <C T="B" I="1" O="true" N="IsHighContrastOn">.. <S T="1" F="IsHighContrastFeatureOn" M="Ignore" />.. </C>.. <C T="W" I="2" O="true" N="HighContrastScheme">.. <S T="1" F="HighContrastScheme" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):403
                                                                    Entropy (8bit):5.261641260441923
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdN0Iun8DWyZcAAwEerwJVOI3ZaNO2su:2dzvDb0wLryZa
                                                                    MD5:3671EA9C5CBDE113F64D8C3561349D0F
                                                                    SHA1:34A9746232B7AD0A407774E6EC07ED97E3A295C2
                                                                    SHA-256:7D7B07D4C42A86C7C69E9FDE8460DA77F21D6B82F7A65F183D859BBE9F76D674
                                                                    SHA-512:7676A3F992C4A0FB1060D6EA5FDD2D352D74713B2EEDF42AF7D88BC96BD48EFA7DC56390F6952DB4C2ADE843F05B7051EFA2F9F37E52008EDA6CA85C49BCD22A
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100084" V="1" DC="SM" EN="Office.UX.AnimationSystemSettings" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bhkth" />.. </S>.. <C T="B" I="0" O="true" N="IsAnimationEnabled">.. <S T="1" F="IsAnimationEnabled" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):421
                                                                    Entropy (8bit):5.2961268242072945
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdG8un8DWyZcAApAQierLYsldUqNO2su:2dG8vDb0/rUqaq
                                                                    MD5:A6451ECAB2CD42E85B452E2BF1A1158C
                                                                    SHA1:A04D2EA4080781702374E87591381B8F54051D4D
                                                                    SHA-256:73FDDEB1B6C49CA452AE79D8975D99891A5CC1B2FA319F933081A7AD82E71955
                                                                    SHA-512:D2631BFDBE43A130052E1436189445246C90AF7DEFC9C6E4031615B9F58F59D9519E11CDD3C6918D0770BD36F9C7958724D21255A5DAB75A5C6E2D4FAB95374A
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100085" V="0" DC="SM" EN="Office.UX.AccChecker" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="be7sb" />.. </S>.. <C T="W" I="0" O="true" N="ShowingAccessibilityChecker">.. <S T="1" F="UxAccChecker" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):457
                                                                    Entropy (8bit):5.193779288742389
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdUW0Tun8DWyZcAAwEer++WuF2yab9zNO2su:2dUW0TvDb0wLrDWQ25
                                                                    MD5:0577879C523FD7CB65C2D80E7A663F27
                                                                    SHA1:7A4863B6468521FC3AFF8331024A7537079A2035
                                                                    SHA-256:7A9EAB976443BEB6F59CBD4F9B572BE0C7521771F3D871C0E4D6F53EB4DBAAC3
                                                                    SHA-512:F4D4156DEF78C290FF6C0009C8DA02AB975B551C633FFC46156E0935D6E02D250F67DCDFFBC4A3DCBB7DEEF7722AD005CFB0BBA3540130CA5A97634D1DEC7564
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100094" V="0" DC="SM" EN="Office.UX.Dialogs.SDM.DoModal" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="cnyur" />.. </S>.. <C T="I32" I="0" O="false" N="HelpId">.. <S T="1" F="DialogId_hid" />.. </C>.. <C T="U32" I="1" O="true" N="ReturnTmc">.. <S T="1" F="Return_tmc" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1594
                                                                    Entropy (8bit):4.552983510334679
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d0NWlw0/53bTwGuNn/hFF4j68OWxue+Iz:c8L0h3bUGuZjF4Bp7z
                                                                    MD5:35A756BB6CA3F8BDDC97342284174200
                                                                    SHA1:22F2158D40D9B17C665A965FE8721D45A352856A
                                                                    SHA-256:8C638B3BF14BACA701C62344E8F41568D031BF006A440F0C92039D3685D13096
                                                                    SHA-512:E31A85134F96F2AB82FA9B9B89BBFBA9EAF15035A397EDA4630D6F42A2859FBED98A112AE4560054D571F836C12C17024821926659AFDABD0C588557D99BEE50
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="1000" V="5" DC="ESM" EN="Office.Telemetry.RuleErrorsAggregated" ATT="f998cc5ba4d448d6a1e8e913ff18be94-dd122e0a-fcf8-4dc5-9dbb-6afac5325183-7405" SP="CriticalBusinessImpact" S="70" DL="A" DCa="PSP PSU" xmlns="">.. <S>.. <Etw T="1" E="159" G="{02fd33df-f746-4a10-93a0-2bc6273bc8e4}" />.. <F T="2">.. <O T="AND">.. <L>.. <O T="NE">.. <L>.. <S T="1" F="Warning" />.. </L>.. <R>.. <V V="37" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="NE">.. <L>.. <S T="1" F="Warning" />.. </L>.. <R>.. <V V="29" T="U32" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <TI T="3" I="10min" />.. <A T="4" E="TelemetrySuspend" />.. <A T="5" E="TelemetryShutdown" />.. </S>.. <G I="true" R="TriggerOldest">.. <S T="2">.. <F N="RuleID" />..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):950
                                                                    Entropy (8bit):5.13263189574204
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dxlKvDb0wGorplx2Lx2divhC152lU00I:cxIRlasomo/0I
                                                                    MD5:11B08F2379BDB049177FAE40A8411612
                                                                    SHA1:42689E356E86F48979F3A338F9ACA5C92CC5A911
                                                                    SHA-256:70BF709198724DA28FC0AFD3B4DB93F514586ACDD769837B367563FAE256DB1E
                                                                    SHA-512:A4584D522DF9196CE0401A593FA284DF21DC9C5D9D7765AF989838AAFB26EB5DCEE3FDA2D3A3AE535C2E7627B24EB6201CF4A78D8298F4E49CD6D33A81B42B21
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100104" V="2" DC="SM" EN="Office.UX.Desktop.SmartContextMenu" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" DCa="PSU" xmlns="">.. <RIS>.. <RI N="ExperimentationCustomData" />.. </RIS>.. <S>.. <UTS T="1" Id="cplfq" />.. </S>.. <C T="G" I="0" O="false" N="ContextMenuSessionId">.. <S T="1" F="ContextMenuSessionId" />.. </C>.. <C T="U64" I="1" O="false" N="TimeTakenBySuggestionProvider">.. <S T="1" F="TimeTakenBySuggestionProvider" />.. </C>.. <C T="U64" I="2" O="true" N="ContextMenuTcid">.. <S T="1" F="ContextMenuTcid" />.. </C>.. <C T="W" I="3" O="true" N="Information">.. <S T="1" F="Information" />.. </C>.. <C T="U32" I="4" O="false" N="UserActionID">.. <V V="0" T="U32" />.. </C>.. <C T="W" I="5" O="false" N="UserActionName">.. <V V="SmartContextMenu_SessionInfo" T="W" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):841
                                                                    Entropy (8bit):5.1130725494870894
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdYislFun8DWyZcAAwHmdertHwr28KCQmFrnytg/84ADFNyFkd+DO2klU3gNOQ:2dclFvDb0wGoryoK3kLD+8lU3I
                                                                    MD5:9991F4C1B6E9408129E4545E3E0C5094
                                                                    SHA1:D57948CEFBEDF08FBA780948F3D8BA208DB1AF76
                                                                    SHA-256:BF1A2025122E71688D123BECAA5B58C35A36DA5FB321F3FECF4D58153975B399
                                                                    SHA-512:502B5BF8FF233D15E8081ED99811AC1F5F3F6F63C8283E5D7FEF5C94571388B69979800F65EF2E0C90383B4D6A594D990EDF1CDEAB12393FEBCBC8FE90E00A20
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100105" V="0" DC="SM" EN="Office.UX.Desktop.SmartContextMenuItem" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" DCa="PSU" xmlns="">.. <RIS>.. <RI N="ExperimentationCustomData" />.. </RIS>.. <S>.. <UTS T="1" Id="ctgzk" />.. </S>.. <C T="G" I="0" O="false" N="ContextMenuSessionId">.. <S T="1" F="ContextMenuSessionId" />.. </C>.. <C T="I32" I="1" O="false" N="SuggestedTcid">.. <S T="1" F="Tcid" />.. </C>.. <C T="I32" I="2" O="false" N="CommandPosition">.. <S T="1" F="Position of suggested tcid" />.. </C>.. <C T="U32" I="3" O="false" N="UserActionID">.. <V V="0" T="U32" />.. </C>.. <C T="W" I="4" O="false" N="UserActionName">.. <V V="SmartContextMenu_MenuItemInfo" T="W" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1045
                                                                    Entropy (8bit):5.1005145953903295
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdY1qgkIun8DWyZcAAwHmderm828KR/utxfHxlF82yp1DEfE5kyjkdKO2klU5k:2dvIvDb0wGorwY/Fk1I85kpKIlU5LI
                                                                    MD5:F06A86C81121B490ECBCD2104D19C599
                                                                    SHA1:F18D7727120EBA5FCFE8536E3FE34E68A2620D61
                                                                    SHA-256:7D72509EBFEFA8422109C6EED61991763C6D9A2E3BC2BDBDA2D8D2FC741A5094
                                                                    SHA-512:32B47E5796409DBCC70360311D0752B562F4D8DB657464E6FB39DD134CD31B326F9B2378476077E997EF53B0C707A86A365AA1945A24B097F0BBCB182F865026
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100106" V="0" DC="SM" EN="Office.UX.Desktop.ContextMenuItemClick" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" DCa="PSU" xmlns="">.. <RIS>.. <RI N="ExperimentationCustomData" />.. </RIS>.. <S>.. <UTS T="1" Id="ctgys" />.. </S>.. <C T="G" I="0" O="false" N="ContextMenuSessionId">.. <S T="1" F="ContextMenuSessionId" />.. </C>.. <C T="I32" I="1" O="false" N="CommandPosition">.. <S T="1" F="CommandPosition" />.. </C>.. <C T="I32" I="2" O="false" N="CommandType">.. <S T="1" F="Command Type" />.. </C>.. <C T="I32" I="3" O="false" N="ResultBindingTcid">.. <S T="1" F="ResultBindingTcid" />.. </C>.. <C T="I32" I="4" O="false" N="ExecutedControlTcid">.. <S T="1" F="ExecutedControlTcid" />.. </C>.. <C T="U32" I="5" O="false" N="UserActionID">.. <V V="0" T="U32" />.. </C>.. <C T="W" I="6" O="false" N="UserActionName">.. <V V="SmartContextMenu_MenuItemClickInfo" T="W" />..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):545
                                                                    Entropy (8bit):5.118071593489877
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdYNxun8DWyZcAAwEerJ7sWtlZXaWtvMfZvwxdy96JfMyxNO2su:2dwxvDb0wLrhdM5wrR0y3
                                                                    MD5:9AA744D5B6B17CD62043AF4E53E7B38F
                                                                    SHA1:D8DBC753961C8404F8D873278E7AB53238C683A7
                                                                    SHA-256:2586C46FF798CBCAC590A3506190AA94DE2A483B31EA20BADABFBED1CFE74AC0
                                                                    SHA-512:D5CD6D35E45B8C3F826762D3AD183E17FFEBDF1E88CE9541D668B14A466184F0E127F67EEF548D821B690675872EF31E67A7203CE38FE77B72790C6EA88E6718
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100109" V="1" DC="SM" EN="Office.UX.HostedSurveyShowed" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="cmgze" />.. </S>.. <C T="W" I="0" O="true" N="SurveyId">.. <S T="1" F="SurveyId" />.. </C>.. <C T="U32" I="1" O="true" N="SurveyType">.. <S T="1" F="SurveyType" />.. </C>.. <C T="W" I="2" O="true" N="ManifestSubType">.. <S T="1" F="ManifestSubType" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):460
                                                                    Entropy (8bit):5.1674364373796875
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd5d20QTun8DWyZcAAwEer+sWtlZXaWtvMfZvwxNO2su:2d5d20QTvDb0wLr+dM5w3
                                                                    MD5:BE4F266143658422F4649C9A2CCF6B60
                                                                    SHA1:FDBC871B6F3403285D9CB928AA42694C645792A3
                                                                    SHA-256:777A02FD054568BBA52B024BC36BB0F9428F5912D1A77F3C0A1AE9BB38305613
                                                                    SHA-512:787D7A32BC01B4081BECB4E2EFAFFCD7DE4F6123620D9707FCCADB7E058ABD40FC15792AAB5EF65BECC8BEF43CBF9469DA22313AFB39656464B44B6BFB3F26E1
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100110" V="1" DC="SM" EN="Office.UX.UpgradeOfficeButtonClicked" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="c7xsl" />.. </S>.. <C T="W" I="0" O="true" N="SurveyId">.. <S T="1" F="SurveyId" />.. </C>.. <C T="U32" I="1" O="true" N="SurveyType">.. <S T="1" F="SurveyType" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):409
                                                                    Entropy (8bit):5.271528662709587
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdTdkOun8DWyZcAAwEerm73tOpvNO2su:2d5bvDb0wLr0U/
                                                                    MD5:02042A13C2C5CD1B3EDC95A6B15E4FC7
                                                                    SHA1:F08188D7215D13A767C4D4FC517BFA881D985712
                                                                    SHA-256:034C44375BF10EF9DF06C6D354EF65C6739D8E467A2F17F2F169C92001EC038F
                                                                    SHA-512:DCC10C3B5065BC5CC7C86834DCEEB9948CA30CF76FCC88F68F6A4BC9048D65D3705BE1380C5F0AC28B738DC38DDBAB122C6A248E460F61D497C294FE8AF3007F
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100124" V="2" DC="SM" EN="Office.UX.TeachingCallout.TeachingCalloutSuppressed" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="4qnt4" />.. </S>.. <C T="W" I="0" O="false" N="TeachingCalloutId">.. <S T="1" F="TeachingCalloutId" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):509
                                                                    Entropy (8bit):5.2429290585512724
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdYdk9un8DWyZcAAwEerHFU3tOpvStMSAY9NO2su:2du8vDb0wLrH+UctMgz
                                                                    MD5:03AED7AA46EBBB9175F30A2BF8F7F530
                                                                    SHA1:F0FA4FAC253E9DE69F814A464BEA53DCDB6D6D7C
                                                                    SHA-256:71BE055A91F15DAAF9F37FA90A0A65D6EBC7C20CEF1D41445854500576F7F068
                                                                    SHA-512:468F848A7DA60EFCDE910031D3AED6E1A9E84016DCA7540B9C4AD3A00492056D3D57E5C596756665B18CA6F661280B22C84594F004110E6E7BBF761B8E206128
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100125" V="2" DC="SM" EN="Office.UX.TeachingCallout.TeachingCalloutFailedToCreateWICFactory" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bisgt" />.. </S>.. <C T="W" I="0" O="false" N="TeachingCalloutId">.. <S T="1" F="TeachingCalloutId" />.. </C>.. <C T="U32" I="1" O="false" N="APIHResult">.. <S T="1" F="APIHResult" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):515
                                                                    Entropy (8bit):5.259684957183188
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd5PdkMSBun8DWyZcAAwEerHFLS3tOpvStMSAY9NO2su:2d51kBvDb0wLrHsUctMgz
                                                                    MD5:170633F0EAB1976D69AF72CD49C6766E
                                                                    SHA1:426EB2461DF891C78C7228EA87262E643D721CBC
                                                                    SHA-256:A1CECD578E1263D01D03633FF36054F5299E6F1F6AB39B1C46D75FBC6005655A
                                                                    SHA-512:F50B9A8422EF1DE054081299EF156C6B436D945A1D6F214CD613BDA1A0CC3B14DD393DB54DB760264B81789900B5DC514D858A5EA111961B04335979B701C130
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100126" V="2" DC="SM" EN="Office.UX.TeachingCallout.TeachingCalloutFailedToGetDecoderFromFilename" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bisgv" />.. </S>.. <C T="W" I="0" O="false" N="TeachingCalloutId">.. <S T="1" F="TeachingCalloutId" />.. </C>.. <C T="U32" I="1" O="false" N="APIHResult">.. <S T="1" F="APIHResult" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):501
                                                                    Entropy (8bit):5.234524039048711
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdWdkLpun8DWyZcAAwEerHFY3tOpvStMSAY9NO2su:2dkkvDb0wLrHyUctMgz
                                                                    MD5:85C60DF6C18137A60BF1A03F35F2EEB5
                                                                    SHA1:F6A5401EC2E7AAF2B706A0FBB694BB84CE41F2D3
                                                                    SHA-256:A31B06DD5540239D68D5F75CF8FC416C1FD5C24A8237EEC8DDD07CE3DFBD92E3
                                                                    SHA-512:AA0766C418EDAC12F5CABA90807FB800E40EB6A6D4A4EDB167755126869F05B295BD3D35B033C06FF7CD1856B77C0A0011C5A095420D8223A0F10ADA3EC80087
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100127" V="2" DC="SM" EN="Office.UX.TeachingCallout.TeachingCalloutFailedToGetFrame" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bisgx" />.. </S>.. <C T="W" I="0" O="false" N="TeachingCalloutId">.. <S T="1" F="TeachingCalloutId" />.. </C>.. <C T="U32" I="1" O="false" N="APIHResult">.. <S T="1" F="APIHResult" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):418
                                                                    Entropy (8bit):5.254995423773981
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdmdkdun8DWyZcAAwEerX3tOpvNO2su:2dUGvDb0wLrXU/
                                                                    MD5:05F479C943851C6FF70E8762CFCAF94A
                                                                    SHA1:98E7C7D2BC7B278F491C7F00F44A42BD8D935E57
                                                                    SHA-256:F19EDD0DEC9F58B711ACD45E52409321BFF693853557690E9CEDB0BD0E71A942
                                                                    SHA-512:23322F5E4CB27432114C91EED94D6FF6E654B63EFA6D28B364CCF01E83306699BAE5869F27B2D295B67070CCB4EC3991DF32B2973D50A23BB1D3D3E6779A7CC4
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100128" V="1" DC="SM" EN="Office.UX.TeachingCallout.TeachingCalloutFailedToCreateVideo" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bl7ep" />.. </S>.. <C T="W" I="0" O="false" N="TeachingCalloutId">.. <S T="1" F="TeachingCalloutId" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):418
                                                                    Entropy (8bit):5.258730267850173
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdcdkxtun8DWyZcAAwEerLVU73tOpvNO2su:2dysvDb0wLr4U/
                                                                    MD5:3BE6320F54CACC68FF5332D7F19017AF
                                                                    SHA1:34321424619ABF9C69E03109C6AC9633C09A0490
                                                                    SHA-256:B10674D4BB061FB003BACC6AFBE070A7183D2D1A287099936FFFB931E3D5F5EE
                                                                    SHA-512:252A8498605D19C3DAF5ED983C40541A6E77B1BAA6AF9BBDC63228C2A81C79076AC3EB405393BB902C79F70E644D7AA103EA8D7FF0D8614C2E432F9143A6FEDE
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100129" V="2" DC="SM" EN="Office.UX.TeachingCallout.TeachingCalloutFailedToCreateImage" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bep2n" />.. </S>.. <C T="W" I="0" O="false" N="TeachingCalloutId">.. <S T="1" F="TeachingCalloutId" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):485
                                                                    Entropy (8bit):5.202017526192053
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdBCvdun8DWyZcAAwEerD43tOpvdmARNO2su:2dGdvDb0wLrkUDT
                                                                    MD5:765304F24D02DEB0E55BE018E9FEFB99
                                                                    SHA1:9B3D0B42621BCF5A5EE53B01E1D841EF21776DE9
                                                                    SHA-256:7962562BFB89190AD2B7C932D1EAC211A8533B7A6D8842736FDB2424EABA22AB
                                                                    SHA-512:CC1E376C53E372A762B4916BDA601EB0D67B337EBCD7E8FD85D3CBD5E0FC1E04E0EEAEAD489D86E354B8B1265DEE491AC594B52A77858F4D7EBB0B3A93779098
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100130" V="0" DC="SM" EN="Office.UX.TeachingCallout.AnchorInvalidCallback" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bmzya" />.. </S>.. <C T="W" I="0" O="false" N="TeachingCalloutId">.. <S T="1" F="TeachingCalloutId" />.. </C>.. <C T="W" I="1" O="false" N="AnchorId">.. <S T="1" F="AnchorId" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):639
                                                                    Entropy (8bit):5.057028798011694
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdy/dkkLun8DWyZcAAwEerZ3tOpvdmARdyEXqdUNIdNO2su:2dClvDb0wLrZUD/Ip
                                                                    MD5:FE6EFF7CC51E8C64DAFE15F2F5B08F0A
                                                                    SHA1:3619F72BC2A5656EDA6B3098629BC1D43F567143
                                                                    SHA-256:DCA842112B5A586E2B07AC91EE140B305C57F4004D40CAF8E8AFC09D4FFE2089
                                                                    SHA-512:00E577AEFF86E2F062336BA1C634F087B62C824F0D7EADC92B8971A6A3D6532853458E1F2CB7AFF4C11141681CAE3EC77068EEEC0CA9CB01F3A21A5168D7EC96
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100131" V="1" DC="SM" EN="Office.UX.TeachingCallout.TeachingCalloutCoachmarkShown" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="4qnuf" />.. </S>.. <C T="W" I="0" O="false" N="TeachingCalloutId">.. <S T="1" F="TeachingCalloutId" />.. </C>.. <C T="W" I="1" O="false" N="AnchorId">.. <S T="1" F="AnchorId" />.. </C>.. <C T="W" I="2" O="false" N="Title">.. <S T="1" F="Title" />.. </C>.. <C T="W" I="3" O="false" N="Info">.. <S T="1" F="Info" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):656
                                                                    Entropy (8bit):5.097491847536972
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdVndkkD5kEcFdun8DWyZcAAwEeri3tOpvdmARdyEXqdUNIdNO2su:2dzNLc7vDb0wLriUD/Ip
                                                                    MD5:109B2CA6601FAFC1E0C81848FE7B35FF
                                                                    SHA1:012627B761E319EB73B51190DC3D884FE84D7D8D
                                                                    SHA-256:1E6A4E86CEF8C6EB85D2297E959D418BEA102DAD9133177462800CB4AF3E8533
                                                                    SHA-512:D97E22E0E603B06C1EFCFFAFFA413BF2AE4231545D717063D01E6D7445985F7E6CA65D89FE961F2C7BDC65A28AA93C88224C007715CA2A6B171D97DB7D27DA18
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100132" V="1" DC="SM" EN="Office.UX.TeachingCallout.TeachingCalloutCoachmarkHiddenWithoutExpanding" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="4qnue" />.. </S>.. <C T="W" I="0" O="false" N="TeachingCalloutId">.. <S T="1" F="TeachingCalloutId" />.. </C>.. <C T="W" I="1" O="false" N="AnchorId">.. <S T="1" F="AnchorId" />.. </C>.. <C T="W" I="2" O="false" N="Title">.. <S T="1" F="Title" />.. </C>.. <C T="W" I="3" O="false" N="Info">.. <S T="1" F="Info" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):643
                                                                    Entropy (8bit):5.0658952579474645
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdo/dkk8Lun8DWyZcAAwEerPMS3tOpvdmARdyEXqdUNIdNO2su:2doFuLvDb0wLrPMSUD/Ip
                                                                    MD5:3711CCBD08320FAE2AEE12194EA45A68
                                                                    SHA1:970D1B229C11C851E0964A7C0F333377734F1D10
                                                                    SHA-256:78AFCBBCFDE75A7DEB70B8AE80213D76D06D824D5F494719081F507E791E889D
                                                                    SHA-512:5300894FDDB0A075E7DA7FE828000B64EDB7795E47219EAB2BD7504E7C1D058381CB213D59D587185F92A40AB6F029E4AEB29E4DA83984983C409B9864B68ACD
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100133" V="1" DC="SM" EN="Office.UX.TeachingCallout.TeachingCalloutCoachmarksTUIShown" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="4qnud" />.. </S>.. <C T="W" I="0" O="false" N="TeachingCalloutId">.. <S T="1" F="TeachingCalloutId" />.. </C>.. <C T="W" I="1" O="false" N="AnchorId">.. <S T="1" F="AnchorId" />.. </C>.. <C T="W" I="2" O="false" N="Title">.. <S T="1" F="Title" />.. </C>.. <C T="W" I="3" O="false" N="Info">.. <S T="1" F="Info" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):742
                                                                    Entropy (8bit):5.0659835404992695
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdNAOdkk8/LIun8DWyZcAAwEerhS3tOpvdmARdyEXqdUNIdnHD9rgL0NO2su:2dN/ucvDb0wLrhSUD/IDR1
                                                                    MD5:570EE9E464A3F9CF12C8FB0F50B48E06
                                                                    SHA1:AC394C063E80F880195FE859048B90BB2E42891F
                                                                    SHA-256:B881023859406F131865B38F176EA00D08C3D9A0BEDBF9BB189BF051D99504D5
                                                                    SHA-512:97EB77C67DF5604B3A6ADFB0911446492C9B83C87D1FB8A47B9D84AA16162489FEAAFCE1112C6A720B2DC02579FF9F55E64BFD5AAAC998461DDDE6FA4A967B8E
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100134" V="1" DC="SM" EN="Office.UX.TeachingCallout.TeachingCalloutCoachmarksTUIHidden" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="4qnuc" />.. </S>.. <C T="W" I="0" O="false" N="TeachingCalloutId">.. <S T="1" F="TeachingCalloutId" />.. </C>.. <C T="W" I="1" O="false" N="AnchorId">.. <S T="1" F="AnchorId" />.. </C>.. <C T="W" I="2" O="false" N="Title">.. <S T="1" F="Title" />.. </C>.. <C T="W" I="3" O="false" N="Info">.. <S T="1" F="Info" />.. </C>.. <C T="B" I="4" O="false" N="CalloutAlwaysShow">.. <S T="1" F="CalloutAlwaysShow" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):409
                                                                    Entropy (8bit):5.284731259430513
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd0Q4Iun8DWyZcAApAQierVLE7WNoSNO2su:2dN4IvDb0/r9H
                                                                    MD5:1EA191226A363A271C15C2F470CA5A27
                                                                    SHA1:88C8FFA286C023D049F764164C905993F326AF75
                                                                    SHA-256:5AB9DBD686E3724114A39F1F5B743186C3E54BDA7651C7116484CBFE2472EA20
                                                                    SHA-512:BA80F037204D9050EBC138C88657810F7D26552608D942678853B05F3E7A90B9960BA92C5E460F37C6927614FBE6474AAC271BDD935C667D1108A68A731267E3
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100201" V="0" DC="SM" EN="Office.UX.HyperlinkDialogControlTriggered" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bg4y8" />.. </S>.. <C T="U32" I="0" O="false" N="Surface">.. <S T="1" F="Surface" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):595
                                                                    Entropy (8bit):5.183023140804415
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdZqRoun8DWyZcAApAQierRD2HXAGMnPyfY7KMyntwKXO+NO2su:2d4CvDb0/rRa95qKEz+
                                                                    MD5:0DF2BC07A6BBFDF8FA8DAFF18DE89752
                                                                    SHA1:95BFD0A56DF9F1B8CBB157C102EFCD17E7D13813
                                                                    SHA-256:7C039ED8E77E4B44A8A4EDC8DDD3F020893B8EE3588E52A31505774EF53A882C
                                                                    SHA-512:17DDC165955D9C28519AB0FF4B82F80F3757A7063289C12D25A8146558380FBC311B56C9C8CC633831466430A14A3ED233DD0454217F172A2ADA487CADE2F094
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="100202" V="0" DC="SM" EN="Office.UX.HyperlinkDialogInsert" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bhdvx" />.. </S>.. <C T="U32" I="0" O="false" N="ActivePane">.. <S T="1" F="ActivePane" />.. </C>.. <C T="B" I="1" O="false" N="HasScreenTip">.. <S T="1" F="HasScreenTip" />.. </C>.. <C T="B" I="2" O="false" N="HasDistinctFriendly">.. <S T="1" F="HasDistinctFriendly" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):3146
                                                                    Entropy (8bit):4.508946786981067
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dpW/dRgell5hl5Sl5Il5kl5Vl5nV/l5oiml5/s/ghTPrTPU2PqTPwSH8PB15/fw:cpWVRgeTrsST/s22taZ3ijd7
                                                                    MD5:6FF3467268BD237803A45014883BB526
                                                                    SHA1:F5DDFEEAAE8B71F3AC671F309822D45BB42033E0
                                                                    SHA-256:2AC1F2E48418DA10E57310FD901C76F19F8764ADE0E6570EF1E2ACF3D199845D
                                                                    SHA-512:690531C90F83679ED68B8F4694A28C0CEBD84675DF19248939797DCF3CFE9D04859EFEDE7954F0FB16A56D8688784C0E27D2B350EA31678C20DB9DD7B30A6235
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10100" V="4" DC="SM" EN="Office.Outlook.Desktop.ImapSessionStatistics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="104" G="{265f23e0-615d-4082-8e17-ddcd7e6f7eb4}" />.. <Etw T="2" E="107" G="{265f23e0-615d-4082-8e17-ddcd7e6f7eb4}" />.. <Etw T="3" E="110" G="{265f23e0-615d-4082-8e17-ddcd7e6f7eb4}" />.. <Etw T="4" E="111" G="{265f23e0-615d-4082-8e17-ddcd7e6f7eb4}" />.. <Etw T="5" E="114" G="{265f23e0-615d-4082-8e17-ddcd7e6f7eb4}" />.. <Etw T="6" E="136" G="{265f23e0-615d-4082-8e17-ddcd7e6f7eb4}" />.. <Etw T="7" E="137" G="{265f23e0-615d-4082-8e17-ddcd7e6f7eb4}" />.. <Etw T="8" E="135" G="{265f23e0-615d-4082-8e17-ddcd7e6f7eb4}" />.. <F T="9">.. <O T="EQ">.. <L>.. <S T="2" F="Cookie" />.. </L>.. <R>.. <V V="2" T="I32" />.. </R>.. </O>.. </F>.. <F T="10">.. <O T="OR">..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):727
                                                                    Entropy (8bit):5.108505754989354
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdDRSVzjx5dRDDHwpat5rkimbx5blVGS6a9S6yp9DuMbHyKS/rmNOqHNUlu:2dgT5dRgeWiml5bPjqHbHmA7
                                                                    MD5:2B9151DFC36BEA465EE7FBBDB954C535
                                                                    SHA1:5AEB74704975487E194AD391CD5C85A3221E64F4
                                                                    SHA-256:F6F01D681A446C0770D08489DD51189DA4CDD2EB8C5E6890FF036FA399E39A34
                                                                    SHA-512:D75FA40A4E3181B123B04C16A8CDB4DEEA74B7149E4F640CC891D8592BB7E89D31DE2986C5238D74BFCC3626608667701D2FF4B0747864850E9D73A728043F09
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10101" V="1" DC="SM" EN="Office.Outlook.Desktop.ImapRedownloadedMessagesDetail" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="10" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="135" G="{265f23e0-615d-4082-8e17-ddcd7e6f7eb4}" />.. </S>.. <C T="FT" I="0" O="false" N="EventTime">.. <S T="1" F="TimeStamp100ns" />.. </C>.. <C T="U32" I="1" O="true" N="FolderUid">.. <S T="1" F="FolderUid" />.. </C>.. <C T="U32" I="2" O="true" N="MessageUid">.. <S T="1" F="MessageUid" />.. </C>.. <C T="U32" I="3" O="false" N="Reason">.. <S T="1" F="Reason" />.. </C>.. <T>.. <S T="1" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):3581
                                                                    Entropy (8bit):4.319953654572439
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dKkNF0ClsP6pBk370emPAPm3VZPD+KPMmB/1uPWqQpQPaX4PZqK7TPXq3wiPlXe:cnxsC3DjwXHQz/IER2
                                                                    MD5:FFB8D60DF34E2B842ADBE605BA68D3BB
                                                                    SHA1:56034F7C1A9302916BCBB5C26B5395A1C027F663
                                                                    SHA-256:863AA2C79B6B94241211F41954762B70F073C06491AE2CDC04694393F6F55DD3
                                                                    SHA-512:9387BC2E91C898CA7C2D84793FA2FAC98E783588AEA6622742679B8068A99EAA63617047A2C55065BDB7B22F9F12E193A1E6F27FF329CD5526510FE2A878B52B
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10111" V="3" DC="ESM" T="Subrule" xmlns="">.. <S>.. <TI T="1" I="1min" />.. <Etw T="2" E="4086" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <Etw T="3" E="270" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <Etw T="4" E="4106" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <Etw T="5" E="566" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <Etw T="6" E="675" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <Etw T="7" E="676" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <Etw T="8" E="277" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <R T="9" R="10408" />.. <R T="10" R="10111" />.. </S>.. <G>.. <S T="2">.. <F N="ConnID" />.. </S>.. <S T="3">.. <F N="ConnID" />.. </S>.. <S T="4">.. <F N="ConnID" />.. </S>.. <S T="5">.. <F N="ConnID" />.. </S>.. <S T="6">.. <F N="ConnID" />.. </S>.. <S T="7">.. <F N="ConnID" />.. </S>.. <S T="10">..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):2575
                                                                    Entropy (8bit):4.943690754092889
                                                                    Encrypted:false
                                                                    SSDEEP:48:cCaKK+RgemvSpfSPc6qCh3Jbf6/i0iC/Rakf:vRgemi2q6JbAdJX
                                                                    MD5:51C90B69B876269DC33BD8D8FEA793E3
                                                                    SHA1:7AD16FA0855410498763EBCC126C164C262993E4
                                                                    SHA-256:68863C7CF677C677A6349F09BCAC56136B1FC2676BFA5BBE4D1FBC8CD7D02654
                                                                    SHA-512:9427D8441953C82D70BD215313D2DC9A95D55C5575E057BA5DA13A67C3B4A81C2D4B09F75898803305D73002A978C7E58D8E146B804210E1924B4898B327F057
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10119" V="5" DC="SM" EN="Office.Outlook.Desktop.OutlookLayout" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="8100" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="1" F="TimeStamp100ns" />.. </C>.. <C T="B" I="1" O="false" N="AwesomeBarExpanded">.. <S T="1" F="AwesomeBarExpanded" />.. </C>.. <C T="B" I="2" O="false" N="TouchModeOn">.. <S T="1" F="TouchModeOn" />.. </C>.. <C T="B" I="3" O="false" N="PortraitModeOn">.. <S T="1" F="PortraitModeOn" />.. </C>.. <C T="U32" I="4" O="false" N="DPI">.. <S T="1" F="DPI" />.. </C>.. <C T="U32" I="5" O="false" N="ScreenResolutionX">.. <S T="1" F="ScreenResolutionX" />.. </C>.. <C T="U32" I="6" O="false" N="ScreenResolutionY">.. <S T="1" F="ScreenResolutionY" />..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):852
                                                                    Entropy (8bit):5.106585100855806
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdT2CVzjRdRDDHwpatE4HmDaHcoNBiPQxlVZmOJBRXHaSMpRVr7XHhSMNOAdHb:2djXdRgewovFPrRcr7D7
                                                                    MD5:AB10F26BADEC1D42F0080AC8A2EC289A
                                                                    SHA1:7780651F9B12BEBC502FC0D6A73F8BB397270CF4
                                                                    SHA-256:EB84D268F96520E655D4D409569B5100DE0D36110E7985C2309F3CDAF40A3601
                                                                    SHA-512:6A221BBB0803016BEFD49C195F5BC3515C84BA4B81C76C0CAB8C904257D4AB884786356EA3FFD4A07D65A473E15D058358E2FB403FDD1455DE47FA42E1CD7289
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10145" V="2" DC="SM" EN="Office.Outlook.Desktop.AttachmentsFailure" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="4110" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="4112" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="3" I="Daily" />.. <A T="4" E="TelemetryShutdown" />.. <TR T="5" />.. </S>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="5" F="TimeStamp100ns" />.. </C>.. <C T="U32" I="1" O="false" N="GalleryClosedCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="GalleryBrowseButtonClickCount">.. <C>.. <S T="2" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="4" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):3877
                                                                    Entropy (8bit):3.925777788823839
                                                                    Encrypted:false
                                                                    SSDEEP:48:cfcRgehqyQJJeuDvQsW0mpDfu/s+GtLY7:PRge9Sg24agDfuBOY7
                                                                    MD5:49F5C886CD66DFFE23CABB589481F00C
                                                                    SHA1:B1135101F93767957D9B29212B78C80BFA3A0851
                                                                    SHA-256:D627E61866107DB48D77661FD746744F6A9EEEEA0193077EFAD152E1A6BF3970
                                                                    SHA-512:48AE868716DBF64EDC8B3F8F2DB9E6578808F3B68011503794973880774F23A0B5F511A6786AB2E8C7A36A2FB99A1A06A3EFA6EE5D0693A269B68CD1DCC9C5FC
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10146" V="1" DC="SM" EN="Office.Outlook.Desktop.AttachmentsSuccess" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="4111" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <TR T="4" />.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="Index" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="Index" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="1" F="Index" />.. </L>.. <R>.. <V V="2" T="U32" />.. </R>.. </O>.. </F>.. <F T="8">.. <O T="EQ">.. <L>.. <S T="1" F="Index" />.. </L>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):760
                                                                    Entropy (8bit):5.190312368254792
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdIVzjTzhdRDDHwpatETswXFJicoNKlVGSLWT8oXHaSMp/bSAWNywfXNOBsu:2dIRldRgeOsEvSkPCTA5
                                                                    MD5:272EB1EC59F9D51625FA2D7446C8DADE
                                                                    SHA1:6CC60666ABB895525230A71284CA7661606D26E6
                                                                    SHA-256:B749DE176193BB7EE0F1B220D20A4FAE1CD8F91AD49FAC187189F089DB4387C8
                                                                    SHA-512:2B27990B8A1A0C80FAB8757B1D5AE938BD7C15869FA2EFE3030D0FA9D607917A015D9D1CD21C8CA17956A1030C4B0FDA542002E029ED74D63FFB448BADC39D4D
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10148" V="0" DC="SM" EN="Office.Outlook.Desktop.SearchSessionQueries" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="7001" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <SQ T="4" R="([2]|[3])" />.. </S>.. <C T="FT" I="0" O="false" N="EventTime">.. <S T="4" F="TimeStamp100ns" />.. </C>.. <C T="U32" I="1" O="false" N="SearchSessionCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="TotalDistinctQueries">.. <A T="SUM">.. <S T="1" F="FollowUpQueries" />.. </A>.. </C>.. <T>.. <S T="4" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):579
                                                                    Entropy (8bit):4.8007189542904944
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdSOfwHNaHlFylVDdIb8OKX/c//fpONkQz:2deO4P9/z
                                                                    MD5:0DEFB7361DF6139054B2DD12853092E0
                                                                    SHA1:74F3DCC66C980937F6E134F9A71206ADD50D247F
                                                                    SHA-256:75628F173F32E77C6EC3115D6733346B2BE6A032D6199EDAF34440A27B40A67F
                                                                    SHA-512:3B6D2227BAB188BFFAB098EB9E9EAA8F2B427609AA43FE849AAD1AD1EC863DF57FAF37CDAB3356CF9D68C0009EB5672F3BB726A3015B36495A07C756932C4C80
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10155" V="1" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="4104" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="4105" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="FT" I="0" O="false">.. <S T="2" F="TimeStamp100ns" />.. </C>.. <C T="U32" I="1" O="false">.. <U T="100nsToMs">.. <O T="SUB">.. <L>.. <S T="2" F="TimeStamp100ns" />.. </L>.. <R>.. <S T="1" F="TimeStamp100ns" />.. </R>.. </O>.. </U>.. </C>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):579
                                                                    Entropy (8bit):4.7993548413267595
                                                                    Encrypted:false
                                                                    SSDEEP:6:TMVBd7p+HfHSH4IyuUNIyubjxPVL/kylnJUq+/bwe/NX7Su//My6X/c//zy6B/O1:TMHdEfZHZylVDdIb8OKX/c//fpONkQz
                                                                    MD5:2DF47221FCD5ACFE77DB18C83E99AB2D
                                                                    SHA1:8209F1E0F885E2906685964E529E1DA018F9345B
                                                                    SHA-256:826DEB2CDEAB0229866D098A86A8F5E1BA6F9DBEE212D801D5B4DCB42CB94CEC
                                                                    SHA-512:34B53783DD5EB157529326A43F89829E59A9B651737CCE0EDC720E0F549106A7C40CA7AE79487BD642D55D17A1E22EC8288B12416DACABC2110196AC2875C10C
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10156" V="1" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="4106" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="4107" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="FT" I="0" O="false">.. <S T="2" F="TimeStamp100ns" />.. </C>.. <C T="U32" I="1" O="false">.. <U T="100nsToMs">.. <O T="SUB">.. <L>.. <S T="2" F="TimeStamp100ns" />.. </L>.. <R>.. <S T="1" F="TimeStamp100ns" />.. </R>.. </O>.. </U>.. </C>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):579
                                                                    Entropy (8bit):4.798169602663376
                                                                    Encrypted:false
                                                                    SSDEEP:6:TMVBd7rfHDRIyuUzIyubjxPVL/kylnJUq+/bwe/NX7Su//My6X/c//zy6B/ONkQz:TMHdHfjFH7ylVDdIb8OKX/c//fpONkQz
                                                                    MD5:62E54506D475F39D5D6ADDA2D649C90B
                                                                    SHA1:FAA204C07798F56D4ACAA03DD3E0DCBF2CA63A04
                                                                    SHA-256:7A9AAFCCC77ABEC5724396BC8C0F3610A32B61BFD45A189ECB5FDE04ED2D0A67
                                                                    SHA-512:1C884BFAA4BAE6E9806196B7D454BD200481F2AFC565EAB3B5658C1120EDC3DB65B2332466B620D52B8392517D9D3E6FEC4290EA353A85D458A9B585DCBA8D4C
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10157" V="1" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="4115" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="4116" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="FT" I="0" O="false">.. <S T="2" F="TimeStamp100ns" />.. </C>.. <C T="U32" I="1" O="false">.. <U T="100nsToMs">.. <O T="SUB">.. <L>.. <S T="2" F="TimeStamp100ns" />.. </L>.. <R>.. <S T="1" F="TimeStamp100ns" />.. </R>.. </O>.. </U>.. </C>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):579
                                                                    Entropy (8bit):4.7968257638721274
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdif0HYHLylVDdIb8OKX/c//fpONkQz:2dHjP9/z
                                                                    MD5:655AA6B7E0D318C3CC36CBF6119D9848
                                                                    SHA1:2C581E12C2E0487D239FB580BACF839C0B17D9FA
                                                                    SHA-256:218C268719118758D6A61A1970BE9478C7E42A16CEE3654289BE9A41C270204F
                                                                    SHA-512:BD5D5F80C41ADDE63B1B8DFD9DD4247E30F413B4DCEC395FCFA1D2342F929BAA2694CA9A6D71AEAFAC28906014084C9226FFECAACB94AA44589753930A3355A1
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10158" V="1" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="4100" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="4101" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="FT" I="0" O="false">.. <S T="2" F="TimeStamp100ns" />.. </C>.. <C T="U32" I="1" O="false">.. <U T="100nsToMs">.. <O T="SUB">.. <L>.. <S T="2" F="TimeStamp100ns" />.. </L>.. <R>.. <S T="1" F="TimeStamp100ns" />.. </R>.. </O>.. </U>.. </C>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):8281
                                                                    Entropy (8bit):3.9192806348703595
                                                                    Encrypted:false
                                                                    SSDEEP:48:cZXRgeATkQXJiuNvb0shlXl6fg5Si+rKSYl/z+M4lFv8W+S3/uJAFz/lJkAZvlsO:qRgeAACQuYC16fg5Si+rKSYl/z+M0f6O
                                                                    MD5:B66A367E476ACC8C56C788850E5F5C2C
                                                                    SHA1:186B0D405F4E2A6C011D15C7189E392E03FA4EF5
                                                                    SHA-256:E66C552809AFF9B7A5E5A903271C1EA12C1A561F6E4C740402A04ED88FFB0CB1
                                                                    SHA-512:7BD68CA560C7F13BA85D94C60B62A4C72066AA25E34D787E73A0C230CF10E6DA412FE59B92A4E2F65FE1FBC09EE40F363139D4738F25329B0C84D67A01B357A7
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10166" V="1" DC="SM" EN="Office.Outlook.Desktop.MailAttachmentSizeNumber" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="10000" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Hourly" />.. <SQ T="3" R="[1][2]" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="numOfAttachments" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="numOfAttachments" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="numOfAttachments" />.. </L>.. <R>.. <V V="2" T="U32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="1" F="numOfAttachments" />
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):4486
                                                                    Entropy (8bit):3.7678228223786885
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d4ddRge8rqywOjreUSleavv/eswte+tLe/9QemDEPcskX1ru+2koSA7:c4fRgeUqyJCJmKMKklq+u7
                                                                    MD5:505E8F9CEDDF4C1450117FA672F9611B
                                                                    SHA1:07A92E09D9DB152370193D0A6E167F1A3BDB7D16
                                                                    SHA-256:1E5406A0FA73FD7180D1C3D03C286869E0ADADCE287589C40786BCC179C69570
                                                                    SHA-512:89394D35E8DDB4DCBC490884EE62B0828072BA6BBAF276079B384D1F16819F5F83CC79DC75C23C0D692D88B3AFA9456FFB6DCCA2ED5909DBC6856913B258F56B
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10177" V="2" DC="SM" EN="Office.Outlook.Desktop.AttachmentLocalMruRefreshUpload" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="10155" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <TR T="4" />.. <F T="5">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LE">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <V V="300" T="U32" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="6">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <V V="301" T="U32"
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):4470
                                                                    Entropy (8bit):3.80724102352738
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dYZdRge8YqQwOjreUSleavv/eswte+tLe/9QemDEPc1X1LuCu4wS/:cYjRgenqQJCJmKMjlKCF
                                                                    MD5:C884F342BEFE8025A359FA3D1A931DFC
                                                                    SHA1:42A007E8CD713233AD35E6F05A3C85FC9D15E9FE
                                                                    SHA-256:60A7902E22F25A698C1DE4C52F1FE854686CF263433F85B9566A6F3676D3D48B
                                                                    SHA-512:F9C1E9B9E9A5A4BB60C97FF450D70A3B0166EB0F4E14297A99757FA1D5AAA20747E9BE3FFA24CAA29AB038AD0BFBFB1CA53D6B7C302E092A7112BB45152CC104
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10178" V="1" DC="SM" EN="Office.Outlook.Desktop.AttachmentRoamingMruRefreshUpload" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="10156" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <SQ T="4" R="[1]([3]|[2])" />.. <F T="5">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LE">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <V V="300" T="U32" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="6">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="1" />.. </L>.. <R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):2369
                                                                    Entropy (8bit):4.152848078919524
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dsaedRge8NqQwOapISqeOvvzeaz/IPcz+E+x+iX1J+j+ai:csaCRgeqqQQi93zt+E+x+ilJ+j+x
                                                                    MD5:9A28F393C3C78BD48A446BC179F95C5F
                                                                    SHA1:C9D56BF09053471D3CDB2B0C7C326E9891FD4DE0
                                                                    SHA-256:0143CD233C0975EB010D5CD4E3B3436113A08990845CD6DC06D7ACC7EC079B4F
                                                                    SHA-512:F214F60C6143FF492A4D2B0DCA28C1AF2623FA430C7D7DD32103338CB356458FF6061400832536E83EF7E0CA2C160B01E786238870B86B44CBBDA2C2CEBA69E9
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10179" V="0" DC="SM" EN="Office.Outlook.Desktop.AttachmentMasterMruMergeUpload" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="10157" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <SQ T="4" R="[1]([3]|[2])" />.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LE">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <V V="100" T="U32" />.. </R>.. </O>.. </R>.. </O>.. </F>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):3586
                                                                    Entropy (8bit):3.905238509406438
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dFVddRge8SqywOapISqelvieewPTeOtvzed1CdPcwq1X1Fag17:cFtRgeVqyQiU0MtsF1lFaY7
                                                                    MD5:CEBD6F38A643CCCC409E61F2FF7CAA69
                                                                    SHA1:19C493EAD92B7F3FB66582E567A6A816C0F933D1
                                                                    SHA-256:70F2CC759F96BD6F86BD8E691F2A9424BC40301F2DB608C997176528FE127166
                                                                    SHA-512:A85517AE0EA0C23FA5E6E417E22AA7EE8086C5FEFA424B63864268E985CF37B850A5F2D2233B76170B389D44A58BBD3CB6671DFFDA1C1CD82CFF366D345F091C
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10180" V="1" DC="SM" EN="Office.Outlook.Desktop.AttachmentGalleryPopulateUpload" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="10158" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <TR T="4" />.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LE">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <V V="20" T="U32" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="7">..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):494
                                                                    Entropy (8bit):5.29821635346088
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdRVzjTTdRDDHwpat5lilFQsrlVZ6Cnf/tz:2dRRTdRgensrPHn3tz
                                                                    MD5:D4A849BE3E71FED884E424B7159FBF55
                                                                    SHA1:C702FAF3B512E3FAB4E22FED589C6D20FEB77FA2
                                                                    SHA-256:3DC9BF1AA4CE04479493C9BA0C8DBEB35F246B424756CD9E91C8AF8E03B8B415
                                                                    SHA-512:33E7032AE25F5E1108EF13B8C208980019C2A5696DA5B19E3905DBFCB265D2401A83839A0269B1414CDEF44437D114F7DC16E7B63EAD377EF3E6CCE30C6EFC25
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10202" V="0" DC="SM" EN="Office.Outlook.Desktop.SearchHealthState.CEIP" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="20" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="6500" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. </S>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="1" F="TimeStamp100ns" />.. </C>.. <C T="U32" I="1" O="false" N="ErrorState">.. <S T="1" F="State" />.. </C>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):495
                                                                    Entropy (8bit):5.339202817505073
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHda1VzjV5fdRDDHwpat5lil1wJe1zRlVZ6dkQ/Zz:2dcJdRgecwkP0kQxz
                                                                    MD5:BC17C2C7ECBED3A0F78EBFDE28859285
                                                                    SHA1:F01F249EEF7C20DBF964F3CE4776CD49C84EB738
                                                                    SHA-256:900A61A99BF493AF06E100AFD56D9BA092E4B43E44A1F2E3B761D6B0DB094AC2
                                                                    SHA-512:DF0C79D077677AD2FB4C3298346D1DFF63748753716C0AA9DA47A27A7AE73D5062D456B7C4F8D8B37C085DD4A54A0A013BDDF4EF369EE22295105B0F96BBD7AF
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10203" V="0" DC="SM" EN="Office.Outlook.Desktop.RepushToIndexer.CEIP" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="20" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="552" G="{2adf8e23-0af9-43c9-ba4c-952ee130540d}" />.. </S>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="1" F="TimeStamp100ns" />.. </C>.. <C T="W" I="1" O="false" N="RepushReason">.. <S T="1" F="pwzReason" />.. </C>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):765
                                                                    Entropy (8bit):5.2033766222867275
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd/VzjT/CdRDDHwpatETswXFJicoNKlVGSLWT8oXHaSMp/bSAWNywfXNOBsu:2d/R/CdRgeOsEvSkPCTA5
                                                                    MD5:4D83B5D170E9F9ABEEEEFF0EC67EFEA7
                                                                    SHA1:71FC24F35566B456A296FAF7F1060AF724AE82D9
                                                                    SHA-256:72DECE77E6DF06472192D9CF5C2B872974239E494719E35F51307734DDDFE085
                                                                    SHA-512:1198718952E6E25BBA118CD4BEB38EF9D61A26D9A1DA22AF7F6632E1567BDC42137561F59D8C13CC962FCA33F8F40D662F02BA032C2BDECEBB70F057FC763C61
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10204" V="0" DC="SM" EN="Office.Outlook.Desktop.SearchSessionQueries.CEIP" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="7001" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <SQ T="4" R="([2]|[3])" />.. </S>.. <C T="FT" I="0" O="false" N="EventTime">.. <S T="4" F="TimeStamp100ns" />.. </C>.. <C T="U32" I="1" O="false" N="SearchSessionCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="TotalDistinctQueries">.. <A T="SUM">.. <S T="1" F="FollowUpQueries" />.. </A>.. </C>.. <T>.. <S T="4" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1728
                                                                    Entropy (8bit):4.6960452034160864
                                                                    Encrypted:false
                                                                    SSDEEP:24:2deqWQdRgeGFI+t4UjqTUiAwOkQP7FFiKPBdUPRX11yQh4J:ceqWIRgeGFI+t4uqTm5jFgZ7th4J
                                                                    MD5:4C5F246DE21CDBD172E0C0480CA8BA1B
                                                                    SHA1:29FC484692F3BB5BE7A126A9ED40BC646D96060D
                                                                    SHA-256:69219BEC3B67F362E27382527694CFED0906B188DE29326B31CA55B21ACE8F57
                                                                    SHA-512:193EAEA9E8DCE03DF32B021C5E92BABE13167BE7C1962E74670FECB8E6FD4FF14738EE01BADF34D2FE9FD5F3C7048F504C0B95DBBB29EF1B533230953CDBA080
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10207" V="4" DC="SM" EN="Office.Outlook.Desktop.ForegroundRPCPerHour" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="561" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="2" E="558" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <F T="3">.. <O T="EQ">.. <L>.. <S T="2" F="FForbidden" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="4">.. <O T="EQ">.. <L>.. <S T="2" F="FForbidden" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="NE">.. <L>.. <S T="2" F="BlockingBugId" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <TI T="6" I="Hourly" />.. <A T="7" E="TelemetryShutdown" />.. <TR T="8" />.. <R T
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):564
                                                                    Entropy (8bit):5.236745811461481
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd7Vzjzo8dRDDHwpatE6ylVZ6W+/bOppGNkz:2d7ho8dRgekPeuz
                                                                    MD5:AB3919EDCA75CC637FD94123D56C0699
                                                                    SHA1:08E25031E465F0FCA798A19F16B9EC14B0D11CAA
                                                                    SHA-256:6E7F60AE0F2BF5B851128FC19856E2D71EF25E7F210C310B08FDE57795F79F58
                                                                    SHA-512:8B84BFE2D565F6AE22E73C0A7D94C87D105D24DA71B32BF474701EEAFE00503266E3CEFE64AB5310B42CD52896151CC5C8F247AF988F3D0B8BF44DE71EB6377C
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10208" V="0" DC="SM" EN="Office.Outlook.Desktop.OutlookTheme" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="8101" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="1" F="TimeStamp100ns" />.. </C>.. <C T="U32" I="1" O="false" N="CurrentTheme">.. <S T="1" F="CurrentTheme" />.. </C>.. <C T="U32" I="2" O="false" N="Timing">.. <S T="1" F="Timing" />.. </C>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):509
                                                                    Entropy (8bit):5.204853110720731
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdSijVzjiJ0dRDDHwpat5DQWNzklVZ6dJweMNO2su:2dPjw0dRgeRYP0u
                                                                    MD5:23BBCFCC28C498CE4C6E35225534300D
                                                                    SHA1:21AAE8C55AC91901A869A1719BCDD8CA3BBF93CE
                                                                    SHA-256:EF387F995F932BFDC068743C204906B7A7A8909B14749C17BB47EB251ACAD1CC
                                                                    SHA-512:A615E5F1FCF81A933EEDB7DCF0C77E45AC157E5D3D03028550D5D4315A419A704C622418C00C9C65FD770636D95212B5426FF14AC1C125AD4B49D409E4EECB2E
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10217" V="0" DC="SM" EN="Office.Outlook.Desktop.DefaultFont" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="1" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="1508" G="{daf0b914-9c1c-450a-81b2-fea7244f6ffa}" />.. </S>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="1" F="TimeStamp100ns" />.. </C>.. <C T="W" I="1" O="false" N="Font">.. <S T="1" F="FontName" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):511
                                                                    Entropy (8bit):5.2224101127064895
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdS/VzjABkdRDDHwpat5Gs41WNzklVZ6dsweMNO2su:2dYS+dRgeMkYP0b
                                                                    MD5:F8B68775E57C14130F182027350D750B
                                                                    SHA1:1992BECCF8BDE4572B6F8589E0063ADEECBC964E
                                                                    SHA-256:79CDDCB1937F19D6E2AC43DDC8D1872121F1B71874B959007E80EDE8BAFAB2F7
                                                                    SHA-512:FFF4A818717E742852D6F0F8F53FFCC624D60C6C0CC6FF001DC4F1168DBDB5EA1B0FBDC455E476EE811A62588B9FB7C20B6DC2D3F9625F9B43C6AF1CBFC2A2A6
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10218" V="0" DC="SM" EN="Office.Outlook.Desktop.AppliedFont" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="15" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="1507" G="{daf0b914-9c1c-450a-81b2-fea7244f6ffa}" />.. </S>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="1" F="TimeStamp100ns" />.. </C>.. <C T="W" I="1" O="false" N="Event">.. <S T="1" F="FontName" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):819
                                                                    Entropy (8bit):5.1129913733810595
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdxMVzjABdRDDHwpat5rAES10UgOO/DfOOW8/TO1lVXSdMOydyVEBuvxNO2su:2dxMQdRgeqESGtO+OgrCPXGiaEg3
                                                                    MD5:4FBDE5AAE43D6174395019D841AF2475
                                                                    SHA1:CAEDA33ED7919BEFF86EC8DDA98BD8A999305A9E
                                                                    SHA-256:803912A1B19C8A701002507D9AB2F24AD42A6A17E033E1BAB41E6D200C2AA2CD
                                                                    SHA-512:4B4FF455789287AC419C132DA4F7FA30741A0FCDF2BC7BA443E75DD56BCB742154B37A3BA44C02095A812E9DEFFD972109E7B3389A1355269BF627CF2BB95CCA
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10244" V="1" DC="SM" EN="Office.Outlook.Desktop.ImapCapability" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="10" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="115" G="{13967ee5-6b23-4bcd-a496-1d788449a8cf}" />.. <SR T="2" R="CAPABILITY">.. <S T="1" F="ResponseBuffer" />.. </SR>.. </S>.. <G>.. <S T="1">.. <F N="ResponseBuffer" />.. </S>.. <S T="2">.. <F N="Input" />.. </S>.. </G>.. <C T="FT" I="0" O="falseNoError" N="CollectionTime">.. <S T="2" F="TimeStamp100ns" />.. </C>.. <C T="U32" I="1" O="false" N="ConnectionId">.. <S T="1" F="ConnectionID" />.. </C>.. <C T="W" I="2" O="falseNoError" N="Capability">.. <S T="2" F="Input" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):742
                                                                    Entropy (8bit):4.973626752240643
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd+omVzjJPdRDDHwpatq+icWiqHNyLX3DydOfDxpbXHISMNO52su:2dXmPPdRgeLy+uoO
                                                                    MD5:BE2A7B5FC3E03C7C85FAEB2AE375FA47
                                                                    SHA1:76B6F3457B038812AB1F009465950FB2ED57A44E
                                                                    SHA-256:2BAABE84A76F275857F2E25D941B97ADD23844A3FC8C4AAD725CC950F229BAEA
                                                                    SHA-512:BABEFA4917A30ACCB10572231CD76FFF28F6ACF74CD8CDFD1C8F26175F0941F0ADCADE84CE7262116ACB3C142F2D387CD6C10F8EF567FAAF320382D42EF9C785
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10300" V="1" DC="ESM" EN="Office.Outlook.Desktop.ExchangePuidAndTenantCorrelation" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" SP="CriticalUsage" DL="A" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="15min" />.. <R T="3" R="12076" />.. </S>.. <G>.. <S T="3">.. <F N="0" />.. <F N="1" />.. </S>.. </G>.. <C T="W" I="0" O="false" N="PUID">.. <S T="3" F="0" />.. </C>.. <C T="W" I="1" O="false" N="OMSTenantId">.. <S T="3" F="1" />.. </C>.. <C T="U32" I="2" O="false" N="ConnectionCount">.. <C>.. <S T="3" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1967
                                                                    Entropy (8bit):5.0585162123390495
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dUAu4OHPdRge6YOZG+W2m+kHPQ0cAKi9X1qcYqRp2RxrK+:c64OHlRge9RL7lqqb2C+
                                                                    MD5:8A4BA7FA8322A12CBAE30438DAE8B06C
                                                                    SHA1:0F7338B4EB8CD978A9B9543734B5E140C50DE783
                                                                    SHA-256:89791DD62F7E5779A9760F91F73804E77FFE78DECDEBEB9EB3AD9AEC8ED53C61
                                                                    SHA-512:076497B075591054EE3A930D280DE36C616BB20364B8CB195D00DFE8E9CF349F1D86089EF9A86FFBD7B265736DA2079B9F0B6DE07F478DEE0029B944E6156062
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10642" V="3" DC="SM" EN="Office.Outlook.Desktop.InformationRightsManagementHealth" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DL="A" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="1000" G="{2adf8e23-0af9-43c9-ba4c-952ee130540d}" />.. <Etw T="2" E="1001" G="{2adf8e23-0af9-43c9-ba4c-952ee130540d}" />.. <Etw T="3" E="1002" G="{2adf8e23-0af9-43c9-ba4c-952ee130540d}" />.. <Etw T="4" E="1004" G="{2adf8e23-0af9-43c9-ba4c-952ee130540d}" />.. <Etw T="5" E="3800" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="6" E="3801" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="7" E="3802" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="8" E="3803" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="9" E="3804" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <R T="10" R="11724" />.. <R T="11" R="11725" />.. <TI T="12" I="Hourly" />.. <A T="13" E="TelemetryShu
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):578
                                                                    Entropy (8bit):5.2121422760306855
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdCvSVzj+dRDDHwpatTilYSIMAKlMdLGce/oyNOqHNUlu:2doSMdRgerSIMjwZeAg7
                                                                    MD5:2FB37372ECFACB6729C856B4ECBB5959
                                                                    SHA1:556100BBA3D7166D65BE8F59ADDE6EB8A4F913A0
                                                                    SHA-256:8014165625A32E8C1A755096261CBFDB56E0CC1F21F7663C0394657239CCC0E3
                                                                    SHA-512:8664553F45AEDAA00896BA5D61168F077358875EE95414EBDD9FF1D2D003895468581E49245D6151796A2F758EE0B471CC31AB8DBBAC2A3D5258172DF576E9B0
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10643" V="1" DC="SM" EN="Office.Outlook.Desktop.ImapIdServerInfo" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" SP="CriticalUsage" S="20" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="101" G="{13967ee5-6b23-4bcd-a496-1d788449a8cf}" />.. </S>.. <C T="W" I="0" O="falseNoError" N="ServerName">.. <S T="1" F="ServerName" />.. </C>.. <C T="W" I="1" O="true" N="ServerVersion">.. <S T="1" F="ServerVersion" />.. </C>.. <T>.. <S T="1" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1689
                                                                    Entropy (8bit):4.398092692066297
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dn5ndRgekvS8TdUjqwOam+sjqctUyzT2+syw5W+sGltOE9J7:cnXRgekvS8T4qQmvqcb2kIuMJ7
                                                                    MD5:CF52DB4F119209E42F12EC5FA20713CF
                                                                    SHA1:AAF3D72A93118F0C598F955225853B54A88163E4
                                                                    SHA-256:6F0ED0AABB899198C2AEDB81F9200D40459198432F0018BD6996021B8173DE4F
                                                                    SHA-512:351B3515673262B531E7B2BE228DBCAB0D7145A5596148D282F472B9A9B125282C5AB7F6609778B84BFBBC11FC4EC8FC42CC56A6DB7DB1A9FFE56ACA1D5678D3
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10644" V="0" DC="SM" EN="Office.Outlook.Desktop.StoreConnFromServerDNHowFound" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="810" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="DefaultStoreConnection" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="FoundByStoreServerKey" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <S T="1" F="DefaultStoreConnection" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):601
                                                                    Entropy (8bit):5.277891299223542
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdIVzjgu0WAdRDDHwpatEFq3xF7dqClVzRD6jlWR8dNOjsu:2dIB0NdRgeVBFACPAY
                                                                    MD5:2A5F0BB262A5A68CFBADC00958EC49C4
                                                                    SHA1:C65F352F1067693FBE1640574B656F9500839F8F
                                                                    SHA-256:867E44045FC889AD459FDFE4726916A7127198BDC9A2FA91A9D53A013233270D
                                                                    SHA-512:0A30BA968AC3A39BAE33F7F20FAFD8A070E773F05C85464BFA4B5E94CE5E3A6E0625635072572A200FC148A70D4A7A193FEDE6BFE875DB8CE619CD90E4A684B7
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10645" V="2" DC="SM" EN="Office.Outlook.Desktop.TelemetryOnOutlookFirstBoot" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="415" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="2" E="416" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. </S>.. <C T="FT" I="0" O="true" N="FirstBootStart">.. <S T="1" F="TimeStamp100ns" />.. </C>.. <C T="FT" I="1" O="true" N="FirstBootEnd">.. <S T="2" F="TimeStamp100ns" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):4845
                                                                    Entropy (8bit):3.932422649152658
                                                                    Encrypted:false
                                                                    SSDEEP:48:c2BuyGt44TxQWJIuBvbs6wuq8xq/4qfybqFlbqIJqLhG2rd70p8wrhGt8:VuVvlFi8zdMtnfpb+1FvrFanl
                                                                    MD5:EE6E2F272951DDBE9319247D0FAA7A4E
                                                                    SHA1:E4D5D09EC427D3E920C83E699592D9241DB79903
                                                                    SHA-256:FA3670AE49FA7778450DE0A447F24A097DF501082EAE596C44B4B8A93D1F8A09
                                                                    SHA-512:9471D5C93FB8C17C7250A6430E68DA060F25F78BD0014093A81FC840B00B1FA9B7384699A8CCA364ED40BC00C1EDE723C3BFE46778030DB7B24EFC02FE8867EC
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10646" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="352" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <F T="2">.. <O T="EQ">.. <L>.. <S T="1" F="Planner Mode" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="3">.. <O T="EQ">.. <L>.. <S T="1" F="Planner Mode" />.. </L>.. <R>.. <V V="2" T="U32" />.. </R>.. </O>.. </F>.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="Planner Mode" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="Input Device During Focus" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="Input Device During F
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):2248
                                                                    Entropy (8bit):4.659184776077476
                                                                    Encrypted:false
                                                                    SSDEEP:48:cQ4RRgeTqJ34Ob+hhgIsXhy5fDmqG4k4jS:oRRge834Ob+hWI4hy5fDmqrk4jS
                                                                    MD5:9ADFFAC8A44FD653681AC1E18E2CB37C
                                                                    SHA1:6189CF1CD270A77B483AFFC5A2671B28BF23B8A7
                                                                    SHA-256:83896E1513FF46C5ADFEA555E3D80E1763EC7193632B2D70FE4870088B5AFC63
                                                                    SHA-512:C6A4D1F6EE7CCD67C275BC6F112D7475D9BE089A1BECA17E729589428B3D1685D3227B2399BC46A292D852C623D4CCF51E7E97FD44731196CAD1C9697590FE6A
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10647" V="0" DC="SM" EN="Office.Outlook.Desktop.AttendeeListSchedulingAssistantLostFocusAggregated" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="10646" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="NE">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="FreeBusyAttendeeGridLostFocus">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="InputNone">.. <A T="SUM">.. <S T="4" F="3" />.. </A>.. </C>.. <C T="U32" I="2" O="false" N="InputMouse">.. <A T="SUM">.. <S T="4" F="4" />.. </A>.. </C>.. <C T="U32" I="3" O="false" N="InputKeyboard">.. <A T="SUM">.. <S T="4" F="5" />.. </A>.. </C>.. <C T="U32" I="4" O="false" N="InputKeybo
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):2237
                                                                    Entropy (8bit):4.650423548009724
                                                                    Encrypted:false
                                                                    SSDEEP:48:czFRgeTqJI4Ob+hhgIsXhy5fDmqG4k4jS:kRge8I4Ob+hWI4hy5fDmqrk4jS
                                                                    MD5:F8AC04FF763D9AB3D179A2F6D02E7D11
                                                                    SHA1:16E7B70CD643EEE5C59B7F3755170B7D7EF0F2FF
                                                                    SHA-256:E1426699D2845F7DEC2638963B22B6E87C6834EB7F603B3B046C1087C1244E12
                                                                    SHA-512:E27CDBEE816C3BB3D7BC8C1FB65698C8784AC6D610CAA1F7A98732256E8DB9C56AB9C04459B3CAA6ADE22F9BCE431631F6D06DD102397999DF2BEE85D6448A16
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10648" V="0" DC="SM" EN="Office.Outlook.Desktop.AttendeeListTrackingLostFocusAggregated" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="10646" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="NE">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="FreeBusyAttendeeGridLostFocus">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="InputNone">.. <A T="SUM">.. <S T="4" F="3" />.. </A>.. </C>.. <C T="U32" I="2" O="false" N="InputMouse">.. <A T="SUM">.. <S T="4" F="4" />.. </A>.. </C>.. <C T="U32" I="3" O="false" N="InputKeyboard">.. <A T="SUM">.. <S T="4" F="5" />.. </A>.. </C>.. <C T="U32" I="4" O="false" N="InputKeyboardMouse">.
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):2845
                                                                    Entropy (8bit):4.344086938096499
                                                                    Encrypted:false
                                                                    SSDEEP:48:cubRgeBnqJTWQIJBubvxqsQRq8BoRq/p8qDl/Ak:RRgeuSPX6oRgwoghp5ok
                                                                    MD5:54067ED027A72FD6ECE8939849EF8463
                                                                    SHA1:DFB90DBB8D63E3CE1E180B71C52FD12A2D00C5FE
                                                                    SHA-256:12FCD8D37E74A4CA75DCA0A871FBF818D63ACB5CE9FB46F66E0BE7582648AA8D
                                                                    SHA-512:6645AECC4CA5C983ECE5CCB1C17D4B5AE1D9B14D78E22624DDFAAAFB0CEC2260BA2E666DC03B715C86DEA4424EEF96EA22879267C26B108FEB54C919EB4D7D1C
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10649" V="0" DC="SM" EN="Office.Outlook.Desktop.FreeBusyMapLostFocusAggregated" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="353" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="Input Device During Focus" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="Input Device During Focus" />.. </L>.. <R>.. <V V="2" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="Input Device During Focus" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):515
                                                                    Entropy (8bit):5.280761302407042
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdaKVzjzo30qMdRDDHwpatEBx4Ik0NzdLBjS4qNO2su:2dlho30qMdRgekxQqlRq
                                                                    MD5:B0D0659E91355D2026A9A79991DF17D8
                                                                    SHA1:ACE8BF330F75CD04B54A79AE438F8D29D61E64FF
                                                                    SHA-256:922FF437201298BF577967B0898CDFBB28F0F3F437F031FD5D4A3937EDAB6B59
                                                                    SHA-512:2371CAADB81AF61396484EC1DE2D507DA06A9CB06301A2E55ED6DE1476B4B75C49FE3AD558F3F05F7D71919DCF36D77E2B16A62C813C7341BEA851ECBD6EACD2
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10659" V="0" DC="SM" EN="Office.Outlook.Desktop.OutlookInAppRating" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="20730" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="I32" I="0" O="false" N="Rating">.. <S T="1" F="Rating" />.. </C>.. <C T="W" I="1" O="true" N="FeedbackComments">.. <S T="1" F="FeedbackComments" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):699
                                                                    Entropy (8bit):4.712692920339422
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdTWifH2GeOSh2GeOjDhW8/hfDb8OKX/c//fpONkMIvwzz:2d6MvLYvLlQrzz
                                                                    MD5:EFFAEABF3756C3E2047C976C41135B2A
                                                                    SHA1:A69545C2EC1DCF17C56B0DF4ED76B5315EEA1EA9
                                                                    SHA-256:2CC17C6ABA7DB98C5BAF4567C25CA68E58F546878399AEE9ADBFCB0C4CDF561E
                                                                    SHA-512:65487A4747624B965E06A72ED5357A94AA8D3E52140743BDEFC40F880F2CFBD901A7C2C067B2379D2DE5830FEEEAB293FD97741C720F94FA783DB1106FD3835D
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10660" V="2" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="338" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="2" E="339" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. </S>.. <G>.. <S T="1">.. <F N="ThreadId" />.. </S>.. <S T="2">.. <F N="ThreadId" />.. </S>.. </G>.. <C T="U32" I="0" O="false">.. <U T="100nsToMs">.. <O T="SUB">.. <L>.. <S T="2" F="TimeStamp100ns" />.. </L>.. <R>.. <S T="1" F="TimeStamp100ns" />.. </R>.. </O>.. </U>.. </C>.. <C T="U32" I="1" O="false">.. <S T="2" F="CountUrlsRetrieved" />.. </C>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):4489
                                                                    Entropy (8bit):3.7170559421323106
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dWmKhdRge84qJBr7UwOml7a/v/7sCt7+FL7/4Q7mfibAoAMArhGX18ANAM4AAVt:cWmqRgezqJ6No/hKDGldm7
                                                                    MD5:96A9B05F0BB30D832DF270FD34C31B61
                                                                    SHA1:16610686ABE35565C75C80CB68470B5EEA448871
                                                                    SHA-256:60891EA76C1F8236F043BBB6B1A93CC0A7A9A94287BA43D6672EB9EBD3862874
                                                                    SHA-512:8166EB433DC1DD99A4C2962812AD219165AA6BF17F01C9E8C4AF32BC0336735CAFEC24D5A30D4E1087F6EE7D3383728D6C22A826523496C077146EBCC794009C
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10661" V="2" DC="SM" EN="Office.Outlook.Desktop.SharePointOnPremUrlRetrievalPerf" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="10660" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LE">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="300" T="U32" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="5">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="301" T="U32" />.. <
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1201
                                                                    Entropy (8bit):4.7047018694905365
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdq4VzjozPdRDDHwpatEFHh2GeOScoNBi+wsvXqNO0OX/c//tpONd+aqNO0OXH:2djmrdRgemvLivJwOahaIJhal1aN8r
                                                                    MD5:DAB06A176A635F30C100621BEC0E89E6
                                                                    SHA1:4F9293F82D6A077EA985FB4BF848C04925A28183
                                                                    SHA-256:82A80F991BBCA212108EF506DDF85CAC784903D41641EDF98EB68283A9EC2AF1
                                                                    SHA-512:DB62AAA783349CB6131A6A8D286C1C9212C3E3CA086B6050AA24E88D4F38CCC3D04288CAA453C24A2ADE9B086EF69E3DD5E4E8421B5EF0A8C11098879CB31AF2
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10662" V="0" DC="SM" EN="Office.Outlook.Desktop.SharePointOnPremUrlFound" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="4223" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="339" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <TI T="3" I="Daily" />.. <A T="4" E="TelemetryShutdown" />.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="Type" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="Type" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="Internal">.. <C>.. <S T="5" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="External">.. <C>.. <S T="6" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1263
                                                                    Entropy (8bit):4.815484846268293
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdfVVzjn/CdRDDHwpatEBPq+A+KbSWUA+KbSJBicGN+aqNOTNX/c//aUpONd+j:2dfVIdRgekCu88JeJdkuZJdYPcF7zFor
                                                                    MD5:AE0554F415F0C0A0BD9B38B75D55723D
                                                                    SHA1:1825B37E1710897E2F82083B15AF6D161C07CF86
                                                                    SHA-256:52A9BE47192D68E8BB1BDF82D47A75BC4500214FC085812B951B23B2CF7A9F4C
                                                                    SHA-512:11A34602A50DF3BD87E8EDCBC4D4F78A2C42DF549F88E813A694AC565C2A3EF366BBC5B215A911CC8A45A5DCE7ED27585C61CDA59D5B9199615A023C0B1D30A0
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10664" V="0" DC="SM" EN="Office.Outlook.Desktop.ReferralTaskSuccessFailureGetFQDNFromLegacyDN" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="212" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <Etw T="2" E="213" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <TR T="3" />.. <A T="4" E="TelemetryShutdown" />.. <TI T="5" I="Daily" />.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="RequestMethod" />.. </L>.. <R>.. <V V="39" T="I32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="2" F="RequestMethod" />.. </L>.. <R>.. <V V="39" T="I32" />.. </R>.. </O>.. </F>.. </S>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="3" F="TimeStamp100ns" />.. </C>.. <C T="U32" I="1" O="false" N="SuccessfulTaskCompletions">
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):7291
                                                                    Entropy (8bit):4.2924586770926245
                                                                    Encrypted:false
                                                                    SSDEEP:48:cNqLuyI0H93WOh0ExiYWrcHcrQTaWqRWD3Ro+O7hb2O4pO5vPzw0Nw8+d5EdVKQe:oqLuzS4rgNAFKGNm
                                                                    MD5:6C8C9AB257C887579D14B2C1A3A6691D
                                                                    SHA1:675609E8BE93C95F88EE976DED8A13102A4E6AE8
                                                                    SHA-256:4E5366C2C06BCFD4D243FC54BFA0136A17D9FA3C73DBADA09793098555471C79
                                                                    SHA-512:81D707700F6D5D4CDDE0E43A4DAF36AC5B785A1D616CFCA129C0E16E8B7EB79AB6BE1F7C65BF5602FE24EACF1B41476C2EAE834BE1B202C811BE95EE64BF0480
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10665" V="4" DC="SM EUII" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="7068" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <F T="2">.. <O T="EQ">.. <L>.. <S T="1" F="AuthRefactorFlightedOn" M="Ignore" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <Etw T="3" E="7090" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <Etw T="4" E="7092" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <Etw T="5" E="7094" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <US T="6">.. <S T="3" />.. <S T="4" />.. <S T="5" />.. </US>.. <Etw T="7" E="7091" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <Etw T="8" E="7093" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <Etw T="9" E="7095" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <US T="10">.. <S T="7" />.. <S T="8" />.. <S T="9" />.. </US>.. <UTS T="11" Id=
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):972
                                                                    Entropy (8bit):5.074924607619298
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdZ4VzjJG6dRDDHwpatE5HQ4HcoNBzDPvNW8/PvNfeGfTvM3lmcXHhSMpE1XHn:2dZ4jG6dRgefyvXvpnvYGLv+lmcS1EG
                                                                    MD5:AC519113BFA0619F92C7CF1D52C4B3C4
                                                                    SHA1:6450E3C28C756156F2216094D834C97D47BFF881
                                                                    SHA-256:9ADC20294144947971736F3EA343D65710FC3A530155A3B3AACF4C85D217809F
                                                                    SHA-512:1591A41225736266EDAE43A7D453A7789AC1285AC22CB763F895DD68FC788761C13D19AA535E047408C3B87C430C2FC15C0ECBE89C82B6EB63A188E1BA2C07EB
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10670" V="0" DC="SM" EN="Office.Outlook.Desktop.AttachmentShortcuts" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="4227" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="4228" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="3" I="Daily" />.. <A T="4" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="BrowseLocation" />.. </S>.. <S T="2">.. <F N="BrowseLocation" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="BrowseLocationType">.. <S T="2" F="BrowseLocation" />.. </C>.. <C T="U32" I="1" O="false" N="BrowseLocationDisplayCount">.. <C>.. <S T="2" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="BrowseLocationClickCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="4" />.. </T>.. <ST>.. <S T="2" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1078
                                                                    Entropy (8bit):5.0144713527098554
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdzVzj26dRDDHwpatERtaHc1NQzD0Mc3SfRcSZjZs5fXp3qSt9RM+SHaSM4DFV:2dzM6dRgeS1qs5E2oGc+a8yP7
                                                                    MD5:04C64E6D8665B380B075B4D9680E95A7
                                                                    SHA1:B991FA6FC0BD28DC740D694D2B8F1EB5E399E13E
                                                                    SHA-256:6C9DF1DE65C45B8965B4646DF85FD8FBCCFA2532021D94327C89500F3674E0FD
                                                                    SHA-512:28CECD71B745B4C25E2F08B465BDC90A3480822F7396734054607FBA0F5C0ED034E65D008EF51615D3607A40E827053705ABFCB3680ABA5AA4BE9B4BDE35E345
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10671" V="0" DC="SM" EN="Office.Outlook.Desktop.AttachmentsPropertyStoreResults" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="4224" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="HRESULT" />.. <F N="PropertyStoreResult" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="HResult">.. <S T="1" F="HRESULT" />.. </C>.. <C T="F" I="1" O="false" N="AvgTimeInMS">.. <A T="AVG">.. <S T="1" F="TimeInMS" />.. </A>.. </C>.. <C T="U32" I="2" O="false" N="PropertyStoreResult">.. <S T="1" F="PropertyStoreResult" />.. </C>.. <C T="U32" I="3" O="false" N="CountResults">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U64" I="4" O="false" N="MaxTimeInMS">.. <A T="MAX">.. <S T="1" F="TimeInMS" />.. </A>.. </C>.. <T>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1666
                                                                    Entropy (8bit):4.698378831456289
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d+fZ2dRgeUOOt4macwkZSTmaJwkZSwOamajwkZSJmaQwkZ1X4:c+fERgeUt4m0PTmLPQm1PJmAiX4
                                                                    MD5:9BF3249EE45635399FDFF439060F656A
                                                                    SHA1:89F92582EA905535E4B146641C21D8B0715286EC
                                                                    SHA-256:DCA735297B74930BFEA715A4F1E641D54BB1620AB2297A74EBE643A7F12EC885
                                                                    SHA-512:BCCC94E59E9AD9B626C97209972029BF0420967DAC13CBF8E6C19BAEEC957A2EB6F36A23ED7E8FBC1D2D10E2B166C01C8DF4CE047255244FA2CC6DCBE4F42469
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10676" V="2" DC="SM" EN="Office.Outlook.Desktop.AccountConfiguration.AccountsInProfile" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="414" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="2" E="418" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <F T="3">.. <O T="EQ">.. <L>.. <S T="1" F="AccountType" />.. </L>.. <R>.. <V V="{ED475411-B0D6-11d2-8C3B-00104B2A6676}" T="G" />.. </R>.. </O>.. </F>.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="AccountType" />.. </L>.. <R>.. <V V="{ED475412-B0D6-11d2-8C3B-00104B2A6676}" T="G" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="AccountType" />.. </L>.. <R>.. <V V="{ED475414-B0D6-11d2-8C3B-00104B2A6676}" T="G" />.. </
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):800
                                                                    Entropy (8bit):4.860299152352607
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdWOFrA+KbSK0A+KbS0A+Kbj8/hWDhWHNhOAEyImb+xoZNO/a//E:2dUHXr5qX
                                                                    MD5:A9727DFDFE19840889B273B87FA4A145
                                                                    SHA1:64FA94553F688D9860E8FF8FD4375ADFA5C94B7C
                                                                    SHA-256:067A9433AE90DD88E2CB0316DC8B6981B5DBF094F18CDCAD88D8942405437FF5
                                                                    SHA-512:C17C075191E4A691B4844FBE9ED98CE32CFB2231E5D7DD52923A327D7CCF9C8480526A9DBDC902D73210BFF572B66A69B73A2AC7B27049791358C0A5FF38B5DA
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10678" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="670" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <Etw T="2" E="7063" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <Etw T="3" E="7034" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. </S>.. <G>.. <S T="2">.. <F N="ClientRequestId" />.. </S>.. <S T="1">.. <F N="ClientRequestId" />.. </S>.. <S T="3">.. <F N="ClientRequestId" />.. </S>.. </G>.. <C T="G" I="0" O="false">.. <S T="1" F="AccountInstance" />.. </C>.. <C T="U32" I="1" O="false">.. <S T="2" F="AuthScheme" />.. </C>.. <C T="U8" I="2" O="false">.. <S T="2" F="Prompted" />.. </C>.. <T>.. <S T="2" />.. </T>.. <R>.. <S T="3" />.. </R>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):3272
                                                                    Entropy (8bit):4.135926409353128
                                                                    Encrypted:false
                                                                    SSDEEP:48:c2oRgeLbhjFgJJVPuVkvnr8yZfypgTiZROYSQ7:ORgev6nPqkfrNZfIW4OYSQ7
                                                                    MD5:99A5409CC6C157A11DE8B61194BCC3D6
                                                                    SHA1:5C0F64E64020AB7B33C1B9D69FC1B23CB48B10E6
                                                                    SHA-256:D04E1D3A05C5C4C473B051BE5556D50DB4F67BDBDC699A14A26062958986A097
                                                                    SHA-512:A782FF0629650D190971D04E739E131A7390320D63F3ED5EB8B45A8870A88DDE722810729231EC0735CA5C3867531203FB8AC481CB520F81EB03E70311BF0D09
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10682" V="3" DC="SM" EN="Office.Outlook.Desktop.ContactCardAddEdit" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="blelq" />.. <UTS T="2" Id="blelr" />.. <UTS T="3" Id="blels" />.. <TI T="4" I="Daily" />.. <A T="5" E="TelemetryShutdown" />.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="MsoAddEditType" />.. </L>.. <R>.. <V V="Add" T="W" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="1" F="MsoAddEditType" />.. </L>.. <R>.. <V V="Edit" T="W" />.. </R>.. </O>.. </F>.. <F T="8">.. <O T="EQ">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="U64" />.. </R>.. </O>.. </F>.. <F T="9">.. <O T="NE">.. <L>.. <S T="1" F="HRESULT" />
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):743
                                                                    Entropy (8bit):5.100051536114664
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd8SVzjlBDGdRDDHwpatEPPnc1NQzD2gLf5gy+ugWCxXHaSMNO5AHNUlu:2d8SZDGdRgekWq+gtgighx07
                                                                    MD5:5641096ECB4A8F6BBC492007CB270A8B
                                                                    SHA1:52278332259B61B8662B5D1C2CC2DF50ED00C85C
                                                                    SHA-256:6F68A41FF6510BEA504FE2AA0BFC4BE05E13093861985A1AE643B8C67B80B647
                                                                    SHA-512:0B77E5562A68CC3E39D2464315A0A616C5449BC411C37D72D5D0B176FDD49A3ADB551B34C8A48E6CA442E1A58ADF636EB56086A385482157B218437BCE181A4D
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10683" V="1" DC="SM" EN="Office.Outlook.Desktop.DiagnosticsSystem.CallingFunction" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3760" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="DiagnosticScenario" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="DiagnosticScenario">.. <S T="1" F="DiagnosticScenario" />.. </C>.. <C T="U32" I="1" O="false" N="CallCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1317
                                                                    Entropy (8bit):4.638570457615204
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdBOgi2GeOSp2GeOSB2GeOSZ2GeOS02GeOSU2GeOSxi2GeOXDHaSMIHhSMpxHY:2dJivLavL+vLOvLDvLjvL+ivLv1F3Jmz
                                                                    MD5:666F009C533CD289740D021DB5B24BC9
                                                                    SHA1:C63E04D19EB1FE92EADE4369641C7BAFEE63DD78
                                                                    SHA-256:57F9BF2A094BFE8BD7033D59E3C79965CEC806F3084A55C88227BF0362640A25
                                                                    SHA-512:3E5C88EE9E94AD22C5567921DCFAD6BBD303B3B2BCC13668427CF401E2DA8DDBA2A77C0A3252041D6A1A4B87D675FADC72DD0BE8320C201002CF6206779ECAF7
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10684" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="1016" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="2" E="1017" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="3" E="1018" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="4" E="1019" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="5" E="1020" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="6" E="1021" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="7" E="1022" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. </S>.. <C T="U32" I="0" O="false">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false">.. <C>.. <S T="2" />.. </C>.. </C>.. <C T="U32" I="2" O="false">.. <C>.. <S T="3" />.. </C>.. </C>.. <C T="U32" I="3" O="false">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U32" I="4" O="false">.. <C>.. <S T="5" />.. </C>.. </C>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):5236
                                                                    Entropy (8bit):4.53088724832978
                                                                    Encrypted:false
                                                                    SSDEEP:96:tRge4uB0x2gEagBRa3g62aLjjR9jjgG1LG3j7uVkEVUmR2M:tDpPJBRa3g62aLjd9ngG1LG3/uVkEVUu
                                                                    MD5:F0D3B33E5A688B26ED6F0A5CF8F73E43
                                                                    SHA1:12A6B4CD1C57BEB97AF0ED6497D42658DB0153A9
                                                                    SHA-256:1849767FFCC708DDEAF5651B9CED03332217E0B1CF401D2E42EC8C5CB021BE8A
                                                                    SHA-512:27297F8949E723EA0988CC484CDC803AC5CB57EC1C3CB4BF4526CB0E5D1D0045E9E34D7D3280F3140DF189EDFFDE338B50B294242C8CCA64DE1E75131365B42B
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10688" V="5" DC="ESM" EN="Office.Outlook.Desktop.ExchangeAvailability2.MapiHTTP" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="817" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <F T="2">.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <S T="1" F="ullNone" />.. </L>.. <R>.. <V V="0" T="U64" />.. </R>.. </O>.. </L>.. <R>.. <O T="EQ">.. <L>.. <S T="1" F="ullDead" />.. </L>.. <R>.. <V V="0" T="U64" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <TI T="3" I="15min" />.. <A T="4" E="TelemetryShutdown" />.. <SS T="5" G="{d024ae8e-84fe-4491-8801-3b0e647439b7}" />.. <F T="6">.. <O T="AND">.. <L>.. <O T="AND">.. <L>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1848
                                                                    Entropy (8bit):4.370899785242188
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dyuldRgeLr3hrRFrlr/wOZrjrPKEVZeTP4PkZJsPTZZeZZ77:cZHRgeLbhjRTL/CMOYSf7
                                                                    MD5:4E196EBFEBBE4614513498E6BC64A72F
                                                                    SHA1:254846EB51C5E6EB50AB2B1B5F9F04A55799163F
                                                                    SHA-256:922C52F83B91DA65B1BBB6C29FD62A98A86ABDFA47E400246E7913EFC4D98022
                                                                    SHA-512:FB0763E2EED81CE62675877D15EF4115FCFE798AE62A46E749D0BD167441F4B439478CE1C95457CE232409D10DE3A69FCD61DBF8B67259187CAB29EFDDE9AA47
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10689" V="3" DC="SM" EN="Office.Outlook.Desktop.ContactCardAddEditErrors" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="blelq" />.. <UTS T="2" Id="blelr" />.. <UTS T="3" Id="blels" />.. <UTS T="4" Id="blelt" />.. <F T="5">.. <O T="NE">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="I64" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="NE">.. <L>.. <S T="2" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="I64" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="NE">.. <L>.. <S T="3" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="I64" />.. </R>.. </O>.. </F>.. <SQ T="8" R="([5][4])|([6][4])|([7][4])" />.. </S>.. <C T="I64" I="0" O="true" N="AddEdit_Error_HRESULT">.. <S T="5"
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1270
                                                                    Entropy (8bit):4.868272845617514
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdWVObbnhnegD4fW8/4fWHN4ffDwi/IpeMwxZnu8XqlNynHDRhUmYk4XqmbnVq:2dWCbheX3Q6yncIUNAPP216DU123D
                                                                    MD5:7ED5436F835CCA784D4AAC7176D507D5
                                                                    SHA1:EDE910B8F99D9D3082388744B409B3AB8C198495
                                                                    SHA-256:1D6FCEC2CCE2F1B75569DCADE796EC7515AF56F5342FAE18F1238F3D16E5772A
                                                                    SHA-512:82318ED33F551F26AB0E4566E5DFD60745A1F933CC61EC13128A667F0FB6E30BC7BCDDD32C73DB55173D3BFDF21BAF70723E300E1C99E63A1805D9668C9FE0D8
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10695" V="1" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="356" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="2" E="443" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="3" E="441" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. </S>.. <G>.. <S T="1">.. <F N="AutoDiscoverTaskID" />.. </S>.. <S T="2">.. <F N="AutoDiscoverTaskID" />.. </S>.. <S T="3">.. <F N="AutoDiscoverTaskID" />.. </S>.. </G>.. <C T="U32" I="0" O="false">.. <S T="1" F="SSLErrorFlags" />.. </C>.. <C T="U32" I="1" O="false">.. <S T="1" F="SecurityFlagsToAdd" />.. </C>.. <C T="I64" I="2" O="false">.. <S T="1" F="HRESULT" />.. </C>.. <C T="B" I="3" O="false">.. <S T="1" F="fIsCaptivePortal" />.. </C>.. <C T="B" I="4" O="false">.. <S T="1" F="fDialogSupressed" />.. </C>.. <C T="U32" I="5" O="false">.. <S T="1" F="CaptivePortalDetectionTime" />.. </C>.. <C T="B" I="6" O
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1543
                                                                    Entropy (8bit):4.556151531652635
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdWwO80A+KbSvA+KbS+tNqNOAX/c//+4pONd+kXqNOAX/c//TpON+DhWHNhWW9:2dWmt4n9ATn1fcIUNAPP216DU1235
                                                                    MD5:F119B8FFF9098AF77EA29BD9FC8CF6B5
                                                                    SHA1:DB3B8BF701644AEABD51FBDC0B336DAAD4735C6B
                                                                    SHA-256:859F80F276A22CEE18949EB7D8185293E1A3562955E5D9D9F6B216BB79F19564
                                                                    SHA-512:58B9ED6249E21E4302D1EE0E1AFBB247B410DCDD3F7D797126DD01C1EFE31CCA1E1868C5ADAD1965AF07C4D08DE3C7B92A936F7E72EC024477462D4FF8959FD4
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10696" V="1" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="7059" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <Etw T="2" E="7072" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <F T="3">.. <O T="EQ">.. <L>.. <S T="2" F="Status" />.. </L>.. <R>.. <V V="17" T="U32" />.. </R>.. </O>.. </F>.. <F T="4">.. <O T="EQ">.. <L>.. <S T="2" F="Status" />.. </L>.. <R>.. <V V="19" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="1">.. <F N="ClientRequestId" />.. </S>.. <S T="3">.. <F N="ClientRequestId" />.. </S>.. <S T="4">.. <F N="ClientRequestId" />.. </S>.. </G>.. <C T="U32" I="0" O="false">.. <S T="1" F="SSLErrorFlags" />.. </C>.. <C T="U32" I="1" O="false">.. <S T="1" F="SecurityFlagsToAdd" />.. </C>.. <C T="I64" I="2" O="false">.. <S T="1" F="HRE
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1566
                                                                    Entropy (8bit):4.843283995145095
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dW8NCOgdRge8QqRvDXyaVdTuwKhiDUy03+xXPRR7:c3NbYRgevqlGedT1Khi4yM+9PRR7
                                                                    MD5:154E9AF31A47A39D31B0124DFED37D21
                                                                    SHA1:552D26B92C4DB217935D58AE38CD5002502901E4
                                                                    SHA-256:6BAE353AC2EC6B713FA62931243BCA7A212639FDCF5931B8E536771C0983673F
                                                                    SHA-512:7BC90443EB5642F466E303B78477ECA0CE47871A60B80AE8098093BDBB1F073739C9718DDC4F995F6BFBAAAFE1340B650BE57FAE84D35BC6F8DBE976A5A55290
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10697" V="2" DC="SM" EN="Office.Outlook.Desktop.AutoDiscoverHandleSSLCertificateError" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="10695" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="0" />.. <F N="2" />.. <F N="3" />.. <F N="4" />.. <F N="6" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="SSLErrorFlags">.. <S T="1" F="0" />.. </C>.. <C T="U32" I="1" O="false" N="SecurityFlagsToAdd">.. <S T="1" F="1" />.. </C>.. <C T="I64" I="2" O="false" N="HandleCertHResult">.. <S T="1" F="2" />.. </C>.. <C T="B" I="3" O="false" N="IsCaptivePortal">.. <S T="1" F="3" />.. </C>.. <C T="B" I="4" O="false" N="IsDialogSupressed">.. <S T="1" F="4" />.. </C>.. <C T="U32" I="5" O="false" N="TotalCaptivePortalDetectionTime">.. <A T="SUM">.. <S T="1" F="5" />..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1571
                                                                    Entropy (8bit):4.844163444873834
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dWdf1cdRge8nDqRvDXyaVdTuwKhiDUy03+xXPRR7:caf1sRgecqlGedT1Khi4yM+9PRR7
                                                                    MD5:1A6570C846569EDB64B3C40FF7C9AAA1
                                                                    SHA1:69B152EF819A21EB379BB6F2120131F6A5644C51
                                                                    SHA-256:EC8C207232BF2B80E85715BF9E2858F090793A45BC7E7320C4E0292998DDEAEC
                                                                    SHA-512:07BC800E74D1F1F4CAABD64A76B27C18C070BA181EE3468FB3FD3125BDFF7B417821A15A2403323F298B0AB896FDF60DC73723D47DAF36A1D742A47C546C1300
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10698" V="2" DC="SM" EN="Office.Outlook.Desktop.HttpServiceClientHandleSSLCertificateError" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="10696" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="0" />.. <F N="2" />.. <F N="3" />.. <F N="4" />.. <F N="6" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="SSLErrorFlags">.. <S T="1" F="0" />.. </C>.. <C T="U32" I="1" O="false" N="SecurityFlagsToAdd">.. <S T="1" F="1" />.. </C>.. <C T="I64" I="2" O="false" N="HandleCertHResult">.. <S T="1" F="2" />.. </C>.. <C T="B" I="3" O="false" N="IsCaptivePortal">.. <S T="1" F="3" />.. </C>.. <C T="B" I="4" O="false" N="IsDialogSupressed">.. <S T="1" F="4" />.. </C>.. <C T="U32" I="5" O="false" N="TotalCaptivePortalDetectionTime">.. <A T="SUM">.. <S T="1" F="5"
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):2233
                                                                    Entropy (8bit):4.316460563047353
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dWKedRgeLr6qJTwrwOawEJwgCuw2vwfXfXlJ32F9qm1aCcHNfa7:cRCRgeL+qJTuQ1J8uDvWXfVGX8HNfa7
                                                                    MD5:95344DF7161F68E0A4D12854F1959544
                                                                    SHA1:ACA58090D347E9665A1EA02351BDBF88AC74AA64
                                                                    SHA-256:B0795BD883E2CB5B3803257110F6739D714996D79B69B9F9D972124C648724C1
                                                                    SHA-512:D3474962DCE44BBCBE03705BBBDC0710CF3A915BB4328476C150D98D780AC3587D7B4B22F9CFAAC34B9722E86082EBB743EE261851B2531DB2E83A3B015D42F9
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10699" V="0" DC="SM" EN="Office.Outlook.Desktop.AddRecipientUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="ber0h" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="Index" />.. </L>.. <R>.. <V V="0" T="I64" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="Index" />.. </L>.. <R>.. <V V="1" T="I64" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="Index" />.. </L>.. <R>.. <V V="2" T="I64" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="1" F="Index" />.. </L>.. <R>.. <V V="3" T="I64" />.. </R>.. </O>
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):660
                                                                    Entropy (8bit):5.274276796119823
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd11VzjqOURXpdRDDHwpat5lilBfdq3XqnOM7SZnGqd8DSeNO/HNUlu:2d114OeXpdRgeQ8KOM7M6D07
                                                                    MD5:F69833CB53077551B90BC60FC4BF3F18
                                                                    SHA1:80718E0A3A3960DBDDCE5392C582143BEBC86A97
                                                                    SHA-256:DC029A990C150D234C0798BE225DB2C437CC21BF25BF32A3A12065A256B52817
                                                                    SHA-512:D837C56DC59D414971F9F6508699F8C0B0895713489FDAF2F7BE11FC9D00BEEFC4F07D71C899CA7FFD7B23F2A1C14F0B737860590734AC8AE63434659B5191A0
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10701" V="0" DC="SM" EN="Office.Outlook.Desktop.InAppPromptMsoFloodgateEngineStartStopResult" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="20" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="215" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="2" E="216" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. </S>.. <C T="I64" I="0" O="false" N="FloodgateStartResult">.. <S T="1" F="HRESULT" />.. </C>.. <C T="B" I="1" O="false" N="FloodgateStopResult">.. <S T="2" F="Success" />.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1718
                                                                    Entropy (8bit):4.595621349152158
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dhY3WsdRgelf6DwOaW/JWghuD/vDgDelFeDH:c2TRgelfgQgJ5uDvEelFeDH
                                                                    MD5:0059F14ACBDB3A47DD3F422B43FE7191
                                                                    SHA1:84C207905B0A840E03E045DED62047CE636C0C52
                                                                    SHA-256:4A384290A95C54E7D959C38C6F5D1175D3187DE382757046CA28C1DDCCC35847
                                                                    SHA-512:61BD6359B4109B703FC709F16111FA449F692D03007940B0F851BBB11AEAD05903E0C4E6CE8BB2119194529C48C0BA8DCD6F03AF05FDB4002DABE523740402AC
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10704" V="0" DC="SM" EN="Office.Outlook.Desktop.MCRP.VisualV2" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <Etw T="3" E="20045" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="4" E="20046" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <F T="5">.. <O T="EQ">.. <L>.. <S T="3" F="UIFlight" />.. </L>.. <R>.. <V V="1" T="I32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="3" F="UIFlight" />.. </L>.. <R>.. <V V="2" T="I32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="4" F="UIFlight" />.. </L>.. <R>.. <V V="1" T="I32" />.. </R>.. </O>.. </F>.. <F T="8">.. <O T="EQ">.. <
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1602
                                                                    Entropy (8bit):5.060767159898663
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dRjddRgeyxv1STnWJMRR/FJjxAhRbQn9X1ucwIPAFJ:cRTRgeyxv1kWyRD9l3AFJ
                                                                    MD5:BC003388DAD4124BC2E2F0A6DF013D42
                                                                    SHA1:2FD87593656A42B45AF294BE3D627631C9F17E9B
                                                                    SHA-256:577B254FC1083648521747D25F3194FABB3A237616A786EB0155904AE68BAB91
                                                                    SHA-512:82A2A9D14FF7CE9C766D8226B9951733BD6EA8B7C7FDC21110B92B1C3C7B588B2A2FAACB41DBDCA3168E14DAF0A065F0D626B45AAA0CBC6324BDBEAEF7B64DF8
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10705" V="2" DC="SM" EN="Office.Outlook.Desktop.AttachmentImageThumbnailGenerateCount" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <TI T="1" I="Daily" />.. <A T="2" E="TelemetryShutdown" />.. <Etw T="3" E="4236" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="4" E="4237" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="5" E="4238" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="6" E="4239" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="7" E="4240" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="8" E="4250" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="U32" I="0" O="false" N="GenerateThumbnailStreamExistsCount">.. <C>.. <S T="3" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="GenerateThumbnailMapiNotEnoughMemoryCount">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U32" I="2
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):488
                                                                    Entropy (8bit):5.300184761134992
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdZVzjjpvEQdRDDHwpat5lilSdBORaSC7/rmNOqHNUlu:2dZTvEQdRge9dtSC7A7
                                                                    MD5:431C1799C52DBCBB3862D1AADB2D382F
                                                                    SHA1:1A1D5EF7C90C59352B10BCCFD7B8CED1439E5F98
                                                                    SHA-256:A83F9B3DF1535231BB64C5E96DCE7323C2DCF181A6920625B9E2DED84ABB3A95
                                                                    SHA-512:63597167F5016977253CC30DC90733C797891FD5277F00635FAF3B8672050CCD550770BD9AB8CE0A1ABF84D928175D25E6882E290A8F12CF5674D3781B6CA0C3
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10707" V="0" DC="SM" EN="Office.Outlook.Desktop.POP3.InvalidPopBlobExceptionReason" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="20" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="1000" G="{31b56255-5883-4f3e-8350-d7d6d88a4908}" />.. </S>.. <C T="W" I="0" O="false" N="InvalidPopBlobReason">.. <S T="1" F="Reason" />.. </C>.. <T>.. <S T="1" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):975
                                                                    Entropy (8bit):5.1291781033179324
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdqVzjjpvEHdRDDHwpatESdBORafKzdBORafadBORafBicG2AYvEP/HaSMjF4e:2dqTvEHdRgepdtSzdtidtp8qvEPEWTo
                                                                    MD5:17F9F4955A2B3C72AB6D61D95AA4BC05
                                                                    SHA1:306A0E2962C151CB17CBDC54B34985231F99ABAE
                                                                    SHA-256:A4E3DAC9C4EC740C6DE965BEF0B3A60A47647770FC9FFB81719B0E1B173FD415
                                                                    SHA-512:1530E79B248C5717783DFF0760F3FB95C1124E97FF2D9E4825416260D071E19468FC8CB590A402A36CD2395A0B73E7A7CA108D97D273D653D416AB07A86C6375
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10708" V="0" DC="SM" EN="Office.Outlook.Desktop.POP3.InvalidPopBlobExceptionMetrics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="1000" G="{31b56255-5883-4f3e-8350-d7d6d88a4908}" />.. <Etw T="2" E="1001" G="{31b56255-5883-4f3e-8350-d7d6d88a4908}" />.. <Etw T="3" E="1002" G="{31b56255-5883-4f3e-8350-d7d6d88a4908}" />.. <A T="4" E="TelemetryShutdown" />.. <TI T="5" I="Daily" />.. </S>.. <C T="U32" I="0" O="false" N="Count_InvalidPopBlobException">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="Count_FailedToSaveResTag">.. <C>.. <S T="2" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="Count_FailedToReadResTag">.. <C>.. <S T="3" />.. </C>.. </C>.. <T>.. <S T="4" />.. <S T="5" />.. </T>.. <ST>.. <S T="1" />.. <S T="2" />.. <S T="3" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1027
                                                                    Entropy (8bit):4.470901556113302
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdqryNFsA+KbSAA+KbS+tNqNOQhX/c//ltpONd+kXqNOGMOX/c//HpON+HNKhV:2dWPt4dsTSa6YhVA99PzitZ
                                                                    MD5:59A3740357D8EEFE69FD938E54ACD0EB
                                                                    SHA1:2F73688861A9C1820E78D5B003F4FF757F6BA1E2
                                                                    SHA-256:88795A98DB9351DB0B25BC712BF496CA88AC379A21CC28B951BCEEA372D903FF
                                                                    SHA-512:CF1516609A9095613FAB290D9AD043122F912AA1CFB771097626CC78E83334B64DAA9EDA2D922E456AE8FAFE0B448E08E9D0323BA92177706F4D167C515E0E62
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10713" V="1" DC="SM" T="Subrule" DCa="DC" xmlns="">.. <S>.. <Etw T="1" E="6028" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <Etw T="2" E="7068" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <F T="3">.. <O T="EQ">.. <L>.. <S T="2" F="CallerKeyword" />.. </L>.. <R>.. <V V="MapiHttp" T="W" />.. </R>.. </O>.. </F>.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="NewState" />.. </L>.. <R>.. <V V="2048" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="3">.. <F N="CallerID" />.. </S>.. <S T="4">.. <F N="RequestID" />.. </S>.. </G>.. <C T="FT" I="0" O="false">.. <S T="4" F="TimeStamp100ns" />.. </C>.. <C T="U32" I="1" O="false">.. <S T="3" F="ConnID" />.. </C>.. <C T="W" I="2" O="false">.. <S T="3" F="ClientRequestId" />.. </C>.. <T>.. <S T="4" />.. </T>.. <ST>.. <
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1032
                                                                    Entropy (8bit):5.040346653370313
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdmVzjeK6dRDDHwpatER2GeOSc1NQzD+S0MCf9bFx9/cSZMlbSjyVEEN1DaeQh:2dmsldRge8vLvqHMa1xg
                                                                    MD5:FACF9E5E5EB7B519B506F47A1F27E96D
                                                                    SHA1:619683A978789BB1070F13CAD9C6CDACBF8804F9
                                                                    SHA-256:44F68E3087B4BAC7C4C3275A87AF55D900AB8D38CA60FBC33167C6C54F6BA43D
                                                                    SHA-512:1D1E6053ACF29CD0FF4959DA53A268D2631F39C39C34CEC73B989A2BA85E7574B247932CEEDDF518894682362D02D1D2E578CA3357353C77B134A9E67C7EC63B
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10717" V="0" DC="SM" EN="Office.Outlook.Desktop.GroupsDataDetailsErrors" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3476" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="CONTEXT" />.. <F N="HRESULT" />.. <F N="LowLevelError" />.. <F N="ErrorContext" />.. </S>.. </G>.. <C T="I32" I="0" O="false" N="Context">.. <S T="1" F="CONTEXT" />.. </C>.. <C T="I64" I="1" O="false" N="HResult">.. <S T="1" F="HRESULT" />.. </C>.. <C T="U64" I="2" O="false" N="LowLevelError">.. <S T="1" F="LowLevelError" />.. </C>.. <C T="U64" I="3" O="false" N="ErrorContext">.. <S T="1" F="ErrorContext" />.. </C>.. <C T="U32" I="4" O="false" N="CountGroupsDataDetailsError">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):699
                                                                    Entropy (8bit):5.128210137833051
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdNVzjePShdRDDHwpatEf2GeOSc1NQzDvrNxKuEMjjWSeSHaSMNO5csu:2dNsQdRge2vLvqu1
                                                                    MD5:DC99ABE1F69F3E7D1CCEBCD2ECCC6897
                                                                    SHA1:A6DB1A637790B4F54EAD8DB3149D4099BE6C744E
                                                                    SHA-256:F3C033B04A5E3EB0D524BE8C76F7F4B0A3E6BE33F248B749C45390550CE7A5FF
                                                                    SHA-512:20F3D1F5F287B05B2128767935E9D4EDAE01D8F2AE243B30CAD2CA29787BAB24D9B873D5CA956558EAC412D71529F256F112D3D5CB35468499DCF452E8E5B8BA
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10718" V="0" DC="SM" EN="Office.Outlook.Desktop.GroupsDataDetailsSavedServerCall" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3478" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="FullDetails" />.. </S>.. </G>.. <C T="B" I="0" O="false" N="IsFullDetails">.. <S T="1" F="FullDetails" />.. </C>.. <C T="U32" I="1" O="false" N="CountSavedServerCalls">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):698
                                                                    Entropy (8bit):5.159252596670504
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd43VzjeMdRDDHwpatES2GeOSc1NQzD/NxDfOMjdSHaSMNO5csu:2d43sMdRge7vLvqnrGQh
                                                                    MD5:23913A0C3E7E5610AA204F35449EA3C6
                                                                    SHA1:74C6A9F7D6E3D181A8758D33822F1EC14DC23717
                                                                    SHA-256:D20CC196666CB34A28921C12F5D5BA0B75CF341500346CD0263C2D1E7FC37633
                                                                    SHA-512:073D78C05947E9C7514F51220FA3DF16C4B8CAFC768B317DC386AC8C2ABE15139B2837BCFB4FC9FA054B17A1249C5161180E6FCF82C16BE16AB418549EC16FE8
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10719" V="0" DC="SM" EN="Office.Outlook.Desktop.GroupsDataDetailsRequested" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3477" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="FFlightEnabled" />.. </S>.. </G>.. <C T="B" I="0" O="false" N="FlightEnabled">.. <S T="1" F="FFlightEnabled" />.. </C>.. <C T="U32" I="1" O="false" N="CountDetailsRequests">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1027
                                                                    Entropy (8bit):5.024812970941374
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdRVzjOl6dRDDHwpatEG2GeOSc1NQzD+S0MCf9bFx9/cSZMlbSjyVEEN1Da27+:2dRjdRgezvLvqHMa1I
                                                                    MD5:702AC93C98BF3C733E134BBB99DFC78C
                                                                    SHA1:D930A9F72972D98210E4A63BFC249E3EF8695A28
                                                                    SHA-256:2484353F9EBB44241D1E70114C2DF411275D61914D9808D7D300BE6D7386216A
                                                                    SHA-512:D0080B95395ABEA0C815A54D16FC8FE69AECE9169B5CB82FE3DD0DBE43BC03EE3E2A03C47CDE3E3BB5FB2BB7B3D8362F308AA1FAD5C69C3A2C879529DDF4352B
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10721" V="0" DC="SM" EN="Office.Outlook.Desktop.GroupsDataContentErrors" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3451" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="CONTEXT" />.. <F N="HRESULT" />.. <F N="LowLevelError" />.. <F N="ErrorContext" />.. </S>.. </G>.. <C T="I32" I="0" O="false" N="Context">.. <S T="1" F="CONTEXT" />.. </C>.. <C T="I64" I="1" O="false" N="HResult">.. <S T="1" F="HRESULT" />.. </C>.. <C T="U64" I="2" O="false" N="LowLevelError">.. <S T="1" F="LowLevelError" />.. </C>.. <C T="U64" I="3" O="false" N="ErrorContext">.. <S T="1" F="ErrorContext" />.. </C>.. <C T="U32" I="4" O="false" N="CountDataContentErrors">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1030
                                                                    Entropy (8bit):5.0477112915064195
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdOVzjnkL6dRDDHwpatEb2GeOSc1NQzD+S0MCf9bFx9/cSZMlbSjyVEEN1DanC:2dOxndRgeevLvqHMa1YC
                                                                    MD5:9073D8E495CE954CC1101F3715B4716A
                                                                    SHA1:11B60AD602D97CABA662ECC224566B32F85C28D5
                                                                    SHA-256:EB6AE0CBCAD4549D1F96A19042A1FDE91E17923C96A6DDE753F3B2BFC642FD37
                                                                    SHA-512:1DED90125D4F3222846B05C0CB502403E92DE167ACA97E18965EEB5D9850D64C0038237749451D7EEC97D7661F643BAC72D3EEF9C358FB97980F002BB99302C3
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10722" V="0" DC="SM" EN="Office.Outlook.Desktop.GroupsDataJoinedErrors" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3351" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="CONTEXT" />.. <F N="HRESULT" />.. <F N="LowLevelError" />.. <F N="ErrorContext" />.. </S>.. </G>.. <C T="I32" I="0" O="false" N="Context">.. <S T="1" F="CONTEXT" />.. </C>.. <C T="I64" I="1" O="false" N="HResult">.. <S T="1" F="HRESULT" />.. </C>.. <C T="U64" I="2" O="false" N="LowLevelError">.. <S T="1" F="LowLevelError" />.. </C>.. <C T="U64" I="3" O="false" N="ErrorContext">.. <S T="1" F="ErrorContext" />.. </C>.. <C T="U32" I="4" O="false" N="CountGroupsDataJoinedError">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1232
                                                                    Entropy (8bit):4.655188184670387
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd9VzjWOx6dRDDHwpatEi0Kc1NQi+kXZO5fX/c//xpONd+wsvXxH/O5fX/c///:2d91x6dRge8nqJ7YwO4L8yVBbB0T7
                                                                    MD5:EDA75561B8C19B4C4D92BEE6AFC98DC9
                                                                    SHA1:5ADC7790F2EF746B0804A84B4D1515FE5B38AFDB
                                                                    SHA-256:83B64EE2E5566C773FBD564EC6EE4CB1AE70E7C2E0900D889701D396298E297B
                                                                    SHA-512:0AF4C19F220325D117DF33D2A03AE2B14D9DEDB105724851A70E6665832C6A8A5348ADAB1AC5D6D210A95F89AF1EC95158DB265C670E6E1BB3A7FE46A93D19F6
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10725" V="0" DC="SM" EN="Office.Outlook.Desktop.ClassicReadingPaneLoadStats" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="10726" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="LE">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="60000" T="U16" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="GT">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="60000" T="U16" />.. </R>.. </O>.. </F>.. </S>.. <C T="U16" I="0" O="false" N="CountOfTimesFullyLoadPerfEventTriggered">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="F" I="1" O="true" N="AvgFullyLoadPerfTime">.. <A T="AVG">.. <S T="4" F="0" />.. </A>.. </C>.. <C T="U16" I="2" O="true" N="MaxFullyLoadPerfTime">.. <A T="MAX">.. <S T="4
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):688
                                                                    Entropy (8bit):4.652872274228483
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdVYfFOHnAD+NW8/+NfDb8OKX/c//fpONkMNO/HNUlu:2dVVpWME7
                                                                    MD5:5AA209B1409D10B0EA859A20F1F582F6
                                                                    SHA1:B6C5E62A13EF2D372C3FDC97AFF9CF85563A6503
                                                                    SHA-256:A367E3290DCCE6C50E5C976188C19327378F40A78BFE159597102E74F2A5C557
                                                                    SHA-512:BC061738C0D3858DB8C28A6D2952F858C25E82E2B920A2265490707D09CE1F1662C3289F1066E94E65D2520485CE53179F209C8E433AAB47A59E0B78061CCADA
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10726" V="0" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="6109" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="6110" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <G>.. <S T="1">.. <F N="EntryIdW" />.. </S>.. <S T="2">.. <F N="EntryIdW" />.. </S>.. </G>.. <C T="U32" I="0" O="false">.. <U T="100nsToMs">.. <O T="SUB">.. <L>.. <S T="2" F="TimeStamp100ns" />.. </L>.. <R>.. <S T="1" F="TimeStamp100ns" />.. </R>.. </O>.. </U>.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1144
                                                                    Entropy (8bit):5.06980741556941
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd5Vzj1LQXdRDDHwpatE+ic1NXUFH1YHI6H26UxXHISMiLXHfSMpiPFXHfOSMM:2d53IdRgelfs3D2Ns9HF+
                                                                    MD5:B91E06D9D66C4ABC56382A42E3A1280F
                                                                    SHA1:754A56A921CDE2E6981910B32211B15EC514C0FC
                                                                    SHA-256:E430F9004AD25E89903ADF485937FD4AA6ED8196613360EB975D0B0F87641A4F
                                                                    SHA-512:9F5E66D2BFDE32D3D3D0B278A2A80D87BAC476464BE8086774BBACC4730160464D1015390761CDA7276B30A4858F7C82F21DEC7BDCF2B137B553C74887953CAE
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10729" V="0" DC="SM" EN="Office.Outlook.Desktop.MCRP.ThreadWhispersInfo" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <Etw T="3" E="20048" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="4" E="20049" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="5" E="20050" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="6" E="20051" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="U32" I="0" O="false" N="WhisperRendered_Count">.. <C>.. <S T="3" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="WhisperClicked_Count">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="BacklinkRendered_Count">.. <C>.. <S T="5" />.. </C>.. </C>.. <C T="U32" I="3" O="false" N="BacklinkClicked_Count">.. <C>.. <S T="6" />.. </C>.. </
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1126
                                                                    Entropy (8bit):4.879603911423696
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdmVzjlKk5mWgBdRDDHwpatEBSas3HqmXFJicoN+kX5lOeX/c//tpON+WX0MVJ:2dmixvBdRgekYRvS8+EVBxh1Zc
                                                                    MD5:765B7B60BE6DF7223942AC314F56B1B9
                                                                    SHA1:BF5330C9FC17AEB8E4D198BFC6C4C9D534ECC01C
                                                                    SHA-256:885475B97150C479CEA095B07DA88E71BA6C8C49248F3F83889A560700B45051
                                                                    SHA-512:C37E192A60EC8F35309D85A2FC3DAC978C170DDE8D3ADAA6E514B69A6CBB8C8F3A2CDD341220D1D8CCD186B878CAED5BA773AC748E219549B84EB5FA27C4F808
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10730" V="1" DC="SM" EN="Office.Outlook.Desktop.DiagnosticsSystem.HttpRequestResult" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="20" G="{ad58872e-4df6-4b26-9841-5d7887a1c7a5}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="NE">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="4">.. <F N="HRESULT" />.. <F N="HttpRequestKind" />.. <F N="URL" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="HResult">.. <S T="4" F="HRESULT" />.. </C>.. <C T="U32" I="1" O="false" N="HttpRequestKind">.. <S T="4" F="HttpRequestKind" />.. </C>.. <C T="W" I="2" O="false" N="EndpointURL">.. <S T="4" F="URL" />.. </C>.. <C T="U32" I="3" O="false" N="HttpRequestFailedCount">.. <C>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1685
                                                                    Entropy (8bit):4.562340878031908
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d6tMBdRgegDlQJ8wOanIkIu4ItU2Xe2X7taXag7:c64Rgeg5QJ8QIduRnG7
                                                                    MD5:B57497B3C1004D7720671FE752879557
                                                                    SHA1:34E9DD2EFD4AB25712FD7AB620587CCFCA8505FA
                                                                    SHA-256:17FA34811E4D8DF37ABCB06918CE50D735913492370CD810BDB347580582B011
                                                                    SHA-512:A28F87BB0ACF9370FBBE223946F49101647E14DEAB68DDD991FCB0F895637101E98498B4B1FFE8FD4C13B48F823CE6699B3CB347F5C3D6A5D339445C72DA9089
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10731" V="0" DC="SM" EN="Office.Outlook.Desktop.DiagnosticsSystem.OpenHelpShiftTicketResult" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3773" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="2" E="3774" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <A T="3" E="TelemetryShutdown" />.. <TI T="4" I="Daily" />.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="NE">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="2" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="8">..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1038
                                                                    Entropy (8bit):4.724554991273104
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdN3VzjlKk5mWgqdRDDHwpatEOnXFJicoN+kXqNOeX/c//tpONd+wsvX5lOeXo:2dN3ixvqdRgetXvS8TnIwOZm7NZ7
                                                                    MD5:E2B2476E614450B94D9620FE839BF4B4
                                                                    SHA1:52E74D9E382574C0468B4D5F5C4A7D51B8ACEFCE
                                                                    SHA-256:8C86D10255B75C82417B327AA7805C71F1E39B73A59F1F3636AFF55B6DCAB40E
                                                                    SHA-512:ABFFA0115AEBEB8F256C0C45E66FF9C26D24276D08E5FF7D54507E9A81F88F45DB03041488CA49C55CA7741E35DF8579AF0EADB6D557F04D075DBD979294B71A
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10732" V="0" DC="SM" EN="Office.Outlook.Desktop.DiagnosticsSystem.HttpRequestResultSuccessFail" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3772" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="NE">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="HTTPRequestSucceeded">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="HTTPRequestFailed">.. <C>.. <S T="5" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):758
                                                                    Entropy (8bit):4.70014845671891
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdcrfBkqaH6ADjf0W8/jf0fDb8OKX/c//fpONkMNO/HNUlu:2dcdkbqrJE7
                                                                    MD5:D6DA2A20557ABDE506656F567B9449C0
                                                                    SHA1:78D9920B7DA9F28558973F40352E047792269B21
                                                                    SHA-256:B5A707A403CFC86C04C411A81DF57C2CA949684A703C81EA63F2A9DD7CDE0F58
                                                                    SHA-512:6013074491CA816CA6C1A7034FE7930AD17FC1F2388ED2E0D9ADED77F95C6C2F541EA2B9412819E47BFC2423407821F3403F8BCDE5508FC50AA065393A8430BD
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10737" V="0" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="20004" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="20047" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <G>.. <S T="1">.. <F N="ConversationIdW" />.. <F N="ThreadIdW" />.. </S>.. <S T="2">.. <F N="ConversationIdW" />.. <F N="ThreadIdW" />.. </S>.. </G>.. <C T="U32" I="0" O="false">.. <U T="100nsToMs">.. <O T="SUB">.. <L>.. <S T="2" F="TimeStamp100ns" />.. </L>.. <R>.. <S T="1" F="TimeStamp100ns" />.. </R>.. </O>.. </U>.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):775
                                                                    Entropy (8bit):5.149938745161758
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdCVzjU2X6dRDDHwpatE6IqB2M5IqB2coNBnAUVyFNHaSMjxHbSHhSMNOAdHNN:2dCedRgeXIi35IiOv4F4ir
                                                                    MD5:3A35D76F3A8F716B547B54AA227AFA3C
                                                                    SHA1:7C44BF0F2686ABA6ECFF14C73B1422A2023C851E
                                                                    SHA-256:30CF20A2269F920756A7D20A2B649BF087F2B8C55217AC9BB9AAB5D59BF55182
                                                                    SHA-512:4EFBD8F8FBD6852F51C5397C005CE005B7B7C4D2C75183D818EF32C627F8B1C5A922E2A4A04B0A1436BA90C9D10020B558659EE642612355B5C13A0468C07642
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10739" V="0" DC="SM" EN="Office.Outlook.Desktop.SchedulingAssistantZoomChange" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="355" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <Etw T="2" E="356" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <TI T="3" I="Daily" />.. <A T="4" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="CountSchedulingAssistantInitializations">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="CountZoomChanges">.. <C>.. <S T="2" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="4" />.. </T>.. <ST>.. <S T="1" />.. <S T="2" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):3228
                                                                    Entropy (8bit):4.247067069050775
                                                                    Encrypted:false
                                                                    SSDEEP:48:c+GnRgehqJKvNvJuupvFsa8m/hfyUFvj17R7:wnRgeO01EMdtZJfl1/7
                                                                    MD5:C9650F76052C1626BFAE4C0E2A22A812
                                                                    SHA1:FD854A3A1F28CB50A24B4AEDD2156D158456EC62
                                                                    SHA-256:517D86C14935F3ED9A72602ABDEFC275663F4AC6FB863617C8126FD695685D1A
                                                                    SHA-512:9A3C45B58376590A5A37FE092EDF46BB3F65A34EA11EF07C041CDFA5BF607BF914A4F0DEA0709E91BC8D6B7233F8FB77956F3204EDC8964D60DD11553DA4098F
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10740" V="0" DC="SM" EN="Office.Outlook.Desktop.EmsConfiguration.ResolveNames" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="10684" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="LT">.. <L>.. <S T="1" F="6" />.. </L>.. <R>.. <V V="2147483648" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="GE">.. <L>.. <S T="1" F="6" />.. </L>.. <R>.. <V V="2147483648" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="4" F="5" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="4" F="4" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1654
                                                                    Entropy (8bit):4.554017495890807
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d4hJnDdRgepRvS8TdYPjqwOadYPiAJ5rjqu5riu7m+KlGKa7:c6JBRgeDvS8TdYbqQdYPJJqufgo7
                                                                    MD5:CCBD4BA6FD3CE83A50A03D3FA380820B
                                                                    SHA1:27E9AA847B689DD9D065914D84D9F66B4D6D0909
                                                                    SHA-256:20E62A24204252A81F29378EFEE18DBEBF0680D0FBD60C0FA9D278786158A355
                                                                    SHA-512:03E92B546EF16ED5405DF364869F2D199188D545C13148C7909CB6D3C4E13462179276DD76B45C2CE758D3C43F0E01D921B374375F8715C6F18163F95F2D3584
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10741" V="1" DC="SM" EN="Office.Outlook.Desktop.DiagnosticsSystem.SARADiagnosisResult" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="17" G="{ad58872e-4df6-4b26-9841-5d7887a1c7a5}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="ResolutionFound" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="ResolutionFound" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="NonEmptyRootCauseDescription" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):2051
                                                                    Entropy (8bit):4.021274365490137
                                                                    Encrypted:false
                                                                    SSDEEP:24:2db44bOx6dRge8ovqJOJ37NwOapccJ3QyAyVBbB0ZrIU07z7:cM4ax2RgeXqJODQecFAunz7
                                                                    MD5:F7EDEDFBF2FC81D57452BC1389AB1824
                                                                    SHA1:B6FC44494F3CD8BE8142642EA6D1E567FE545E99
                                                                    SHA-256:A4EE086DB47F26AAD4CD2EC67EDABAEA35B82A2297DDE1E4CBC6656EF8B3D21C
                                                                    SHA-512:85C201E6CAD9DFD92AB4112F810D2F0D454A0F7431533842BC5A33E2F6A5C386A5F6FB0FA28AFEB24F01DAC355F8662C9B8B400CB2E5157391032DF6CEF9EB92
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10742" V="0" DC="SM" EN="Office.Outlook.Desktop.InspectorVerbStats" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="10743" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <V V="0" T="I32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LE">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="60000" T="U16" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <V V="0" T="I32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="AND">.. <L>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):819
                                                                    Entropy (8bit):4.630679580795938
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdHfFVHsNaAD9fW8/9ffDb8OKX/c//fpONkMEUtxQNO/HNUlu:2dG33liR7
                                                                    MD5:5CAC2B8B663329D4F4B71EE341068B7D
                                                                    SHA1:18C302FDDC261BA7AE68C6683EAAA335BE8F4ABE
                                                                    SHA-256:19F1142A05C036E80A4958E68CAB8B8D3B46D83767A68289BF131449AB9DFB65
                                                                    SHA-512:BD915CA197DBFDB060F6AA56D070818D72054D5536C1AD60D807905CCCDDEF9EAB19A1C2C4D213D88EA3A96BA4C3BC2F2753E8716B7465510AD1FE58CAD64232
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10743" V="0" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="6111" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="6112" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <G>.. <S T="1">.. <F N="EntryID" />.. </S>.. <S T="2">.. <F N="EntryID" />.. </S>.. </G>.. <C T="U32" I="0" O="false">.. <U T="100nsToMs">.. <O T="SUB">.. <L>.. <S T="2" F="TimeStamp100ns" />.. </L>.. <R>.. <S T="1" F="TimeStamp100ns" />.. </R>.. </O>.. </U>.. </C>.. <C T="I32" I="1" O="false">.. <S T="2" F="Verb" />.. </C>.. <C T="I32" I="2" O="false">.. <S T="2" F="HRESULT" />.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1151
                                                                    Entropy (8bit):4.825890710775881
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdAjVzj+hdRDDHwpatE+ic1NTXaHqX++qsN+wsvXqNO8X/c//wVrMpONd+axHq:2d6EdRgelf7+q8wOaTjqWwAwPlHH
                                                                    MD5:7B714825A1E78CC5348D249A411FF3E7
                                                                    SHA1:7AF6AB375BC8BD26858A0409FB0E7D839C090A47
                                                                    SHA-256:7B2AA7D4B000D6C4EEF353E84C8C6056061123B4B11F5BF0534F88DE1CDE4CE3
                                                                    SHA-512:9A27DB1C1F0E091B0C88A0EAFE263445148E8553B358A1D4B7A0970523E26E2A46708343C64D6B34D3AA16B60A85923FCF83970A282C8E2C680B6AE98A277C19
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10744" V="0" DC="SM" EN="Office.Outlook.Desktop.UnsupportedHtmlTagsInfo" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <Etw T="3" E="4204" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="4" E="323" G="{bb00e856-a12f-4ab7-b2c8-4e80caea5b07}" />.. <F T="5">.. <O T="EQ">.. <L>.. <S T="3" F="HasUnsupported" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="GT">.. <L>.. <S T="4" F="unknownUnsupported" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="UnknownHtmlRenders_CountInNotModern">.. <C>.. <S T="5" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="UnknownHtmlRenders_CountInModern">..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1655
                                                                    Entropy (8bit):4.541476459013172
                                                                    Encrypted:false
                                                                    SSDEEP:24:2doLAdRgekXURvS8TnIwOZIJR7jquR7iMeue/J6M7:coL4RgekX+vS8TIoJRvquRk6M7
                                                                    MD5:9344BE5D8457F75D478A00C82F9946E5
                                                                    SHA1:AA2AE901819CCC0EFA809B6FA9731769089FDB50
                                                                    SHA-256:746DC7F2E803E846F58CB7B27C086A0E26B7A80A502CD9D859AEB1610CC61C0D
                                                                    SHA-512:23BB8DEEFFE4C9AC8F7B507A52B4C611A58D81F9D0AB21417114CA3C4ACBB5BD9846251B3AE38350B4BBB4978308BF563233D7AB66B79D99786AFF389C83B83F
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10750" V="1" DC="SM" EN="Office.Outlook.Desktop.DiagnosticsSystem.GetETLFileUploadURLResult" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="24" G="{ad58872e-4df6-4b26-9841-5d7887a1c7a5}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="NE">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="ETLFileUploadURLRetrieved" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="1" F="ETL
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):719
                                                                    Entropy (8bit):5.086988211731638
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd8VzjKhdRDDHwpatEBQHP4HcoNBnqXHaSMWp6XHhSMNO3AHNUlu:2d84hdRgekAyvq+97
                                                                    MD5:B34CAD4A18D3477263505F28C73B1098
                                                                    SHA1:0A271C6D985BAF4D62020264A09C5171E79FEB97
                                                                    SHA-256:7428F9F31B1C238B5C063BE77873B158B7B1EA6A8B7CD9B3060DF131037A7DE5
                                                                    SHA-512:393F07293B4B811B6D9CF5EA1E718E4F6B0BD52516A0657A1F92161930F5B8223F6BCA678EEEE8A630F6CF374B98026758791379E0D43E2C5E14D8ED363ED8E0
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10751" V="0" DC="SM" EN="Office.Outlook.Desktop.Subject.AtMention" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="22200" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="22201" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="3" I="Daily" />.. <A T="4" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="LaunchCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="SelectedCount">.. <C>.. <S T="2" />.. </C>.. </C>.. <T>.. <S T="4" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):3027
                                                                    Entropy (8bit):4.253812969954003
                                                                    Encrypted:false
                                                                    SSDEEP:48:cRauRgeqqJTkQXJiuNvb0shl8NA/JfyCU+byde7:qRgehQ6sS46fhfC+97
                                                                    MD5:F481EE9288B0A9FBDBD2E410DC3C8354
                                                                    SHA1:1E2FA600CC09A3C75F2F2EEBE2C299091E78D26D
                                                                    SHA-256:5AAFBF18408D48B368FC3EA8E757DF8713E6FE3D8B248D0C0F6124E55CF50DD0
                                                                    SHA-512:EA8293F1B0854BE3AA14189CAC744A93B20EFF57EDC1245EFF246ED2D564E08D6899E5210576DBF091BD8111C489E981892F0247DE96E25C31224014502210FF
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10754" V="1" DC="SM" EN="Office.Outlook.Desktop.NavPaneModuleClickDistribution" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3204" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="ModuleId" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="ModuleId" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="ModuleId" />.. </L>.. <R>.. <V V="2" T="U32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="1" F="Mo
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1184
                                                                    Entropy (8bit):4.706862813147077
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdI3VzjlzadRDDHwpatE/nXFJicoN+kXqNOeX/c//tpONd+wsvX5lOeX/c//tl:2doudRge0XvS8TnIwOZQ4REm4h/K/27
                                                                    MD5:557669BBCBE6E9D9B2221B57A754ABFA
                                                                    SHA1:5323F9A426F9C2D7DA645D84AD003F4CA2E56B37
                                                                    SHA-256:5A7FBEDF0579791EFC64B4E8995D0C1652632C3BC843BAE40066E649EB221245
                                                                    SHA-512:8E3D7DC6445E5E19BCEAF67581CB2F9045B7219395D9266B6841B30F7B338D04AF68CA1203602BE9C8D121567D8BF7ED7E536078093CBAB0358C5218F55660CD
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10755" V="0" DC="SM" EN="Office.Outlook.Desktop.DiagnosticsSystem.UploadFileResult" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3777" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="NE">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="1">.. <F N="ProviderType" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="ProviderType">.. <S T="1" F="ProviderType" />.. </C>.. <C T="U32" I="1" O="false" N="FileUploadSucceeded">.. <C>.. <S T="4" />.. </C>.. </C>.. <
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):4053
                                                                    Entropy (8bit):3.836061934703254
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dWWdRgekbRvS8r/PwODv27vOcv67v+HvK7vUavE7v/lvB7vAs/c/Ki/RN/xb/0h:cWaRgektvS8TtSDd8rQffN7
                                                                    MD5:84CEF52ABA34364BB85B0F3AD2C2CBA5
                                                                    SHA1:271185CCF86F4A64209F085D8DB18AB44F160F10
                                                                    SHA-256:B3E9900C287721A7AAAC8A13A6E879AE71D8E46DF738A3D42BF4F8427A140C26
                                                                    SHA-512:3EC575C7CD421F484A02AA5A995DE481F71BF2751D80496345604679FB1C8B08C490731987C01A9B1A3BFF9E146F8AF2066C4842A779F5121FAB43AF3483C505
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10756" V="1" DC="SM" EN="Office.Outlook.Desktop.DiagnosticsSystem.UploadFileTime" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="25" G="{ad58872e-4df6-4b26-9841-5d7887a1c7a5}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="LE">.. <L>.. <S T="1" F="TimeDifference" />.. </L>.. <R>.. <V V="1000" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="AND">.. <L>.. <O T="GT">.. <L>.. <S T="1" F="TimeDifference" />.. </L>.. <R>.. <V V="1000" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LE">.. <L>.. <S T="1" F="TimeDifference" />.. </L>.. <R>.. <V V="5000" T="U32" />.. </R>.
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):4130
                                                                    Entropy (8bit):3.900669303722967
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dztSdRgekRvS8r/PwODv27vOcv67v+HvK7vUavE7v/lvB7vAs/TaM5JaMu4aMU0:czoRgeOvS8TtSDd8ZGfx9z7
                                                                    MD5:60786B80936C9644A9B6A50192307428
                                                                    SHA1:3B73B41BC2F4F231AA0217E56506E4D889F6F871
                                                                    SHA-256:D1B3C48AD31F2FF5AAC4001E1B57ABA19ED1FEDE5EBABA948DE5318AF7B0F716
                                                                    SHA-512:F4D1BBC08D54B41459A6AE1E8F268A33D552CEC8F2727DFF13149F5B841283B97DDD05096606A7CB5F6F520D58FF826D43BB29BD2C53A1CCFBCC3AA44E9CD957
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10757" V="1" DC="SM" EN="Office.Outlook.Desktop.DiagnosticsSystem.OpenHelpShiftTicketTotalTime" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="14" G="{ad58872e-4df6-4b26-9841-5d7887a1c7a5}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="LE">.. <L>.. <S T="1" F="TimeDifference" />.. </L>.. <R>.. <V V="1000" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="AND">.. <L>.. <O T="GT">.. <L>.. <S T="1" F="TimeDifference" />.. </L>.. <R>.. <V V="1000" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LE">.. <L>.. <S T="1" F="TimeDifference" />.. </L>.. <R>.. <V V="5000" T="U32" />..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):6421
                                                                    Entropy (8bit):4.217545078480636
                                                                    Encrypted:false
                                                                    SSDEEP:48:cuK6sRgeEfoBOq8QrqJpquvqvhTqsebq8f7q/V/qfyVRTqFVObqIVv7qLQqGkTq6:gRgeVufW1kAfsfJZZL6rOgb7FFKLf4a
                                                                    MD5:99A376E93471334EC88A6473602A8659
                                                                    SHA1:E77FEE174CC5B13D26A233A02605F0E9F4093A0B
                                                                    SHA-256:69F269B5CFCC9D7266600262032DB238D67F6F405098F8B7B1BF1FF4E4E4C11E
                                                                    SHA-512:47E647493A538799F292EEB05265D08D2B04B9144717C0560408BEFD229E0E0ABC691E478A0E875E115A3D2E9BCAD8ABB585960F12BCE8E7D9033AADB1EA66A0
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10759" V="2" DC="SM" EN="Office.Outlook.Desktop.OutlookCalendarUsageErr.MeetAcptRcpt.Rule.O16" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <Etw T="3" E="357" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <F T="4">.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <S T="3" F="IsRecurring" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </L>.. <R>.. <O T="EQ">.. <L>.. <S T="3" F="IsException" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="3" F="IsRecurring" />.. </L>.
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):909
                                                                    Entropy (8bit):5.091434923170552
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd+jVzjJFfdRDDHwpat5D+igq3Xu7dq3hmUmXHhSM4XHISMjt9pCsYFXNOqHNr:2d+jrpdRgeg0K0RggQN0bh
                                                                    MD5:E77476C1500E35E9BFCF41725DEE327C
                                                                    SHA1:62695740BCA5F20509D97B095F116912C758E578
                                                                    SHA-256:898366B722C3FA76D9654F99C7C68BC32678723ECDC2529E0D9230080753EC12
                                                                    SHA-512:E0D0C70F91AFDEA3C463FB04410DAEF156AB10C2E635B4F7CC48B33AA083369F524791739C70831D886857C122C2C3EDAFCA15A88C388528BDE87EC4A0C6A488
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10760" V="0" DC="SM" EN="Office.Outlook.Desktop.AddinsLoadPerfInfo" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="1" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <Etw T="2" E="147" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="3" E="214" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="4" E="3000" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="U32" I="0" O="false" N="LoadedOnBoot_Count">.. <C>.. <S T="2" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="LoadedAfterBoot_Count">.. <C>.. <S T="3" />.. </C>.. </C>.. <C T="F" I="2" O="true" N="AvgLoadTime">.. <A T="AVG">.. <S T="4" F="DelayTime" />.. </A>.. </C>.. <T>.. <S T="1" />.. </T>.. <ST>.. <S T="2" />.. <S T="3" />.. <S T="4" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):718
                                                                    Entropy (8bit):5.05355657164101
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdNVzj+sdRDDHwpatEhX4FHc1NQzDaNPfM4EXHaSMNO5AHNUlu:2dNDdRgeoX/qC1607
                                                                    MD5:BC16F0A276623F9D01DB0761CF81ABCB
                                                                    SHA1:37E9847C1A350ACE7CF348C46E8B5C224F1930E8
                                                                    SHA-256:8712FA85D202A75CB2DC661B31EC7C8A910107A84C11D93794DA3C5B0E816197
                                                                    SHA-512:F54BA27C648DB9D5ECDA0BEF5BB51EAE537FC6A16FD206DA5A1CE681E3DC4F3173CB7B81193896AD23054BD058F249C25B13204C56D3DC0E3DF5093EA4C5B0FA
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10761" V="0" DC="SM" EN="Office.Outlook.Desktop.AttachmentsWebRefPaste" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="4242" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="ResponseCode" />.. </S>.. </G>.. <C T="U64" I="0" O="false" N="ResponseCode">.. <S T="1" F="ResponseCode" />.. </C>.. <C T="U32" I="1" O="false" N="ResponseCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):719
                                                                    Entropy (8bit):5.058525313468289
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdF4VzjZBdRDDHwpatEpHc1NQzDaNPfM4EXHaSMNO5AHNUlu:2da3BdRgexqC1607
                                                                    MD5:7AD05071AC6E15295D633092EF954AD0
                                                                    SHA1:F65C5A7DE4AC38AD5DC9003EE611EBA758411285
                                                                    SHA-256:EF14C8A6ABBC342594D2E19F0C52EFD1504627E0C4C6B52BE4CC521D54A80227
                                                                    SHA-512:1BD0DF7E8FE190F317ADAC27C6CB575084C1F73558F5A930E76CE2B06FC32570DBD1ED3D069CC7C1A4BA4603C26FE85FB4E7E427DC38F4A9B026CF9F0A134D99
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10762" V="0" DC="SM" EN="Office.Outlook.Desktop.AttachmentsWebRefSaveAs" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="4230" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="ResponseCode" />.. </S>.. </G>.. <C T="U64" I="0" O="false" N="ResponseCode">.. <S T="1" F="ResponseCode" />.. </C>.. <C T="U32" I="1" O="false" N="ResponseCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):530
                                                                    Entropy (8bit):5.181057119492566
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdsVzjJix6dRDDHwpatEgV2a6ZFaywS/rmNOqHNUlu:2dsrix6dRgetVtUwoA7
                                                                    MD5:A5E250615511D18DC0ECD4A023B28334
                                                                    SHA1:92DAA4795C76E82BE0B5A8B515E64A05C423758E
                                                                    SHA-256:F74148CF462583CFE1B5A629BF3E1DC571F5465C616C00BA3F94201C50E0A7A2
                                                                    SHA-512:32084EC602802D333A8DA88CA1E72B4418829D030E06779CED439A0B73065447F4EAB7AFCAF13CFB42462E9D588859A8A0D73E8D581745B10C0CCEA550FAC93A
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10764" V="0" DC="SM" EN="Office.Outlook.Desktop.AddinsDisabledStats" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3002" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="W" I="0" O="false" N="ProgID">.. <S T="1" F="ProgID" />.. </C>.. <C T="I32" I="1" O="false" N="Reason">.. <S T="1" F="Reason" />.. </C>.. <T>.. <S T="1" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):580
                                                                    Entropy (8bit):5.170919110449742
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdhVzjJR7dRDDHwpatE+ic1NmFUzKAWNfK/XNO5qHNClu:2dhrR7dRgelfQO/Z
                                                                    MD5:B662E3D027D5B732A2C86143A22A71DE
                                                                    SHA1:5530D7AB14C74BF065C6E30C4C8F837DB63B3FD5
                                                                    SHA-256:BEACBBA66AB2535012CA69C65A85A71A302D21A8EB23BCE7E6055CBD0F26F432
                                                                    SHA-512:FBE77C1B964B2063C9D206A2C849FDF161A9D94687286FBF7EE443A598D9098284E11DB498B9F87997879736666931505CF1E24AF2FD7256EEF80CDFF90CC6E1
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10765" V="0" DC="SM" EN="Office.Outlook.Desktop.AddinsRuntimePerfInfo" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <Etw T="3" E="3003" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="U32" I="0" O="true" N="ExecutionTime">.. <A T="SUM">.. <S T="3" F="TimeElapsed" />.. </A>.. </C>.. <T>.. <S T="2" />.. <S T="1" />.. </T>.. <ST>.. <S T="3" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):582
                                                                    Entropy (8bit):5.203905853647658
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdvq4Vzjxs6dRDDHwpatE+ic1NvU6mSXHISMNO5qHNClu:2di4j/dRgelf2SUZ
                                                                    MD5:F6A40762C802CCE35020135D6FB88944
                                                                    SHA1:F62D99C1FF4BA3F63BFB84A87A9A9C8F5EBED36F
                                                                    SHA-256:DD4EAB916F872602D70421ABC4D5967077F687C6AA11387F90BF08ADCD2056D7
                                                                    SHA-512:F77C456FAFA56B27981AAC66A1948F9918EEC815B177D98B5F993832413992467332462EF0B8FC9600C21D7780069E63FB51A2EE38D67CE37665ACC5BB1435EC
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10770" V="0" DC="SM" EN="Office.Outlook.Desktop.AccessibilityCheckerUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <Etw T="3" E="15010" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="U32" I="0" O="false" N="AccessibilityCheckerClicked_Count">.. <C>.. <S T="3" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="1" />.. </T>.. <ST>.. <S T="3" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1115
                                                                    Entropy (8bit):4.641491901940376
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdGVzjQuNH+6dRDDHwpatEerL2c1NQi+kXqNO8X/c//wpONd+wsvXqNO8X/c/a:2dGG2BdRgeLr3qJTLrwOaLfXb6LpEJZ7
                                                                    MD5:6D65E5D863EE2A8D3BA656EBB7E33162
                                                                    SHA1:719966BF569DC04DF10652209916480AD76DB202
                                                                    SHA-256:72677F75CAA3D73F33D8F5F84B0E7BF2933596E7FDD4149A19F0857C81748FF2
                                                                    SHA-512:D493AB00A03154E8D747BD56F0E88D03B91085B64F45AA4B607A58B176281492D0301AACEF70AF497C06AF5F817E86329949AA00D2EA468473AA976AF4E67881
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10771" V="0" DC="SM" EN="Office.Outlook.Desktop.DeleteSuggestionUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="ber0i" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="DataSource" />.. </L>.. <R>.. <V V="0" T="I64" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="DataSource" />.. </L>.. <R>.. <V V="1" T="I64" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="DeleteSuggestion_DataSource_0_Count">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="DeleteSuggestion_DataSource_1_Count">.. <C>.. <S T="5" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="DeleteSuggestion_Total">.. <C>.. <S T=
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):609
                                                                    Entropy (8bit):5.258518464171147
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdCVzj92u6dRDDHwpatEc6NXFJiX5Ua/PHISMNOS/HNClu:2dCn2RdRgeyxvIj/mZ
                                                                    MD5:3ED6266889B063E8256FD55CF83BF496
                                                                    SHA1:8C9C8DB4623105F2A1EBF241601C6FE6C3DB558F
                                                                    SHA-256:95B8508F090313E3B5A788AAA657A2FADA6CA9E3A72BCA3EA83F043839903E2E
                                                                    SHA-512:E91DB169E46FA13598EFEB1B33C4DEF800554D43E7072C24E9D293A8BA57CFA8F91B0F473C23EE22BA2D21F83A3DBEF062F0B053790CC7BCFF013D1C2AC77097
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10775" V="0" DC="SM" EN="Office.Outlook.Desktop.ConversationLevelAttachmentWellErrors" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <TI T="1" I="Daily" />.. <A T="2" E="TelemetryShutdown" />.. <Etw T="3" E="4247" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="U32" I="0" O="false" N="ConLevelAttWellAttachmentsCountNotEqualToExpected">.. <C>.. <S T="3" />.. </C>.. </C>.. <T>.. <S T="1" />.. <S T="2" />.. </T>.. <ST>.. <S T="3" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):537
                                                                    Entropy (8bit):4.771450186310447
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdrfhOH+zUDb8OKX/c//fpONkMNOjsu:2d9bL+
                                                                    MD5:D0641CB4093402E90C9C3532A33B1461
                                                                    SHA1:9231742E8E259F243E49035FE4DB6CAE97592F3F
                                                                    SHA-256:805B2B64EB1ABA039585CBB2FD29D831DE7C9270A8575E1E4DE87F4362F7541C
                                                                    SHA-512:270788BA78960F78AA9113949442F40F6ED43E3771903E68D3A5BC819E3342D63A188BB68E62B7E808BD2D63F8F2B415723D76F880BACD83D6D99D5CC1E97798
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10776" V="0" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="4248" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="4249" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="U32" I="0" O="false">.. <U T="100nsToMs">.. <O T="SUB">.. <L>.. <S T="2" F="TimeStamp100ns" />.. </L>.. <R>.. <S T="1" F="TimeStamp100ns" />.. </R>.. </O>.. </U>.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):4266
                                                                    Entropy (8bit):3.640353454574905
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dgnNdRge8gqJBr7qwOmH7a/v/7sCt7+FL7/4Q7mfEInuGX1radB7:cgPRgeDqJkjo/hKQGlrm7
                                                                    MD5:04194346E4EDEE758102130EF0D59C2A
                                                                    SHA1:40711DA4CB2B8C923D30F0DA89ACAC7303FC4092
                                                                    SHA-256:6F7EF4CF703ABD1A83B346A214B65CE48A3D890D7DAA9B448610472D76BB17AE
                                                                    SHA-512:2946250C0E9FE5AFD712349AF745AC33E6C2075484C16CE5FC0E7DAEB98A0A25C8CFA228399FBDDB94E4030CC604F9F0E20BAA8199E8CB513EFB6D07E351F304
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10777" V="0" DC="SM" EN="Office.Outlook.Desktop.ConversationLevelAttachmentWellPerfUpload" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="10776" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LE">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="500" T="U32" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="5">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="501" T="U32" />..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):15109
                                                                    Entropy (8bit):3.872226608992995
                                                                    Encrypted:false
                                                                    SSDEEP:96:NRgeiadOhxFAqFDxVaqVqx/Tq/fsxgxAVqgxAex/Hq/IxVrdqVyxfYOqfbxJyqJp:NDi3vkeWGmc7
                                                                    MD5:0C0B628026DB23C2D486CE636331F8FD
                                                                    SHA1:6989EF24F273EF3A7F5D1C0D34D37DBE83D6BFF1
                                                                    SHA-256:F807DF0A8B6E0DD2EFB6AA94420023497DBCD3D5D7CF30742EC042B750F87482
                                                                    SHA-512:4BC7184E0607216AD4D6734B127F0760E791C04AAD941F9160DDC4B00A1FD15A6AB8A3D8882C6454BE5D49257705D6EED22ADC15D67FBA0458596F5DD16A8BD3
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10779" V="3" DC="SM" EN="Office.Outlook.Desktop.OpenMessageStore.EmsLogonHelperResultsStats" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DL="A" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="2066" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="LT">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="2147483648" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="2147483648" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="NE">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="2147746077" T="U32" />..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):479
                                                                    Entropy (8bit):4.329435177677775
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHddRyberiNereujDb8OKX/c//fpONkMNO/HNUlu:2dd9riYrtuE7
                                                                    MD5:6F934C775A771C17017E8BC2085D9A37
                                                                    SHA1:84B8A31BE7DF60E200DA64A5C3CF9960D0A2F636
                                                                    SHA-256:F0A4C86159BB76DBE5AEFA4ACBD458603FCD36DC672F5D40178B3A7FFE034924
                                                                    SHA-512:F159A83ED11531EA1B3B357947763FE0C053D3E3DF12E5B6C32130D764067748322E7E5A73003AFD7147F682951E6F1A23526B7F8BA227FE1DD4A809525C870D
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10781" V="1" DC="SM" T="Subrule" xmlns="">.. <S>.. <UTS T="1" Id="bgo4t" />.. <UTS T="2" Id="bhlvy" />.. </S>.. <C T="I32" I="0" O="false">.. <U T="100nsToMs">.. <O T="SUB">.. <L>.. <S T="2" F="TimeStamp100ns" />.. </L>.. <R>.. <S T="1" F="TimeStamp100ns" />.. </R>.. </O>.. </U>.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):536
                                                                    Entropy (8bit):5.1310885117643315
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdeYVzjsdRDDHwpatEerOXFJico2AbHaSMNO5AHNUlu:2d9mdRgeLrevS27
                                                                    MD5:0613F23EDDFDC6270B9956260403689C
                                                                    SHA1:D6CBEB4F9D71F9223B4CD7E8DE4A074CBF08278F
                                                                    SHA-256:4499CC092E419610F334A50A500B305161AE68DFAC88DC4E42B233DDFAD0CDB1
                                                                    SHA-512:908206151F6CDB44FFA4C25EE7653CC885B807FFC318D0FD900D65BE028327894A9C6C16F8540EFDC399FE0CD7318640E2CAB0D42343D8B2FE2A721E6F6B6D1A
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10783" V="0" DC="SM" EN="Office.Outlook.Desktop.RecipientAutoCompleteZeroInput" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bg085" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <C T="U32" I="0" O="false" N="CountOfZeroInputSearches">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1736
                                                                    Entropy (8bit):4.825673007247234
                                                                    Encrypted:false
                                                                    SSDEEP:48:cONRgeWqiLsV/6xP+YyKJkyiyqy40yymP7:3RgemLsV/6tnHkcqR01mP7
                                                                    MD5:478DA0EDAF828CE7FAD17CB9A41C741E
                                                                    SHA1:09BF669F108E10E6CFA738C0FBF01612647D5C5F
                                                                    SHA-256:8737205FE766B0B5529AAE314794BD4BB4B1EA7970257289C14A26C54EA97091
                                                                    SHA-512:9002600D2E10E95B9DAF3347F0765826A1248B9D6C776910441C42C4CAD7DAA15F05B1E2B4340D6E91A79BC7E71D47F91B65CFFBE8B535C1FFD2ED5E1085175D
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10784" V="0" DC="SM" EN="Office.Outlook.Desktop.PeoplePickerSelectionStatistics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="10625" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <C T="I32" I="0" O="false" N="AlgorithmVersion">.. <S T="1" F="0" />.. </C>.. <C T="I32" I="1" O="false" N="SelectedIndexPosition0Count">.. <A T="SUM">.. <S T="1" F="1" />.. </A>.. </C>.. <C T="I32" I="2" O="false" N="SelectedIndexPosition1Count">.. <A T="SUM">.. <S T="1" F="2" />.. </A>.. </C>.. <C T="I32" I="3" O="false" N="SelectedIndexPosition2Count">.. <A T="SUM">.. <S T="1" F="3" />.. </A>.. </C>.. <C T="I32" I="4" O="false" N="SelectedIndexPosition3Count">.. <A T="SUM">.. <S T="1" F="4" />.. </A>.. </C>.. <C T="I32" I="5" O="false" N="SelectedIndexPosition4Count">.. <A T="SUM">..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1428
                                                                    Entropy (8bit):5.043679177232869
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdIVzjTyux6dRDDHwpatEPeA+KbSDA+KbSDA+KbScitLhfHaSMYHISMpRNNHh5:2dIgux6dRge6eFOyLk1C6rMu
                                                                    MD5:0BF7A0F1043436AFA1F662F919AFEFEE
                                                                    SHA1:C39E9308756DEF1827EA8347CA5C67C6EC836E8D
                                                                    SHA-256:945B700A9642AEF2F81993D5997326FB89C4A2C1861020EE642728213B23E90E
                                                                    SHA-512:6709750F32CEFF8119313540A1E03D9799EFEC0D831B98400FD54110876DC5DF96DAE70AEC5611C3BF23634C56392FB4F9B8B49DF70D6634CCF9FF814B0E244D
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10787" V="1" DC="SM" EN="Office.Outlook.Desktop.ExchangeInfoStorageStats" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="819" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <Etw T="2" E="820" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <Etw T="3" E="821" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <TI T="4" I="Hourly" />.. </S>.. <C T="U32" I="0" O="false" N="NumNewConnsAdded">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="NumConnsRemoved">.. <C>.. <S T="3" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="NumCallsToGetAllInfo">.. <C>.. <S T="2" />.. </C>.. </C>.. <C T="U32" I="3" O="true" N="MaxNumConnectionsReported">.. <A T="MAX">.. <S T="2" F="NumConnections" />.. </A>.. </C>.. <C T="U32" I="4" O="true" N="AvgNumConnectionsReported">.. <A T="AVG">.. <S T="2" F
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):807
                                                                    Entropy (8bit):5.045465152145595
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd4YYVzjn6dRDDHwpatEbR2GeOSc1NQzD+S0MbFx9/cSZp6ZSHaSMNO5AHNUlu:2d4YYsdRge+RvLvqwn7
                                                                    MD5:BB2534A5BB291169F1A47B95B96F879D
                                                                    SHA1:2942A1518DB2266A5E9E83D066B851C6417125AC
                                                                    SHA-256:830000B921E320A79B8DEBACC33383AB056293EC85B8EC97B701FFCE6C3E6677
                                                                    SHA-512:7C89E12F542F37049DB1C0E114D38D9775FAA8014B4F26CCC16CDEB03536B417E33CD8E11133435B9752B1FAB8A7988584CE0A04B01F955506C238E144EA3C6E
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10788" V="0" DC="SM" EN="Office.Outlook.Desktop.GroupsApiErrors" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3201" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="CONTEXT" />.. <F N="HRESULT" />.. </S>.. </G>.. <C T="I32" I="0" O="false" N="Context">.. <S T="1" F="CONTEXT" />.. </C>.. <C T="I64" I="1" O="false" N="HResult">.. <S T="1" F="HRESULT" />.. </C>.. <C T="U32" I="2" O="false" N="CountGroupsApiError">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):811
                                                                    Entropy (8bit):5.036294966960726
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdV2YVzji6dRDDHwpatEgs2GeOSc1NQzD+S0MbFx9/cSZp64SHaSMNO5AHNUlu:2dV1zdRgetsvLvqwG7
                                                                    MD5:BF4C580CAE133A50DC3B0E62DA4EF22C
                                                                    SHA1:F0ABE04914A9D13CF4677B5B27CD1BBB8DB78110
                                                                    SHA-256:3828D7A7183C1514FD5A7CB95C10CC3942EF5ED5837DA8560FA8F75542375BA0
                                                                    SHA-512:B0BE7BA07CC0999DF0DECC8FCB26999E33800DBFA852B0CF2FBC81961316685AC72985FF19EE72D8F7DE8EBAED26FCCC4991634F0B21DD92795FC3140C8FC1FA
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10789" V="0" DC="SM" EN="Office.Outlook.Desktop.GroupsStoreErrors" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3001" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="CONTEXT" />.. <F N="HRESULT" />.. </S>.. </G>.. <C T="I32" I="0" O="false" N="Context">.. <S T="1" F="CONTEXT" />.. </C>.. <C T="I64" I="1" O="false" N="HResult">.. <S T="1" F="HRESULT" />.. </C>.. <C T="U32" I="2" O="false" N="CountGroupsStoreError">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):937
                                                                    Entropy (8bit):5.023117170680329
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdEVzj0F6dRDDHwpatyw2GeOSc1NQzD+S0MUTObFx9/cSZw1zfTTxR0XSHaSML:2dEtdRge/vLvq8lFP87
                                                                    MD5:A8D2672E23073CC74A8274A294552FA1
                                                                    SHA1:BB2DC7DF6B69B243F329C0521BC06F2E928556E6
                                                                    SHA-256:20A4BCF7780D0831FA6E0BE12211380E5EC9212F7B439CD363B4FA6A7BDA0539
                                                                    SHA-512:C110403C997FAB7B75C01637286E1232CB817AE6D6D4E589B3D59D9507D117F9AD55612D9B037C613E06E161153CB14B419242F5BA425CB46D3777789446198A
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10790" V="1" DC="SM" EN="Office.Outlook.Desktop.GroupsHierarchyErrors" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DL="A" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3101" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="CONTEXT" />.. <F N="HRESULT" />.. <F N="StoreType" />.. </S>.. </G>.. <C T="I32" I="0" O="false" N="Context">.. <S T="1" F="CONTEXT" />.. </C>.. <C T="I64" I="1" O="false" N="HResult">.. <S T="1" F="HRESULT" />.. </C>.. <C T="I64" I="2" O="false" N="StoreType">.. <S T="1" F="StoreType" />.. </C>.. <C T="U32" I="3" O="false" N="CountGroupsHierarchyError">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):779
                                                                    Entropy (8bit):5.161151811323201
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdMVzjhwqG6dRDDHwpatE68HB82HcoNBnA8clkqoHaSMj8clkqXHhSMNOAdHNN:2dMMqJdRge38v1qQqDr
                                                                    MD5:34D8D0BE5EC9BA54086585D52DCAA765
                                                                    SHA1:A34B03741597DF1BF8873986DA2551C26B1BCE2D
                                                                    SHA-256:1645D706B39B8595C8DA53989E5958906F14C95F751366CE8379B8A36131A6C5
                                                                    SHA-512:70F3340971B6ACBEE822EABECB765A4A9B730277A18B8B50708EBE61998EFCB32D0192B74B5C981BBE2D1A9D1400AFABB3F6C5878E36810C1C55331CF6DEB789
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10795" V="0" DC="SM" EN="Office.Outlook.Desktop.FocusedInboxUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9006" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="9007" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="3" I="Daily" />.. <A T="4" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="Count_FolderBarFocusedInboxEnabled">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="Count_FolderBarFocusedInboxDisabled">.. <C>.. <S T="2" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="4" />.. </T>.. <ST>.. <S T="1" />.. <S T="2" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):451
                                                                    Entropy (8bit):5.366900726500801
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdDVzjfNXkBdRDDHwpatE6Ok/m/IlMNO2su:2dDfXkBdRgenmd
                                                                    MD5:49BCDE64B5A80FB149C06EFAFF42B05B
                                                                    SHA1:DDF3DEC0B08B9560F73DFC4F70B69794CC723A00
                                                                    SHA-256:9BE698D7058DFCE0731108CD09E931B468F23F58230C35BBA7E14F5F5B43D836
                                                                    SHA-512:E4B639272CC55BD9D209B55F995ACD86E1DB05A53A8FA5D7F84F860F332F65E3EA6FACFDD04592F3ED80C7B6F5EF1E9DCC8170264A144C65AEAA5ECB4B8F2ECA
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10796" V="0" DC="SM" EN="Office.Outlook.Desktop.FolderBarPivotFocusedActivated" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9008" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="U64" I="0" O="false" N="UnseenMailCountOnActivation">.. <S T="1" F="Count" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):449
                                                                    Entropy (8bit):5.374048743236743
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd6F3VzjftEkBdRDDHwpatE6zk/m/IlMNO2su:2d+4kBdRgeMmd
                                                                    MD5:FD45346EFEE8BDE1CE59658150E87204
                                                                    SHA1:AA2E330556025428A9C770AECEDE075BE3060C64
                                                                    SHA-256:29E9D20B98DB4185F562D7A484471E2852D63B0FE89F5FC73D4D7F1B94240F0E
                                                                    SHA-512:AFEF9A8FECC55C8E2F70DE33060C8C34C3557BC7B46F276A1B4D979531BB03A05433EBD7E0E5D7E536C7BC7858F449C0F3BC86AAE3B8D877F6F4C81F6BC06E30
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10797" V="0" DC="SM" EN="Office.Outlook.Desktop.FolderBarPivotOtherActivated" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9009" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="U64" I="0" O="false" N="UnseenMailCountOnActivation">.. <S T="1" F="Count" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):999
                                                                    Entropy (8bit):5.154650853375804
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdJq4Vzjhwqfty6dRDDHwpatEqHBYHSqaHcih2NanApXkhduXHaSMjGkhduXHR:2dVMqFtdRgesDg4XkhoTkhom6Ato
                                                                    MD5:C18FA821BC2342FDD9DE87C4DC81969E
                                                                    SHA1:B1591B4733CAAD1AD880D3BF0721045AACF7E476
                                                                    SHA-256:BAE15FD17C1572DA5672684F2F113E5F6BDAB555E0E5B35A8FEE54DD4360B95C
                                                                    SHA-512:CC049C0ACDC4193487632046533700A869259D7FEBA6579338D7BAD356F92D3A0EE67942F4E9DF254A640BCE7E8F5323FA690EE227CE3424ACD202C329FDBD13
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10798" V="0" DC="SM" EN="Office.Outlook.Desktop.FocusedInboxUnseenMailHintUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9010" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="9011" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="3" E="9012" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="4" I="Daily" />.. <A T="5" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="Count_PivotFocusedActivatedOnUnseenHint">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="Count_PivotOtherActivatedOnUnseenHint">.. <C>.. <S T="2" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="Count_UnseenMailHintDismissed">.. <C>.. <S T="3" />.. </C>.. </C>.. <T>.. <S T="4" />.. <S T="5" />.. </T>.. <ST>.. <S T="1" />.. <S T="2" />.. <S T="3" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):960
                                                                    Entropy (8bit):5.079567413942803
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdgVzjfcIE6dRDDHwpatE5HW6H016Hcih2NanAIOHaSMj+VhOHhSMp66Q0OHIC:2dgt3dRgeT1jgCDOo
                                                                    MD5:A0A46C8B589CCE40341A90ADBA317250
                                                                    SHA1:CF97D024EEEBF86A9C15B0EBF547ABFD3C35AD53
                                                                    SHA-256:FB0A4B1603A188D29C9B7732A97580CB503F4E4B1570BFC4C3535D0D0E7295E5
                                                                    SHA-512:7AE86E1F4FF6455BCC281A3A156283ED457C3F79C7AF05E921411648CC05A28ABD23D653B256A56DE51EA5BC1D19DE06D0B1790B196D8DA9305B828D7BB6C527
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10799" V="0" DC="SM" EN="Office.Outlook.Desktop.FolderBarFilterUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9013" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="9014" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="3" E="9015" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="4" I="Daily" />.. <A T="5" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="Count_FilterAllSelected">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="Count_FilterUnreadSelected">.. <C>.. <S T="2" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="Count_FilterMentionsSelected">.. <C>.. <S T="3" />.. </C>.. </C>.. <T>.. <S T="4" />.. <S T="5" />.. </T>.. <ST>.. <S T="1" />.. <S T="2" />.. <S T="3" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):455
                                                                    Entropy (8bit):4.385258368553274
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd/fercferSDb8OKX/c//fpONkMNOjsu:2d+rRrt+
                                                                    MD5:D32DB9ADFAAAEE45D3B6AE82A3292BE4
                                                                    SHA1:3F56B0B338398FB2BCCB8EC1645F2D5A07AEA938
                                                                    SHA-256:3967AEC34F6F912314E4B09F719349EE20160EC6E460DB0F4DC55EBD81D2F075
                                                                    SHA-512:326E86F467BF6292A7AF84F058D9990401C3DC1D27F2196060DE94DF2DF73FF8DD8EDAB77D998FA3775AB4C0B4AA4FF4311A58EB9F225E476AD2754465BD1937
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10800" V="0" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <UTS T="1" Id="bhlvz" />.. <UTS T="2" Id="bhlv0" />.. </S>.. <C T="I32" I="0" O="false">.. <U T="100nsToMs">.. <O T="SUB">.. <L>.. <S T="2" F="TimeStamp100ns" />.. </L>.. <R>.. <S T="1" F="TimeStamp100ns" />.. </R>.. </O>.. </U>.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):2683
                                                                    Entropy (8bit):3.339202408736384
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdCZfi0DO5Q//WRff/0//ShmMnENWwmhfP/k//ix2Nf/0//g//mhfP/k//4x23:2dCfDyjOOpOO1H1HOcEIO9DO2nP
                                                                    MD5:3F36A9C98F1F9A7C0274B018EA824F2B
                                                                    SHA1:D4D59977A39D2A21F26DEC9A296DDB6DD89E9482
                                                                    SHA-256:FA747FCC832754D1C1F4181E8E225898E66E4FE466940EA53F3FF67A7FEDE0C5
                                                                    SHA-512:AB2E7FB650998947F29EF1C4B99C7ACA4DED646F334B0D6408527A1309A7316441B5464C7B3D5FAE0399051E8EFFBA4A9B9BE53B39C9F59C74AB4274F386D3FA
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10801" V="0" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <R T="1" R="10781" />.. </S>.. <C T="B" I="0" O="false">.. <O T="LT">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="50" T="I32" />.. </R>.. </O>.. </C>.. <C T="B" I="1" O="false">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="50" T="I32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LT">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="100" T="I32" />.. </R>.. </O>.. </R>.. </O>.. </C>.. <C T="B" I="2" O="false">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="100" T="I32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LT
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):2683
                                                                    Entropy (8bit):3.336471169334665
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdxfi0S15Q//WRff/0//ShmMnENWwmhfP/k//ix2Nf/0//g//mhfP/k//4x2NR:2dXkjOOpOO1H1HOcEIO9DO2nP
                                                                    MD5:34009FBF6298E1EAED5DB556C610DCE4
                                                                    SHA1:4023B2C284673A052F31C40F92F1E9E062BFF840
                                                                    SHA-256:BE81E59C2BBA681945CFD10AE299D0AA83B638D0943CBCF5E069F4B28213615F
                                                                    SHA-512:63508D855ABBA44ACDDE3BE0411C7F7CE6385B997679E794D2C45CF7D7EB4D215A2C8975AE5161C6B11B58488949FC5B09BA70D6668FC9E9EED064BCD63548BC
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10802" V="0" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <R T="1" R="10800" />.. </S>.. <C T="B" I="0" O="false">.. <O T="LT">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="50" T="I32" />.. </R>.. </O>.. </C>.. <C T="B" I="1" O="false">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="50" T="I32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LT">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="100" T="I32" />.. </R>.. </O>.. </R>.. </O>.. </C>.. <C T="B" I="2" O="false">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="100" T="I32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LT
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):4305
                                                                    Entropy (8bit):4.705471543668782
                                                                    Encrypted:false
                                                                    SSDEEP:96:rGRgeGe8Z8g9NQy2SjEDcAIEp+HBUhSS4Kx2XbmJPJwYPwMvwN7wZLwtHnwRnwCH:rGDU9uy2SjEDcAIEpsBuVzYXKxOYIMoE
                                                                    MD5:22ECF976C9843FD6C46022B73B3948F2
                                                                    SHA1:46DB28D4FE84D38FE72949B882C67A7AB7EAD845
                                                                    SHA-256:B33939E23CAD9B9B9C13B16E1015E9F9FCA182C15C6AA1EB004F40EEAC05C8AE
                                                                    SHA-512:0CEBC1457B6A68A2E61F6AFA0B48D0913978EE839C718AA74C875CAD59BE59B3C95F255BFB49DC16322031F12069AD42452B91F8BA35310FE28C37060E9F2AF4
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10803" V="1" DC="SM" EN="Office.Outlook.Desktop.RecipientAutoCompletePerformanceStatistics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bgo5g" />.. <UTS T="2" Id="bgo5h" />.. <R T="3" R="10801" />.. <R T="4" R="10802" />.. <R T="5" R="10880" />.. <R T="6" R="10882" />.. <TI T="7" I="Daily" />.. <A T="8" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="SomeAutoCompleteSearchResultsCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="NoAutoCompleteSearchResultsCount">.. <C>.. <S T="2" />.. </C>.. </C>.. <C T="I32" I="2" O="false" N="DisplayUnder50msCount">.. <A T="SUM">.. <S T="3" F="0" />.. </A>.. </C>.. <C T="I32" I="3" O="false" N="Display50To100msCount">.. <A T="SUM">.. <S T="3" F="1" />.. </A>.. </C>.. <C T="I32" I="4" O="false" N="Display100To2
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):995
                                                                    Entropy (8bit):4.289383640645895
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd0LOertDkqZnECNWKf/0//ks4DhmMntxCNWKf/0//Tm3hmMnuCNWKf/0//kX7:2dorOc50v5sk5/OQ5SE
                                                                    MD5:FC2C37EE38A3EAD195CA7034A4C21811
                                                                    SHA1:A8E252007CC0BE00E4C9CBACD4EBEFE7A63C1880
                                                                    SHA-256:71DDAB80391BFA696D2A9D7F10A656DA92FC854A525F81A5BC38DEDB6C23B881
                                                                    SHA-512:34FA6D3E8B800915894871D97A57DCC004AB5AACB9C0B04CE733EE564F79C4014432502E51ED57B263CDB46A390F0B642DC85D6EA78E1AE822D75F0EB87B290B
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10807" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bhpn8" />.. </S>.. <C T="I32" I="0" O="false">.. <S T="1" F="errorCode" />.. </C>.. <C T="B" I="1" O="false">.. <O T="EQ">.. <L>.. <S T="1" F="callName" />.. </L>.. <R>.. <V V="HrInit" T="W" />.. </R>.. </O>.. </C>.. <C T="B" I="2" O="false">.. <O T="EQ">.. <L>.. <S T="1" F="callName" />.. </L>.. <R>.. <V V="CompleteRecipient" T="W" />.. </R>.. </O>.. </C>.. <C T="B" I="3" O="false">.. <O T="EQ">.. <L>.. <S T="1" F="callName" />.. </L>.. <R>.. <V V="HrShowAutoComplete" T="W" />.. </R>.. </O>.. </C>.. <C T="B" I="4" O="false">.. <O T="EQ">.. <L>.. <S T="1" F="callName" />.. </L>.. <R>.. <V V="HrDeleteAutoCompleteItem" T="W" />.. </R>.. </O>.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1061
                                                                    Entropy (8bit):4.899146707537674
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dxWQdRge8fq79OOQE9OOQR5OOQH1GpOOQcP7:cxhRgeAqofBfRYfVGof27
                                                                    MD5:ACEF7985804D93211B6B522A14E8D515
                                                                    SHA1:C68809DCAD83C8DE77C39FAEB28163067408A588
                                                                    SHA-256:0EB6285F536AD8D31EE2558BB0A1E88E58E1B071C8D6EE56FFC162A125E552D2
                                                                    SHA-512:C5CD22BC1D00A1CD6C5E2ADD466C0B563AD3B5DF0523CCBF9392FC8A427C17C3BFF3DCEF0320258A795AD71563A48B2A2AAAC67041BEC58ADFBF12EBDDA70780
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10808" V="0" DC="SM" EN="Office.Outlook.Desktop.RecipientAutoCompleteErrorStatistics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="10807" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="0" />.. </S>.. </G>.. <C T="I32" I="0" O="false" N="ErrorCode">.. <S T="1" F="0" />.. </C>.. <C T="I32" I="1" O="false" N="HrInitResultCount">.. <A T="SUM">.. <S T="1" F="1" />.. </A>.. </C>.. <C T="I32" I="2" O="false" N="CompleteRecipientResultCount">.. <A T="SUM">.. <S T="1" F="2" />.. </A>.. </C>.. <C T="I32" I="3" O="false" N="HrShowAutoCompleteResultCount">.. <A T="SUM">.. <S T="1" F="3" />.. </A>.. </C>.. <C T="I32" I="4" O="false" N="HrDeleteAutoCompleteItemResultCount">.. <A T="SUM">.. <S T="1" F="4" />.. </A>.. </C>.. <T>.. <S T="2" />..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1499
                                                                    Entropy (8bit):4.77143182696172
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd0VzjHRvGL4dRDDHwpatEP4HXFJicoN+kXqNOEX/c//wVrMpONd+wsvXqNOEb:2d0Hg4dRgeLvS8TpjqwOapiZbPU
                                                                    MD5:46055EACB2D7BBC1DCFD2F1BAF4DCC33
                                                                    SHA1:D569C19D5342C472848CF8D07FB47FAD10AE6085
                                                                    SHA-256:313DA9086B2E9FD07A99DE93C8F814E601384123C4CCE22582B18D73B8E60BBB
                                                                    SHA-512:C8521C06327051A5AC2B9EBEE9FFE5AF88C188AFEA357D91CB7AFD5F79A4C9B24BBF6159155BAF4EC31348DDCF6FE27BA58FF1928C599656413B02CECA2E7D1C
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10812" V="0" DC="SM" EN="Office.Outlook.Desktop.Rule.Olk.WebExtensions.NavigateInNewWindow" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="8217" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="Success" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="Success" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="1">.. <F N="OriginFunction" />.. <F N="InitialChecksPassed" />.. </S>.. <S T="4">.. <F N="OriginFunction" />.. <F N="InitialChecksPassed" />.. </S>.. <S T="5">.. <F N="OriginFunction" />.. <F N=
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1308
                                                                    Entropy (8bit):4.7820199210090575
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdVVzjHRvG39zdRDDHwpatEm2HXFJicoN+kXqNOEX/c//wVrMpONd+wsvXqNOB:2dVHMdRgehMvS8TpjqwOapinyU
                                                                    MD5:2A9B8697F67DFF630D637B9990D7AE13
                                                                    SHA1:7CF5BA9224A1BF3BF8AFAC8EC8C6462797EF8D2E
                                                                    SHA-256:B52B593352E24E347458FB374BC84B03676BE2A18EE5A5FF6033F895718F7B30
                                                                    SHA-512:B830E799049B2A383A043B3EB13A4AC7F2E1CA84C63A1FF9C27E97C54068B0ED42333B69048E50E682E05F08082F4CFC3FA9AE616B2CE3832FBEABE6BE15474D
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10817" V="0" DC="SM" EN="Office.Outlook.Desktop.Rule.Olk.WebExtensions.NavigateInCurrentWindow" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="8218" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="Success" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="Success" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="1">.. <F N="IsQueryStringEmpty" />.. </S>.. <S T="4">.. <F N="IsQueryStringEmpty" />.. </S>.. <S T="5">.. <F N="IsQueryStringEmpty" />.. </S>.. </G>.. <C T="B" I="0" O="false" N="IsQueryStringEmpty">.
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):790
                                                                    Entropy (8bit):4.264971683918691
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdY7ObervSernDmfW8/mffDb8OKX/c//fpONkM17PNWnFZFf/0//phmMNO/HN9:2dGnrNrq3eiFPUZ5V7
                                                                    MD5:7FDB0D30BCE859350AE0F6710C398544
                                                                    SHA1:B2C812FE419BA84C432A0CE5147517FE1105FFCD
                                                                    SHA-256:CF03A73CBA7372F2DD1B81EC9A9F452B6F779E54E88021F168F91656C2971244
                                                                    SHA-512:7CA22C6822118D950441273CEFA5ECE3722C989FBDCF35D3FEE3DF39BD3CA47566DBFEBE2EC89A044E2564D2F998074EA73C85B7C100E9CFA59386D25A20D2B1
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10818" V="3" DC="SM" T="Subrule" xmlns="">.. <S>.. <UTS T="1" Id="blelm" />.. <UTS T="2" Id="blelt" />.. </S>.. <G>.. <S T="1">.. <F N="UniqueID" />.. </S>.. <S T="2">.. <F N="UniqueID" />.. </S>.. </G>.. <C T="U32" I="0" O="false">.. <U T="100nsToMs">.. <O T="SUB">.. <L>.. <S T="2" F="TimeStamp100ns" />.. </L>.. <R>.. <S T="1" F="TimeStamp100ns" />.. </R>.. </O>.. </U>.. </C>.. <C T="U64" I="1" O="false">.. <O T="COALESCE">.. <L>.. <S T="1" F="CardVersion" M="Ignore" />.. </L>.. <R>.. <V V="1" T="U64" />.. </R>.. </O>.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):8435
                                                                    Entropy (8bit):3.4038221245401568
                                                                    Encrypted:false
                                                                    SSDEEP:48:c6jJlRgeRvS8rzvNwNBlfu/SnbrdsxSLfv9m96S7:tRgeRbrzvNwNBlfu/SnbrdsxYfI96S7
                                                                    MD5:C747CD34026E1302C1614C323ADE9808
                                                                    SHA1:BCFA859ACC88409E96449FF3EAA8EC933967B39B
                                                                    SHA-256:2F50C4C4879C6036FE6E115C5063065C00380209A7D4461B5285B1F9DCE1F5CE
                                                                    SHA-512:6E7620831D20384015CCFAAD9CE81EBEF444B6DFED9259818C8B7ECEED3F9BEAE1E1ABA565FD3069AE07F96F80931D72E7DCF87E958DB75E61E02A7A43058CE3
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10819" V="1" DC="SM" EN="Office.Outlook.Desktop.ContactCardTimestampInformation" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="10818" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="LE">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="500" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="AND">.. <L>.. <O T="GT">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="500" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LE">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="1000" T="U32" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="6">.. <O T="AND"
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):5508
                                                                    Entropy (8bit):4.114083575416656
                                                                    Encrypted:false
                                                                    SSDEEP:96:IRgeuIuhrKYnRXmWrfnY4RR/qjzsrw+FxYh+uOFMoHh8K/KlAZ:IDsQfox/KlAZ
                                                                    MD5:1DFB43EAA09AC0AE7EB5384813A40433
                                                                    SHA1:60B268869771CF0CFD7C7CA8B74D3AA893C023FB
                                                                    SHA-256:C242FB7C96AC9816B01125D1BEEAD43D73806875F03C8313E08206E9E2137796
                                                                    SHA-512:9CDBFB054C7D15DDF638BB24252CEF20AB70AB4FFFF8CC674248A5A78DC3FAFAE0E46F9BE08E91C7BC2FD3E71182FB221156B76CBBB3732A3E1ABE59D421DF3B
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10820" V="3" DC="SM" EN="Office.Outlook.Desktop.ContactCardPropertiesCounts" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <UTS T="3" Id="blelm" />.. <UTS T="4" Id="blelt" />.. <F T="5">.. <O T="EQ">.. <L>.. <S T="4" F="IsHosted" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="4" F="IsHosted" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="4" F="CardType" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="8">.. <O T="EQ">.. <L>.. <S T="4" F="CardType" />.. </L>.. <R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):4453
                                                                    Entropy (8bit):4.611929344749824
                                                                    Encrypted:false
                                                                    SSDEEP:48:ctzeRgelfYvi6LmWv/dvl7sZ2cS4znJaIzNC2bXXtG931KcjJvi4pme9MOsmbmEF:5RgezO7p+Osh7bRlAZ
                                                                    MD5:44E94A2EB7901D6FF85292A6ACAC80FC
                                                                    SHA1:805C47614E74F202CAEAC376654AA91542DBE5A4
                                                                    SHA-256:8BFFA7414C818F25F55F02040D08E59E220FC0009C577DF8930FB72B75FB204B
                                                                    SHA-512:EB025C1EAE42B97944B919296632FB4B06F4E899F2442C5929B42F261D9B0CD736097992FB1E47C0B8CCB77F0F2DBC64E70886EB5637A42060181E7DC9D70E74
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10821" V="3" DC="SM" EN="Office.Outlook.Desktop.ContactCardClickCountsA" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <UTS T="3" Id="blelm" />.. <UTS T="4" Id="blekv" />.. <UTS T="5" Id="bleld" />.. <UTS T="6" Id="blekw" />.. <UTS T="7" Id="blekx" />.. <UTS T="8" Id="bleky" />.. <UTS T="9" Id="blekz" />.. <UTS T="10" Id="blek0" />.. <UTS T="11" Id="blek1" />.. <UTS T="12" Id="blek2" />.. <UTS T="13" Id="blek3" />.. <UTS T="14" Id="bleko" />.. <UTS T="15" Id="a9ceo" />.. <UTS T="16" Id="a9cdl" />.. <UTS T="17" Id="a9cer" />.. <UTS T="18" Id="blekq" />.. <UTS T="19" Id="a9ceh" />.. <UTS T="20" Id="a9cei" />.. <UTS T="21" Id="a9cel" />.. <UTS T="22" Id="a9cem" />.. <UTS T="23" Id="a9cep" />.. <UTS T="24" Id="a9ceq" />.. <UTS T="25" Id="blekr" />
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):4452
                                                                    Entropy (8bit):4.616080154641149
                                                                    Encrypted:false
                                                                    SSDEEP:48:cbzrRgelfYv05YoaMKN2Xn4O0CsWz1FvauzNoYHXHr7KTWr+LY0AcXjNY7AnNAm7:qRgebZLyH5lNAX23YlAZ
                                                                    MD5:3C4AD726AF98C553C2EDBFB9F106B71A
                                                                    SHA1:1B8D4F15173C774CC3EB88E8E001BC93DD7B78E3
                                                                    SHA-256:36C4D95619B7D07968DBA0E91F8F01AF384D0B239BD69A77C9F005EB3E883D22
                                                                    SHA-512:70044DEE2025104E34B0FA47455B09268EF86FA045D7B4A8E789856C3CC128399511E853D7E719FAAB2B0E9A77D7CE3078D2BB248647F353694868F301C88B65
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10822" V="2" DC="SM" EN="Office.Outlook.Desktop.ContactCardClickCountsB" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <UTS T="3" Id="blelm" />.. <UTS T="4" Id="blek4" />.. <UTS T="5" Id="blek5" />.. <UTS T="6" Id="blek6" />.. <UTS T="7" Id="blek7" />.. <UTS T="8" Id="blek8" />.. <UTS T="9" Id="blek9" />.. <UTS T="10" Id="blela" />.. <UTS T="11" Id="blelc" />.. <UTS T="12" Id="blele" />.. <UTS T="13" Id="blelf" />.. <UTS T="14" Id="blelb" />.. <UTS T="15" Id="blelg" />.. <UTS T="16" Id="blelh" />.. <UTS T="17" Id="bleli" />.. <UTS T="18" Id="blelj" />.. <UTS T="19" Id="blelk" />.. <UTS T="20" Id="blell" />.. <UTS T="21" Id="blekj" />.. <UTS T="22" Id="blekk" />.. <UTS T="23" Id="blekl" />.. <UTS T="24" Id="blekm" />.. <UTS T="25" Id="blekn" />
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):2696
                                                                    Entropy (8bit):4.965168964040294
                                                                    Encrypted:false
                                                                    SSDEEP:48:cUaKvRgek+sHq8mnopno0nAzplX9xmVsXXV/W0wJSbN+:JHRgek+ZdqqA
                                                                    MD5:7994AE221F53ABF1FB3BAAD3775BDECE
                                                                    SHA1:CEF4FFF1B183887611E4BEE01205145EA37282B0
                                                                    SHA-256:EA5B45902DC96775E9FC9F862E25825DF06F1CBDB7BE315604F458D69EE60AC3
                                                                    SHA-512:28ED525284A94ADC34594AFEFB7C460FC13BE55FDBA525C72FA03BC27BAF5B6C5E8D2BA6E05A244DF7894D40C38B46C86905C5DDF6805FE9CC54F0EB50C525A0
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10829" V="1" DC="SM" EN="Office.Outlook.Desktop.Outlook.Logging.Metrics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="21000" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="21001" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="3" E="21002" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="4" E="21004" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="5" E="21005" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="6" E="21007" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="7" E="21008" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="8" E="21014" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <F T="9">.. <O T="EQ">.. <L>.. <S T="7" F="Canceled" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="10">..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1364
                                                                    Entropy (8bit):4.76829343806172
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dS+hoXD8dRged+t4vjqTvirRQei8Iw1MfI:cS+KTMRged+t47qT6RWeMfI
                                                                    MD5:95BCF8C7E0BD81EF03F686A70BB41BC4
                                                                    SHA1:CB26F74468D9C87CCA37FD4F0C972462571033C1
                                                                    SHA-256:785B31E3347B07F5138710C0D237457A54AA33E20EF278800A9F122414F01BDF
                                                                    SHA-512:E077944FAAB284058B39A7756B4886B4617974F12490FA4DEA605795BFFBCCB07BF861C7C76B02939C9600FBBB025C9EDEEFA2D38C898657FEB7487A3C9CFE60
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10830" V="1" DC="SM" EN="Office.Outlook.Desktop.Outlook.Logging.Providers" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="128" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="21013" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="21009" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <F T="3">.. <O T="EQ">.. <L>.. <S T="1" F="FromChangeNotify" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="FromChangeNotify" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="2">.. <F N="ProfileName" />.. <F N="Enabled" />.. <F N="Level" />.. </S>.. </G>.. <C T="W" I="0" O="false" N="LogProfile">.. <S T="2" F="ProfileName" />.. </C>.. <C T="B" I="1" O="false" N="Enable
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):587
                                                                    Entropy (8bit):5.2288146299496425
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdSSVzjzdRDDHwpatEBiHXFJico2AdHaSMNO5AHNUlu:2dSSRdRgekgvSY7
                                                                    MD5:FE3BF59F62679594B538EF61A57D8CF0
                                                                    SHA1:B3D05F2938AC329CECFDB766C327438E21B78593
                                                                    SHA-256:AFF0D0013DD2C9AFBE87DE47C18C20AA6CF4E0A0C905823F97875AB113F44E63
                                                                    SHA-512:926B9EC78D80C4F26BDE5D5BEA90015C58AD22BA666436D3CC6D4D2CC5D2761022A83DD1A448C1A55FD0C6FE229BEED5D0B4B88843E18B36B7C9BC12204D6FCE
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10831" V="0" DC="SM" EN="Office.Outlook.Desktop.Holiday.OptionsButtonAddHolidays" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="22400" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <C T="U32" I="0" O="false" N="CountOfOptionsButtonAddHolidays">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):567
                                                                    Entropy (8bit):5.192498919771027
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdSlVzjKKdRDDHwpatEB3HXFJico2AeGHaSMNO5AHNUlu:2dSlYKdRgeknvSMB7
                                                                    MD5:B857AD9DBA7632DB4FA59D606651D1BA
                                                                    SHA1:00ABB5A6FE3F627985C02A2FE560CD8C4B88116F
                                                                    SHA-256:4034A4ADDFEB97CEA5F1B119B646B53E4C73367BB6B40E2E16EEACF85001C944
                                                                    SHA-512:6701396ACC6ABC9B2764E61926C2A7BD45CC358A6B582CA0101C5A6CD9C6A06CF2283EBBCD8AB288A791E33572C4A0D74D5C8953E10C6D0E73889DD5BAFADA91
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10832" V="0" DC="SM" EN="Office.Outlook.Desktop.Holiday.CommandLineHOL" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="22401" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <C T="U32" I="0" O="false" N="CountOfCommandLineHOL">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):577
                                                                    Entropy (8bit):5.194499200189728
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdSwVzju4IdRDDHwpatEB0HXFJico2AGHaSMNO5AHNUlu:2dSwkdRgek+vSD7
                                                                    MD5:7F7A3B618E2D1442030B2465ED39E505
                                                                    SHA1:83594F0DD160912888C204C99FB98A5CA1CBEC9E
                                                                    SHA-256:4A0B4BB1E405BCA274BF5C7975CD156099FF671C29DE8017AD598C05903621B3
                                                                    SHA-512:0001ACC43429F4882AB48F73FAEF40FCDA02FC5653499F84B16E58D3499F34548DF605025220132D76AAE4E1CE2918F1A39E3C81F4D8C8E6AB141BEDCDDABCA5
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10833" V="0" DC="SM" EN="Office.Outlook.Desktop.Holiday.AddHolidaysTransfer" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="22402" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <C T="U32" I="0" O="false" N="CountOfAddHolidaysTransfer">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1158
                                                                    Entropy (8bit):5.12689155289185
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dShF3TjdRgekdvSFcmcQgvZ4ocWvXczEvv1AcivB7:cShVlRgekdvSXgn/1q57
                                                                    MD5:DF18DB8E05DDA4FC76A9F64A8DB46484
                                                                    SHA1:7A1624FD1F8483F729B86CE70B741EC596397A4E
                                                                    SHA-256:D0278D7D0DA5E41E40C5E8B71B116689D9F990003CBB264684D939BED596EAA6
                                                                    SHA-512:11E4530B6715503B0947FFF54882B9F5CDD31CB5C187D558729B1DA9DA755696E5242A3F24C1017259D52F91BEB634FA19B540ECBAB623C72A932E83B2535173
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10834" V="0" DC="SM" EN="Office.Outlook.Desktop.Holiday.AddHolidaysGroupCount" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="22403" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <C T="U32" I="0" O="false" N="CountOf_AddHolidaysGroupCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="SumOf_AddHolidaysGroupCount">.. <A T="SUM">.. <S T="1" F="AddHolidaysGroupCount" />.. </A>.. </C>.. <C T="F" I="2" O="false" N="Average_AddHolidaysGroupCount">.. <A T="AVG">.. <S T="1" F="AddHolidaysGroupCount" />.. </A>.. </C>.. <C T="U32" I="3" O="false" N="Maximum_AddHolidaysGroupCount">.. <A T="MAX">.. <S T="1" F="AddHolidaysGroupCount" />.. </A>.. </C>.. <C T="U32" I="4" O="false" N="Minimum_AddHolidaysGroupCount">.. <A T="M
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):2183
                                                                    Entropy (8bit):5.048469810735926
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dS5BdRgeyxvvPrVQqTueEprKsfvg1EV/kLFb:cS5rRgeyxvbd1EprKsXPV/yFb
                                                                    MD5:E8CC98189471039A9F440938CC82FA49
                                                                    SHA1:7C285F6FCFE06EEB7047FBF4C1632B2925A4E8DC
                                                                    SHA-256:88DD193DE3E18B24EE3D814B1698CAA148FE681F6A493C3E69674CB2FE4D5CFD
                                                                    SHA-512:B80732ACDA1DEE58040B0358747D8A30A7C320D11C97AE61DE00B4134BC10E432BB06C00CF23E58B60E91D6D93B0F680C7F8ADDD84B402F6F02540C7744EA874
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10836" V="0" DC="SM" EN="Office.Outlook.Desktop.FeedbackandSupportClicks" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <TI T="1" I="Daily" />.. <A T="2" E="TelemetryShutdown" />.. <Etw T="3" E="20703" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="4" E="20708" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="5" E="20707" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="6" E="20704" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="7" E="20705" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="8" E="22210" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="9" E="22211" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="10" E="20730" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="11" E="20706" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="U16" I="0" O="false" N="Count_OpenHel
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):5178
                                                                    Entropy (8bit):4.093194344076953
                                                                    Encrypted:false
                                                                    SSDEEP:48:cSOEFRge12UA88JkuXvisN8b0/hlfycAFHIbLlGz3rdzC0z9Y4O33OC0OrvcoI/3:dRgeyegKYlbf+lWBSrgWYVTq/5VOo
                                                                    MD5:1C0F7CB02335D784CD8DD4B42CF6717D
                                                                    SHA1:4C467E31A85DD0DA11ADE388E02D971A6B0905FA
                                                                    SHA-256:D4A7137EAAE959D3C770CC4DF88F52D135F0B82B9B221D6689F9782B7E73CCB2
                                                                    SHA-512:37673A3D6C3709E9098A509FC67D61D388520895E7D5B0145C61BEC63E5791770B5B02746F849AB453ECC4B02834D06E30128618F4780D8D5325475E5DA863AA
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10837" V="2" DC="SM" EN="Office.Outlook.Desktop.CalendarViewModeChanges" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="400" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <Etw T="2" E="401" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <Etw T="3" E="420" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <A T="4" E="TelemetryShutdown" />.. <TI T="5" I="Daily" />.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="CalendarMode" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="1" F="CalendarMode" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="8">.. <O T="EQ">.. <L>.. <S T="1" F="CalendarMode" />.. </L>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):2489
                                                                    Entropy (8bit):4.497566133266252
                                                                    Encrypted:false
                                                                    SSDEEP:48:cS2rRgehEvlTY38hQY382JY387uY38ovY38exlxrr:aRgeaNk38hn382a387d38oQ38Yd
                                                                    MD5:03D5B2DECE1B481D6CEE9113063E8955
                                                                    SHA1:C53427E291EDCE495BCCC428F690759E9E9D7AA8
                                                                    SHA-256:EF45755D9549452461C18E6BE93FF0A00836046A3D8AE5B8CD047E5D10B8D8EA
                                                                    SHA-512:DA0328F8861A0B630204D8BB0F0A7EF5D27DE252BA79F23F38690AFEF76BA8B1B98F32521325D0AEF44309125E92A73FF46BFDACB77263386C95763AD26B936F
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10838" V="1" DC="SM" EN="Office.Outlook.Desktop.SearchUIResultSource" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="7089" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Hourly" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="SearchResultSource" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="SearchResultSource" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="SearchResultSource" />.. </L>.. <R>.. <V V="2" T="U32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="1" F="SearchRes
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1525
                                                                    Entropy (8bit):4.77334761805966
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dSgmndRgeKXvLvivLEe08O0izPAqtoRPih6PHTBQ1Th7:cSgeRge2oYe5Oh8OmmV
                                                                    MD5:69FECF39B512C1116BCF4605D70042EE
                                                                    SHA1:807CD3E3EB690BAFD0D7869B94722D0630DF77F9
                                                                    SHA-256:D810655D3DC6EC2BD2EC3D03B6E5AFE64FADF4BA82DABCFDA3BF79385008BC05
                                                                    SHA-512:18B18EC0AA4FD766D26864488DDFE2EA8DD19D7C36F435BEFE9F1B014D03D21B2C1ADC2F74C6083B793705DEAE0EECE8F51B2E7CC3EE66A863969649211CFEC4
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10839" V="2" DC="SM" EN="Office.Outlook.Desktop.Groups.VerbsExecution.Metrics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DL="A" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="336" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="2" E="337" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <TI T="3" I="Hourly" />.. <A T="4" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="StoreType" />.. <F N="VerbIdNew" />.. <F N="HRESULT" />.. </S>.. <S T="2">.. <F N="StoreType" />.. <F N="VerbIdNew" />.. <F N="HRESULT" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="StoreType">.. <O T="COALESCE">.. <L>.. <S T="1" F="StoreType" />.. </L>.. <R>.. <S T="2" F="StoreType" />.. </R>.. </O>.. </C>.. <C T="U32" I="1" O="false" N="VerbId">.. <O T="COALESCE">.. <L>.. <S T="1" F="VerbIdNew" />.. </
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):2514
                                                                    Entropy (8bit):4.807512960860602
                                                                    Encrypted:false
                                                                    SSDEEP:48:co22Rge+djb8678co41JxVFfr9m40BLJxMjmr:jRgeuRDN4
                                                                    MD5:8A5750DE3007ECEA395CAB6550FDC67C
                                                                    SHA1:B32FA8915D807119E7EBC07FADD10AECF4E0D06A
                                                                    SHA-256:991A2A4FFE4E3BDD23492E8D5DE4BD3146D45ED373E76A8C47F6F551E75DD10E
                                                                    SHA-512:39A4D1ECF419AF2C1107A6045485A0E0ABECBB45EFB3FCE8E686E63ED56EAB16F1119D34BC60E49D39BBFEE51CA119B354763BCB703BACDF0C18CF6F2A3FC1C9
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10841" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.ApiCounts" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3201" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="2" E="3203" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="3" E="3204" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="4" E="3206" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="5" E="3207" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="6" E="3208" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="7" E="3250" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="8" E="3251" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="9" E="3252" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="10" E="3253" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="11" E="3254" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}"
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):9082
                                                                    Entropy (8bit):3.7506683981346014
                                                                    Encrypted:false
                                                                    SSDEEP:96:lCRgeFI6eHSgb4fiaASGKrlCYj1U+SMdsT06ELPl8oYPUF8gmpz7:lCDBzlS0sPUd+7
                                                                    MD5:FF61FF98069FC4481501DE0B020ABE8D
                                                                    SHA1:CD6A0CC21E49B7EF6C49BE39028F92B274CC5642
                                                                    SHA-256:F401D4BE65BF576A70AF18E3783CB2FC9F90237FF05620AE95D4512F0E60AD36
                                                                    SHA-512:00ACAF32CC18FDBBBAD9D016DC3372E62A14C8A4C825A47574DA30CE52A1BB38E8EC4D1F9D99B87D93E5B507139218D3A5055EA20B6B7FDE9E1824DA9C2A529F
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10860" V="1" DC="SM" EN="Office.Outlook.Desktop.ModConvVerbExecutionFailureRate" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="10861" />.. <TI T="2" I="Hourly" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="LT">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <V V="0" T="I32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="0" T="I32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="LT">.. <L>.. <S T="5" F="1" />.. </L>.. <R>.. <V V="0" T="I32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="1" T="I32" />.. </R>.. </O>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):393
                                                                    Entropy (8bit):4.838353697219681
                                                                    Encrypted:false
                                                                    SSDEEP:6:TMVBd7opZ4HpBCDmIyublrL/CynlUq+/ZNOnqHNnUWsby:TMHdEpZOBC2IDbEZNOqHNUlu
                                                                    MD5:25FCE034336F890DC7AD11723FA7B35F
                                                                    SHA1:4FF47C1D6950E1820B46CA78A5231C9130A75D9D
                                                                    SHA-256:C78A9DB7B723DE7C3B977C4F633BA61AEB2D564475F8C73BD98742232A91928A
                                                                    SHA-512:86E44CC7734FC855B33198FC585E9340FBC620844020C79806E79AEABA0502708CE4D469455B3CE38A14A6B463DAA05FEA11AA88B3922586F9477F7408E13A90
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10861" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="20054" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="I32" I="0" O="false">.. <S T="1" F="Verb" />.. </C>.. <C T="I32" I="1" O="false">.. <S T="1" F="HRESULT" />.. </C>.. <T>.. <S T="1" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1901
                                                                    Entropy (8bit):4.99213994548585
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dh4PdRgeoFvLuvLjvL5TghnYU9nm6mvhgP84+gOtBQPfg7:ch4lRgeopUn9Tej9EPgOtIg7
                                                                    MD5:57E71E3AA9BF05172515C67529D1622C
                                                                    SHA1:9EB3ACBE10F54607C97ED889C588328AA7197E8F
                                                                    SHA-256:456C7F5C09555465FE27D30FDC617BF85432653DA9AC906B37B72D53F636CB4A
                                                                    SHA-512:836FB8C13E4A0E7CE79D3FC96E5C3F447E5F2980E1E41D1A14B0D1D2C39A528239E97314A38394F4EA74B12A63AB4067AEB2FB1151B0EFEB51ED3B27E81A3275
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10864" V="2" DC="SM" EN="Office.Outlook.Desktop.DownloadFilesUsingBITSWithAuthentication" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="64" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="26103" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="2" E="26113" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="3" E="26120" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="2" F="FunctionName" />.. </L>.. <R>.. <V V="DownloadFilesUsingBITS" T="W" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="1">.. <F N="ThreadId" />.. </S>.. <S T="4">.. <F N="ThreadId" />.. </S>.. <S T="3">.. <F N="ThreadId" />.. </S>.. </G>.. <C T="W" I="0" O="false" N="JobDescription">.. <S T="1" F="JobDescription" />.. </C>.. <C T="B" I="1" O="false" N="FManualDownload">.. <S T="1" F=
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1651
                                                                    Entropy (8bit):4.575370307988862
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dM2YdAZdRgekKqJhXwOyXJFgjqumgjt0J94C7:cM2YdGRgekKqJdAJFyqumyId7
                                                                    MD5:6B48D65A351EA5438E63B2AE44A777B5
                                                                    SHA1:0DDCAA9BFCEB482658DDB5A61B9D80313C2B1DA0
                                                                    SHA-256:066ADBF47AE7B0495E5FF7E28FE2F4714012F18E42FBB6210D4C7C55434A393E
                                                                    SHA-512:B978F669E3E3B161C3E012F927F98B49378B143CFDA35F1C82121F6949BACC063396685989F133802445B640541E234ED2E878B19FBD480C80248B4637CECF8F
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10869" V="0" DC="SM" EN="Office.Outlook.Desktop.OpenMessageStore.EmsProviderResult" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="2067" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="LT">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="2147483648" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="GE">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="2147483648" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="4" F="fLogonObjectUsed" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="5" F="f
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):455
                                                                    Entropy (8bit):4.399188454050293
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdWKferiNerEHDb8OKX/c//fpONkMNOjsu:2dGriYrEC+
                                                                    MD5:D6C398FAC8F9D87101DB8FEF53C2B876
                                                                    SHA1:C01F2FFB8D8C3FCEBCD0B29709C1C4F40044D83D
                                                                    SHA-256:653F87BAC5821A543929EC0015FB8B6F86C77B227F6AB063210D9B594D5D376D
                                                                    SHA-512:C7771791F75D9DB8A9A9B78DB310F988BFEFBB89EA2011770F7857C5780CAA1DE2F87070C3E886B77A8142E43B83CDA74A27D09F771DBBF38292F1F61976F47A
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10879" V="0" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <UTS T="1" Id="bgo4t" />.. <UTS T="2" Id="bisag" />.. </S>.. <C T="I32" I="0" O="false">.. <U T="100nsToMs">.. <O T="SUB">.. <L>.. <S T="2" F="TimeStamp100ns" />.. </L>.. <R>.. <S T="1" F="TimeStamp100ns" />.. </R>.. </O>.. </U>.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):2683
                                                                    Entropy (8bit):3.342342111015339
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdnfi0o5Q//WRff/0//ShmMnENWwmhfP/k//ix2Nf/0//g//mhfP/k//4x2Nhv:2dF4jOOpOO1H1HOcEIO9DO2nP
                                                                    MD5:D5628C2352A9B3D4C4602F5AFA2036E4
                                                                    SHA1:E7D8230316AC0DD065D2638EEC718EAE75794AC0
                                                                    SHA-256:7466102BD56EFEC53753921C3F7A6D7E03C0F5BCC8BDFA9E071D413A31E71BD3
                                                                    SHA-512:1E83F499724E6DDBEB51ACF21191075C5B502FC34967D2137EF383951253FF835AA7F9261A600CE6ED7F9E8B11A72BF59A65724850B5113249F0AFD6FD374CE8
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10880" V="0" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <R T="1" R="10879" />.. </S>.. <C T="B" I="0" O="false">.. <O T="LT">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="50" T="I32" />.. </R>.. </O>.. </C>.. <C T="B" I="1" O="false">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="50" T="I32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LT">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="100" T="I32" />.. </R>.. </O>.. </R>.. </O>.. </C>.. <C T="B" I="2" O="false">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="100" T="I32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LT
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):489
                                                                    Entropy (8bit):4.337646480264813
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdQyferKerEYDb8OKX/c//fpONkMNO/HNUlu:2dirdrETE7
                                                                    MD5:9776094DC797155D2034F31172F11855
                                                                    SHA1:64D1EBADBE368C9871662A8E55A508A916A0D3DD
                                                                    SHA-256:D29FF2CF8D1225E5908F202F04F77FF6687E74444ECF6D4C08CE772AD3CD85C3
                                                                    SHA-512:B949FA714541012864CAD0E3F664AB0C02DD41470B8F1A3E2EB18A825341EBB2859C6EE0E3654AB3E426EAD57F06E81E9D1B2469F088B055135FECF95D7FBCCA
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10881" V="1" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <UTS T="1" Id="bgo5i" />.. <UTS T="2" Id="bisaf" />.. </S>.. <C T="I32" I="0" O="false">.. <U T="100nsToMs">.. <O T="SUB">.. <L>.. <S T="2" F="TimeStamp100ns" />.. </L>.. <R>.. <S T="1" F="TimeStamp100ns" />.. </R>.. </O>.. </U>.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):2683
                                                                    Entropy (8bit):3.339338030411146
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdZfi0z5Q//WRff/0//ShmMnENWwmhfP/k//ix2Nf/0//g//mhfP/k//4x2Nhv:2dfXjOOpOO1H1HOcEIO9DO2nP
                                                                    MD5:9CD208B8D4670DA9984D5A05AE008E00
                                                                    SHA1:99CFE5945C3AB601460B083F61A237E5ECC9BF97
                                                                    SHA-256:8E2B06BC23226F0819031A9FB7CE418A3BABF447164286D58FCD291ADD0E6DEF
                                                                    SHA-512:6A87B9EE407EA4494AFB5267B829859319DBC7C557A64F9BBA6C2BBF836AB3A687A8E2AEDA431943F89686FE64A9A50FC71AEDA4E6484CBD5E1D80E14406826F
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10882" V="0" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <R T="1" R="10881" />.. </S>.. <C T="B" I="0" O="false">.. <O T="LT">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="50" T="I32" />.. </R>.. </O>.. </C>.. <C T="B" I="1" O="false">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="50" T="I32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LT">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="100" T="I32" />.. </R>.. </O>.. </R>.. </O>.. </C>.. <C T="B" I="2" O="false">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="100" T="I32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LT
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):820
                                                                    Entropy (8bit):5.074444213126179
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdzVzjlV0dRDDHwpat5CkYnuoRcSU9QROb8OKX/c//fpONkMNO/HNUlu:2dz2dRgeM/uhTWJE7
                                                                    MD5:45A992255B5F03F0CE41DCEC8CE960D9
                                                                    SHA1:074615840424803A0F703D4459D7D64948C2B824
                                                                    SHA-256:AA190D2453B55A1428AEB31BD89A3D2C0553CAC9541902CCEDF5AA3E726B28E9
                                                                    SHA-512:FFC0D353FC56AA2919948E77D6A6FE8D8D26187402F0ABFBB679A0A05B01C5DFFE5970E7DEBA7F82A34CA151A2D33AF3AC21C09F3C9060D95C45D19423A0EF09
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10891" V="0" DC="SM" EN="Office.Outlook.Desktop.DiagnosticsSystem.WriteAutoDiscoverDataResult" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="50" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3781" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="2" E="3782" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. </S>.. <C T="I32" I="0" O="false" N="HResult">.. <S T="2" F="HResult" />.. </C>.. <C T="U32" I="1" O="false" N="TotalWriteTime">.. <U T="100nsToMs">.. <O T="SUB">.. <L>.. <S T="2" F="TimeStamp100ns" />.. </L>.. <R>.. <S T="1" F="TimeStamp100ns" />.. </R>.. </O>.. </U>.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):3929
                                                                    Entropy (8bit):3.7501724045260145
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d8OdRge8LvS8ugwOmjeePqeOy6eqdmeag2esv6uA1Rpuff7:c8yRgewvS8FUABGF1MSff7
                                                                    MD5:33AEFA9BD440EC07CB4E96B198B57FE4
                                                                    SHA1:4EFD098E990A4CE8664222F6BC69179FD56E4263
                                                                    SHA-256:2857C56AFA3022DFD51A46D8C2AB1230B15FB8F503580CEBCBC8C439D6656F6A
                                                                    SHA-512:3A2940060F865EAB84E366BADA1AB0A232500327F15A9D4CA44651C56429282B68A53E1FC0909DED96D927CD7E9F3A5EE497CA0FAFD52BB11791AD33BD6CC680
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10892" V="0" DC="SM" EN="Office.Outlook.Desktop.DiagnosticsSystem.WriteAutoDiscoverDataTime" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="10891" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="LE">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <V V="20" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="AND">.. <L>.. <O T="GT">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <V V="20" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LE">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <V V="50" T="U32" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="6">.. <O
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):6204
                                                                    Entropy (8bit):4.17420265539919
                                                                    Encrypted:false
                                                                    SSDEEP:96:wRgeiufWfzbi2fc6YdFrRgU1mHAhT+NsbioCAfca3r2ZXyJQ2:wD+aHr2ZXyJQ2
                                                                    MD5:919C09AB54D28E65A531FA089373418C
                                                                    SHA1:084A7D4563376931CCBBFE2F43C5001AD678368C
                                                                    SHA-256:2A109199232490F60855DCB384B16285371C068D21BEB0A2B457339C3CCA074C
                                                                    SHA-512:16C5FC091162BBAFCCBB3942FFCC03405AAEE17075E5FC09E8B8E50BD9108D12302B8F84AA183DD4419DA990D051F67B9F6F6C6909F91615CB90D410D0A6E02D
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10893" V="0" DC="SM" EN="Office.Outlook.Desktop.OutlookCalendarUsageErr.MeetRcpt.ReplyActions.Rule.O16" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <Etw T="3" E="360" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <F T="4">.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <S T="3" F="IsRecurring" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </L>.. <R>.. <O T="EQ">.. <L>.. <S T="3" F="IsException" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="3" F="IsRecurring" />.. </L>.. <R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):6317
                                                                    Entropy (8bit):4.210749911883675
                                                                    Encrypted:false
                                                                    SSDEEP:96:3Rge9ufWk0h7Vf1o9qirbDU1mHAhT+NsbioCAfcEE49nOR2qT:3Dljc49nOR2qT
                                                                    MD5:91EFB1362FFDCC8D0FA4D7EE08AE0242
                                                                    SHA1:90AF5EC31F16D598CB6D87AC49737D056C4104A8
                                                                    SHA-256:272BB90CD416423C462A0760EF2FF3165ED3E5D4A95A3A911476C16D46A45C8E
                                                                    SHA-512:CDAF60B2FC5A8EFB423BF1B37168829E680423BDC3BEFF6058C67E1966EDF817905C8203AA02B2B43BDAF517C003D499859CD304F21F18358A608F2703535F10
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10894" V="1" DC="SM" EN="Office.Outlook.Desktop.OutlookCalendarUsageErr.MeetRcpt.ForwardActions.Rule.O16" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" SP="CriticalUsage" S="25" DL="B" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <Etw T="3" E="361" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <F T="4">.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <S T="3" F="IsRecurring" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </L>.. <R>.. <O T="EQ">.. <L>.. <S T="3" F="IsException" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="3" F="IsRecurring" /
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1942
                                                                    Entropy (8bit):4.392957633399417
                                                                    Encrypted:false
                                                                    SSDEEP:48:cWK6zTRgeJlfABOq8QrqJpwknGVKUkA0V:LRgeJoufFnGVfkAu
                                                                    MD5:1788792A021ECD72DD00F6420AE78925
                                                                    SHA1:04F4D5E83DC73194148BEB9C72BB950525EFF7D9
                                                                    SHA-256:BCFEE5A1EF936AD9149B99EF8E179F4491B10957A98341279CC47D962A147C03
                                                                    SHA-512:A2AF4D1B51EDDB8B9564C31F5F861E1A92DD106BF64F987F46FAA443EAF998AB95B86C7E2DF39CA4CDEC27F9E849013F393591F8D8ABFA5EB6868C0FADC234D3
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10895" V="1" DC="SM" EN="Office.Outlook.Desktop.OutlookCalendarUsageErr.MeetRcpt.CallActions.Rule.O16" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" SP="CriticalUsage" S="50" DL="B" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <Etw T="3" E="362" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <F T="4">.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <S T="3" F="IsRecurring" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </L>.. <R>.. <O T="EQ">.. <L>.. <S T="3" F="IsException" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="3" F="IsRecurring" />..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1885
                                                                    Entropy (8bit):4.326159243020675
                                                                    Encrypted:false
                                                                    SSDEEP:24:2doho6UO/dRgelfFIilOXvyzTX9yVwOaH/jqJHtjwsC0AslV:coK6tRgelfFBOq8QrqJpwSA0V
                                                                    MD5:F7E52F658C1EB673E356AB0D878BBF55
                                                                    SHA1:698A7DAE1B6F6BB443B389DD1ED6FD4C4160108E
                                                                    SHA-256:DF01598ACA84ABA01DECCDC2FE078DD00CC491038F10177906D43E660DD1C05A
                                                                    SHA-512:82DD3E1BB869F2650FF024FFC2AE2923105AEF6853167439E68CD39EE43B5E9A03F2857464458A413554CD58A05F6454A9EEF02B6086E8B7E258F394112FFA8F
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10896" V="0" DC="SM" EN="Office.Outlook.Desktop.OutlookCalendarUsageErr.MeetRcpt.DialActions.Rule.O16" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <Etw T="3" E="363" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <F T="4">.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <S T="3" F="IsRecurring" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </L>.. <R>.. <O T="EQ">.. <L>.. <S T="3" F="IsException" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="3" F="IsRecurring" />.. </L>.. <R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):2096
                                                                    Entropy (8bit):4.393976266815697
                                                                    Encrypted:false
                                                                    SSDEEP:48:cdK6+gRgelfWBOq8QrqJpwkU1m/UM530V:mRgeGufFU1mcM53u
                                                                    MD5:D01A35D03F86073E8121C7D00BF8F5FB
                                                                    SHA1:0167D6F1053612D140285F245647368A91D6CA19
                                                                    SHA-256:9F03BC33E1A226C9F37BCAB7DDD6B486D400329FF08E145EA3DDF2A74A979270
                                                                    SHA-512:BDE2D53A186DBB46A9B3717587960BD130CDAB7FB8751A4FB194CBA2AA7BDF184A54C9F12289110177809721A4E8602A965616784B2DC2577FBB3DAF9AD2F605
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10897" V="0" DC="SM" EN="Office.Outlook.Desktop.OutlookCalendarUsageErr.MeetRcpt.GalContDialActions.Rule.O16" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <Etw T="3" E="364" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <F T="4">.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <S T="3" F="IsRecurring" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </L>.. <R>.. <O T="EQ">.. <L>.. <S T="3" F="IsException" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="3" F="IsRecurring" />.. </L>.. <R>.
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):3889
                                                                    Entropy (8bit):4.290086920856266
                                                                    Encrypted:false
                                                                    SSDEEP:48:cyVK6gRgelfTBTrqQpqJaquSqvv7qsX7q8Bq/xqfy87qF27wBBtbGBaO5rI92:ToRgebyVbCuxh4fIDBtbGBaaI92
                                                                    MD5:60E5125166216451E82793B1C438056F
                                                                    SHA1:B8D9452E3D1B01AEF6EF06C5FF64395F2CFFCE58
                                                                    SHA-256:91FDD4808565FE9197B4D18FA5E47F6FC2D706430EF4423DEC22CE6A281D2042
                                                                    SHA-512:20C27B460F12654603367C16F3CA4227DB825E32A3E831F1DA4862AB8EF39A00D8210CAE7EC9636A0F3977955E11D041FBB0F4DD4BEEA0FF9C3F7FDA5E530191
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10898" V="0" DC="SM" EN="Office.Outlook.Desktop.OutlookCalendarUsageErr.MeetRcpt.ForwardOcrSerActions.Rule.O16" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <Etw T="3" E="365" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="3" F="IsRecurring" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="3" F="IsException" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="5" F="IsForwardSeries" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1080
                                                                    Entropy (8bit):5.070464270382312
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdzzjVzjx76dRDDHwpatEc6NXFJim1DZ1DOW1DR1gHpEfXHISMHyXHfOSMpMOI:2dbOdRgeyxv+pEfOy649ZZ
                                                                    MD5:5897BA24F7A84704E1578791374B304E
                                                                    SHA1:574C853EF0AA209703FB68591C075134F6DBF8E5
                                                                    SHA-256:D8C9E32B86FB1AD02DE9D849E751BB4A6B8FB6D32D31DB270D8EE52DBDD8BFA0
                                                                    SHA-512:995675B0774516BACB780EC3BB18083AE16C5DB3F0A85C77167AC2C061F2142D43F53B9BECC412F65A512124F76B1EFB4FC80AC3C1E224C5736E4C7BAE5758B4
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10899" V="0" DC="SM" EN="Office.Outlook.Desktop.TXPUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <TI T="1" I="Daily" />.. <A T="2" E="TelemetryShutdown" />.. <Etw T="3" E="105" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. <Etw T="4" E="101" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. <Etw T="5" E="104" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. <Etw T="6" E="107" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. </S>.. <C T="U32" I="0" O="false" N="TXPParseEventCount">.. <C>.. <S T="3" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="TXPIndividualCardParseCount">.. <C>.. <S T="5" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="TXPCardAddedToFlexCount">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U32" I="3" O="false" N="TXPCardParseExceptionCount">.. <C>.. <S T="6" />.. </C>.. </C>.. <T>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):708
                                                                    Entropy (8bit):5.097047229171639
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdjYVzjxOGyc6dRDDHwpatEc6NXFJikW10HNJ9OXWcxCf2xccRXHISMNOS/HN/:2dsDyc6dRgeyxvZv9qWc0u6cR+Z
                                                                    MD5:B713DA663859968261BB406FF3C1D5D0
                                                                    SHA1:E02F4C64E6643B42AAFF29BA8198F093C6772928
                                                                    SHA-256:1F3DAA0C1B756DD4DB7D712B61BCAACC1579E738AB73A11B15EFD3BA303838C5
                                                                    SHA-512:2C5AC1ED6DDBA22159E60BD05828472CB49F67DFD07E4EFB5E4BFEBF2749581D7BA904A578CDCFA7B61999EBFFD9A91BFCF896332ADCE2255F36571A41B1E133
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10900" V="0" DC="SM" EN="Office.Outlook.Desktop.TXPParseActivityBreakdown" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <TI T="1" I="Daily" />.. <A T="2" E="TelemetryShutdown" />.. <Etw T="3" E="104" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. </S>.. <G>.. <S T="3">.. <F N="Type" />.. </S>.. </G>.. <C T="W" I="0" O="false" N="TXPActivityType">.. <S T="3" F="Type" />.. </C>.. <C T="U32" I="1" O="false" N="TXPActivityCount">.. <C>.. <S T="3" />.. </C>.. </C>.. <T>.. <S T="1" />.. <S T="2" />.. </T>.. <ST>.. <S T="3" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):723
                                                                    Entropy (8bit):5.101960741262951
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd6YVzjxidRDDHwpatEc6NXFJiy10HNkOf7fOMxfXHISMNOS/HNClu:2d6YKdRgeyxvAm2p5+Z
                                                                    MD5:5FE8DD40F214DC4EC444A6588A11896F
                                                                    SHA1:84E04000C5A94C60DF14D68BE8E107E8AD95F735
                                                                    SHA-256:440A0C63788189E3094E60972BE0926F4DBC4E71B19410F5AC6A6D11FD6223BC
                                                                    SHA-512:CF734CCA2BBE33F0E4CDD13500FA49A05F42B86CCC01B15B953FD4E2468DB463F9992AB02D0466941796394233143A8180FCE375396DA7F1D73B2FAD91691C20
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10901" V="0" DC="SM" EN="Office.Outlook.Desktop.TXPUICardBreakdown" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <TI T="1" I="Daily" />.. <A T="2" E="TelemetryShutdown" />.. <Etw T="3" E="101" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. </S>.. <G>.. <S T="3">.. <F N="EntityType" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="TXPCardEntityType">.. <S T="3" F="EntityType" />.. </C>.. <C T="U32" I="1" O="false" N="TXPCardEntityTypeCount">.. <C>.. <S T="3" />.. </C>.. </C>.. <T>.. <S T="1" />.. <S T="2" />.. </T>.. <ST>.. <S T="3" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):687
                                                                    Entropy (8bit):5.154773160698925
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdcjVzjzoB8HSdRDDHwpatEjJe1zuXFJicouDr0/f+0upSj8HaSMNOAjsu:2dcjhoB8HSdRgeqFvSopy
                                                                    MD5:FEAACA09FB62C5CFB917CAE5237FC877
                                                                    SHA1:5FDE90894237354A828F6B1B74FD50D4BA4353F1
                                                                    SHA-256:FD63052C95C11D915B143B48823E7DCB6313048BC7B0420EF791DA6190D266B0
                                                                    SHA-512:1FD47C44C947D3D85DC3920831C4ACCA20AEF26995D920ACAB005CA04B927C9BC2D3663E2C4817580C8C1EB51D2B1F6CCFD50AC9EDD1ECFCD59916EC07756E7C
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10902" V="0" DC="SM" EN="Office.Outlook.Desktop.Outlook.Pst.BFillLevelNeeded.Invalid" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="481" G="{2adf8e23-0af9-43c9-ba4c-952ee130540d}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="PageSize" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="PageSize">.. <S T="1" F="PageSize" />.. </C>.. <C T="U32" I="1" O="false" N="CountOfFailures">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1700
                                                                    Entropy (8bit):4.862082336706875
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdjVzjZtw6dRDDHwpatEj6HD6HiHBicGN+aqNOcfX/c//wVrMpONd+r5lOJ7Xn:2djhdRgeYE88Jvjq0jV8T9Ior1cEQd7
                                                                    MD5:6F7CB4DA9824B12F3E0892FA4B923C1E
                                                                    SHA1:F0DAD9754A35F22B9E0D719F600EAFCB339A895A
                                                                    SHA-256:3E47CB19289689F6359D38617EF1D7208AB8CC29B82064DB547675AAE2698235
                                                                    SHA-512:EFBB3277E47A7BDAA57435805863F60C5D0E30BE192C3998B028FAF3645A03080326F99CF8595F68F4FCBD8A660A349B936FAD60635D0531A7F430E2D98E3B68
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10903" V="0" DC="SM" EN="Office.Outlook.Desktop.RecoverDeletedItemsUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9050" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="9051" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="3" E="9052" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="4" E="TelemetryShutdown" />.. <TI T="5" I="Daily" />.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="ButtonShown" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="NE">.. <L>.. <S T="1" F="HResultShowButton" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="DeletedItemsFolderSelectedCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):981
                                                                    Entropy (8bit):4.69715613136981
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdYVzj4lKdRDDHwpatEzFHc1NQi+kXqNOIfX/c//wVrMpONGANHfSMjNKUWXqk:2dYilKdRgemAqJTnvjdWJ7
                                                                    MD5:944D8A618C775CCC109E0B1F7D1A2AE2
                                                                    SHA1:622A0A9AE9DCE54421A637F777FB19599BD80841
                                                                    SHA-256:1DC4FA81F39E11267A2B90884942205400E011EA7DE72068792461E39AA0D7FE
                                                                    SHA-512:9505A6CF8348FFAFCCC2871D8AFF76009C3181266009A9EDD5913926EF25FA591D02B46ADA77ECA7CCBD99AA5216B2F731CBDE6C32B2CE64334DFBA12EDCAD38
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10904" V="0" DC="SM" EN="Office.Outlook.Desktop.SafeOpenDialogHasIDispatch" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="4252" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="Has IDispatch" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="CountHasIDispatch">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="CountNoIDispatch">.. <O T="SUB">.. <L>.. <C>.. <S T="1" />.. </C>.. </L>.. <R>.. <C>.. <S T="4" />.. </C>.. </R>.. </O>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1064
                                                                    Entropy (8bit):5.0762674365907134
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dj2KdRgefDkPSAsx+AQ0ehi+JWEbWWEieeqiK5fejM:cjDRgefZlx+9pYEbREBZ
                                                                    MD5:0C98E8F4582E20A6CD3615D3BB144989
                                                                    SHA1:2F05EA2B3862AA41C02C0883AB229F313054A190
                                                                    SHA-256:DF43FD7E80C4416BBA49E6D58BD1B38A23FAE380B75DD8C008E930ACAFE73CE6
                                                                    SHA-512:CE8D69FE375909D49608ED5C44CEB269770D4465B488ABED1445134FEA1BD19C471EC710C244336DA2C0D29B1047895C7AC09D6C66BC2706E2FA3C7217EB0C41
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10906" V="1" DC="SM" EN="Office.Outlook.Desktop.NDBCorruptStore.Warning" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" SP="CriticalUsage" DL="B" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="397" G="{2adf8e23-0af9-43c9-ba4c-952ee130540d}" />.. </S>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="1" F="TimeStamp100ns" />.. </C>.. <C T="U32" I="1" O="false" N="Context">.. <S T="1" F="Context" />.. </C>.. <C T="U32" I="2" O="false" N="NdbType">.. <S T="1" F="NdbType" />.. </C>.. <C T="U32" I="3" O="false" N="Version">.. <S T="1" F="Version" />.. </C>.. <C T="W" I="4" O="false" N="ProcessName">.. <S T="1" F="ProcessName" />.. </C>.. <C T="W" I="5" O="false" N="PstVersion">.. <S T="1" F="PstVersion" />.. </C>.. <C T="W" I="6" O="false" N="Details">.. <S T="1" F="Details" />.. </C>.. <C T="U32" I="7" O="true" N="CreatedWithVersion">.. <S T="1" F="CreatedWithVersio
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):603
                                                                    Entropy (8bit):5.22423592707578
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdsYVzj+MUdRDDHwpat5DrJe1zjFPdhdzWCHbSTWCHydybe/TW1yNO2su:2dsYSdRgeRwjWEbWWEiAerW1i
                                                                    MD5:918EF7DF4CDE0AF53B2F7C803FFF103A
                                                                    SHA1:CF97A237A7B69D714ED36B3755CD08EB8E576EA0
                                                                    SHA-256:3A357011143D8ADB29D928C1F186AAF0E72FAAA6F4BD0C4069E639A1CCB644F9
                                                                    SHA-512:55AB72E88E18C82B3490ED8FB6A3C38397ED929CCC293B4086E9A83146493920B89ECF33714A646204CD455EB05F29D2588A5B1D0F97A30D42687B793AFD1969
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10907" V="0" DC="SM" EN="Office.Outlook.Desktop.NDB.Unknown.Corruption" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="395" G="{2adf8e23-0af9-43c9-ba4c-952ee130540d}" />.. </S>.. <C T="U32" I="0" O="false" N="Context">.. <S T="1" F="Context" />.. </C>.. <C T="W" I="1" O="false" N="ProcessName">.. <S T="1" F="ProcessName" />.. </C>.. <C T="W" I="2" O="false" N="Version">.. <S T="1" F="ProcessVersion" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):8775
                                                                    Entropy (8bit):4.250960369844161
                                                                    Encrypted:false
                                                                    SSDEEP:96:ERgeEvF7tHC0fqIe0LJrqJAYX5F9+OE85JZRZEz8DCAvp39cDncSmr:EDqaLct82Avp39cDncdr
                                                                    MD5:8306324D2691D1B4944871DC08B0A67F
                                                                    SHA1:989A08BDCD2141BA98D7DA36297B1BB699E12A18
                                                                    SHA-256:112BC9595B68E4EDF46762B62DF73334542562C21714618118F55CE6D92439CC
                                                                    SHA-512:D4B2152DF6DE73059145565415B27063DBE8CD1BB50DF44EC44929EC877A91BB77815AEC60465B3B8DCD7F8F947CA37EB2DCAE4F8E168D2320C6B14FE2910E00
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10911" V="0" DC="SM" EN="Office.Outlook.Desktop.CalendarVTPApptMeetingActions" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="600" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <Etw T="2" E="601" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <TI T="3" I="Daily" />.. <A T="4" E="TelemetryShutdown" />.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="ApptMeetAction" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="ApptMeetAction" />.. </L>.. <R>.. <V V="2" T="U32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="1" F="ApptMeetAction" />.. </L>.. <R>.. <V V="3" T="U32" />.. </R>.. </O>.. </F>.. <F T="8"
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):2440
                                                                    Entropy (8bit):4.995886413020794
                                                                    Encrypted:false
                                                                    SSDEEP:48:clVRgeOvaEGsyH3n0siyjpb53Nz7+OcYm7:ARgeOvaEGsyHsygOch7
                                                                    MD5:4F28E9FBF9B04B3E4D1679E882821CA0
                                                                    SHA1:FCBA62E5FAC59B7F9205127F0BD3C832592B5C8D
                                                                    SHA-256:24E84E12B5B4B8528FED4E9861E28A46E5ADEA9752B9D9A4FCDE31083875221F
                                                                    SHA-512:7CD69E53F4A5BD00380A3E47B82B133B1AE1897EB77F7D9F9F960BDB7DEF5DC446894C23F7CE6F532E798F668D965928AAEEB7618571B430FE9AFE417B3D96E6
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10917" V="1" DC="SM" EN="Office.Outlook.Desktop.AutodiscoverV2Info" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="50" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="610" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="2" E="611" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="3" E="612" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="4" E="613" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="5" E="614" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="6" E="615" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. </S>.. <G>.. <S T="1">.. <F N="EmailAddress" />.. </S>.. <S T="2">.. <F N="EmailAddress" />.. </S>.. <S T="3">.. <F N="EmailAddress" />.. </S>.. <S T="4">.. <F N="EmailAddress" />.. </S>.. <S T="5">.. <F N="EmailAddress" />.. </S>.. <S T="6">.. <F N="EmailAddress" />.. </S>.. </
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):719
                                                                    Entropy (8bit):5.062023756744965
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdgVzj/usdRDDHwpatERHc1NQzDaNPfM4EXHaSMNO5AHNUlu:2dg0sdRgeRqC1607
                                                                    MD5:CD6A3796AB237DAC37A0D6249C04BFFE
                                                                    SHA1:E1B283274CFEBB48EC5244BEA31C5A1E83A783D0
                                                                    SHA-256:178D2D3D2EBD9D494500CE582ACE831B2008FAFD0026C3CABEA4819AF570125A
                                                                    SHA-512:335531C4A6E86D1CB05658BE68A2B6D7092028E30EB62F96E7AF8B61FC94FA33921AF54B4B43EDD912E203251DC5BCEFBA07317359B698939DC5F91775E8D63C
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10922" V="0" DC="SM" EN="Office.Outlook.Desktop.AttachmentsAttachAsCopy" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="4263" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="ResponseCode" />.. </S>.. </G>.. <C T="U64" I="0" O="false" N="ResponseCode">.. <S T="1" F="ResponseCode" />.. </C>.. <C T="U32" I="1" O="false" N="ResponseCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):2195
                                                                    Entropy (8bit):4.543003914440266
                                                                    Encrypted:false
                                                                    SSDEEP:48:cVtC2RgeUqJTGnQG0JGduGg3h343v3+3WohEl/p:g/RgeP6nh0IdXg3h343v3+3WoKR
                                                                    MD5:7C81A89E09C1CC5BAA7096A03F275EAC
                                                                    SHA1:ECF560CF20E24A73C61E6F73F51701E1BCA9B0AC
                                                                    SHA-256:AEF478CB5C451C23B8B3265C91E04570A87D4A746B1F4F8F4E67E8002964ECDC
                                                                    SHA-512:BF0DF6483D2F1AF229F87D1BF7453F8D18C6916A4956C90BAE4077FBE980B98A41D1B0E1A6C8F325413E86A47E35DA0A8AE36A7A7FF5506BF12720D6BB332B43
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10923" V="0" DC="SM" EN="Office.Outlook.Desktop.AttachmentsSharePointOnPremShouldAttemptConnectionResults" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="4264" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="Result" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="Result" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="Result" />.. </L>.. <R>.. <V V="2" T="U32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="1" F="Result" /
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):557
                                                                    Entropy (8bit):5.186702507368891
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdGVzjHa1dRDDHwpatEerGXFJico2AE5aIfHaSMNO5AHNUlu:2dGJ+dRgeLr2vSa5FM7
                                                                    MD5:4B8072735030B28C33E36E2EFEE4C9D1
                                                                    SHA1:552DF1D720F6E3BCAADAB492B869A8A1E273100C
                                                                    SHA-256:97E70ABD7A17256B70074373AECD5E90095D469B172EA0E8CD4C12AC238BBC37
                                                                    SHA-512:6C9B535453688390A4F0728B2567E30D48240D9F5BF3EDB56B53EEEBC176D4E92FFB8C0739C21492483F23D385800134C537FDCCF89686ED6A53B8D2CB549BDE
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10924" V="0" DC="SM" EN="Office.Outlook.Desktop.PeopleSearchStartingUsingZeroInput" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bjynu" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <C T="U32" I="0" O="false" N="CountOfPeopleSearchStartingUsingZeroInput">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):715
                                                                    Entropy (8bit):5.0661969034328775
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdrVzjUKGdRDDHwpatEerzXFJicouD+py/fQSNySjE2KtfHaSMNO5AHNUlu:2drPGdRgeLrLvSFTftM7
                                                                    MD5:C4CEA076980DEB12C0991D7B101110C9
                                                                    SHA1:E2A238F706EA93CFFF0889EF57FCCEB48DE5B725
                                                                    SHA-256:46CB0F703C967BC7F9E8FBD425A6EE75C880B5F01A1AE3C160663A1525324CEF
                                                                    SHA-512:6F97BE0F973DB7F7F2C6D5382D2AE4114C05B4BC96970B935AA47BA20CCAA876F0B4406A773B7C85BF7B654257E7D5A161B285CA290F62E4384C188901AD7A19
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10925" V="0" DC="SM" EN="Office.Outlook.Desktop.PeopleSearchSelectionUsingZeroInput" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bjyn0" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="SelectedIndex" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="Result">.. <S T="1" F="SelectedIndex" />.. </C>.. <C T="U32" I="1" O="false" N="CountOfPeopleSearchSelectionUsingZeroInput">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):575
                                                                    Entropy (8bit):5.209495134611662
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdT4VzjOY9qdRDDHwpatEst32GeOSc1NQnLbSHaSMNO5AHNUlu:2dT4H4dRgen3vLvqLbd7
                                                                    MD5:C28087E5EE2D13E15FB4856CF61B1AA2
                                                                    SHA1:6F2E97B3975C2B8920CEA9C067343BD27D089125
                                                                    SHA-256:DB0762199DFB81B19E34818CF7100AA34D15CAE124D29747C045DD4A437F6DD4
                                                                    SHA-512:CCCD837BEDFBF2F8586B772CD71AF245AE3F0EE4374D9F21BAB1533A335319EE1BC9190ED51490B5F3E01AF71B0B6F5AFC7D19EB905515E9D26A98E4B369A9F9
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10926" V="0" DC="SM" EN="Office.Outlook.Desktop.WriteSharePointUrlsToCacheFailure" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="340" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="FailedWritingToCache">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):2848
                                                                    Entropy (8bit):4.453500762587206
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dpRWdRgemsEvlTRiAwOaRjqJYeImeIvzrI3rKs6PEsNTP1BOb5n1jAQ:cp4RgeJEvlTtQ1qJ8OvQk251jAQ
                                                                    MD5:84D67A3ED7A805E3F665A788EF5350C2
                                                                    SHA1:40BD9449EE165F01AA2154C27D57A3F04E15909A
                                                                    SHA-256:84E130B8D9B48D2D573CB628F7CC646A180899BB362AADAEA1E47A95A0038A01
                                                                    SHA-512:5563A56367FCBF5B93C9677CCA234D4B225792E8AD5CDE097A576510872AD990DBB03106C5A34BD77C00F709A85F0FFB8CC4C30FAA736EA0753D6CA7F152AE17
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10927" V="0" DC="SM" EN="Office.Outlook.Desktop.SearchMCRPConvSource" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="7092" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Hourly" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="LoadConversationFromCache" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="LoadConversationFromCache" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="4" F="HResultLoadFromOnline" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="NE">.. <L>.. <
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):856
                                                                    Entropy (8bit):4.959871810940435
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd6VzjlVPdRDDHwpatEer6erkerWcih2NanrLevHaSMiLAHhSMpt+HISMNO3Xr:2d67VPdRgeLrNrrr9grLe1LIjo
                                                                    MD5:3CA27CA1541687046DCF868EF8522AEE
                                                                    SHA1:7C9A61E00266BE5288BF6618D7CA8516014D2169
                                                                    SHA-256:B609B8128D03222158AE66683F509EE6D08291BAA6BF6C948178619E5FFAB064
                                                                    SHA-512:DABD6236B986AA367A73B5298AA6ADD61E181FD6C2F724A4F1D6FAFA8FD8537BF0FFA7FDB49139FC5BFFACD20AB6C93A2D7B6B6B71B19A67EFB9EB405D241F0B
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10928" V="0" DC="SM" EN="Office.Outlook.Desktop.OneDriveTransportFileAndFolderParsing" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bjaje" />.. <UTS T="2" Id="bjajf" />.. <UTS T="3" Id="bjai6" />.. <TI T="4" I="Daily" />.. <A T="5" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="CouldNotDetermineFolderName">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="CouldNotDetermineFolderPath">.. <C>.. <S T="2" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="CouldNotDetermineFileName">.. <C>.. <S T="3" />.. </C>.. </C>.. <T>.. <S T="4" />.. <S T="5" />.. </T>.. <ST>.. <S T="1" />.. <S T="2" />.. <S T="3" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):690
                                                                    Entropy (8bit):5.057508655522115
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdmVzjlMdRDDHwpatEerZNerDfcoNBn0oXHaSMWRXHhSMNOAdHNS7lu:2dmbMdRgeLrZYrfv0oRDr
                                                                    MD5:876144B7A0C2E3F970E81464E14BA8CB
                                                                    SHA1:CA2611FB6A256E9A4DFD460489731EA34B26DCCA
                                                                    SHA-256:D8DE7B3D7B3B20D53EB59118FA71B9145B8674F3A8040227B999C44B9D4AE6AD
                                                                    SHA-512:964114A024B98796B333AC587B95724644E213B0358BF416D1333657C49E0B1F0005DAEDE1160A7769067DA92506B722A94CFCCD039E9CF3CCC2DADA40F90DFB
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10929" V="1" DC="SM" EN="Office.Outlook.Desktop.OneDriveTransportJsonParsing" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bhzqp" />.. <UTS T="2" Id="bhzqq" />.. <TI T="3" I="Daily" />.. <A T="4" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="MissingOrInvalidJsonCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="MissingOrInvalidJson2Count">.. <C>.. <S T="2" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="4" />.. </T>.. <ST>.. <S T="1" />.. <S T="2" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):706
                                                                    Entropy (8bit):5.067582940614538
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdQVzjFzcdRDDHwpatEerGc1NQzDI7WgOSfQS5WgO9jz7SHaSMNO5AHNUlu:2dQnIdRgeLrbqA7vOtOvO9d7
                                                                    MD5:4DB5E2A2D57B6C8756EB654C1474752B
                                                                    SHA1:A40BD8D776E2784EC14EAC55B775BEC1C1D1C8AB
                                                                    SHA-256:1E71C68FE8F672C95669517916CA8CD52D8048CC26D227ED54873B6D7F56AF0D
                                                                    SHA-512:32074B3F7D125871B89F7CA99856935D0A90DA5814971348AE98D5929FB51D24E92EDC98CF70F2DDE289CF64BD3C6FAB3C69F33EF8C62B49E1BF7F819FB9EB1A
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10931" V="0" DC="SM" EN="Office.Outlook.Desktop.OneDriveTransportGetDocumentAndPlaceInfoFromServer" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bjnkq" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="TransportResult" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="Result">.. <S T="1" F="TransportResult" />.. </C>.. <C T="U32" I="1" O="false" N="CountForResult">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):708
                                                                    Entropy (8bit):5.0612072696667685
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdnVzjFvwSndRDDHwpatEer9c1NQzDI7WgOSfQS5WgO9jz7SHaSMNO5AHNUlu:2dnnvBdRgeLr4qA7vOtOvO9d7
                                                                    MD5:FEB3B5BA422B59B8A92EF532D677309A
                                                                    SHA1:6EDF0E1B01BBDBAD2F708BB74AB92AA2AF098402
                                                                    SHA-256:9539DC21D8BDECF0F9E1C8706C4E2B0ACD44AC5B0779E4C44BD6B103CDA59E01
                                                                    SHA-512:6B21784908B666EC59DD73E112EA34A6ABC5C3067F2C9969A1064976BCB4AF24E680AE9AAFBEFC957554855EB185F5E4FE3D7CE4C721FBB07961A6541A612051
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10932" V="0" DC="SM" EN="Office.Outlook.Desktop.OneDriveTransportGetPersonalUploadLocationFromServer" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bgmo2" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="TransportResult" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="Result">.. <S T="1" F="TransportResult" />.. </C>.. <C T="U32" I="1" O="false" N="CountForResult">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):682
                                                                    Entropy (8bit):5.012009004579065
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdyVzjF6dRDDHwpatEerWc1NQzDI7WgOSfQS5WgO9jz7SHaSMNO5AHNUlu:2dyn6dRgeLrLqA7vOtOvO9d7
                                                                    MD5:AFAEC3D4F55AE7E3E9CC569DF5A3009F
                                                                    SHA1:EEE729FBAFD64A69F4284FCE448E819403FF660B
                                                                    SHA-256:02FB26A6532D9AA632653E37FC6507397212917E8ED5BCEE17124CAE65CBCF0F
                                                                    SHA-512:BFC15FD1BAC47DCB432851E5CEC27194A3E51E4BE357D6C9AD8104C90FE22E4491F0F15E246740A2576448CF4DEB7B98F86C78AA07A801DFBC1415ABA2A5E853
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10933" V="0" DC="SM" EN="Office.Outlook.Desktop.OneDriveTransportGetDigest" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bgmo1" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="TransportResult" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="Result">.. <S T="1" F="TransportResult" />.. </C>.. <C T="U32" I="1" O="false" N="CountForResult">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):681
                                                                    Entropy (8bit):5.029278739629518
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdR+4VzjwrHeKdRDDHwpatEerGerGfcoNBnAlFVHOHaSMjzWVHOHhSMNOAdHNN:2dZWr+KdRgeLrZrcvoLIWr
                                                                    MD5:AE9C4FC5FA46E0BC1F3E71C9DDD3FD57
                                                                    SHA1:ECAEE9C32A1DD7C150B969A83269C16C5ED66905
                                                                    SHA-256:BFA91C40C0B32B93B1D3AF459881F21B19D72A9D73EE9A5E71FB36F7E3B16371
                                                                    SHA-512:6CE41E75831C3A4882E59CA8538923C648C8EBEFA8C63F20C97B9600EFB5AF6F3D7F057AE173469440B0F0AAEA841B3277D60CD470771A895357AD78B4602F3E
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10934" V="0" DC="SM" EN="Office.Outlook.Desktop.OneDriveTransportMruItems" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bjaja" />.. <UTS T="2" Id="bjajb" />.. <TI T="3" I="Daily" />.. <A T="4" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="CountOfHavingMruItems">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="CountOfNotHavingMruItems">.. <C>.. <S T="2" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="4" />.. </T>.. <ST>.. <S T="1" />.. <S T="2" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):593
                                                                    Entropy (8bit):5.261598261749258
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdkVzjHRvoadRDDHwpatEPHXFJico2ADUsSHaSMNOA/HNUlu:2dkHQadRgeSvSS87
                                                                    MD5:F5BAAB5AA4B1B25CBAB3BB44CA5F6B3D
                                                                    SHA1:05613FDA1A874B5495357EE2B4F2DEE1D9C2B809
                                                                    SHA-256:4BAAEDC67B47B9B4ABAD921BB637A263722E8E37C406B9AAD88C3E30CBCE0D4F
                                                                    SHA-512:497D2D96164225CCD77CF1843C867E4AF1F7D4DAFEC33B7890216E91C76CD6949BA9E3234AD4140619226EE206C32714C27034C638BA6C4FD464051F01C0F64A
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10935" V="0" DC="SM" EN="Office.Outlook.Desktop.Rule.Olk.WebExtensions.BigWebExtPaddingError" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="8221" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <C T="U32" I="0" O="false" N="CountBigWebExtPaddingError">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):551
                                                                    Entropy (8bit):5.183233007684959
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdoVzjYdddRDDHwpatEerbXFJico2AEOdQfHaSMNO5AHNUlu:2doWdRgeLrTvSatM7
                                                                    MD5:20B506C4E954324503FC29A917134690
                                                                    SHA1:11C22010AB256A96E145C879D85261AB50AE80D0
                                                                    SHA-256:69D015A975443A6CECCF863EA9FF6ECA053D463F8F94FF288C61C381071DFC33
                                                                    SHA-512:2DDD90CFFFDB5574D719599143E8F0FD5147F66847BC3AA224E76F6B0333F2E6923C1814B7D65899FBFE5625C6583635FEDBC490C109988D631618A0D0786321
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10940" V="0" DC="SM" EN="Office.Outlook.Desktop.PeopleSearchErrorUsingZeroInput" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bjynx" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <C T="U32" I="0" O="false" N="CountOfPeopleSearchErrorUsingZeroInput">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):797
                                                                    Entropy (8bit):4.692658451750095
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdZyfencgDCW8/HXu+RQpxb8OKX/c//fpONkMNOjsu:2dzc7Pr+
                                                                    MD5:31DB8902BB579E102BA2A2D3E9669F9B
                                                                    SHA1:3324ED8C0845F3616CB10A112ACF1E4E73B6ADF7
                                                                    SHA-256:A65B6C352BF9DE871B18C26BF7D58780A31CA918E368E46637C73B06E69BDF1B
                                                                    SHA-512:72E4EAF7CF9B6C06CA81AA7BB236728425D4D7B37057F4B016C4AAE2DA6C8C7F8AE662D4A43DBF8E39377B10CC3A6FCC610BFB535960C03BC58B6EE76C503D6D
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10941" V="1" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="3783" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="2" E="3784" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. </S>.. <G>.. <S T="1">.. <F N="Function" />.. </S>.. <S T="2">.. <F N="FunctionName" />.. </S>.. </G>.. <C T="W" I="0" O="false">.. <S T="2" F="FunctionName" />.. </C>.. <C T="I64" I="1" O="false">.. <S T="2" F="HRESULT" />.. </C>.. <C T="U32" I="2" O="false">.. <U T="100nsToMs">.. <O T="SUB">.. <L>.. <S T="2" F="TimeStamp100ns" />.. </L>.. <R>.. <S T="1" F="TimeStamp100ns" />.. </R>.. </O>.. </U>.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1560
                                                                    Entropy (8bit):4.215153378750664
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dtHB8wwdRge/lvS8TprwOAasuq82jR2j:cthJoRge9vS8ThJ7
                                                                    MD5:934E257FFE05CB5103C449217187FDD3
                                                                    SHA1:B0B2DD907B04919736B2D2898B92838653210CCB
                                                                    SHA-256:913DAF004FFB2CFC4D90443C8EBC67E82FA87B37F55D151D7DBF58E4DE373704
                                                                    SHA-512:459A822D7249B1A8CB0107818F625A4BE6A756B2C26429DE82B74E27F3003C251008A3C128849AE9E8E95D4589B0FF3087C93FA6466A0A68BE310483F5BBA1DE
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10942" V="1" DC="SM" EN="Office.Outlook.Desktop.DiagnosticsSystemFileCollectionSuccessPerfRule" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSP" xmlns="">.. <S>.. <R T="1" R="10941" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <V V="0" T="I64" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="AND">.. <L>.. <O T="NE">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <V V="0" T="I64" />.. </R>.. </O>.. </L>.. <R>.. <O T="NE">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <V V="-2147024846" T="I64" />.. </R>.. </O>.. </R>.. </O>.. </F>.. </S>.. <G>
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1212
                                                                    Entropy (8bit):4.373047821440982
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd8guVzjlksBdRDDHwpatEi0uOXFJicoN+kXlOpleFOH/M//A5eNX/c//pleF2:2dBu8sBdRge8lvS8vasuq/Dr
                                                                    MD5:7817DBC828FBF11F91AE65B293F4F620
                                                                    SHA1:7F57406F0C8C88082F1934B6B9547C739A9A4386
                                                                    SHA-256:4B579D67D4E5152B6E465584C2F5061E91C47E58F57269C53C52AF8332FFAE84
                                                                    SHA-512:508E0DD57AD455F0EAB7601D5D5BE0C9747DB8D86C8EF48182D04B620D714A42E0DCB7265BFF9897A7A40C2D3E541F5C8F8D17AE51AF140231E8EB971F9D415D
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10943" V="3" DC="SM" EN="Office.Outlook.Desktop.DiagnosticsSystemFileCollectionFailureHRESULTRule" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="10941" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="AND">.. <L>.. <O T="NE">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <V V="0" T="I64" />.. </R>.. </O>.. </L>.. <R>.. <O T="NE">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <V V="-2147024846" T="I64" />.. </R>.. </O>.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="4">.. <F N="0" />.. <F N="1" />.. </S>.. </G>.. <C T="W" I="0" O="true" N="FunctionName">.. <S T="4" F="0" />.. </C>.. <C T="I64" I="1
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):829
                                                                    Entropy (8bit):5.113178696233751
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd8VzjlJedRDDHwpatElbnXFJicouDb/d+O/fAtfGd+xGpr6TSHaSMNOAjsu:2d88dRge2bXvSO/UvtOUhn
                                                                    MD5:C0163A9EA76FC3401B84CB59EE04C19A
                                                                    SHA1:40D5779D9ECFD0961D15CAC4DBE60DAFBCAA026D
                                                                    SHA-256:C9416F422C2EED02EAF3C48BA1C0F2D5EEF4FA0A97036914F93C79C297374791
                                                                    SHA-512:F18A0AFF20B26003A8D06F36BCB2724F471F4E0589A430DACA3FD6059EDE8B54D3FED3A47C1934E970388456C71A6B4D296B215D07877D354AF9D7427B509449
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10944" V="0" DC="SM" EN="Office.Outlook.Desktop.DiagnosticsSystemFileUploadSuccessFailureRule" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3780" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="FileUploadType" />.. <F N="ResultStatus" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="FileType">.. <S T="1" F="FileUploadType" />.. </C>.. <C T="U32" I="1" O="false" N="ResultStatus">.. <S T="1" F="ResultStatus" />.. </C>.. <C T="U16" I="2" O="false" N="CountPerHResult">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):793
                                                                    Entropy (8bit):5.111349636543579
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdsjVzjd+dRDDHwpatEH6Hc1NQzD0MPtfQo/vAswcSZp6dYSHaSMNO5csu:2duX+dRgeCVqz3HBYh
                                                                    MD5:B7843CBD337E7BA7F8F819F6A5BE893C
                                                                    SHA1:B96F55A81666F29B1EDF042211420A141AAD1C87
                                                                    SHA-256:5B9DE00DB52D4D8719A7F8A91C5466C9172C58C15805A1F97512B9BB39B24860
                                                                    SHA-512:70BDB7031272DE194317C67EBD58E77C5CFF159E0FF406980622C7F2568E8F57DAC27CE3208868A8CA2DC6D141BB9A531604449A5943AAD1986E2701B7D80A5E
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10946" V="0" DC="SM" EN="Office.Outlook.Desktop.GroupsActionResult" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="18050" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="HRESULT" />.. <F N="GroupAction" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="GroupAction">.. <S T="1" F="GroupAction" />.. </C>.. <C T="I32" I="1" O="false" N="HResult">.. <S T="1" F="HRESULT" />.. </C>.. <C T="U32" I="2" O="false" N="CountGroupsActionResult">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1670
                                                                    Entropy (8bit):4.499108503976622
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdpf32GeOSU6HGHUFHAHMH5liFHZIffONf0n+8ujOaNesAtH/M//k5eNX/c//V:2dxvLXeirpDtKqTtKw6ZK+ZFz
                                                                    MD5:46EBC33C0B8AD7289C0955D12CB3069C
                                                                    SHA1:BFBC76BC956AF42B10277AFAF53E2E81B1A30C29
                                                                    SHA-256:9A797CA2D656CCC23A86C1C766A846DB4F3D7445A7E545615836502C4EDF7735
                                                                    SHA-512:6C3B2650E73B698510062AC23603B99B9AB1E1DF49E571DDD0C9D98F63ED5D732CD07DDAE905B4EEFB2F04B28B475AD2D978F85CDF3C9D63DC6C81DD1920BF1E
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10947" V="0" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="3117" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="2" E="18050" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="3" E="18030" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="4" E="18000" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="5" E="3726" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="6" E="19001" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="7" E="19002" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <US T="8">.. <S T="3" />.. <S T="4" />.. <S T="5" />.. <S T="6" />.. <S T="7" />.. </US>.. <F T="9">.. <O T="OR">.. <L>.. <O T="EQ">.. <L>.. <S T="2" F="GroupAction" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </L>.. <R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):959
                                                                    Entropy (8bit):4.860146495849858
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdfYVzj/dRDDHwpatEi03c1NQzDyLg5/bXoXBynjONxtfcSOVo/1N1DUgXHaSk:2dfY9dRge8GqTjoA6T1Yg07
                                                                    MD5:E3CFF4B2AD5A5D56CF16B8408472EE03
                                                                    SHA1:A97BE5A11111946DF52664DB5AF8817D849D0CAE
                                                                    SHA-256:E6947546E0286D8799466ECA739DA4D861A5B6DFEF83D011E6C3ED863F62B142
                                                                    SHA-512:B03B03BE1339197C7166FE563A8877B6D9E72B95335434062FE4241B08F2B69D5EE068FAFDA9D082D85AC62F2FF3F26271718D13EE1B93C782382FA3E4445D86
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10948" V="0" DC="SM" EN="Office.Outlook.Desktop.GroupsNavigateToNonjoined" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="10947" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="0" />.. <F N="1" />.. <F N="2" />.. <F N="3" />.. </S>.. </G>.. <C T="I32" I="0" O="false" N="EntryPoint">.. <S T="1" F="0" />.. </C>.. <C T="B" I="1" O="false" N="NonjoinedGroupCreated">.. <S T="1" F="1" />.. </C>.. <C T="I32" I="2" O="false" N="HResult">.. <S T="1" F="2" />.. </C>.. <C T="U32" I="3" O="false" N="GroupAction">.. <S T="1" F="3" />.. </C>.. <C T="U32" I="4" O="false" N="NavigateToNonjoinedCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):694
                                                                    Entropy (8bit):5.042230748420477
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdGYVzjZpPdRDDHwpatlerVer/coNBnAov3gHaSMjoLHhSMNOAdHNS7lu:2dF9PdRgeQrArLvNYfr
                                                                    MD5:FC81BC677F5DB285B3D7C1BC9D8FAAE9
                                                                    SHA1:366A4F8A0756523D817A39B9946D3CDCDC2BB7DC
                                                                    SHA-256:AED314B6CCA9865E7FFC9681C2BE374E3DB61F1B3C9A5EC9F2298B911981A7EB
                                                                    SHA-512:64D429F872173C46EC2001BAE253BAC6841EDF5B299BD694BD385C334E455B86CE4D358EFAB78ED98C243DF586F66179B68FA2A2AC13D0C9B44C9E5B47EEE534
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10949" V="0" DC="SM" EN="Office.Outlook.Desktop.OneDriveTransportMissingMruItemInformation" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSP" xmlns="">.. <S>.. <UTS T="1" Id="bjai7" />.. <UTS T="2" Id="bjai8" />.. <TI T="3" I="Daily" />.. <A T="4" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="CountMissingFilePath">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="CountMissingTimeStamp">.. <C>.. <S T="2" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="4" />.. </T>.. <ST>.. <S T="1" />.. <S T="2" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):8195
                                                                    Entropy (8bit):4.2929142187390035
                                                                    Encrypted:false
                                                                    SSDEEP:96:ZlRgeUvdfiZm2Ovrxk6YHXj+PpFQmKfzB8N4ZtD1vPCczNlAZ:XDkcytszPbzNlAZ
                                                                    MD5:BAF641B9B63941B3F96C99BD4A2423FD
                                                                    SHA1:F925E3A3E0FF6A906D2E773539BE93025A6883D1
                                                                    SHA-256:2C06DC5B4079E454F5B306E1207447E3901C378BC3A795B7A5132D202AA3309C
                                                                    SHA-512:344CE2775D17BCD42A2BADEED3934B44A83E33866E5CACC34C264FCC112A481185D844F10CBD7942C4371A697F2F313BBE8B979A0B53634C3E062F192D7BE732
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10952" V="1" DC="SM" EN="Office.Outlook.Desktop.ContactCardHealth" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <UTS T="3" Id="blelm" />.. <UTS T="4" Id="bleln" />.. <UTS T="5" Id="blelo" />.. <UTS T="6" Id="blelp" />.. <UTS T="7" Id="blelu" />.. <UTS T="8" Id="blelv" />.. <UTS T="9" Id="blelw" />.. <F T="10">.. <O T="EQ">.. <L>.. <S T="3" F="ValidPersona" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. <F T="11">.. <O T="EQ">.. <L>.. <S T="3" F="ValidManager" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. <F T="12">.. <O T="EQ">.. <L>.. <S T="4" F="ValidPersona" />.. </L>.. <R>.. <V V="fals
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):908
                                                                    Entropy (8bit):4.828833887989631
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdSVzjqdRDDHwpatEerLvXFJicoN+kXqNObX/c//RpON+WX8fWD8fbbpyMSIQl:2dSIdRgeLrLvS8ToWCt
                                                                    MD5:28C43C4D594BE12A1FF9A9C398BB2C9A
                                                                    SHA1:15B9FC017F3B34BDE6031DE15EF13C5F9217B96D
                                                                    SHA-256:20D07A2C04BB1CAAF99EA9B654CE309A478C4CEAE5ECA928258EA86D02FB1DF0
                                                                    SHA-512:C1755AA647CE28BE61BEC1057F501CBACB1236CDD1362756A7D9AE84B1A23196BF9D39AB8A142C8F6D273BD51AB734B6E424EAB4CD159F8E111D6DD596305FC3
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10955" V="0" DC="SM" EN="Office.Outlook.Desktop.RecipientAutoCompleteZeroInputSelection" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="ber0h" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="Length" />.. </L>.. <R>.. <V V="0" T="I32" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="4">.. <F N="Index" />.. </S>.. <S T="1">.. <F N="Index" />.. </S>.. </G>.. <C T="I32" I="0" O="false" N="SelectedIndexResult">.. <S T="1" F="Index" />.. </C>.. <C T="U32" I="1" O="false" N="CountOfRecipientAutoCompleteZeroInputSelection">.. <C>.. <S T="4" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1061
                                                                    Entropy (8bit):4.9087672588253195
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdZaVzjwbRH+dRDDHwpatCzE+q3iFiGsrf7PNWTff/0//4fhmMdO/SwfcSuHlG:2dZaMh+dRgehdzPSBOO5RPnA1J
                                                                    MD5:AFECB76211EEE08FBEDFABC2C76DFD95
                                                                    SHA1:E9C62DA6519DFF690A002E763658B8E95C70A16D
                                                                    SHA-256:59831A155747F1025D1AF8C30D9905CDD2CA542BD6D9D1F8C76AEE2E453C4FDE
                                                                    SHA-512:688EF61638A554C558453B2A46C789AA28004E6343074F0B28B73B6EE0F7A0405BBADCBC7C7E971A4595713BAB28E0E23E042BD818337558CE10880664F151DF
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10956" V="1" DC="SM" EN="Office.Outlook.Desktop.AccountConfiguration.FunctionResults.Global" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" E="false" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="407" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <R T="2" R="10956" />.. <R T="3" R="11010" />.. </S>.. <C T="U32" I="0" O="false" N="AccountConfigType">.. <O T="COALESCE">.. <L>.. <S T="3" F="0" />.. </L>.. <R>.. <S T="2" F="0" />.. </R>.. </O>.. </C>.. <C T="W" I="1" O="false" N="Function">.. <S T="1" F="Function" />.. </C>.. <C T="I64" I="2" O="false" N="HResult">.. <S T="1" F="hrReturn" />.. </C>.. <C T="U32" I="3" O="false" N="AccountStartThreadId">.. <O T="COALESCE">.. <L>.. <S T="3" F="1" />.. </L>.. <R>.. <S T="2" F="3" />.. </R>.. </O>.. </C>.. <C T="U32" I="4" O="false" N="ThreadId">.. <S T="1" F=
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1668
                                                                    Entropy (8bit):4.588149256087889
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dguAdRgeOqJTojqwOaoiAJ7jquYjESEKE9AEC7:c54RgeOqJTKqQKJvqu6FXMAh7
                                                                    MD5:6C57EF83269ACAB356662A22F54ECEAA
                                                                    SHA1:EFAAE40303A2EA677C4D81A3E62291EB430D71DD
                                                                    SHA-256:041674DBFF75C382EBBBABFF8B0EFC946258440A38C638EF24ABA184BEEB1B82
                                                                    SHA-512:A1583A309D80170F668B9E375DCBAFA0222E8542D25B94F12FCBDAE2B382F25D292DE21DE9E3465387E23A97E30BBC30594FE3F2EEF12FED8AB3E6A504FA7346
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10957" V="1" DC="SM" EN="Office.Outlook.Desktop.RopResponse.AuxBufferExceptionInfo" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="4204" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="fEmptyExceptionInfo" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="fEmptyExceptionInfo" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="4" F="fExistingExceptionInfo" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1269
                                                                    Entropy (8bit):4.105362142610501
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdKfTq3jTq3bq3UqtUWLPNmxNP/k//oNx2Nf/0//LPNmbPN2CN//U//fNBGNPj:2dbT2unRPS8cPIP9vsPCR
                                                                    MD5:B73C15A2BFBFB5DB3C2574B4A481D803
                                                                    SHA1:82AF9ED18F557EB45AA7F7A532DB2DB3664D0C84
                                                                    SHA-256:21D7A9375AF4D1E338C6CBA9A4770B4F8B62C323100374CF46A3D336EEA77EA6
                                                                    SHA-512:E1DCD944CB06FF254E6D525D76DC259A2ADAC25E66C7B23E8B3EA393426180757F145786CB99FFCC7772B5D00738D7EEA3943A19BE9F4B604D6183C293E05E06
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10958" V="1" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="307" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="2" E="308" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="3" E="309" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="4" E="310" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. </S>.. <C T="U64" I="0" O="false">.. <O T="SUB">.. <L>.. <O T="COALESCE">.. <L>.. <S T="3" F="TickCount" />.. </L>.. <R>.. <S T="2" F="TickCount" />.. </R>.. </O>.. </L>.. <R>.. <O T="COALESCE">.. <L>.. <O T="COALESCE">.. <L>.. <S T="4" F="TickCount" />.. </L>.. <R>.. <S T="1" F="TickCount" />.. </R>.. </O>.. </L>.. <R>.. <O T="COALESCE">.. <L>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):498
                                                                    Entropy (8bit):4.803488958944331
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdufTq3eqt7PNW4Nf/0///NhmMNOSjsu:2d/dZP7S
                                                                    MD5:D62680C9D72B6C803ACF4D8E2EF9ED1E
                                                                    SHA1:6B17DA714AAE5E035FE1F45804118CD0F6C074EC
                                                                    SHA-256:D9F69753C214A2662AA38D0AB0E61AEFA8F0D8A02428ADE1CEF70D50976CFF64
                                                                    SHA-512:FFD328AE1120FBE976499000266811B6745B9974181DEA393BC1CF65A2B22D0CAFF236AF3AC04D6867C40A49039A04A6F88A51B6E097A00269FCCA9DAB8AF30D
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10959" V="0" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="307" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="2" E="310" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. </S>.. <C T="U64" I="0" O="false">.. <O T="COALESCE">.. <L>.. <S T="2" F="TickCount" />.. </L>.. <R>.. <S T="1" F="TickCount" />.. </R>.. </O>.. </C>.. <T>.. <S T="1" />.. <S T="2" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1121
                                                                    Entropy (8bit):4.1972326312380295
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdtfgq3jTq3bq3iYiwOUW/Nf/0//LPNmbPN2qf//U//ROBGNP/k//vNx2NhmMY:2dlT2uOcPIPZeSPZzR
                                                                    MD5:549545BBB01FF07EB1512913AC93BA5C
                                                                    SHA1:3FD69194EF21A2F97C06683288D54CF84671AD9D
                                                                    SHA-256:519375F0EA1E7C6333CA816C1EA73821EB5C24BC13448BCD88434FBBE3839E70
                                                                    SHA-512:189AB9C7F3851A609E03BE45B2D3B1029F6AF83D650A9BB57367508BBAA2C8C483FA1B07F48C63E1F1E23A25F561F01C3648B2CDB26BA3EFD975C76ED4983E15
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10960" V="1" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="302" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="2" E="308" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="3" E="309" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <R T="4" R="10959" />.. <R T="5" R="10960" />.. </S>.. <C T="U64" I="0" O="false">.. <O T="SUB">.. <L>.. <S T="1" F="TickCount" />.. </L>.. <R>.. <O T="COALESCE">.. <L>.. <O T="COALESCE">.. <L>.. <S T="4" F="0" />.. </L>.. <R>.. <S T="5" F="1" />.. </R>.. </O>.. </L>.. <R>.. <S T="1" F="TickCount" />.. </R>.. </O>.. </R>.. </O>.. </C>.. <C T="U64" I="1" O="true">.. <O T="COALESCE">.. <L>.. <S T="4" F="0" />.. </L>.. <R>.. <S T="5" F="1"
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1908
                                                                    Entropy (8bit):4.540049361664802
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dKydRge5skZ2mXLYgHPm+dPVp+HPlHeWcP2CH:cKORge7YDYp6HoH
                                                                    MD5:62694C10D903DAA9E317ED935B691B3A
                                                                    SHA1:1A9C41C711E9BE1231518D5701A23DA3FF077398
                                                                    SHA-256:7C0B3F86D26E0950368C6B2C87F05174A81C71F506C52C73EBC5249AC9891831
                                                                    SHA-512:29196642CD3747014EE3599B37746C49993C9F6CB26B20671F37F102F4FBB5AEE4932918F552F25C96FA2A86E0770CE8267AB3769C3DB229B76F4F3EFC611821
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10961" V="1" DC="SM" EN="Office.Outlook.Desktop.HangReportingStatistics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="301" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="2" E="302" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="3" E="307" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="4" E="308" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="5" E="310" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <R T="6" R="10958" />.. <R T="7" R="10960" />.. <A T="8" E="TelemetryShutdown" />.. <TI T="9" I="Daily" />.. </S>.. <C T="U32" I="0" O="false" N="HangCount">.. <C>.. <S T="2" />.. </C>.. </C>.. <C T="U64" I="1" O="false" N="AverageHang">.. <O T="COALESCE">.. <L>.. <A T="AVG">.. <S T="2" F="Duration" />.. </A>.. </L>.. <R>.. <V V="0" T="U64" />
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1261
                                                                    Entropy (8bit):4.941047325928528
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdaq4VzjqdRDDHwpatEnq3jTq3Qicih2uDxXyZ+XHaSMMdNscDOXt/scifX4DZ:2dajUdRge3T2gJAbHDyFiAl7DHLI7ir7
                                                                    MD5:2E7B2C1598860EF32C2D722FB7DA346A
                                                                    SHA1:FAF499599CD64D550E9EC82B99DCA45B16330722
                                                                    SHA-256:0A0F9203B760E0FDBA8E1237279F1DC4F5448D0356BC5341931736222C106841
                                                                    SHA-512:3EBC0B871A4118596AB727DE62554502F5FD97123A64A05D9D06B60A14751AF1067A49C08150D188D767C9B5A554468DE03982C0C165081BF3015971BA87DA6D
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10962" V="0" DC="SM" EN="Office.Outlook.Desktop.HangReportingScopes" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="303" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="2" E="308" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <A T="3" E="TelemetryShutdown" />.. <TI T="4" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="ScopeId" />.. </S>.. </G>.. <C T="W" I="0" O="false" N="ScopeId">.. <S T="1" F="ScopeId" />.. </C>.. <C T="U32" I="1" O="false" N="ScopeCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U64" I="2" O="false" N="AverageHang">.. <A T="AVG">.. <S T="1" F="ElapsedHanging" />.. </A>.. </C>.. <C T="U64" I="3" O="false" N="AverageDuration">.. <A T="AVG">.. <S T="1" F="ElapsedTotal" />.. </A>.. </C>.. <C T="U64" I="4" O="false" N="TotalHang">.. <A T="SUM">.. <S T="1" F="Ela
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):543
                                                                    Entropy (8bit):4.743442176023748
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdKq9pWerl+tNqNOIXX/c//R2hapONU5sMNOcsu:2dDprkt4VHS2hDG
                                                                    MD5:AF1D8BCDDDE9B560EE4BBDF9125B9E62
                                                                    SHA1:676DFC27A5D62E3B235DE4756D4C7DE6D883D448
                                                                    SHA-256:84A53F64BE3FF339B84EFBFE586D44B98BC942A2A97BB008A8C1138A7907136F
                                                                    SHA-512:7EC84362FCD477E1A1FD026DC8F8D9E1FDB6FDEEB0783D9B9C35AE1C09FDCA01F8CFD5635C7DAD56E8506130EFE4BE73AA6DB78BC55101AF38CFD58C10DE6910
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10964" V="0" DC="SM" T="Subrule" S="1" DCa="PSP" xmlns="">.. <S>.. <SS T="1" G="{56e6a7c9-845f-48bc-9098-50c70719d01b}" />.. <UTS T="2" Id="a4pqn" />.. <F T="3">.. <O T="EQ">.. <L>.. <S T="2" F="providerId" />.. </L>.. <R>.. <V V="{56e6a7c9-845f-48bc-9098-50c70719d01b}" T="G" />.. </R>.. </O>.. </F>.. </S>.. <C T="B" I="0" O="false">.. <S T="1" F="HangReportingEnabled" />.. </C>.. <T>.. <S T="3" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):538
                                                                    Entropy (8bit):5.196338237033586
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdIVzjR6dRDDHwpatEf4Hc1NQnb+drNO5AHNUlu:2dIOdRgeUqM7
                                                                    MD5:C59CCF2C743F650F270989ED47B760F4
                                                                    SHA1:776AE64F2E4239307085C6E0A29AFE3C380DE06B
                                                                    SHA-256:9CACDE110DCDBF4635FD4D92739579B283472C59E9F96A5381C092739EF2A0F1
                                                                    SHA-512:E7EAED238921177B3038E38CFDB0ABF106ED6A58FA7791431867D88BB78DC531BF24115F34665164FB5904EC982CC0CBD8D41EF03DAD5775BC4F5839092EDEEF
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10966" V="0" DC="SM" EN="Office.Outlook.Desktop.ModernViewUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="13008" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="CurrentView">.. <S T="1" F="View" />.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1846
                                                                    Entropy (8bit):4.988317676855807
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdWVzjdT6dRDDHwpatEMH6HVDaHCHUHiHIHaHGic4kP+IICKtZSHaSMpVFaSHJ:2dWydRgeiWqm0dtfFglj1Z+uhY37
                                                                    MD5:4F40AC7E2BECE07E4A8107F274EB2797
                                                                    SHA1:582CB7F52A559B1F22CAF1D3A9D62A02A55D3D1B
                                                                    SHA-256:65DE72DD6AF39DC1F60D7B4340104E33F02EC4A50C26A7D6D5DE998E3E9CBBAD
                                                                    SHA-512:765E50B29DE113EAA0041589FCF7B8AD3FCB4FC651AB8281EA0FE850A964863842D221B940DA1367DD1F881320319AE8674FF0CA9E36FB1C2D393F42CAB6CC3C
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10968" V="0" DC="SM" EN="Office.Outlook.Desktop.SortGridAccessibilityUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="15002" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="15003" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="3" E="15004" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="4" E="15005" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="5" E="15006" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="6" E="15007" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="7" E="15008" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="8" E="15009" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="9" E="TelemetryShutdown" />.. <TI T="10" I="Daily" />.. </S>.. <C T="B" I="0" O="false" N="IsUiaProvider">.. <S T="1" F="IsUiaProvider" />.. </C>.. <C T="U32" I="1" O="fals
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):576
                                                                    Entropy (8bit):5.242594598324056
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd7VzjrtdRDDHwpatEf4HXFJiiy2zUADy0JZrNOjsu:2d7dtdRgedvkb6G
                                                                    MD5:21325FB2539337FF04F049FB3A7EA5AB
                                                                    SHA1:210CE013EB54FD35C9DC75BBD76C023C1F6FD976
                                                                    SHA-256:3BF44159C54A87FD502C2305403B7F35D4D0BA20662D595EE649B1F8924367D8
                                                                    SHA-512:2D825295F59069266A4B0EB1655B2639AAC990433EECBAA6DCB8F33EFD324CA04FBBBB3071512E9F31EC45F657829F8A4CCF183C62867B69ABFC8D6ED7124CED
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10969" V="0" DC="SM" EN="Office.Outlook.Desktop.ModernViewStartupVsShutdown" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="13008" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. <R T="3" R="10970" />.. </S>.. <C T="U32" I="0" O="true" N="StartupView">.. <S T="3" F="0" />.. </C>.. <C T="U32" I="1" O="false" N="ShutdownView">.. <S T="1" F="View" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):390
                                                                    Entropy (8bit):4.9196546795863405
                                                                    Encrypted:false
                                                                    SSDEEP:6:TMVBd7d+HfflqIyuUXF5XQMfSFJe/h9Jrg7sSBxNOcsby:TMHdp+Hff4HXFJQMfSPOhzPSrNOcsu
                                                                    MD5:5FDC1D1EC6C8308332F7BAF6C7748D5E
                                                                    SHA1:9AB9E34AAAB2E44FBAE87FF631025A3A7409BEEB
                                                                    SHA-256:7AEA3B8FD68659B076640A192B7D689601F38708A6723CF85CD27E04381EA72D
                                                                    SHA-512:84EE9DE2B029BCAA2E8C5C60DA6BB321AC3246B19304AF463B0B1EAD68320C2D1DC591C3C082B68E5532A4D8CA25D310583E300D4ACC40BFEA5A6E01B874A0A5
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10970" V="1" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="13008" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryStartup" />.. <TO T="3" I="30s">.. <S T="2" />.. </TO>.. </S>.. <C T="U32" I="0" O="falseNoError">.. <S T="1" F="View" />.. </C>.. <T>.. <S T="3" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1234
                                                                    Entropy (8bit):5.013255461969232
                                                                    Encrypted:false
                                                                    SSDEEP:24:2daSPxsdRgeMrroWrn3e2qYdrZxrvq+p+npfM:caS+RgeskWbRq0rZxrvqfi
                                                                    MD5:E379D33C062F012EB59117BC83E3B0A1
                                                                    SHA1:A0426E8F4F2B71C2103F00FB0231FA24D48D4AFC
                                                                    SHA-256:74C26DB64DBA38DA36894449693F81D12EFBDE50C556672EE4BF074016077FF2
                                                                    SHA-512:8F598B19926788C9C29105AA1B1A8A2897124A4E9887C85B22634F0D176AF8BB4A122C49F6BA83D237407BE9183BB95B79006AF555BD0E4D59D33D2E5A9EC734
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10973" V="1" DC="SM" EN="Office.Outlook.Desktop.EditGroupActionData" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="50" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bp2a5" />.. <UTS T="2" Id="bp2a7" />.. </S>.. <G>.. <S T="1">.. <F N="UniqueID" />.. </S>.. <S T="2">.. <F N="UniqueID" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="ActionResult">.. <S T="2" F="ActionResult" />.. </C>.. <C T="B" I="1" O="true" N="AccessTypeChange">.. <S T="1" F="AccessTypeChange" />.. </C>.. <C T="B" I="2" O="true" N="NameChange">.. <S T="1" F="NameChange" />.. </C>.. <C T="B" I="3" O="true" N="DescriptionChange">.. <S T="1" F="DescriptionChange" />.. </C>.. <C T="B" I="4" O="true" N="AutoSubscribeChange">.. <S T="1" F="AutoSubscribeChange" />.. </C>.. <C T="B" I="5" O="true" N="LanguageChange">.. <S T="1" F="LanguageChange" />.. </C>.. <C T="B" I="6" O="true"
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1212
                                                                    Entropy (8bit):4.416511931086647
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dt4AaPdRgeOLrtevS8TRDIwOPDBkZODi7:ct4AalRgeSBevS8TRkxYYi7
                                                                    MD5:5C9485637D1C6201B46F2D25715BEF33
                                                                    SHA1:B64AC64955D30E99CDDD2D55237606191BE429EF
                                                                    SHA-256:D74B3215355CF7B4DA70AC52202CA8D00714168A1B4F35A4452B6CA449F0C97C
                                                                    SHA-512:A882AFD77CCE68DBB5AE6E182454E646AA1B7B681EEA7352C8EE61184C3A242D46E1C74969FA6FA1C3B387FF13944C237CE2B4E0099137BB150F62F12FC2A97B
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10974" V="0" DC="SM" EN="Office.Outlook.Desktop.PeopleViewCirclePhotosHealth" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="7" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bl8vt" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="ErrorCode" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="NE">.. <L>.. <S T="1" F="ErrorCode" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <TH T="6">.. <O T="GE">.. <L>.. <C>.. <S T="1" />.. </C>.. </L>.. <R>.. <V V="1000" T="U32" />.. </R>.. </O>.. </TH>.. </S>.. <C T="U32" I="0" O="false" N="PeopleViewSuccessCount">.. <C>.. <S T="4" />.. </C>.. </
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):2021
                                                                    Entropy (8bit):4.670695306961675
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dksdRgesszsLYFwOaY38tGgFJY38tGlluY38tG5Uk3Lu3+402Zft29X1u27B:ck8RgePALYFQY387JY38CluY38SWglz
                                                                    MD5:17FBFA4082399BF1C55C5B4F5F83AC0F
                                                                    SHA1:0DF5C3B0A2922A10F71AA32DBA7E96D1DFF40292
                                                                    SHA-256:EA8D22743DF3EFB6AFC7F597FDF2573FEB63902DD3B9EBA2300D5CC1D383D61F
                                                                    SHA-512:687A749B210E7C3D4DAF72D54D172F09C96036C05A080CAB88C5CE85C33FBEAC702D51441C18359D4B89ED72CF341F80693B2BAF2EED046E9B7E47269A4CBCCA
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10980" V="0" DC="SM" EN="Office.Outlook.Desktop.FastServerResponses" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DL="A" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="7089" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <Etw T="2" E="7098" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <A T="3" E="TelemetryShutdown" />.. <TI T="4" I="Hourly" />.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="SearchResultSource" />.. </L>.. <R>.. <V V="2" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="SearchResultSource" />.. </L>.. <R>.. <V V="5" T="U32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="1" F="SearchResultSource" />.. </L>.. <R>.. <V V="6" T="U32" />.. </R>.. </O>.. </F>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):822
                                                                    Entropy (8bit):4.914465399096125
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdfhVzjKedRDDHwpatE+ic1NigiSiwcArYR1HISMjowQdR1HfSMp6M7SHfOSMc:2dZcedRgelfKRXwER9P2
                                                                    MD5:DDC1C972077B4B1841FAEE605C934491
                                                                    SHA1:B8B79CC5F11FA427BBADAE52A247716B933C723A
                                                                    SHA-256:1BFECF65F973188CA994F99A27F16AF381AC70C6B167A27390F5AC90FB4D1886
                                                                    SHA-512:A18012D4F10889F9756DBF1B92DAC01DDBF2AE05F0E0EB4D81B388E5F564E7EFAE3E6BD6D1B53A19E96244106D1CE2DE4FF2CA70120B35E490AA2740B8426BF9
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10984" V="1" DC="SM" EN="Office.Outlook.Desktop.GroupsGuestAccess" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <R T="3" R="10996" />.. <R T="4" R="10997" />.. <R T="5" R="10998" />.. </S>.. <C T="U32" I="0" O="false" N="CountOutllibGuestElementUsed">.. <C>.. <S T="3" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="CountMsoGuestElementUsed">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="CountDetailsWithGuests">.. <C>.. <S T="5" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="1" />.. </T>.. <ST>.. <S T="3" />.. <S T="4" />.. <S T="5" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1230
                                                                    Entropy (8bit):5.204255427328799
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdNMVzjtmBKSzgBdRDDHwpat5CyVvnmFN99/ZdLQ+vyt99lXjlE4S6sDW/Qe2u:2dNMrmBKS8BdRgeZl49JtARNu82O0Ot
                                                                    MD5:876DEC9A45702AB47980543DD1A9C8CB
                                                                    SHA1:5DC72E5F8B91748813942992F221F5C70ED26607
                                                                    SHA-256:19BF089EDA006A1CC3E683E5EB098D0668638B0546DB82BD21AB979DE01D5598
                                                                    SHA-512:D586A0DCB2B62A8A8E7B7C2DA3CC70879E03C02E1DF144C8299762BCA1071FB88E6C4150FDBD964041F62FCB4F9CE74C7A884FC82C1A55C7C39113CD080E0270
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10987" V="1" DC="SM" EN="Office.Outlook.Desktop.DiagnosticSystem.ContactSupportResult" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="1000" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="3774" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="2" E="20731" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="I64" I="0" O="true" N="HelpShiftTicketHRESULT">.. <S T="1" F="HRESULT" />.. </C>.. <C T="W" I="1" O="true" N="SARATicket">.. <S T="1" F="DiagnosticTicket" />.. </C>.. <C T="I32" I="2" O="true" N="SARATicketThreadId">.. <S T="1" F="ThreadId" />.. </C>.. <C T="FT" I="3" O="true" N="SARATicketTriggerTime">.. <S T="1" F="TimeStamp100ns" />.. </C>.. <C T="I64" I="4" O="false" N="ContactSupportHRESULT">.. <S T="2" F="HRESULT" />.. </C>.. <C T="I32" I="5" O="false" N="OpenSupportTicketAttempted">.. <S T="2" F="OpenSupportTicketAttempted" />.. </C>.. <C T="I32"
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1155
                                                                    Entropy (8bit):3.4875646633932904
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdvOFYH+u/jOzeKNuMe/3/8//UJuNH/M//KNuMe/3/8//0YQ4JuN5eNX/c//aS:2dgJuAxev6Dxev/EThe/V5B7
                                                                    MD5:EFE488D2D1E3E69C2A72D907A4806117
                                                                    SHA1:C92CEB7C42179E5ECAAFFE08760497A2CDC1D9A2
                                                                    SHA-256:6A57CBB36D3AA761042EBC67BBFF8EA885483F15C26FC26FE9B98A45F5D77CE2
                                                                    SHA-512:098AD4AF7D5CDF6949BF75F3FFA798348677AC874A0A0388DB9BA67B8742ACD0BAFCFF42FA71A2CC1F65FFA5DB387F66924A9F0727C68447CD724AEF64062A17
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10996" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="19022" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <F T="2">.. <O T="OR">.. <L>.. <O T="OR">.. <L>.. <O T="EQ">.. <L>.. <S T="1" F="Element" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="EQ">.. <L>.. <S T="1" F="Element" />.. </L>.. <R>.. <V V="4" T="U32" />.. </R>.. </O>.. </R>.. </O>.. </L>.. <R>.. <O T="EQ">.. <L>.. <S T="1" F="Element" />.. </L>.. <R>.. <V V="5" T="U32" />.. </R>.. </O>.. </R>.. </O>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1141
                                                                    Entropy (8bit):3.4139933389862867
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdUOercR+u/jOzeKNuHA1YR/3/8//UJuNH/M//KNuHA1YR/3/8//0YQ4JuN5e4:2darcIuAOZRv6DOZRv/ETeZR/VXZRB7
                                                                    MD5:A8D5A8856E3BCE71E0ED8425D6FE9CA8
                                                                    SHA1:42FCB7A625F42240E7258B150DA77216418B4B94
                                                                    SHA-256:69228F60A5A0139D3A061551A3FE6E8678F6DA23F026BFEA93084E06795CCC3B
                                                                    SHA-512:782C2539EA1EB760045CECEC988201B8704A1A280E578C1EE52866268909BD33F7AF90B2432899E439DEBC57AEB5F3CF7074BDD873C9C8AC17E2C2B1111F1C75
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10997" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bl6lt" />.. <F T="2">.. <O T="OR">.. <L>.. <O T="OR">.. <L>.. <O T="EQ">.. <L>.. <S T="1" F="Groups Element" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="EQ">.. <L>.. <S T="1" F="Groups Element" />.. </L>.. <R>.. <V V="4" T="U32" />.. </R>.. </O>.. </R>.. </O>.. </L>.. <R>.. <O T="EQ">.. <L>.. <S T="1" F="Groups Element" />.. </L>.. <R>.. <V V="5" T="U32" />.. </R>.. </O>.. </R>.. </O>.. </F>.. </S>.. <C T
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):508
                                                                    Entropy (8bit):4.493490823496701
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdmYOJ4YX2GeOS+u/xH/OsNX/c//tpONGDpMNO/HNUlu:2daxvL5up27
                                                                    MD5:8F9C0830D5B864110176DE22CB34BC5D
                                                                    SHA1:492FAE6836BD974EEEAF8DEA07E9BA59FA5FEEF4
                                                                    SHA-256:2483197D7CEA4BC24F75E37D255A83D19571BD5499D37CF9253B8F729159DBC4
                                                                    SHA-512:A6D3A9FDA1396AA5AB0908FC5270EE899050114FB08AC6D65661A835E26A2E40B6F445EA3F66BA49B8EB5D3684DEA984ABBCA91C68107EB12B5A64ECAE9A7A31
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="10998" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3250" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <F T="2">.. <O T="GT">.. <L>.. <S T="1" F="GuestCount" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false">.. <S T="2" F="GuestCount" />.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):918
                                                                    Entropy (8bit):5.100535823253302
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdG3VzjBdRDDHwpatEh4HeHDHcih2Nanf2WUHaSMS2RHhSMpt2lwXHISMNO3Xs:2dm7dRgergfQ0Uwa7
                                                                    MD5:20702307608C35156CC3A442FD0F7B9B
                                                                    SHA1:7E36BA9191F75C52AC20DF38544CD9F3DD36FF78
                                                                    SHA-256:86579E04C4A4D45CCD51979B89CC7559A6E5DB81B10A8B902BE9DA1AD544B87C
                                                                    SHA-512:C70A81F3270BC8F74040E382A1B063528371B45A7DE907B0FEB2C3C7F578EB29907931F4F637DD67D9E9CE400624801ADEA015E2622115D4027F8F0F9754A89C
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11000" V="0" DC="SM" EN="Office.Outlook.Desktop.AttachmentsSafeLinks" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="4268" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="4269" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="3" E="4270" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="4" I="Daily" />.. <A T="5" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="SafeLinkRedirectStarted">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="SafeLinkRedirectSuccess">.. <C>.. <S T="2" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="SafeLinkRedirectFailure">.. <C>.. <S T="3" />.. </C>.. </C>.. <T>.. <S T="4" />.. <S T="5" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):2338
                                                                    Entropy (8bit):4.4535493624422315
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9ffcdRgeshOt4hUjqTmIwOambJmgFumBvmfIPWAU1CH1tgh93wEK7NEO7:c9fkRgejt4huqTnQ0Jduyvk1APu3cx7
                                                                    MD5:22D8769EBC75F2485D2AF66C5413B85D
                                                                    SHA1:96C4B0A472902318532FFF4F3C28B134E276B2DF
                                                                    SHA-256:AE6811FC65EC22D7F2E1249505F0445982FBD66EAD7E2753B863B6562ACF3C24
                                                                    SHA-512:671AB0D38F16E8296303DC7CA2BE63851BAABDD0C5914860CE194F5089ECEF3C3BAD8C5012CD6569FB99A73BD3981D9D868026EA701C02CE1BCEC63322955D67
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11002" V="1" DC="SM" EN="Office.Outlook.Desktop.LegacyWizardHelpLaunched" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="436" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="2" E="413" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <F T="3">.. <O T="EQ">.. <L>.. <S T="1" F="LaunchedFromButton" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="WhichPage" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="WhichPage" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="WhichPage" />..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):4459
                                                                    Entropy (8bit):4.365076894108927
                                                                    Encrypted:false
                                                                    SSDEEP:48:celllRgesqvS8T8qQwJequWv+qs2868q/6wfyPqFrI+YqL+gRUHLWQZ7:1lRgevbXNLB5FbzSwf5ZRzUHh7
                                                                    MD5:73D11D66E73EC499924C062567B82DE7
                                                                    SHA1:5D97C6120345EEF2615F352B2D8710A22348ADAF
                                                                    SHA-256:38F29D5056F9FB96430D446C4D7CC07F7B3D76546C728F116101484970C8BCCE
                                                                    SHA-512:C47AA8B3478B3EF2EA816ADE3BD3B9CDE54D55BC73623B484565DB2893989656D1194D12FB8BC18A39143360B571163CC3E7586828AF73B06FE2AD3784869F89
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11008" V="0" DC="SM" EN="Office.Outlook.Desktop.FindPeoplePersonaDataHealth" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bm9b0" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="HasMapiEntryId" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="HasMapiEntryId" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="HasMapiSearchKey" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="1" F="HasMapiSearchKey" />.. </L>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):382
                                                                    Entropy (8bit):4.948563324130314
                                                                    Encrypted:false
                                                                    SSDEEP:6:TMVBd7M68fXpHoN9I/sJrL/ANrwxnJUq+/dxNOn2sby:TMHdf8ZIN9qEDA2xIXNO2su
                                                                    MD5:D2984D72A2359F6D8B10B8C7AB6D2D45
                                                                    SHA1:AE05ACF16AA63149D85D2029909711EDAC71DC02
                                                                    SHA-256:02502153E7696B677AA5D8C952D2C87ADD2C3F75B79CD30C1C56B0B10E7390E8
                                                                    SHA-512:B3DF6A6658F34C0461D1F993511FEF19B2C93F74A3107AA7CF96EB744BC9C191423FA1C26DFB944836BE07CED32528BCCB27954A6783ABAD8806088B5E663FED
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11010" V="0" DC="SM" T="Subrule" ER="10956" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="412" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. </S>.. <C T="U32" I="0" O="false">.. <S T="1" F="AccountConfigType" />.. </C>.. <C T="U32" I="1" O="false">.. <S T="1" F="ThreadId" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):235
                                                                    Entropy (8bit):5.0040849397162575
                                                                    Encrypted:false
                                                                    SSDEEP:3:vFWWMNHU8LdgCcspMNpux0B7a2mBkEsdKuNFnRxUDCQlIGAXGDMAwGK55xbSJNa3:TMVBd7MNpZU2pH7I/2On2sby
                                                                    MD5:45772E4F4866FF8DB7A4D0FA846C2364
                                                                    SHA1:0B45C9982E3CC7C888092D26AA63296EC37B8183
                                                                    SHA-256:A0056D12DCD4082A145FBCABADBF4AC6C7ED14FD147980907B48DABE6331BF90
                                                                    SHA-512:4668C56F5490122F4A56D34A3AC1899861D0D746D053409DBAD9150E893FCCE980EB36CBD4775A0C5BEB8BC6429C9402FC830FD45A31879087296CF1D3755C03
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11011" V="0" DC="SM" T="Subrule" DR="10956" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="413" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. </S>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):561
                                                                    Entropy (8bit):5.366665078031525
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd7VzjsqrdRDDHwpat5WLFb0SAUyni/A6NO2su:2d7eqrdRgekrp
                                                                    MD5:BFBAAF75F2BA07B929E7889616359F9E
                                                                    SHA1:BEAFD560A963641E3D4A8C0165472790B1CC2CA3
                                                                    SHA-256:00C581A38A38664E6FC4C033FB6F2863210C641BAAEB16B44F7C504693534EA2
                                                                    SHA-512:32226CF81C2993FB5F396958A0F4E46284A26004A1F50C93136137DFF6EDCB7FD2DBB8B9037A86E5EDE625A9A599B09FBD1FC2E4CF39F0F93DB53806D66DC7F2
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11012" V="0" DC="SM" EN="Office.Outlook.Desktop.Autodiscover_NoTempFile" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="5" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="619" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. </S>.. <C T="U32" I="0" O="false" N="AutoDiscoverTaskID">.. <S T="1" F="AutoDiscoverTaskID" />.. </C>.. <C T="B" I="1" O="false" N="AllowFlight_NoTempFile">.. <S T="1" F="AllowFlight_NoTempFile" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):992
                                                                    Entropy (8bit):4.855844164652946
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdQ1VzjkAdRDDHwpatEFZvnTbncoNBi+wsvXY//OcSX/c//RpONGkcXHaSMWpb:2dWLdRgeOfTvJwOkmhcEc8A7
                                                                    MD5:34EC88E5B676E0650D38EDBFA7C04955
                                                                    SHA1:B62262E64C718A87C5A50ECB421836FF8751993F
                                                                    SHA-256:B80B706216ACB2DD7E34596238DC978279C0796D54431CF54D003F17A7B11C85
                                                                    SHA-512:46759729196D3DBB032F9EF0F85AC7EE54DC1DB5F61F37C4D5CA6C15513A15A5DB2D4A0714696ED11810BEBDEA2B0818BBE4E4333998D88BD348EC3F2CA3D55E
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11013" V="0" DC="SM" EN="Office.Outlook.Desktop.IMAP.SpecialFolderPicker" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="617" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="2" E="618" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <TI T="3" I="Daily" />.. <A T="4" E="TelemetryShutdown" />.. <F T="5">.. <O T="LT">.. <L>.. <S T="2" F="HResult" />.. </L>.. <R>.. <V V="0" T="I32" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="InitCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="SelectCount">.. <C>.. <S T="2" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="SelectFailedCount">.. <C>.. <S T="5" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="4" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):574
                                                                    Entropy (8bit):5.176974635862576
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdwVzjNHWBdRDDHwpatEEIqB2XFJico2P5HWuHaSMNO5AHNUlu:2dwzWBdRgeNIimvSY9WZ7
                                                                    MD5:B58DA17B3DD0D5FA34DAA0EB642A6359
                                                                    SHA1:53B19F096DC9368A1F521E52B32A60AA844CC2BE
                                                                    SHA-256:70B325B60105E07F5DFD5D7675912D412DFC391C7293CB529E3F6A42D24C879A
                                                                    SHA-512:CDB41EB53CE5339275BE06EF5501878438B24F51904AADB12D36F384D8E003809611192639DAB6E3D29C7E1D5F5BD8339236925277075D3E470BA31FF3DAE4D2
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11015" V="0" DC="SM" EN="Office.Outlook.Desktop.CalendarModulePeekCounts.O16" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="700" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <C T="U32" I="0" O="false" N="CalendarModulePeekCounts">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):663
                                                                    Entropy (8bit):5.172331117371198
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd1xBkz44ae22Vgk3++qs2aBIyFNaMyFNAvpxyFNENO2su:2drBkkeb+qTFMFPFu
                                                                    MD5:B149253D7EE4902CF04B8FA6CDDFFB50
                                                                    SHA1:F94DD8E737337D9933E28A5D1D618C0695EEE3BA
                                                                    SHA-256:CBE1A375AB76E37F7853E94F8FE2D4150AE56F83DB0CAD039DBDBBADDD5B1966
                                                                    SHA-512:A2CBE985C834000DFD84499575A151CACE3215965AF4D8E1613457DB897311A153F8F4EBFDE6E946A070E62E36D07171CB6548FBB5E37444EF83BFEC055EAD30
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="110228" V="0" DC="SM" EN="Office.Word.Word.AtMentionAddedViaNotificationList" ATT="bffd26d9e49b4b7db4cb4df3425812de-d3cf8f62-3ad9-4007-99a8-8fb5cc89fd5d-7896" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="348" G="{bb00e856-a12f-4ab7-b2c8-4e80caea5b07}" />.. </S>.. <C T="U32" I="0" O="false" N="TotalNotifications">.. <S T="1" F="Total Notifications" />.. </C>.. <C T="U32" I="1" O="false" N="AddedNotifications">.. <S T="1" F="Added Notifications" />.. </C>.. <C T="U32" I="2" O="false" N="RemovedNotifications">.. <S T="1" F="Removed Notifications" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1842
                                                                    Entropy (8bit):4.620023242248927
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dFYcMtpdRgetIiHIiOvJwOafPjqJ5jqu8gFvYjoPSTt6l/+1b69r:cCHzRget76vJQjqJNqufv6Ayaybcr
                                                                    MD5:20D8F2DC2639C6D65CB8EE01FD349D19
                                                                    SHA1:675A17504BEC4EADAC019669F99B56AE6258048E
                                                                    SHA-256:D6BBF50CC8B715A6E78AB7A079662419F0A313CF837B1A8C6FFD6328E2ECCFA0
                                                                    SHA-512:F1BD6383E8EAE3D624098407188A66953294F2A5E08246B9FFDAF4740C6AD3F9371ED0DAF7FB7AF8A2EB3E82EBC061F5637FD04ED4AD95E8407E9888C88D7FDF
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11022" V="0" DC="SM" EN="Office.Outlook.Desktop.Calendar.MeetingAttendeeViewTrackingBasicUsage.O16" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="371" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <Etw T="2" E="372" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <TI T="3" I="Daily" />.. <A T="4" E="TelemetryShutdown" />.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="IsOrganizer" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="IsReceived" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="2" F="Mode" />.. </L>.. <R>.. <V V="2" T="U32" />.. </R>.. </O>.. </F>.. <F
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):2075
                                                                    Entropy (8bit):4.847162304138458
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dudBCeUf5p18D4spT2PKvi+bHKJ+tohpNpUg4a6zGiMFE7:cudseU58DNp/v7qJOUpx49KE7
                                                                    MD5:449BCAA66D7B71CC37B3FC1DE7E72AA9
                                                                    SHA1:A566A3AA39466983C8E93A4708EDAF5021127431
                                                                    SHA-256:B275B0276B3F2AEFF91144915174F22AA391825CE632FFBACCA0D25F92572FD2
                                                                    SHA-512:FC2800A7E9D13456253A910E050671DA92FC353EC340B1F653B953B99E436DFDAA4E03BE5CE7E837AAABDC761580C4061932AF2CAA843A7B3E40FAFD41F0932B
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="110233" V="14" DC="SM" EN="Office.Word.Word.TypingTimeSampling" ATT="bffd26d9e49b4b7db4cb4df3425812de-d3cf8f62-3ad9-4007-99a8-8fb5cc89fd5d-7896" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="1627" G="{daf0b914-9c1c-450a-81b2-fea7244f6ffa}" />.. <R T="2" R="118916" />.. </S>.. <C T="U64" I="0" O="false" N="SampleDurationInMilliseconds">.. <S T="2" F="0" />.. </C>.. <C T="U64" I="1" O="false" N="MessagePostDelayMs">.. <S T="2" F="1" />.. </C>.. <C T="U64" I="2" O="false" N="TypedCharTimeMs">.. <S T="2" F="2" />.. </C>.. <C T="U64" I="3" O="false" N="DisplayTimeMs">.. <S T="2" F="3" />.. </C>.. <C T="U64" I="4" O="false" N="DocumentId">.. <S T="2" F="4" />.. </C>.. <C T="G" I="5" O="false" N="SqmDocId">.. <S T="2" F="5" />.. </C>.. <C T="W" I="6" O="false" N="DocKind">.. <S T="2" F="6" />.. </C>.. <C T="W" I="7" O="true" N="SrcDocKind">.. <S T="2" F="7" M="Ignore" />.. </C>.. <C T="B" I="8" O="fals
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1901
                                                                    Entropy (8bit):4.627241851078075
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdTF+5bREWNzZT/qNO/y6NX/c//64pON1vGM1UyMxvZn6M4DRFFxVpxdKRJd+A:2dTF6flycxp3rKh+YAfQ0qN8Jk87Y7
                                                                    MD5:E3743BC92F783380E1E6500C116A25C7
                                                                    SHA1:6ECD9C6E99D551B92B615207321509A08D6388B4
                                                                    SHA-256:57B99C85D6E02FE331A26A5F69AD9C645187D8C3BA286CCA36A99F99AF8C05B7
                                                                    SHA-512:254F6AA2F24C1B5D9D2BE85146CAD099CCE5B85FFC6DBE6F3A98107F5E9261C640B4DD949553F5164FC548A47B2062C6185EAD9C65C9D0C43CC7A2B45F4AE6E9
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="110234" V="12" DC="SM" T="Subrule" xmlns="">.. <S>.. <Etw T="1" E="1627" G="{daf0b914-9c1c-450a-81b2-fea7244f6ffa}" />.. <TH T="2">.. <O T="EQ">.. <L>.. <C>.. <S T="1" />.. </C>.. </L>.. <R>.. <V V="13" T="U32" />.. </R>.. </O>.. </TH>.. </S>.. <C T="U64" I="0" O="false">.. <S T="2" F="dmsecTypingTime" />.. </C>.. <C T="U64" I="1" O="false">.. <S T="2" F="dmsecMessagePostDelay" />.. </C>.. <C T="U64" I="2" O="false">.. <S T="2" F="dmsecTypedChar" />.. </C>.. <C T="U64" I="3" O="false">.. <S T="2" F="dmsecAirspaceRender" />.. </C>.. <C T="U64" I="4" O="false">.. <S T="2" F="DocumentId" />.. </C>.. <C T="G" I="5" O="false">.. <S T="2" F="SqmDocId" />.. </C>.. <C T="W" I="6" O="false">.. <S T="2" F="DocKind" />.. </C>.. <C T="W" I="7" O="true">.. <S T="2" F="SrcDocKind" M="Ignore" />.. </C>.. <C T="B" I="8" O="false"
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):4546
                                                                    Entropy (8bit):4.1621296359435584
                                                                    Encrypted:false
                                                                    SSDEEP:48:cnNFRge4uyt4KTy0QYJCu6vVsY8bl/rfy8FNl7rmMUftg1UqXYDP:QRge4uyfdXIpNVwDfTv9JUftvqUP
                                                                    MD5:7E7FCFD9667EF114350837EF6859C34E
                                                                    SHA1:99BD45C8DBFD2A2C5B34C3D409AEBC2989716D84
                                                                    SHA-256:5AB0FD3A07238488E2BEB29FEB2D2DEFA06F3BFEC3D8E522CE1D1C63C1FD6CC8
                                                                    SHA-512:CDCB614B486E7EC7D576A77E42CF1F319A965C5387DB1FCED459299ED7F0263FA5880AB59ABF99E7586FD53BDD55025910E18A800CE2E2082C0CB3061B1621FE
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11023" V="2" DC="SM" EN="Office.Outlook.Desktop.Http.TransportFailures" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DL="A" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="10665" />.. <F T="2">.. <O T="NE">.. <L>.. <S T="1" F="7" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="3">.. <O T="EQ">.. <L>.. <S T="2" F="7" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="4">.. <O T="EQ">.. <L>.. <S T="2" F="7" />.. </L>.. <R>.. <V V="4" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="2" F="7" />.. </L>.. <R>.. <V V="7" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):382
                                                                    Entropy (8bit):5.399602338062679
                                                                    Encrypted:false
                                                                    SSDEEP:6:TMVBd7MqkhOVzjIkgMvXKXyiArVBdRijeDHwp1MTZ5mOHpLOqmIyuZOn2sby:TMHdzVzjHRvKX4rdRDDHwpat5DDamO2z
                                                                    MD5:EC11257F68B0A7E223AB2F2948319B3A
                                                                    SHA1:3101C84FBB3CED0709A9C2CD6CFDEF862AB3C712
                                                                    SHA-256:EE1949F30104FFB0249B4D59AB9ECA32752A5D76F7716399C7161A780A404541
                                                                    SHA-512:C7B432BFE86C6B85830F5AD4E095CC9B94B5BD1CF60C8FDC0D95A120148F8EA8ACEB4FD1D1DF552C0CE040B29E8F8BE7007A73BD5C80D8741F9FB4FEB05336D9
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11030" V="0" DC="SM" EN="Office.Outlook.Desktop.Rule.Olk.WebExtensions.PersistentTaskPaneSessionStart" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="1" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="8224" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1397
                                                                    Entropy (8bit):4.730302279138911
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d4sHyX2udRgeOvS8THabwOaHagFJHalNnRN5AnaNlz7:c3k2SRgeOvS8THYQHRJHm9RTAnajz7
                                                                    MD5:267A4D5CCDE3F3C244C83BB711E218B1
                                                                    SHA1:69099B37A210690D6B4CF50D394F14D85C8BFA58
                                                                    SHA-256:E4C1B61C2C9CA5F4D1F4CFFF0A55FC734E8D68B384B01C643BC2E53346158E8B
                                                                    SHA-512:BADFD884942F1DF0CDCC5CD77A321D66F99BD9026A97F32ED94776B710BCD8881A52309E498F33E4FAAF6A8AC002D32C1FA17DEB79E19839627A7A374A34E733
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11031" V="1" DC="SM" EN="Office.Outlook.Desktop.Rule.Olk.WebExtensions.PersistentTaskPaneFlightOn" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="8225" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="ButtonActionType" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="ButtonActionType" />.. </L>.. <R>.. <V V="2" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="ButtonActionType" />.. </L>.. <R>.. <V V="3" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="ShowTaskPaneWit
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):746
                                                                    Entropy (8bit):5.089387027562114
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdD934ae22VgceXFJiQjEmuWNzCWX+xNtNOZvjNOS5AHNBlu:2dD9peEv5dFWc
                                                                    MD5:0FFD79AAF3CCF46CF7837A22D1711EAA
                                                                    SHA1:F97E10344D57932CD8C78996EFA982A5C0C521A2
                                                                    SHA-256:04A9AEDF7AA827A7FC1B5E27F7480FEA4B7D24127BA7CBB332C34534435FB300
                                                                    SHA-512:26AD65075ADD30D1E2666C69EB5D29FBC6D1A8386FC48F56714E06A790C8C2CC4D31468E123BAEB77FE99544B8CBAA50F29967CFD15D9FB744C0F44A715719D5
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="110336" V="2" DC="SM" EN="Office.Word.Display.DrawE2o" ATT="bffd26d9e49b4b7db4cb4df3425812de-d3cf8f62-3ad9-4007-99a8-8fb5cc89fd5d-7896" DCa="PSU" xmlns="">.. <S>.. <TI T="1" I="Hourly" />.. <A T="2" E="TelemetryShutdown" />.. <A T="3" E="TelemetrySuspend" />.. <Etw T="4" E="224" G="{daf0b914-9c1c-450a-81b2-fea7244f6ffa}" />.. </S>.. <G>.. <S T="4">.. <F N="wkWwd" />.. </S>.. </G>.. <C T="B" I="0" O="false" N="FAccessibilityRunning">.. <S T="4" F="fAccessibilityRunning" />.. </C>.. <C T="U32" I="1" O="false" N="WkWwd">.. <S T="4" F="wkWwd" />.. </C>.. <T>.. <S T="1" />.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="4" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):563
                                                                    Entropy (8bit):5.271599786390993
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdccAt4ae22VgtWNzgNtNLZvkNOqHNUlu:2dccOet57
                                                                    MD5:59ADDCAFFF7BFD058AA2A6AFF6A73AB6
                                                                    SHA1:3A98AD7C3D4400E115389E22F86911E22E523695
                                                                    SHA-256:C27912CF53D071DA73131EF25161758492877E6E0E017E11987826F149FA6AB5
                                                                    SHA-512:E84BA0FB05857392F22696BE86F545DE7DC8D01BD6D10BDF0CFD5C787740FE518F828058B940963E639FE81DAD58C85D20F5703431D9CD69E791CF74AD424ED3
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="110337" V="2" DC="SM" EN="Office.Word.Display.ElaboratePrE2oViewTreatment" ATT="bffd26d9e49b4b7db4cb4df3425812de-d3cf8f62-3ad9-4007-99a8-8fb5cc89fd5d-7896" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="351" G="{daf0b914-9c1c-450a-81b2-fea7244f6ffa}" />.. </S>.. <C T="B" I="0" O="false" N="FAccessibilityRunning">.. <S T="1" F="fAccessibilityRunning" />.. </C>.. <C T="U32" I="1" O="false" N="WkWwd">.. <S T="1" F="wkWwd" />.. </C>.. <T>.. <S T="1" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):829
                                                                    Entropy (8bit):5.048582156772682
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd6vSVzjvt4dRDDHwpat5CkerSOerS4DmfW8/mfBqYS+rZ9dzjf+xpuOXklM0o:2d6vSMdRgeMrrgrW3e5qYdrZfXmrwD0
                                                                    MD5:C1DB076E3691F2431F6BB6663C3878C4
                                                                    SHA1:D89141D5D7CDD9360188C0A48F40F464DA142D2C
                                                                    SHA-256:5AE22392C0A7EB97C234F70490950E63BCBE0C0310C560CA3AF23B4E78BAA2D2
                                                                    SHA-512:F2C7901C5ACCFD542C2FA9DCCF407AE1B4B1C26B03C8DBA710995986244A2F60C88C5E3DC025D3170EBC04C339F8250246F147DCB624EBA71DC7D839BCDEDCB0
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11033" V="1" DC="SM" EN="Office.Outlook.Desktop.EidtGroupMember" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="50" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bp2a6" />.. <UTS T="2" Id="bp2a8" />.. </S>.. <G>.. <S T="1">.. <F N="UniqueID" />.. </S>.. <S T="2">.. <F N="UniqueID" />.. </S>.. </G>.. <C T="U64" I="0" O="false" N="ActionResult">.. <S T="2" F="ActionResult" />.. </C>.. <C T="W" I="1" O="false" N="OperationType">.. <S T="2" F="OperationType" />.. </C>.. <C T="U32" I="2" O="false" N="TotalChangedMemberCount">.. <S T="1" F="TotalChangedMemberCount" />.. </C>.. <C T="U32" I="3" O="false" N="GuestCount">.. <S T="1" F="GuestCount" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):913
                                                                    Entropy (8bit):4.769412538377476
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdWBVzj/VKr9PdRDDHwpatEerfBaXFJicoN+kXqNOoGJX/c//bLMpONGPDXAWs:2dWbw9PdRgeLrfQvS8TwNicDQs3y7
                                                                    MD5:EAA20B3BD8511F6DCFFF54057588209A
                                                                    SHA1:B54EC0D3C501FC142C09478BF46C143EB7FB05BD
                                                                    SHA-256:166BCDC82D142BABDF62AF1249AB59723739259F16FA3D61F86F5C96BA35A1A9
                                                                    SHA-512:8F289A958E9EC62ACB8BEC30D6EABEC2C39A5D0134393E2B6BBFDD463E511FF6BF618D125AF6E3D394470A4510940E96E234B8A1CE7D75E484534AA17ACB927E
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11034" V="1" DC="SM" EN="Office.Outlook.Desktop.AddGroupMemberEmailValidation" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bqdxe" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="ActionSucceed" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="GuestCount">.. <A T="SUM">.. <S T="1" F="GuestCount" />.. </A>.. </C>.. <C T="U32" I="1" O="false" N="FailureCount">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="TotalCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1511
                                                                    Entropy (8bit):4.346273725761616
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHds4ae22Vgi0qiBi8OiBcKLvjE8iZahIfg6yLg5/WDyLg5/W8/yLg5/WHNyLgk:2dMeq7v6YXjaR5fwTW/L1je
                                                                    MD5:B818F4D618CF210BC56C3CD8D25DEA51
                                                                    SHA1:047DB3FFB96202BFEF8ED90A7B58F55801F133B4
                                                                    SHA-256:60AD626E6D5D38E35F46BFA292F2808EB066ADF2D070CE87C88D32A6C8F19872
                                                                    SHA-512:3F31763E9282DB0C3A9D9B7E169238A27ADC5F24008EFBBF6E17DE65F4281697517FD7C7D410464FB2F85C42E0910CDE4979D6289EA6F03A56A3B2C1CAE7DA37
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="110360" V="0" DC="SM" EN="Office.Word.Logging.Warnings" ATT="bffd26d9e49b4b7db4cb4df3425812de-d3cf8f62-3ad9-4007-99a8-8fb5cc89fd5d-7896" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="110361" />.. <R T="2" R="110362" />.. <R T="3" R="110363" />.. <R T="4" R="110364" />.. <TI T="5" I="10min" />.. <A T="6" E="TelemetrySuspend" />.. <A T="7" E="TelemetryShutdown" />.. <US T="8">.. <S T="1" />.. <S T="2" />.. <S T="3" />.. <S T="4" />.. </US>.. </S>.. <G>.. <S T="8">.. <F N="0" />.. <F N="1" />.. <F N="2" />.. <F N="3" />.. </S>.. <S T="1">.. <F N="0" />.. <F N="1" />.. <F N="2" />.. <F N="3" />.. </S>.. <S T="2">.. <F N="0" />.. <F N="1" />.. <F N="2" />.. <F N="3" />.. </S>.. <S T="3">.. <F N="0" />.. <F N="1" />.. <F N="2" />.. <F N="3" />.. </S>.. <S T="4">.. <F N="0" />.. <F N="1"
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):3033
                                                                    Entropy (8bit):4.598852864816991
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dDc9pVA97y6pXfwoxSmNa5Q3A5SK+pMSEmukpASV5/n8tLxj3n0tdRuJCh/6ceG:cM4HtAUebmJRvua6dmMw
                                                                    MD5:70EBA2AD5C51F891DEB12BBD1DF84A12
                                                                    SHA1:F50A5920EA4A210781F7CCB29B4FB19FE6D0C508
                                                                    SHA-256:52EF8D83C6BC9A42E8F85F4FD9F818E26C93DE274B9B5E2BA8C8F9D57279F343
                                                                    SHA-512:A65E3287A585936616E91073EEB57DBBB96E03CA09C53150B972EF732870894DFD43954A383DC7BE2DF047177FB75CC3600C83E063CA80D2E7CBBD2052123D7D
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="110361" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <UCSS T="1" C="Word Accessibility" S="Monitorable" />.. <UCSS T="2" C="Word Activation" S="Monitorable" />.. <UCSS T="3" C="Word Acronyms" S="Monitorable" />.. <UCSS T="4" C="Word Addin Monitor" S="Monitorable" />.. <UCSS T="5" C="Word Animation" S="Monitorable" />.. <UCSS T="6" C="Word Async CoAuthoring" S="Monitorable" />.. <UCSS T="7" C="Word Async Edit" S="Monitorable" />.. <UCSS T="8" C="Word At Mentions" S="Monitorable" />.. <UCSS T="9" C="Word Authoring Assistant" S="Monitorable" />.. <UCSS T="10" C="Word Bib Cit" S="Monitorable" />.. <UCSS T="11" C="Word Boot" S="Monitorable" />.. <UCSS T="12" C="Word Bullets Numbering" S="Monitorable" />.. <UCSS T="13" C="Word Clipboard" S="Monitorable" />.. <UCSS T="14" C="Word CoAuthoring" S="Monitorable" />.. <UCSS T="15" C="Word Coauth Undo" S="Monitorable" />.. <UCSS T="16" C="Word C
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):3030
                                                                    Entropy (8bit):4.602277665025217
                                                                    Encrypted:false
                                                                    SSDEEP:24:2daTwCAuyP/zVP18ifqwQKaPkxQaGDbhNnM7pEmTvTfX0x/8MevyZJZIFKee/6c9:c9giiJt/DM72mhiZn6dmMw
                                                                    MD5:A06D984D927F1C26DD11E6A59142BFB5
                                                                    SHA1:5E9D7A2FECF8B4813911640596DE550C7C938EAC
                                                                    SHA-256:A5ACA7CDD3817FD6ED6ECCD73F27D571AC8A636BD4C1EF7DD77916CFBE70044D
                                                                    SHA-512:4C1134CDF1BE1D35F038A0C253843FCB880BEF1BD29FFC7EAB0642B17A78CDD4ABE83D352DB4F17235EA8191106C801F7CCFD407610189D57F9B7689E5D103EF
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="110362" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <UCSS T="1" C="Word File New" S="Monitorable" />.. <UCSS T="2" C="Word File Open" S="Monitorable" />.. <UCSS T="3" C="Word Find Replace" S="Monitorable" />.. <UCSS T="4" C="Word Flash Edits" S="Monitorable" />.. <UCSS T="5" C="Word Focus Mode" S="Monitorable" />.. <UCSS T="6" C="Word Font" S="Monitorable" />.. <UCSS T="7" C="Word Format Consistency Checker" S="Monitorable" />.. <UCSS T="8" C="Word Forms" S="Monitorable" />.. <UCSS T="9" C="Word Global Generic" S="Monitorable" />.. <UCSS T="10" C="Word Global State" S="Monitorable" />.. <UCSS T="11" C="Word Glyph" S="Monitorable" />.. <UCSS T="12" C="Word Graphics" S="Monitorable" />.. <UCSS T="13" C="Word Hashtags" S="Monitorable" />.. <UCSS T="14" C="WordHistory" S="Monitorable" />.. <UCSS T="15" C="Word HrLog" S="Monitorable" />.. <UCSS T="16" C="Word Idle" S="Monitorable" />..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):3026
                                                                    Entropy (8bit):4.592907301316505
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dnolA0yPA/mRUGXu/dFIq2/saXZQQeLeUCQpMC/MfCEmi5a3xfMJRYf2f+pIxdF:cgipvGGtjmi0kly06dmMw
                                                                    MD5:79C0FC0168678F244AC219C593F2F3F2
                                                                    SHA1:08472136EF19A47AA68438E915E783CAE80A0A5E
                                                                    SHA-256:8C4D2DDE926DD6CEEF7E4A26376ADD88F0773BEEE0608FE9A45443E0E8C6FAB1
                                                                    SHA-512:65EE90B53D77A2D9D05F360DE26220A04D950281073F5E82E6345A640A4BCBD2F84CAD61D34C279857CCD311A57B6BBB6758CB0C49203AA2361D375459505F23
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="110363" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <UCSS T="1" C="Word My Local Changes" S="Monitorable" />.. <UCSS T="2" C="Word None" S="Monitorable" />.. <UCSS T="3" C="Word Object Model" S="Monitorable" />.. <UCSS T="4" C="Word OCSB" S="Monitorable" />.. <UCSS T="5" C="Word Office Solution Framework" S="Monitorable" />.. <UCSS T="6" C="Word OLE" S="Monitorable" />.. <UCSS T="7" C="Word OTCoauth" S="Monitorable" />.. <UCSS T="8" C="Word Paragraph IDs" S="Monitorable" />.. <UCSS T="9" C="Word Performance" S="Monitorable" />.. <UCSS T="10" C="Word Power" S="Monitorable" />.. <UCSS T="11" C="Word Print" S="Monitorable" />.. <UCSS T="12" C="Word Print Layout" S="Monitorable" />.. <UCSS T="13" C="Word Programmability" S="Monitorable" />.. <UCSS T="14" C="Word Proofing" S="Monitorable" />.. <UCSS T="15" C="Word Property Formatting" S="Monitorable" />.. <UCSS T="16" C="Word Rasterizat
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1566
                                                                    Entropy (8bit):4.6157843925532855
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dtw5x1VAgyKxvpvukjnKQE7JpajQTraj6SxOKp:c/aKtdCu4OKp
                                                                    MD5:91506AFF576071246FA9DA8D5DD73BFE
                                                                    SHA1:790D4FB3CBF13998242D915479D95E489F911F21
                                                                    SHA-256:598DB0697B62FECCE0D66EEF851D345E0D30957895D6F01F95172B4B5ECA698D
                                                                    SHA-512:DC4F4E8CBB8E5A01E54BC4C28A6916BEA123FA915C7236F02BA5E1A20ADE86F869F090D3438C12060144EBA2212C740049A6C884B08724FD0E824C093A804141
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="110364" V="1" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <UCSS T="1" C="Word Three Way Merge" S="Monitorable" />.. <UCSS T="2" C="Word Touch" S="Monitorable" />.. <UCSS T="3" C="Word Track Changes" S="Monitorable" />.. <UCSS T="4" C="Word UIM" S="Monitorable" />.. <UCSS T="5" C="Word Unit Test" S="Monitorable" />.. <UCSS T="6" C="Word View" S="Monitorable" />.. <UCSS T="7" C="WordWebSuserngView" S="Monitorable" />.. <UCSS T="8" C="WordWordMail" S="Monitorable" />.. <UCSS T="9" C="Word Zoom Scroll" S="Monitorable" />.. <UCSS T="10" C="Word Text Prediction" S="Monitorable" />.. <UCSS T="11" C="Word Augmentation Loop" S="Monitorable" />.. <UCSS T="12" C="Word User Operation" S="Monitorable" />.. <UCSS T="13" C="Word Document Recovery" S="Monitorable" />.. <UCSS T="14" C="Word Intelligence" S="Monitorable" />.. <US T="15">.. <S T="1" />.. <S T="2" />.. <S T="3" />.. <S T="4
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):369
                                                                    Entropy (8bit):5.402515312863235
                                                                    Encrypted:false
                                                                    SSDEEP:6:TMVBd7M5FvkhOVzj1SWksLWwSJABaBdRijeDHwp1MTZ5mOHpA4IyuZOn2sby:TMHdkVzj1ShqWTOBKdRDDHwpat5DFmOQ
                                                                    MD5:579AB8EF4C8636D2CCCEEF1EFDD39F4B
                                                                    SHA1:A1396E024E1B01BA2CA67ABBA6EA0284A41E009B
                                                                    SHA-256:CFBD718A7A532BDA4158746C10C6AE78CE5E7F015C1037E9BD9BF61BF4F22377
                                                                    SHA-512:B36DB1FCD8E9ED2BFA131831C9EB95D49C1F1F712690E87A2E602E6B428AE0E102D3F298740D9C108BC51322A9D59459666C5A5DC04EDDF2940DB093EDC75D69
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11060" V="0" DC="SM" EN="Office.Outlook.Desktop.DesktopFocusedInboxRESTFirstRunCompleted" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="1" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9017" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):375
                                                                    Entropy (8bit):5.427725638236379
                                                                    Encrypted:false
                                                                    SSDEEP:6:TMVBd7MMDkhOVzj1SWksLCx5uoJeqBdRijeDHwp1MTZ5mOHpGqmIyuZOn2sby:TMHdZVzj1ShqCx5BBdRDDHwpat5DymOQ
                                                                    MD5:63BD5A0CC8EA591D0590D28853A3ECDE
                                                                    SHA1:2EF7B9EEB36604F98242B8595AA16914CA2E0AAF
                                                                    SHA-256:551748A8F9E83F44CA1FBE63FFC7CF2CF1C6C4E3B36DFBCB6AB55582E07C8632
                                                                    SHA-512:F17CDE12639761EBAFFEE601A285C0F5AD00AF858BAC0C7BAC3E05BDE58E12D2640DB6ABB2F040D1EF593DDDF7C6C10075FF6CA87DBD10360E4E7C456CE44090
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11061" V="0" DC="SM" EN="Office.Outlook.Desktop.DesktopFocusedInboxRESTRequestServerCapability" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="1" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9018" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):601
                                                                    Entropy (8bit):5.346626833186174
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdyA4Vzj1ShqQgXdRDDHwpat5DqY2YhcBqCH/ITBq+xdLbhcBqjlOITBqjlyN7:2dyVqhqQOdRgeNmqMSqcXmqjlBqjli
                                                                    MD5:04A133A6F35B8848CA6B7123AA9686D2
                                                                    SHA1:F17B8C0757C21D534EB6D1F89DFFDF269EE15A4B
                                                                    SHA-256:F0B393595642789F4E8DAB0C5BD6688D290C9C964B92B0BB9BB198DF3860B4DC
                                                                    SHA-512:506FF9B8E1860491CB9A1D67B9D57631433C11AAFF5C78B19A9893A57BCE2733B0BD99BE03346F2EA4420EF2532CEAE19226A9F24ED8150BE9A1BFE227B5835D
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11062" V="0" DC="SM" EN="Office.Outlook.Desktop.DesktopFocusedInboxRESTClientStateUpdated" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="1" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9019" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="B" I="0" O="false" N="ClientIsFocusedInboxOn">.. <S T="1" F="IsFocusedInboxOn" />.. </C>.. <C T="W" I="1" O="true" N="ClientIsFocusedInboxOnLastUpdateTime">.. <S T="1" F="IsFocusedInboxOnLastUpdateTime" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):365
                                                                    Entropy (8bit):5.401066347662183
                                                                    Encrypted:false
                                                                    SSDEEP:6:TMVBd7MikhOVzj1SWksLEqBdRijeDHwp1MTZ5mOHp43qIyuZOn2sby:TMHdbVzj1Shq3dRDDHwpat5D+2mO2su
                                                                    MD5:CCAABBDFB44C64FFCFF0E05DE59277F7
                                                                    SHA1:6667609322541C2E21E7C1AC36FDB1A49F9F5E38
                                                                    SHA-256:9B99C068A5C22532D67E16A56D32B481FBEFAECCCE1D98FC9B21E905B2FEAC9C
                                                                    SHA-512:1FDE477968B2F8C20E1E4BDDFE2A1D60B867B2ADE89239CC7BED3AAEAD02FCF240FE75336AF062639A6F599DC2CA7A118099CB85B839D9CDC1F88CD942642CC4
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11063" V="0" DC="SM" EN="Office.Outlook.Desktop.DesktopFocusedInboxRESTAdminOverride" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="1" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9020" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1305
                                                                    Entropy (8bit):4.887740661859413
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdfYVzjQ6dRDDHwpatEc6NXFJieHAHBF2HwH+rqNO+TNX/c//tpONGVORCXHIS:2dQxdRgeyxvJuVTJUqC12LGbNyF+
                                                                    MD5:822F5E1937C8EF7949B1D5557495E6D9
                                                                    SHA1:AFA78A0B4D0F8251BDF921A60907BD12576BA0A7
                                                                    SHA-256:919B3DC86FAEE9051F3C425805E8FFBD089CD4C41EE341B0D986F487CCE95D37
                                                                    SHA-512:AF1E716655D0B566367E9948A79F5685C4DD2AFE3EEDBCE9EF2A360A1775C717A8CE21C47AC664BD7F743E2FF070B920D781A5D640C112CFBC6B4182E78D679C
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11064" V="0" DC="SM" EN="Office.Outlook.Desktop.MOTWUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <TI T="1" I="Daily" />.. <A T="2" E="TelemetryShutdown" />.. <Etw T="3" E="4271" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="4" E="4272" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="5" E="4273" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="6" E="4230" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <F T="7">.. <O T="EQ">.. <L>.. <S T="6" F="ResponseCode" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="MarkSetOnClipboardCount">.. <C>.. <S T="3" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="MarkSetOnPasteCount">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="MarkSetO
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1107
                                                                    Entropy (8bit):5.128191074932314
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd10hVzjTmL0dRDDHwpat5lSB7svFI6Fi2Yxppv35HviJ5d+DrBU7Y5GTYOPYD:2d10hRjdRgeI7sFDgv56JT+3qY2Yjmg
                                                                    MD5:DDC684FB8C20913F731479CD7667DFF6
                                                                    SHA1:A00B6BA5DD2D56235FC285E2C4E9B356A36B1AD1
                                                                    SHA-256:2AC4C84BDBE7BF1F9280E2B0749952836CE372A4AD22A8CE0A92437A98644E83
                                                                    SHA-512:E27527CA91DCB915E8B45DDFBF8EF52CA6E5797763D10E5C853AF3BF8A03C4548DBE9F59C9D8D3FA48BAC45E3A9BEFDC4A1246D6AD12C908C7DC463899100A51
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11065" V="1" DC="SM" EN="Office.Outlook.Desktop.SearchSuggestionRetrievalTimes" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="200" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="7106" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. </S>.. <C T="B" I="0" O="false" N="IsQF">.. <S T="1" F="IsQF" />.. </C>.. <C T="I32" I="1" O="false" N="HttpStatusCode">.. <S T="1" F="HTTPStatusCode" />.. </C>.. <C T="U32" I="2" O="false" N="NetworkTimeTicks">.. <S T="1" F="NetworkTimeTicks" />.. </C>.. <C T="U32" I="3" O="false" N="DeserializationTimeTicks">.. <S T="1" F="DeserializationTimeTicks" />.. </C>.. <C T="W" I="4" O="false" N="TraceId">.. <S T="1" F="TraceId" />.. </C>.. <C T="G" I="5" O="true" N="SearchSessionID">.. <S T="1" F="SearchSessionID" M="Ignore" />.. </C>.. <C T="G" I="6" O="true" N="QueryGroupID">.. <S T="1" F="QueryGroupID" M="Ignore" />.. </C>.. <C T="G" I="7" O=
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1165
                                                                    Entropy (8bit):5.058229823280203
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dj5TbdRgeI7sNslsMM/OwuM/Oj0M/OSY2M/9qZn+j:cj5lRgetqiMMGwuMGj0MGSvMgne
                                                                    MD5:EE9034B7303351B07158F3B3AA46997A
                                                                    SHA1:49035AD2012B6A7935375B9FF7BDF868FAC92340
                                                                    SHA-256:737C6E22FEE2F3BC99DDF39D17D7A506D70552B90A4F7392F3DA466691FDE882
                                                                    SHA-512:76D32402D8387C0368825C2316E6154F540846A8F6C8FA2AFCF92B7C9A5D7A8B7343BAC832C6E8B8EF0290206D39979B7E9F736453DBCA5A4207B710C0790812
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11067" V="2" DC="SM" EN="Office.Outlook.Desktop.LogSearchModule" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="25" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="7000" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <Etw T="2" E="7001" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <Etw T="3" E="7002" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. </S>.. <G>.. <S T="1">.. <F N="Search Session ID" />.. <F N="SearchSessionId" />.. </S>.. <S T="2">.. <F N="Search Session ID" />.. <F N="SearchSessionId" />.. </S>.. <S T="3">.. <F N="Search Session ID" />.. <F N="SearchSessionId" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="SearchSessionID">.. <S T="1" F="Search Session ID" />.. </C>.. <C T="U32" I="1" O="falseNoError" N="CurrentModule">.. <S T="3" F="CurrentModule" />.. </C>.. <C T="G" I="2" O="true" N="SearchSessionGUID">.. <S T="
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):753
                                                                    Entropy (8bit):5.184211737684641
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdmVzjLUdRDDHwpatE7Hc1NQzD2DRfAmla/dNHaSMnKPXNSJdIxXHRkMNOAjsu:2dm5UdRgeVqC8FBdyIxf
                                                                    MD5:34EDA7930D6A634D47411A42FDC8A68E
                                                                    SHA1:DF2D1658B841AD7A272277B6122C7031D878AD05
                                                                    SHA-256:BE89580DE13ACB66F55AFAE9EF89F5657833B193D43F8C52173D9E0FF973EB03
                                                                    SHA-512:79A4B8F246A957E58819AAB0E70DF191E6EC7E4C48FA99A75997F86DC9E15A7D41D2A9459DE797DF0D1BE4A3B17A70F47C6243988BE273478CF5E0DDE0C0F2AF
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11068" V="2" DC="SM" EN="Office.Outlook.Desktop.GroupEmailReadsInMeSpace" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="18033" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="SmtpAddress" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="CountOfGroupMailsReadInMeSpace">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="BIN" I="1" O="false" N="UserSmtpAddress">.. <U T="OneWaySHA1HashToBinary">.. <S T="1" F="SmtpAddress" />.. </U>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1709
                                                                    Entropy (8bit):4.971976501981704
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dgqWY+6dRgevo3P8iVXnic+r+V3K9MU+8WerWHiwFW1erW1i3oc330eU4i/NkcS:cbWp2Rgeg3l3+S42JtHwrlQKil+CLf
                                                                    MD5:5BDADD40D817C98E16EBAE63F431DC33
                                                                    SHA1:344373C7858A9F53BEA71E620EAFF40E4261A2AE
                                                                    SHA-256:D07CE100719347089543E330E072C52970D897952258F096DCCEE0805B5257D8
                                                                    SHA-512:3750496EC107A473D14E329A564480F44DC1F17A05F1319939BF2B4BB1716EF54099CD79DB7F5546AADA06F28CB876575E4AB117C9D20C2B70C3DCB13A49405C
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11075" V="4" DC="SM" EN="Office.Outlook.Desktop.WatsonBuckets" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" SP="CriticalUsage" S="1" DL="B" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="500" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <SS T="2" G="{dd5250a9-3404-43b0-9b7a-6f4eaea6497d}" />.. </S>.. <C T="W" I="0" O="false" N="DateTimeStamp">.. <S T="1" F="DateTime" />.. </C>.. <C T="W" I="1" O="false" N="OfficeBuild">.. <S T="1" F="OfficeBuild" />.. </C>.. <C T="W" I="2" O="false" N="WatsonBucket">.. <S T="1" F="WatsonBucket" />.. </C>.. <C T="W" I="3" O="false" N="BucketType">.. <S T="1" F="BucketType" />.. </C>.. <C T="W" I="4" O="false" N="BucketName">.. <S T="1" F="BucketName" />.. </C>.. <C T="W" I="5" O="false" N="Response">.. <S T="1" F="Response" />.. </C>.. <C T="W" I="6" O="false" N="CabId">.. <S T="1" F="CabId" />.. </C>.. <C T="W" I="7" O="false" N=
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):553
                                                                    Entropy (8bit):5.324337528685985
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHds1VzjhwqlCdRDDHwpat5DIasBNOpuynznBqCH/ITBq+xNO2su:2daMqlCdRgeFFEQqMSqI
                                                                    MD5:EAC9B8A2D589F60DC906010BE28B0943
                                                                    SHA1:C71A606EE1260399918EF9E4B36FB478225AABB1
                                                                    SHA-256:909E16EB1A1472781F46F99206D75B833AB32ACF747DD9CAEBE8BC3307F13F0D
                                                                    SHA-512:6B7B9158828899F2C0800572E8FBC9C3BB35C0296B093AE2D3C779823522BD41A884BD0A6066EE37D3E3D31CE3F40FF27229BA92E7142CF1297D1FDF5C0F2803
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11079" V="0" DC="SM" EN="Office.Outlook.Desktop.FocusedInboxTeachingUIDisplayed" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="1" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9016" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="W" I="0" O="true" N="TeachingCalloutID">.. <S T="1" F="TeachingCalloutID" />.. </C>.. <C T="B" I="1" O="false" N="IsFocusedInboxOn">.. <S T="1" F="IsFocusedInboxOn" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):752
                                                                    Entropy (8bit):5.101531601368304
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdBjVzjOEudRDDHwpatEFgHz2HQicih22RyAxXHaSMfNnXHhSMNO3AHNS7lu:2dNjudRgeRJeTxAh9r
                                                                    MD5:267CE6B61A9D71513E90CCB342121F22
                                                                    SHA1:18BFD21CC373093B9EA683E7CA73130664862055
                                                                    SHA-256:4A8F8D89DF6D52DADDA2FE4FCDF10DD05A4EDE4EE8B486CB6B3DA14B43208238
                                                                    SHA-512:757CA6B2873C7BE9C1D92909990692A20E6A5F59BABEB8FE20B6704BA0D148455355E109C1897FADB491A7D46DEAC72D7618DCCF20BFBD22DCF30551DEA21550
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11528" V="0" DC="SM" EN="Office.Outlook.Desktop.EnhancedLocations.WellShown" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="6118" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="6119" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="3" E="TelemetryShutdown" />.. <TI T="4" I="Daily" />.. </S>.. <C T="U32" I="0" O="false" N="EnhancedWellCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="LegacyWellCount">.. <C>.. <S T="2" />.. </C>.. </C>.. <T>.. <S T="4" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. <S T="2" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):609
                                                                    Entropy (8bit):5.269736541765203
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdYVzjqdRDDHwpatE3Hc1NQnAJu/HaSMNOA/HNUlu:2dYQdRgeNqYuq7
                                                                    MD5:C3F590BB9E15B784916B36B318DFFCF2
                                                                    SHA1:B4B40CEE51B23E8B7EB8D1F3AB0124B7362655A6
                                                                    SHA-256:E6AAF5056A7E30B890FF57EF0749A935FCABC5483CCCB4BCCDB63EF822946B76
                                                                    SHA-512:09716345BE8507D60247AF15083889249BE7B5C25C7FA151897C088F2B9D0E3DBE15E1735840141C5EDA09234973373955984B4D83F37960EEFEECF37A17911D
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11529" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.DigestEmailNavToGroupConversationClicked" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="18059" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="CountDigestEmailNavToGroupConversation">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1981
                                                                    Entropy (8bit):4.427959934228141
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dbjtdRgemvS8TuaIwOauabJuagFurajqvVkaja1/W9roQ1KWkERX7:cbDRgemvS8TurQuYJuRuYqvVn3LR7
                                                                    MD5:19AC4ADCE59AE3CBFBE35B34A056E994
                                                                    SHA1:3273A5751560854649755EA25AD4191FB7BEF808
                                                                    SHA-256:583B6A22840F29FF08DDC691E2C1BA3B5F9A7282475D66C72BF7CD37A5CAF96B
                                                                    SHA-512:C32C5C07876C9A5BA8BF3958CD7574DE48248C7793F1A36BBEF9829C38963C94EBD534757EBAAC5CDE4A3144CBF91BF1DCE3D536AFF92B71ECF5EC04E8961648
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11530" V="1" DC="SM" EN="Office.Outlook.Desktop.EnhancedLocations.PickedFromPicker" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="6120" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="LocationType" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="LocationType" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="LocationType" />.. </L>.. <R>.. <V V="2" T="U32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="5" F="IsZeroInput" /
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):990
                                                                    Entropy (8bit):4.873738478043802
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdnVzjOEhH5dRDDHwpatEFcFHcHQicih22LOXHaSMB0XHhSMpvQZOXnWXqiNf/:2dnjN5dRgezfJzA0UOyJt
                                                                    MD5:C3BEC92F99ABB3360CC8D6234094603B
                                                                    SHA1:E360A9031C6C321EE621BEFDD9E48C8FA11591EE
                                                                    SHA-256:53E0796E52CFFE19F04A5BB0AEEEB8FB50572AE1596DDF0A3BDF943B248AF09E
                                                                    SHA-512:9392048DEE2F2678AA6B8586C0D3287CBC075126F947E6D8DAB00E4E25C58EDD6CCCDDDFC959A177A09C58008C9AD2BF94B08FD6094B446C47B3C0572EC7FAB3
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11531" V="0" DC="SM" EN="Office.Outlook.Desktop.EnhancedLocations.AddedWithoutPicker" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="6121" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="6122" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="3" E="TelemetryShutdown" />.. <TI T="4" I="Daily" />.. </S>.. <C T="U32" I="0" O="false" N="RoomFinderCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="TypedCount">.. <C>.. <S T="2" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="TotalLegacyAddCount">.. <O T="ADD">.. <L>.. <C>.. <S T="1" />.. </C>.. </L>.. <R>.. <C>.. <S T="2" />.. </C>.. </R>.. </O>.. </C>.. <T>.. <S T="4" />.. <S T="3" />.. </T>.. <ST>.. <S T="2" />.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1637
                                                                    Entropy (8bit):4.539377584344812
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dzaVEdRgenGIiluyONjqt4+DjqZcwODx2OH8/8gM838/nok7:cuyRgenGBuysqt4+HqOP2OHIXM0Enok7
                                                                    MD5:5D48C4ED7C066AAF069C130955BC6082
                                                                    SHA1:A4BB3D4CBB773003885768238C2CE78E6F69FED4
                                                                    SHA-256:E92A67DC509B356D9346CD0110CD040BDB6A2A2FD9D873CC94F2F58D8FDA40C8
                                                                    SHA-512:6597E9AE0E173FA60B130B366C66591163F173CA925953DC486346EF70530C607D96E04BE414856D9B406B2CB899008AA27EA0100C69B4D992EEAE430BB3C178
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11544" V="1" DC="SM" EN="Office.Outlook.Desktop.Calendar.ReminderJoinOnlineMeetingCount" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="808" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <F T="2">.. <O T="EQ">.. <L>.. <S T="1" F="JoinSkype" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="3">.. <O T="EQ">.. <L>.. <S T="1" F="JoinTeams" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="4">.. <O T="NE">.. <L>.. <S T="2" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="I32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="NE">.. <L>.. <S T="3" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="I32" />.. </R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):544
                                                                    Entropy (8bit):5.139115725994136
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd+Vzj8/5hdRDDHwpat5D62GeOJy/5uFNCNW7nKf/0//khmMNO2su:2d+mLdRgeQvLIkytj
                                                                    MD5:D3D62BD6226676857F3CA3FAC5D2A85A
                                                                    SHA1:25EC53923FEF9EF4147F98B60686C6BEC3B90A94
                                                                    SHA-256:1CDD3DC091F5BDF31235CA8F10EB5C7BFBDF7B64C645F67BE91437F8DD40C95B
                                                                    SHA-512:F25466821C477AAB65703BAF507DB0CFF9AC9A031220850B1FC032B91B7118EC88EEAC2215A3C0E9F9A22FBE43CCA83B65AF6B668C9C3B9858DA837D2EE737B8
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11549" V="0" DC="SM" EN="Office.Outlook.Desktop.OABSizeOnDiskIsZero" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="1" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="1101" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. </S>.. <C T="B" I="0" O="false" N="OABSizeOnDiskIsZero">.. <O T="EQ">.. <L>.. <S T="1" F="OAB Size" />.. </L>.. <R>.. <V V="0" T="U64" />.. </R>.. </O>.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1010
                                                                    Entropy (8bit):5.147676549651255
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dhU7OKPdRgeWbsaPYnibAKMiDT2DW5QF:chU7OKlRgeWIaP/S
                                                                    MD5:90B1B4A8DF00103362FC232C008994BF
                                                                    SHA1:C33D86F59A2B2F27D9AE2C72FEC66F639F1E3EDB
                                                                    SHA-256:03464E65A4FA284A7D8FC691F87BA453E151C68DB24BF92DAB4C7E82804E414C
                                                                    SHA-512:583160B76031AAA13AD2EE0701DA65951A5B79C083DAA722FA30BA92FEFA63813D78F7D6E6605968194E0EE8C6C7B7D520FDD2A0E0D6DBA162C97B4CA5D89F54
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11550" V="1" DC="SM" EN="Office.Outlook.Desktop.ServerSearchRequestHttpRecord" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="200" DL="A" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="7126" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. </S>.. <C T="G" I="0" O="false" N="SearchSessionId">.. <S T="1" F="SearchSessionID" />.. </C>.. <C T="W" I="1" O="true" N="RequestTypeString">.. <S T="1" F="RequestTypeString" />.. </C>.. <C T="G" I="2" O="false" N="ClientQueryID">.. <S T="1" F="ClientQueryID" />.. </C>.. <C T="U32" I="3" O="false" N="HttpStatus">.. <S T="1" F="HttpStatus" />.. </C>.. <C T="U64" I="4" O="false" N="NetworkLatency">.. <S T="1" F="NetworkLatency" />.. </C>.. <C T="W" I="5" O="true" N="ServerErrorCode">.. <S T="1" F="ServerErrorCode" />.. </C>.. <C T="W" I="6" O="true" N="ServerTraceId">.. <S T="1" F="ServerTraceId" />.. </C>.. <T>.. <S T="1" />.. </
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):844
                                                                    Entropy (8bit):4.89785586626707
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdvHxSVzjOEwpdRDDHwpatEFSHXFJicoN+kXqNOgpOX/c//wVrMpONGoXHaSMu:2dkjsdRgePvS8TvajBO2D7
                                                                    MD5:54C7EA54AE2082FFCCFDB64391C3FF3B
                                                                    SHA1:33358F9D5F21F894B22907C5D8EE0ADFB86FB008
                                                                    SHA-256:17564B6F953152A7341C182A1A70F6386869EB3BF5FB9395AED9D431ECFD471E
                                                                    SHA-512:AB622137CE35D599B397FA8E23FE64F9EA7B127B7AEC252039C1D45385F9F72971E1A4084A6B8FB530A0CA008836CB4BDD904F14D88B66A24BC6A639A5ED93FD
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11551" V="1" DC="SM" EN="Office.Outlook.Desktop.EnhancedLocations.PickerShown" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="6123" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="IsZeroInput" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="PickerShownCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="ZeroInputCount">.. <C>.. <S T="4" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):823
                                                                    Entropy (8bit):5.060923510260963
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdRuVzjTLT6dRDDHwpat5Gg8Y3slsqsfEqQxdLwBU7Ydy94IYdVhETd+xVkBoB:2dRuR/6dRgeiY3sl+8Tr0LlER+PK5Q
                                                                    MD5:667FCB02805CBB3F7C41827253DAD1B4
                                                                    SHA1:F59292DBC746EFBD5D75F296C7B7BDD0EB17484E
                                                                    SHA-256:F5E0CFD89B67E4A5FAEAB21685369B8860218E54A06078535515C4D28866BCDD
                                                                    SHA-512:511E7C8AAC4D1FDAAB94C1D6F3CF03DB5459EDCC56C48C7B376457292ED08F1489BAFFC1C2B23862C23F961A3E6C7F054999C192CAED509B772838C2D1317F7A
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11553" V="3" DC="SM" EN="Office.Outlook.Desktop.Search.SearchActions" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="500" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9056" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. </S>.. <C T="W" I="0" O="true" N="EventType">.. <S T="1" F="EventType" />.. </C>.. <C T="W" I="1" O="true" N="TraceId">.. <S T="1" F="TraceId" />.. </C>.. <C T="W" I="2" O="true" N="Id">.. <S T="1" F="Id" />.. </C>.. <C T="W" I="3" O="true" N="EntityId">.. <S T="1" F="EntityId" />.. </C>.. <C T="W" I="4" O="true" N="Localtime">.. <S T="1" F="Localtime" />.. </C>.. <C T="W" I="5" O="true" N="VerbMetadata">.. <S T="1" F="VerbMetadata" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):855
                                                                    Entropy (8bit):5.089141800724169
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdq1uVzjTLwRjodRDDHwpat5GgiiqslswBU7YIBWJzpJkIkftx4DzLiJLmQlcN:2dUuRojodRge47slxTTLcHq
                                                                    MD5:8727820C135175D732D1395EC4468751
                                                                    SHA1:714C35DE98C35D5CB80DCD7DF1FAE727148B2540
                                                                    SHA-256:7552C0C5184C74C255F560E2069EBC5DCA6BF20D05000C6D951132A6E28218B8
                                                                    SHA-512:1FDDF117B5A05332BB9CA891B66CBDD791F3991C65974E0B462FD65D305603B098870C3B1130BC51ACC4827188F3CA3620D77FC2B3910BC3B51A2E0B88D1D238
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11554" V="3" DC="SM" EN="Office.Outlook.Desktop.Search.ResponseReceived" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="500" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="7123" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. </S>.. <C T="W" I="0" O="true" N="TraceId">.. <S T="1" F="TraceId" />.. </C>.. <C T="U64" I="1" O="false" N="Latency">.. <S T="1" F="Latency" />.. </C>.. <C T="U32" I="2" O="false" N="Status">.. <S T="1" F="Status" />.. </C>.. <C T="U32" I="3" O="false" N="Rendered">.. <S T="1" F="Rendered" />.. </C>.. <C T="U64" I="4" O="false" N="RenderingLatency">.. <S T="1" F="RenderingLatency" />.. </C>.. <C T="I64" I="5" O="false" N="PageNumber">.. <S T="1" F="PageNumber" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):538
                                                                    Entropy (8bit):5.12398915550093
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdrHVVzjOEoag3hdRDDHwpatEi074XFJico2bTghXHaSMNOA/HNUlu:2drHVjpidRge87svS0Uy7
                                                                    MD5:9E6ABACD78111D533ADDDEEC14C51AF2
                                                                    SHA1:0117774835F77541FE1427A314CC30D68DD0F62D
                                                                    SHA-256:7EFC1735D5920EF0A8C8387551327A33413473F694801A93E45BDDDFB8DA9A7B
                                                                    SHA-512:5069E110D2E44B78D39177094BFC32139345C4F1705DE6699F294636D0A6931C6288B8CA9C07E3B614148B1C17FA7C51524BF88C12FB33213FD75A35418FE6B4
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11555" V="0" DC="SM" EN="Office.Outlook.Desktop.EnhancedLocations.SearchCreateFailed" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="11565" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <C T="U32" I="0" O="false" N="SearchCreateFailedCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):449
                                                                    Entropy (8bit):4.742322563724399
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdnHr8I/8q3+u/qNOokOX/c//owkZKpONEOjsu:2dIIXOuymajwkZp
                                                                    MD5:A20476D05320EE69C20DDE8A58B33BFD
                                                                    SHA1:4F4D81EEEF07C2B72AC31EE99362DF608D95D8EA
                                                                    SHA-256:3FEBF9DC38A5184CD501A88C661D9BADCA720E72BFE6A0A3AF5D205913EA4B9F
                                                                    SHA-512:6361BE2B38D55AE246FE153A36045231D1E9E5B93B6767F54DA2EB9721F13C3143C9E6BA0A5213E5F314A36D4A4B6031099EE652EAFC898D2E0FD49A734DCEF1
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11559" V="0" DC="SM" T="Subrule" ER="11443" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="445" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <F T="2">.. <O T="EQ">.. <L>.. <S T="1" F="AccountType" />.. </L>.. <R>.. <V V="{ED475414-B0D6-11d2-8C3B-00104B2A6676}" T="G" />.. </R>.. </O>.. </F>.. </S>.. <T>.. <S T="2" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):449
                                                                    Entropy (8bit):4.7314621832431
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdNZOVTq3+u/qNOokOX/c//owkZKpONEOjsu:2d62OuymajwkZp
                                                                    MD5:DD8CEBB0841DBA0F7416A4C67AC34DCA
                                                                    SHA1:54991A03E74AA677B2F2F7232479AB54ED4269CA
                                                                    SHA-256:9FDE5F5829E3398AA756440339398B7E19F4191A1A21D2AACA13DA9B66D9D69F
                                                                    SHA-512:A97D401D3CAA432CD16F3D8D5DB1988E9CAA37B15FCBE253190A09885A97D601096DFD33E29B3D76BF04C7381DFDB61226000A441985419922255D4E745EEED7
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11560" V="0" DC="SM" T="Subrule" DR="11443" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="446" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <F T="2">.. <O T="EQ">.. <L>.. <S T="1" F="AccountType" />.. </L>.. <R>.. <V V="{ED475414-B0D6-11d2-8C3B-00104B2A6676}" T="G" />.. </R>.. </O>.. </F>.. </S>.. <T>.. <S T="2" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1234
                                                                    Entropy (8bit):4.64087353961245
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd8VzjNvp1gsdRDDHwpatEtaHXFJicoN+kXqNOEX/c//wVrMpONd+wsvXqNOEw:2d87MsdRgeQ4vS8TpjqwOapi3XdK0rJ
                                                                    MD5:5661CF27FA9618861F804A4CB39AD4F6
                                                                    SHA1:065B57AC0F7BCE8F51845C4DB7F47008DA756227
                                                                    SHA-256:E5E515C3C19C5130267C28F907904DB6D4715F2D059045193C97E496BE104D05
                                                                    SHA-512:0981729F4ACDA38807FD497884E93193B5F6A5239869F4FFD93D86512DE2BA2F9F2C464E7A63D0F67F9E08B8F5B53A390018BDFC468C8255606CF15A45FD2983
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11561" V="0" DC="SM" EN="Office.Outlook.Desktop.WebExtensions.WebExtAPIMetrics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="8240" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="Success" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="Success" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="1">.. <F N="APICalled" />.. </S>.. <S T="4">.. <F N="APICalled" />.. </S>.. <S T="5">.. <F N="APICalled" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="APICalled">.. <S T="1" F="APICalled" />.. </C>.. <C T="U3
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):960
                                                                    Entropy (8bit):5.038938683038551
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdaBVzjlGZPdRDDHwpatEBs3Hqmc1NQzDJPhVWSyf0umYoi2vLwW9piAROXHaF:2dquZPdRgeDIqhP++FPDTFy07
                                                                    MD5:44CD4F3636AC668C6DE0BE6DD9E25D65
                                                                    SHA1:85C08F8703408AE8BFEB3D25DB95AF2BA4DDFC3B
                                                                    SHA-256:36593804AB8EB727ABA631308F69A9C37ABE629DCFD26E6DF7AD666AEF35C9D1
                                                                    SHA-512:08B1A484E667548E91F8E0BA127F451DAFC10CB79C184ECAFB9B5FDAACD34C4C76C42DC1881F1E61839B23C93642791353667D3885321CCD05B25212E525161A
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11562" V="1" DC="SM" EN="Office.Outlook.Desktop.DiagnosticsSystemV2.Authentication" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="37" G="{ad58872e-4df6-4b26-9841-5d7887a1c7a5}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="TypeOfAuth" />.. <F N="HttpResult" />.. <F N="FeatureScenario" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="Authenticator">.. <S T="1" F="TypeOfAuth" />.. </C>.. <C T="U64" I="1" O="false" N="HttpStatus">.. <S T="1" F="HttpResult" />.. </C>.. <C T="U32" I="2" O="false" N="FeatureScenario">.. <S T="1" F="FeatureScenario" />.. </C>.. <C T="U32" I="3" O="false" N="Count">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):823
                                                                    Entropy (8bit):5.015460474952734
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHddVzjadRDDHwpat67kt9q3+u/xH/OsDOX/c//SpONKuurSpU/EiyMNodNEDxS:2ddQdRgegOuVDaUi48D4
                                                                    MD5:A1A19578FD123DB4527766F6A0C26481
                                                                    SHA1:6A29DA1666244F86BE4D52FE9D025D314A6ADFCF
                                                                    SHA-256:5645B1CEC9F5A1EB799A176C171EA6588006CBD2D8F3B0059312220BA84BC750
                                                                    SHA-512:66724C898BB63CC40CE479E90A6A54493EE142D8D2B8029623D11BD42686B0A133D9FD16D17EA8DAF4922B9FA2D9DCED38F05127768317588ED5083D1A45567C
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11564" V="0" DC="SM" EN="Office.Outlook.Desktop.HangBucketMetrics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" SP="CriticalUsage" S="999" DL="B" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="304" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <F T="2">.. <O T="GT">.. <L>.. <S T="1" F="ElapsedHanging" />.. </L>.. <R>.. <V V="300" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <C T="U64" I="0" O="false" N="BucketId">.. <S T="1" F="BucketId" />.. </C>.. <C T="U64" I="1" O="false" N="ElapsedTotal">.. <S T="1" F="ElapsedTotal" />.. </C>.. <C T="U64" I="2" O="false" N="ElapsedHanging">.. <S T="1" F="ElapsedHanging" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):468
                                                                    Entropy (8bit):4.544906538001387
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdIOF4NaH+u/5lOeX/c//RpONaDQNOjsu:2dWNjuRg
                                                                    MD5:7095AAD71457B3E16BC77BA3074E5084
                                                                    SHA1:41359535073F254E2365343C6571F4C876153D4C
                                                                    SHA-256:FBBC47A93C3A7251FC92DA47890BB657ACB5802252254812D4B42E892A208317
                                                                    SHA-512:F7D158B5D5AD886E5B00FAFF483654AE46A8C59B635329FD6B64A34F22058B058872EF107E742AFA09F7140D96561D9149C287F53B1684758280C543D581037D
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11565" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="6124" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <F T="2">.. <O T="NE">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="I32" />.. </R>.. </O>.. </F>.. </S>.. <C T="I32" I="0" O="false">.. <S T="2" F="HRESULT" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):895
                                                                    Entropy (8bit):5.149399834102735
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdWVzjNvp164sdRDDHwpat5D1as2bSA6ySTZAy7dy9gOKN/c3SATd+xdHqNAhw:2dW79sdRgemiFoZ+Nc
                                                                    MD5:B2D459D267469A347692F9E27FCBA576
                                                                    SHA1:8115390DDB7A38AA47337FAEDDC0D5D851CFEC17
                                                                    SHA-256:12A92F71D127A716D84E4EEB457DE2A9C9EDE237C36866CABE8F1ACA97AEB71D
                                                                    SHA-512:3C23AE9E1EEA821A7A018C488728CBF0A594CA5061D89CC8751CB8CD59B61FED751E035320A0216013E7AB31861EDBB414EF86E408226CDCDA5D71FDD759378C
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11566" V="1" DC="SM" EN="Office.Outlook.Desktop.WebExtensions.WebExtAPILoggerErrorDetails" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="8241" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="W" I="0" O="true" N="AppId">.. <S T="1" F="AppId" />.. </C>.. <C T="U32" I="1" O="false" N="APICalled">.. <S T="1" F="APICalled" />.. </C>.. <C T="W" I="2" O="true" N="ExtraParameterInfo">.. <S T="1" F="ParameterInfo" />.. </C>.. <C T="U32" I="3" O="false" N="APIError">.. <S T="1" F="APIError" />.. </C>.. <C T="W" I="4" O="true" N="AdditionalErrorInfo">.. <S T="1" F="AdditionalErrorInfo" />.. </C>.. <C T="U64" I="5" O="false" N="TimeTaken">.. <S T="1" F="TotalTimeTaken" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):966
                                                                    Entropy (8bit):5.05495997658092
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdDVzjOEoa38XsdRDDHwpatEFwHXFJico2bo9/AWNMdNXV2/AWN4CNXpavEY/K:2dDjp38cdRgepvSUNN65Mxy7
                                                                    MD5:89B13E3D500D725790D2750ED41AD461
                                                                    SHA1:A5B014E42960D1C5C8A18CA2388EF2B9AC808DBF
                                                                    SHA-256:71486383B8CF866D2ACFA842B922341355066B4AEA9260947D3FD3DAD510AFEC
                                                                    SHA-512:A3508F54D6A989CB2EBE8E044A2B6D53FB99081E4F805B31ECB35EAE1F4163C70792A5F73C525D29B407EB75268BA1E21AEC312F2A6BA7B66B8D6C7D2D0611E1
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11571" V="0" DC="SM" EN="Office.Outlook.Desktop.EnhancedLocations.SearchResultsType" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="6125" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <C T="U32" I="0" O="false" N="CustomLocationTotal">.. <A T="SUM">.. <S T="1" F="CustomLocationCount" />.. </A>.. </C>.. <C T="U32" I="1" O="false" N="ConferenceRoomTotal">.. <A T="SUM">.. <S T="1" F="ConferenceRoomCount" />.. </A>.. </C>.. <C T="U32" I="2" O="false" N="PublicLocationTotal">.. <A T="SUM">.. <S T="1" F="PublicLocationCount" />.. </A>.. </C>.. <C T="U32" I="3" O="false" N="CallCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):989
                                                                    Entropy (8bit):4.626693671555136
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdMVzj96dRDDHwpatEergOc1NQi+kXqNO2X/c//wVrMpONd+wsvXqNO2X/c///:2dMCdRgeLrgDqJTnjqwOaniCq7
                                                                    MD5:1D24B501C7B89A161A37188026D22273
                                                                    SHA1:ABD857C4AEC8F2AE271A21F1246CD5519E9A81F6
                                                                    SHA-256:2AE8562365CA1517660C856AE1FBD3D836D912B8ED315A0F9B14D7EF6F2C3DE6
                                                                    SHA-512:8C4A3BF2FE447845F11B765C99C78AFDAA6CE06E4F96A3B805853154CD9044B87FDA114CFD48AB1FAA328FE6FE8ED4E928F89B1AAA1D9C7FD7052EE42B6FE664
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11572" V="0" DC="SM" EN="Office.Outlook.Desktop.ContactCardOOFUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="caxsv" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="Collapsed" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="Collapsed" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="Count_OOFShownCollapsed">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="Count_OOFShownNotCollapsed">.. <C>.. <S T="5" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1850
                                                                    Entropy (8bit):4.903440317966439
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdvVzjnJdRDDHwpatEfbnc1NQzDtylFfzYxKcbhZIwNnXx5Qkn/4nt8FOCFyne:2dv/dRge2Wq7xcBDcd88
                                                                    MD5:7EE3CC1770A222B1894F27AB4EE9EB9E
                                                                    SHA1:141B140B73E148E46FA572A52BEECDC5A3986326
                                                                    SHA-256:4C9E25225929CB6334ED715AFA069AD46F584135B66DCE08C275656D4A86FC2F
                                                                    SHA-512:40781187C43AFAF219DBFD8FA2BC77D8C7EF588C2894C9DF45F96BA094FB2E9D3DB52B9845CF42DF83C14B6D307AE7599136CD4D939A1BFC2CB6B5B251B8C24C
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11575" V="0" DC="SM" EN="Office.Outlook.Desktop.Performance.NCRForegroundCall" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="558" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="FOnline" />.. <F N="FCached" />.. <F N="FActiveDirectory" />.. <F N="FHybridOnline" />.. <F N="FAutodiscover" />.. <F N="FDelegate" />.. <F N="FCachedDelegate" />.. <F N="FOnlineArchive" />.. <F N="FTeamMailbox" />.. <F N="FPublicFolder" />.. <F N="FEWS" />.. </S>.. </G>.. <C T="B" I="0" O="false" N="FOnline">.. <S T="1" F="FOnline" />.. </C>.. <C T="B" I="1" O="false" N="FCached">.. <S T="1" F="FCached" />.. </C>.. <C T="B" I="2" O="false" N="FActiveDirectory">.. <S T="1" F="FActiveDirectory" />.. </C>.. <C T=
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):997
                                                                    Entropy (8bit):4.8929294943027175
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdHfkt9q3Rq3Lqt7rSdrUMx3xnGyN1DRVm0Qxk8xdKRVEYL0d+uGaDL0NO/HN9:2dJ4+sVwY1IPrKDY+cj7
                                                                    MD5:46164FED2229F7FEB8DE8819C5DE7D39
                                                                    SHA1:8065AA2D6422C0FF6723C235E5B8367A76A0643E
                                                                    SHA-256:7043B5A5505BB8CFA5A56F8E6CA0326AC72F3AB03C83D15900DC6EFE061F0BAD
                                                                    SHA-512:82A4FAA5905FF80BEC9ACEF051DDE3F709970E71E69CCAE4B9EFB16BE95809658F54E00E5A1D45FE2DD2E187D494705A6429609802675C086937B276987545A2
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11576" V="1" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="304" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="2" E="306" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="3" E="316" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. </S>.. <C T="U64" I="0" O="false">.. <S T="2" F="BucketId" />.. </C>.. <C T="W" I="1" O="false">.. <S T="2" F="ScopeId" />.. </C>.. <C T="U64" I="2" O="false">.. <S T="2" F="ElapsedHanging" />.. </C>.. <C T="U64" I="3" O="false">.. <S T="2" F="ElapsedTotal" />.. </C>.. <C T="U32" I="4" O="false">.. <S T="3" F="SkippedFrames" />.. </C>.. <C T="U32" I="5" O="false">.. <S T="3" F="Frames" />.. </C>.. <C T="W" I="6" O="false">.. <S T="3" F="SkippedModuleAndOffsetCollection" />.. </C>.. <C T="W" I="7" O="false">.. <S T="3" F="ModuleAndOffsetCollection" />.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1849
                                                                    Entropy (8bit):4.6471061952004336
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dPfSKdRge/0vMENXS0l+76D1nLIHkxtLmWCovki/NCn2:cXvRge8vMYlJ6EM8h
                                                                    MD5:BFBDDE13605514B665C9A51EEC9D096B
                                                                    SHA1:A3B537415116EED6D79D0A3B8064032AE5921AF7
                                                                    SHA-256:0BD8F551465C1C5164D0CA78C4C09C3EB936F482F4E0F348361B9E04068FF0EB
                                                                    SHA-512:DA332079CF71B649CAF6BCB90158944567B5DD3BD9D89607762B6950E8226AAA7B29CEE4984C96F88178F4A73BAF4D700ED08B52E30ABE2F2717FC5F02F0424D
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11577" V="2" DC="SM" EN="Office.Outlook.Desktop.HangReportingSummary" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSP" xmlns="">.. <S>.. <R T="1" R="11576" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="15min" />.. <F T="4">.. <O T="GE">.. <L>.. <S T="1" F="2" />.. </L>.. <R>.. <V V="200" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="4">.. <F N="0" />.. <F N="1" />.. </S>.. </G>.. <C T="U64" I="0" O="false" N="BucketId">.. <S T="4" F="0" />.. </C>.. <C T="W" I="1" O="false" N="ScopeId">.. <S T="4" F="1" />.. </C>.. <C T="U32" I="2" O="false" N="HangCount">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U64" I="3" O="false" N="AverageHang">.. <A T="AVG">.. <S T="4" F="2" />.. </A>.. </C>.. <C T="U64" I="4" O="false" N="TotalHang">.. <A T="SUM">.. <S T="4" F
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):780
                                                                    Entropy (8bit):5.169807413233588
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdCVzjrdRDDHwpat5lSPBAYykE5zNyp1fEmxjcXUtbMN1DLcXdbMNO2su:2dCtdRge3phdEQ1Mq
                                                                    MD5:0BF5CDD84CEE3B5F650550249C9890A0
                                                                    SHA1:DD3E1E63EAF182B9182AC0AB1C2C618FFB2AB107
                                                                    SHA-256:49B50BE12E7C97DD255508B3F55059F864C12782CE0DD652BC6444439F943198
                                                                    SHA-512:ACFC42E03696E472C95C628B2FBC2621CAA281CC30D544CC83B75A3A70E4C3B43744A834A0FB2D13E9E0F74DA3A9DB12F49444381DF4709CF05C466DBD4483C5
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11579" V="1" DC="SM" EN="Office.Outlook.Desktop.ComAddin.AddinEventPerf" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="200" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3013" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="G" I="0" O="false" N="AddinId">.. <S T="1" F="AddinId" />.. </C>.. <C T="G" I="1" O="false" N="EventGroup">.. <S T="1" F="EventGroup" />.. </C>.. <C T="U32" I="2" O="false" N="EventId">.. <S T="1" F="EventId" />.. </C>.. <C T="U32" I="3" O="false" N="UnhealthyCount">.. <S T="1" F="UnhealthyCount" />.. </C>.. <C T="U32" I="4" O="false" N="HealthyCount">.. <S T="1" F="HealthyCount" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1727
                                                                    Entropy (8bit):5.060237616145602
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdhVzjrdRDDHwpat5lSPBAYdLEZFayQykE5zNyAfEmxN1D2cXUtbMccXdbMxcW:2dhtdRge26wQpie1NEEEcYLqIY+NHN
                                                                    MD5:A0C0FC7C7912E651E86590301BC4A9BC
                                                                    SHA1:AE03D75EE100CFA2285C6CC10C503F5B0F50194B
                                                                    SHA-256:636CE2A813DBE4387EA9D2A4693D6A0BC599E4C9CD07B72A5D50C8EE5BB4AD2E
                                                                    SHA-512:ABB71A6AD6CCABA617E916A7CE2AC01B1C7E8F5A5BEE788BB72E38A53FC9CFB10F9A09E670F05CD90C7FF682C78822765072F6F9D53F4EE4C70C6855AE33A118
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11579" V="2" DC="SM" EN="Office.Outlook.Desktop.ComAddin.AddinEventPerf" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="200" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3013" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="G" I="0" O="false" N="AddinId">.. <S T="1" F="AddinId" />.. </C>.. <C T="W" I="1" O="true" N="ProgID">.. <S T="1" F="ProgID" />.. </C>.. <C T="G" I="2" O="false" N="EventGroup">.. <S T="1" F="EventGroup" />.. </C>.. <C T="U32" I="3" O="false" N="EventId">.. <S T="1" F="EventId" />.. </C>.. <C T="U32" I="4" O="false" N="UnhealthyCount">.. <S T="1" F="UnhealthyCount" />.. </C>.. <C T="U32" I="5" O="false" N="HealthyCount">.. <S T="1" F="HealthyCount" />.. </C>.. <C T="U32" I="6" O="false" N="GreatestElapsedTime">.. <S T="1" F="GreatestElapsedTime" />.. </C>.. <C T="U32" I="7" O="false" N="SmallestElapsedTime">.. <S T="1" F="Smallest
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1443
                                                                    Entropy (8bit):4.5876919138809225
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dS6dRgeKIirqJTOv/wOaOvghJOvDoLPnJ7:cS2RgeKnqJTO3QOCJOsJ7
                                                                    MD5:0389FAC00E751CA7770653005A982105
                                                                    SHA1:3ABD993C86DFE70344409E3C8F398A6928CD55EA
                                                                    SHA-256:337E67814E5E251E7B82931F28CA01F8549BAD41746557A11DA5584DA494C693
                                                                    SHA-512:972A735434F7814CC6AAD250733461514849D6904AB159342C7D3EF40349D6AE0F47998B34D2C5C9F3E40E4961AEFF289463DE4FCEC9380E7C32AAD7A5817128
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11581" V="0" DC="SM" EN="Office.Outlook.Desktop.Calendar.TimeZoneSelection" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="831" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="NrTimeZones" />.. </L>.. <R>.. <V V="1" T="I32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="NrTimeZones" />.. </L>.. <R>.. <V V="2" T="I32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="NrTimeZones" />.. </L>.. <R>.. <V V="3" T="I32" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="CalendarTimeZonesSelectionFrequency">.. <C>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1389
                                                                    Entropy (8bit):4.683887789015413
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dlFkhdRgeIIirqJT8hiAwOa8hjqHhPKvVBsCLDmJ7:clFkLRgeInqJT89Q8FqHFkVB/LaJ7
                                                                    MD5:37ED823C67FB02E2D49931EC3CA11295
                                                                    SHA1:CD34F1E553C38D5F91CCDE273C6BE8D14A2FAEC1
                                                                    SHA-256:E72EA1282C20D373998B3C546D1100D20C871275D3D68EB1CD52481283361AD4
                                                                    SHA-512:AAB2A02BF50230DCC272DD628871A6B29BF07F92B9DDD7ADBBAD86DE376BD46E74F5635A368618B1F243EE78A931DE8AC35B6EAED4EE7388405720FC7CF27AF7
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11582" V="0" DC="SM" EN="Office.Outlook.Desktop.Calendar.ShowRemindersOnTopUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="833" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="ShowRemindersOnTop" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="ShowRemindersOnTop" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="AND">.. <L>.. <S T="1" F="ShowRemindersOnTop" />.. </L>.. <R>.. <S T="1" F="ReminderShownOnTopOfOtherApps" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false"
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1811
                                                                    Entropy (8bit):4.17344594271943
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dSrP6dRgejKugD2ROmCg+9CDD4ROmCAq413WROH3YROfvrr:cSCRgejKu8zlY1sblTXVv
                                                                    MD5:6F4526507B71551351CCFFBBCE296A38
                                                                    SHA1:F31A54C0664DAC8B5792450C1BA41FA2B631DD24
                                                                    SHA-256:9F86AFED08E86675A9DB31E2A5BFF1EBFAC62BB914EA22EC49A25DCE6172789F
                                                                    SHA-512:98A8AE29917400B8E7F458A020E79150406E954B2781988CC8BBDA4C6ECB229419BFBC17E27955D319EC1CA2532109D97FDF10186AB4FE3C31D38CCE64AC202C
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11584" V="1" DC="SM" EN="Office.Outlook.Desktop.Mail.ToastNotificationCustomActivatorRegistryNotSet" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="1" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="23402" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <F T="2">.. <O T="OR">.. <L>.. <O T="AND">.. <L>.. <S T="1" F="IsC2RBuild" />.. </L>.. <R>.. <O T="EQ">.. <L>.. <S T="1" F="fC2RRegKeyExists" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </R>.. </O>.. </L>.. <R>.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <S T="1" F="IsC2RBuild" />.. </L>.. <R>.. <V V="false" T="B" />.
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):482
                                                                    Entropy (8bit):5.402511118481495
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdWVzjNJh6dRDDHwpat5lil+NFIqBdzbuJENO2su:2dWFcdRgeJIi9Ss
                                                                    MD5:E32167A29069C0C7FF6D3E55D7397C14
                                                                    SHA1:18CBED1EE16237BEAAAC65418DE5223657F19C8B
                                                                    SHA-256:71E4A1EF364BEC64E2D41295E47AB3D4FA72F9C50FA51DEA6C66ED9A2B4AD0DF
                                                                    SHA-512:E1186FA48090591884F4C80AF9016A128156ECA20B96942FCBC3D3A9DF0EC6E9CB410656EA719E7D73DAEB0BC2D5480EBACD7BC16BB48C3CA8ACFFA1EB7647F3
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11585" V="0" DC="SM" EN="Office.Outlook.Desktop.Calendar.ShowRemindersOnTopOptionsUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="20" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="832" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. </S>.. <C T="B" I="0" O="false" N="ShowRemindersOnTopFeatureToggled">.. <S T="1" F="ShowRemindersOnTop" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):600
                                                                    Entropy (8bit):5.1976634978025436
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdLVzjp3PdRDDHwpatEqa2Hc1NQn94XjuMm3NXNO5AHNUlu:2dLX/dRgeZiq94zPmd7
                                                                    MD5:F54D0E7EF047FDB216255E3658544250
                                                                    SHA1:012E9B3E9F0E3C87553947F468262A78BF7FB535
                                                                    SHA-256:530DCB9E2BE273A5D2E7833F6A12CEA4320A8A644757B8779CED810ACCCCD64A
                                                                    SHA-512:44232D994CA5C23EF3B7E8E9D7C4C3B968F6DB1574896790483499E5AA24A232718F758E5422890906550AF737E6454FBE0AB625F784CF7CB92A296F17C9858A
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11593" V="0" DC="SM" EN="Office.Outlook.Desktop.UserDefinedRulesCount" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="13101" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="UserDefinedRulesCount">.. <A T="MAX">.. <S T="1" F="UserDefinedRulesCount" />.. </A>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):841
                                                                    Entropy (8bit):5.212523722154653
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdXVzjUnPkdRDDHwpat5DU2KP6DNSJdIxX3AvDRkMdVlOKXtMdfMxONLd+DUiN:2dXBdRgeouyIxnOVz+dkg7+z
                                                                    MD5:B0409870D83FC2B81EFB6FE40D078DF8
                                                                    SHA1:88C66C8692B10048AED6C859F38D7F7598095FE3
                                                                    SHA-256:94D8C0DC7C075D5A3B6026DE63125F400277A633032CB46ED76B9A65C0213FDC
                                                                    SHA-512:4ED16BC8731D07A470FB54F4E4570D29B9F7B99A3C6901B68AE9B6FCF69AD88A164B152A4B9E6C24322B439C2F8239579C4230FB5216185247DA58072261047B
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11597" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.ModConvGroupSendLocalLieAction" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="13031" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="BIN" I="0" O="false" N="HashGroupSmtpAddress">.. <U T="OneWaySHA1HashToBinary">.. <S T="1" F="GroupSmtpAddress" />.. </U>.. </C>.. <C T="W" I="1" O="false" N="NewConvId">.. <S T="1" F="NewConvId" />.. </C>.. <C T="I32" I="2" O="false" N="ActionType">.. <S T="1" F="Type" />.. </C>.. <C T="U32" I="3" O="false" N="Source">.. <S T="1" F="Source" />.. </C>.. <C T="W" I="4" O="false" N="OldConvId">.. <S T="1" F="OldConvId" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):674
                                                                    Entropy (8bit):5.283524920229644
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdr1Vzj+1MYOaBdRDDHwpat5DBN2KP6DNSJdIxX3AvDRkMcNLtolfMxNO2su:2dr181caBdRgeTluyIxn9Ok3
                                                                    MD5:E290D90EE8D7DDB3DFF1D72CB3EB85C6
                                                                    SHA1:95D499091026BC262EE1CCD67AE52B87D0371C32
                                                                    SHA-256:5E5F51372B6F412A1485D0A77191D011AF2908C394CC55C0F6236C8670936C0D
                                                                    SHA-512:B82D5AEE4C2B7C1DE27F04B227811E3EAC118197AB708DFBB986DECCFAD0312EC0C0B68F570A0A2887C6E1EECBD0E68F9A3A875F67179D6F9EE3E0F43078E04A
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11599" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.GroupTransitCacheNotifyCache" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="20070" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="BIN" I="0" O="false" N="HashGroupSmtpAddress">.. <U T="OneWaySHA1HashToBinary">.. <S T="1" F="GroupSmtpAddress" />.. </U>.. </C>.. <C T="I32" I="1" O="false" N="Source">.. <S T="1" F="Source" />.. </C>.. <C T="I32" I="2" O="false" N="NotifType">.. <S T="1" F="Type" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):773
                                                                    Entropy (8bit):5.1682185883197285
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdGOjVzjNa/h6dRDDHwpatEYIqB2iIqB2coNBHpYXHaSMwSXHhSMNOAdHNS7lu:2dGoucdRge5IipIiOvHpYuDr
                                                                    MD5:51F3D63DA3A162B4E417E6971EF43A9D
                                                                    SHA1:89C619EEE779C08D5F910B06C77693418E017F80
                                                                    SHA-256:004569769A4C76FCAE6C99EACF56CF7633AD60FAFB7E0CE23DBECB4AD0DF54A8
                                                                    SHA-512:D21BEC0DACB781FAA1CCB9C32885BFC572A501BC3586D36296233329A73C83FEC112D4CEC544D81C8518C3AADF4C740E43447D46C60850D48C9BF1ED9F7CCC6D
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11601" V="0" DC="SM" EN="Office.Outlook.Desktop.Calendar.OrganizerDNFUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="902" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <Etw T="2" E="903" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <TI T="3" I="Daily" />.. <A T="4" E="TelemetryShutdown" />.. </S>.. <C T="U16" I="0" O="false" N="MeetingsWithDNFAvailableCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U16" I="1" O="false" N="MeetingsWithDNFEnabledCount">.. <C>.. <S T="2" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="4" />.. </T>.. <ST>.. <S T="1" />.. <S T="2" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):768
                                                                    Entropy (8bit):5.148924262031493
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdGfVzjNoc6dRDDHwpatE+tFIqB25GIqB2coNBvXHaSMFy8XHhSMNOAdHNS7lu:2dGfMvdRgeDTIi/IiOvv2tDr
                                                                    MD5:CAC570D07C2689D6B7078B966C2A14B6
                                                                    SHA1:C846A38B97C2A11B6EC2B779D0D3D1BA59E445D0
                                                                    SHA-256:28F341EA9A54F05FD502C789D55E2A022FE1CCCC8E1BBA0128CF1946AA65FA44
                                                                    SHA-512:B645F7D4335DE0FECE615D6D7CD7F8E943E86B3816331B067293C6E98F55D269CDC18C3766053B517931DEDF2BE9755A1AE1F24FF01DC5443815DE35C38A7294
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11602" V="0" DC="SM" EN="Office.Outlook.Desktop.Calendar.AttendeeDNFUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="904" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <Etw T="2" E="905" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <TI T="3" I="Daily" />.. <A T="4" E="TelemetryShutdown" />.. </S>.. <C T="U16" I="0" O="false" N="MeetingsWithDNFCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U16" I="1" O="false" N="ForwardAttempedOnDNFMeetingCount">.. <C>.. <S T="2" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="4" />.. </T>.. <ST>.. <S T="1" />.. <S T="2" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):2823
                                                                    Entropy (8bit):4.667743054516838
                                                                    Encrypted:false
                                                                    SSDEEP:48:cGq4RgeqRpPYBf+unhvn2sn0kQ5MHtnIFc:VLRgeqRRYBf+4hP26w5MtKc
                                                                    MD5:88F9AD5500BA7A90B93ACADE3A279F98
                                                                    SHA1:A4EE759E607A4C8FB782AC3D1DDE253ED54500B6
                                                                    SHA-256:2F23335CB7D55DA7F03712822DCFF409C09B0D85C455C46EF003266BB3DE61D2
                                                                    SHA-512:37388FB2BEADF9FCE9524CC1F8A409064C170F88617F85AE46C60B2268349F7FF07C5376D6E6398A78CA95E0637214AC335F3B143BF7427E4E33C640F9F824A8
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11603" V="0" DC="SM" EN="Office.Outlook.Desktop.CMapiSvcMetrics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="1" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="823" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="2" E="825" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="3" E="824" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="4" E="839" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="5" E="840" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="6" E="841" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <F T="7">.. <O T="EQ">.. <L>.. <S T="5" F="PrivateMapiSvcInfFileSource" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="8">.. <O T="EQ">.. <L>.. <S T="5" F="PrivateMapiSvcInfFileSource" />.. </L>.. <R>.. <V V="1" T="U32" />.
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):507
                                                                    Entropy (8bit):5.261684898715884
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdG8VzjyWoe6dRDDHwpat5CcTer3e/1yf87SZNO2su:2dG8QxdRgeMc6r3edx7I
                                                                    MD5:4FF6E7DD1A005A6E0EA09EB6C84CB4EE
                                                                    SHA1:F2CD21F7D451000F25B231E5BA2EC29BB93A6972
                                                                    SHA-256:4CADE7447043CEC0D4E40FC8E157C30A2AEE4FFB1D4BD0A384ADA34395AE0D72
                                                                    SHA-512:F85846879A851F3BAA27CB5ECA0DE56D6CBC1964AA55661BCB2A5CADEA1466204758A7EEC3A8BBDCFE3D75CC69B715F46ED6261F5F682A8D69C6EBFC236FAFAA
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11605" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.CreateUnifiedGroupServerResponse" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="50" DL="A" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="cjmad" />.. </S>.. <C T="U64" I="0" O="false" N="DialogVersion">.. <S T="1" F="DialogVersion" />.. </C>.. <C T="I64" I="1" O="false" N="Hresult">.. <S T="1" F="HRESULT" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1526
                                                                    Entropy (8bit):4.252850455875291
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdGOfkWx2GeOSq2H+tNqNO/qNX/c//wVrMpONdJH+wsvXlOaNeFOH/M//O5eN9:2dG0vLRHt4y0jUwOfI6Ah7vLLaVun3j
                                                                    MD5:375962AC37B863FB8F56595FE41A4220
                                                                    SHA1:C35BB4FFD7877681A03CB4C1FC200235B6C12AFC
                                                                    SHA-256:2D7D1A73B0CE6FEA475C5F07C94EE62A90D3A0DFD2938E7777B1D19B80777F85
                                                                    SHA-512:7C53646A0C957A46B61B60FFD147EC00ABD5DF824AA8FA860473D93E0558AFE0239C4614BFC9E3808CFC0D6F4F6061D1A4EB025ABDBA674EDF9AAEB1E4CDA2D5
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11607" V="0" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="3483" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="2" E="18034" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <F T="3">.. <O T="EQ">.. <L>.. <S T="2" F="hasGroupRecipient" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <Etw T="4" E="13031" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <F T="5">.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <S T="4" F="Type" />.. </L>.. <R>.. <V V="3" T="I32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LE">.. <L>.. <S T="4" F="Source" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <Etw T="6" E="348
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):590
                                                                    Entropy (8bit):4.92401885448348
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdG3VVzjUCRlsdRDDHwpat5Di0cg+u/Y//O5fX/c//kopONGYM6gEoyNOjsu:2dGFV6dRgercfudTRs
                                                                    MD5:C9ED7E00C5FC6A2437F9DEFB2CAD4266
                                                                    SHA1:6DB6A4CEDAFD240DA128CB0B89D052BACD48120D
                                                                    SHA-256:9D8A2BF7AE190FE35A148480EA604BD1641A2F392E2B3458F5F766C02A0DDE0A
                                                                    SHA-512:7519ADFC64CEECC861D2E481B1DAEC444331EB3E1C4CA5493F774A19C38AE126503669CB6DB1510E4A39BA15F18B736E37C68CBEEAA3FEFF615A6FE662BFA2CE
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11608" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.ModConvDisplayLocalLieLatency" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="11607" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="86400000" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="LocalLieDisplayedLatency">.. <S T="2" F="0" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1518
                                                                    Entropy (8bit):4.257585206740892
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dGgvL9t4malTVcwOaV/JVg9vL59qhUPa2HLkq:cGWxt4maTyQtJifLkq
                                                                    MD5:5E44132333395A63CEBC650C9EE72AF7
                                                                    SHA1:2A6C61334547CEC32D45465FA9281295B81EF829
                                                                    SHA-256:3C69F711C08A729821A020F4121E0C022F7F14B8FEECCDA19EB9D1942AD0B89F
                                                                    SHA-512:A1E64365D3FD7EA54422AA1521FFF9F973C72002E17F454FD7C49F79CDD62A78577BCF3C86CFF6637356320F3AA6E7238CD0F78C9918B0CEE8D16A411EF46C65
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11610" V="0" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="3483" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="2" E="13031" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <F T="3">.. <O T="EQ">.. <L>.. <S T="2" F="Type" />.. </L>.. <R>.. <V V="3" T="I32" />.. </R>.. </O>.. </F>.. <F T="4">.. <O T="EQ">.. <L>.. <S T="3" F="Source" />.. </L>.. <R>.. <V V="0" T="I32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="3" F="Source" />.. </L>.. <R>.. <V V="1" T="I32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="3" F="Source" />.. </L>.. <R>.. <V V="2" T="I32" />.. </R>.. </O>.. </F>.. <Etw T="7" E="3484" G="{aa8fa310-0939-4ce3-b9bb-ae0
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1612
                                                                    Entropy (8bit):3.261252887216048
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdGrZfi0c5Mf+u/lO1eKNuG/BfMN3/8//7LMJuNH/M//KNuG/NOMN3/8//7LMo:2dGrfcTuyQCDDNCgTeyHqV
                                                                    MD5:41E04558B36BC671E456895430C55C14
                                                                    SHA1:2BA621AF7827DE517A5FB2986BCB14E480A1F6F9
                                                                    SHA-256:7274EECE758E786BFBA3AD8C4FAE8B7064ED96DA2DCF7D2C9E5CDB67F23660CF
                                                                    SHA-512:6B8FEBD4099106E425743BEAB19B48E02130F3E3DC8E76D46C1B971237F9F60906CB75A84822FAA4D70BB3D1384E461A2B1357DF0E18ED2495103F1841C03B33
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11611" V="0" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <R T="1" R="11610" />.. <F T="2">.. <O T="AND">.. <L>.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <U T="EqualsNull">.. <S T="1" F="0" />.. </U>.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </L>.. <R>.. <O T="EQ">.. <L>.. <U T="EqualsNull">.. <S T="1" F="1" />.. </U>.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </R>.. </O>.. </L>.. <R>.. <O T="EQ">.. <L>.. <U T="EqualsNull">.. <S T="1" F="2" />.. </U>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):988
                                                                    Entropy (8bit):4.421351563273142
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdG4VzjUysdRDDHwpat5ai0c1+u/lOo//eJfH/M//Uo5eNX/c//o//eFOH/M/+:2dG4+dRgeQc0uaDbJAs
                                                                    MD5:BEAA2FD1A2D038F5DEE15C2DBABF4C88
                                                                    SHA1:D689718FB5220A21093922E5BAD77889E9197CF7
                                                                    SHA-256:E548AFC38ABC73D008C0587FC1F9DF5EF993FFD1C6858AD8577F9350F2AA4DF1
                                                                    SHA-512:72DDA1F28D4B19A8BB9570EDA3492EC9957A833CF1481CF3D0A7526438C65D6763D5646E6E4BA8B4FE470F5DA196DC7B5D9138BDCE5CB231C0ED186CEAE6CFAB
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11612" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.ModConvReplaceLocalLieLatency" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSP" xmlns="">.. <S>.. <R T="1" R="11611" />.. <F T="2">.. <O T="AND">.. <L>.. <O T="LT">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="86400000" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LT">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <V V="86400000" T="U32" />.. </R>.. </O>.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="LatencyReplacedBySentItemLocalLie">.. <S T="2" F="0" />.. </C>.. <C T="U32" I="1" O="false" N="LatencyReplacedByTruth">.. <S T="2" F="1" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1384
                                                                    Entropy (8bit):4.376237125125716
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dGP1PdRge8cTuywiAt4tiATuiEK2CmRcrEEwuo0+7:cGP1lRge/uyit45TIK29mH+7
                                                                    MD5:E4345E31645B23CBD29C50789BF9128D
                                                                    SHA1:A27FAF9D4998A48401AC3262E773F13E294A3380
                                                                    SHA-256:3A0BDBF2A24D2F185BACF9B61A5C5B550BE1A20D0E22AA6E115793CF4E85F275
                                                                    SHA-512:26A35C0CD4A2657D7DFD2BBBC25BCABEEB989C5AA28FFB6F5E057B4A1F0512818BA383DE05075BC422702FD6EC071B4C948B86F59310769DF509A747673926D8
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11613" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.ModConvLocalLieCount" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="11610" />.. <F T="2">.. <O T="EQ">.. <L>.. <U T="EqualsNull">.. <S T="1" F="0" />.. </U>.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. <F T="3">.. <O T="EQ">.. <L>.. <U T="EqualsNull">.. <S T="1" F="1" />.. </U>.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. <F T="4">.. <O T="EQ">.. <L>.. <U T="EqualsNull">.. <S T="1" F="2" />.. </U>.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. <A T="5" E="TelemetryShutdown" />.. <TI T="6" I="Daily" />.. </S>.. <C T="
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):361
                                                                    Entropy (8bit):5.39233656535639
                                                                    Encrypted:false
                                                                    SSDEEP:6:TMVBd7K+GkhOVzjTjceBeaBdRijeDHwp1MTZ5CuHps3a31On2sby:TMHdG3VzjTjc7KdRDDHwpat5Cks3s1OQ
                                                                    MD5:F8744BD1BE5242D88C34AA2C556EC16B
                                                                    SHA1:AD14C087BDE7EB78DA6475ED280FCECEA51B8AA1
                                                                    SHA-256:D9260C1466FE0EA17B7D9AB97F7889B44C8CD9A4A3153C12708EB08A565D4A01
                                                                    SHA-512:9AD9FAE2CCCBCD6B9FCAA96B33DF7A4689FF836E163709676B70212DAB2F9EB87D817B0A581B6930BB8E18E4560146CAB239447C3F670DAF2BD64A24844DCF5C
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11620" V="0" DC="SM" EN="Office.Outlook.Desktop.SearchFeedbackButtonClickCount2" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="50" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9057" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. </S>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):412
                                                                    Entropy (8bit):5.288494063001617
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdGCVzjen4ndRDDHwpat5Cker3Xy0Q4gU4o9NO2su:2dGCoedRgeMrr3ir65z
                                                                    MD5:8DCAAA83EE50033AF90C1787EADECF6C
                                                                    SHA1:9B662B4672E5D3BB8837158B15125F486C9B0123
                                                                    SHA-256:8C12B4ACC9D2F30E767F1FD733D844C72308517A0641FA8AF63226C8838DC48D
                                                                    SHA-512:064C0A4BF927F278B3859A1A0A38FA21CD967F30BB539A0ECF5E9DCBA9ABBCC4DEEE9E959FDB50E6D8899A8F0FA423F9B133CB88D09B18FCA0D382D4E17A9FD4
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11621" V="0" DC="SM" EN="Office.Outlook.Desktop.AutodiscoverServiceClient.SuccessPath" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="50" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="ci7jr" />.. </S>.. <C T="W" I="0" O="false" N="SuccessPath">.. <S T="1" F="SuccessPath" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):997
                                                                    Entropy (8bit):5.11152206841213
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dG0odRgeMrrZmedqQToGyo0X1VdoPWUoA+07I:cG0ARgesAQToGyo0lVdoPWUoA+0U
                                                                    MD5:2B92E217714E525D779D275EC93B5614
                                                                    SHA1:F0D066061FC8C5421BE7FCA595999617834F307E
                                                                    SHA-256:0DB79E1F1623E80DCBBD309266DB672C5848087973D3572B28F054BA0094DE95
                                                                    SHA-512:048901F4EC602786A82BF720668D116A0CC6983FE81A915E151312E2149E13F5AA5E5AF8433A25DFB288439B551D1F4C47BEA3D0424358404159250C9F1152C7
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11627" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.GroupMembershipChange" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="50" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="ckvxl" />.. </S>.. <C T="U64" I="0" O="false" N="DialogVersion">.. <S T="1" F="DialogVersion" />.. </C>.. <C T="U32" I="1" O="false" N="DialogType">.. <S T="1" F="DialogType" />.. </C>.. <C T="U32" I="2" O="false" N="NumberOfAddedUsers">.. <S T="1" F="NumberOfAddedUsers" />.. </C>.. <C T="U32" I="3" O="false" N="NumberOfRemovedUsers">.. <S T="1" F="NumberOfRemovedUsers" />.. </C>.. <C T="U32" I="4" O="false" N="NumberOfPromotedUsers">.. <S T="1" F="NumberOfPromotedUsers" />.. </C>.. <C T="U32" I="5" O="false" N="NumberOfDemotedUsers">.. <S T="1" F="NumberOfDemotedUsers" />.. </C>.. <C T="I64" I="6" O="false" N="Hresult">.. <S T="1" F="HRESULT" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):460
                                                                    Entropy (8bit):5.368196352254861
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdGT1VzjaBdRDDHwpat5DL2GeOXlet1MNO2su:2dG5OdRgedvLAk
                                                                    MD5:878875EF33D9BB4782972971DFFB2F4F
                                                                    SHA1:F9B747392C37CDF72E10FE8EAE966049715C4C92
                                                                    SHA-256:6BF7C3F96B107DA94786A8D72C7D2DE7753B28B32464EF79251C363EC67C7CAA
                                                                    SHA-512:B9F3844F1E6D2494B4B98204221023E6CE07D84AFD5E8E70C4FF4CA103D87B81BF0C0B7EC0E4F15FBB00729EB57F3FB82CB213F93E5E105FD0E57703D6FF7BDB
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11631" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.StopGroupTimerSync" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="1" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3126" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. </S>.. <C T="U32" I="0" O="false" N="TimedSyncRegDisabled">.. <S T="1" F="TimedSyncRegDisabled" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1213
                                                                    Entropy (8bit):4.7939456440401305
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdG9OkWx2GeOSNX2GeOSaTb2GeOSSwdOanD2DRW8/PlNfXES/odXS61CSpx+IA:2dGcvLOvL5vLsG1luDjCUu3rNl1R
                                                                    MD5:14795F07F55479AC04D0225B2D9738DC
                                                                    SHA1:A279817545F47B08AA9C479F1F92119CCB91ADCF
                                                                    SHA-256:5635AF79DC4D130D6D20D4C07D840C538FC5289D1F970B7C51AF710369EC8FFB
                                                                    SHA-512:877410D8475D535AD904186288524F261EA1F6590AF6F355117FB905E7A37AB45F097AFB1EA2B5ED13715BD206C2E3DC3EB0973D8770202B4D7FCD209B9844D6
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11637" V="0" DC="EUII SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3483" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="2" E="3459" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="3" E="3484" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <TO T="4" I="30s">.. <S T="1" />.. </TO>.. </S>.. <G>.. <S T="1">.. <F N="SmtpAddress" />.. </S>.. <S T="2">.. <F N="Group" />.. </S>.. </G>.. <C T="W" I="0" O="falseNoError">.. <S T="1" F="SmtpAddress" />.. </C>.. <C T="W" I="1" O="falseNoError">.. <S T="2" F="DisplayName" />.. </C>.. <C T="U32" I="2" O="false">.. <S T="2" F="UnseenCount" />.. </C>.. <C T="B" I="3" O="false">.. <S T="2" F="ShouldAdvise" />.. </C>.. <C T="B" I="4" O="false">.. <S T="2" F="IsFavorite" />.. </C>.. <C T="B" I="5" O="false">.. <S T="2" F="IsTopPrankie" />.. </C>.. <C T="B" I="6" O="false">.. <S T="2" F="IsRecentlyVis
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):922
                                                                    Entropy (8bit):4.823261789882077
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdGbpjVzjfmBwdRDDHwpat5ti0c9+u/5lOrX/c//tpONGA2doXjnu0nt7tOcyr:2dGtjJfdRge9csuQaoz/SIyh7
                                                                    MD5:5F18C5EE2EE201C21B03C935D738A85C
                                                                    SHA1:BB672F26D1B52F34CEAA74350BAF1EAF0DFE5F4D
                                                                    SHA-256:E5362153CA6F04F6F4EF13D69D7B82DA690FA119F40CC184E40F8BBC391C4F74
                                                                    SHA-512:892F749435D553170EE8A45403164CDCF69F8C13D82224F921112AF75C012596BA7E15E5594E89ED8FF1A3639E532877145FF2B0345B78258F3FD86E7960C4D9
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11639" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.GroupVisitedWithNonZeroUnseen" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="300" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="11637" />.. <F T="2">.. <O T="NE">.. <L>.. <S T="1" F="2" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="NonZeroUnseenCount">.. <S T="2" F="2" />.. </C>.. <C T="B" I="1" O="false" N="ShouldAdvise">.. <S T="2" F="3" />.. </C>.. <C T="B" I="2" O="false" N="IsFavorite">.. <S T="2" F="4" />.. </C>.. <C T="B" I="3" O="false" N="IsTopPrankie">.. <S T="2" F="5" />.. </C>.. <C T="B" I="4" O="false" N="IsRecentlyVisited">.. <S T="2" F="6" />.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):701
                                                                    Entropy (8bit):4.832194960740667
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdGZVzjfmMwdRDDHwpatEi0c9+u/qNOrX/c//tpONdQicih224eLEXHhSMNO3+:2dGZJKdRge8csuyyuJZ97
                                                                    MD5:2BD8AB15237D265974F14E0BDCC69F9D
                                                                    SHA1:C2575F3A9A15D80C08AE20C2C1884222E29FFC9F
                                                                    SHA-256:4F43B19151FA9E90C2A88A7F26420515AE7A8C5AF6653722C90CAAD74D4230CE
                                                                    SHA-512:B3B6EE2309A4DF631FD0A09896E60FAE3FFCB3938A5CB93A10448B5FAC9F233B9A3DDD53420B061DA27DC69EB73DAAFE25E77AE38FC579C09F0FF1F904D850E5
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11640" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.GroupVisitedWithZeroUnseen" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="11637" />.. <F T="2">.. <O T="EQ">.. <L>.. <S T="1" F="2" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <A T="3" E="TelemetryShutdown" />.. <TI T="4" I="Daily" />.. </S>.. <C T="U32" I="0" O="false" N="ZeroUnseenVisitCount">.. <C>.. <S T="2" />.. </C>.. </C>.. <T>.. <S T="4" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1399
                                                                    Entropy (8bit):4.07908865712039
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdGkfkTb2GeOSiM9+tN5lOkX/c//tpONdSwOS/I+xczPO+alOaNevTOH/M//k0:2dGnvLCstV1Qck6qTPfXK5xAZ
                                                                    MD5:5CF1168B92DF59DD85035277F7EB3C0D
                                                                    SHA1:8F7FA47B49568155722110550D95FD531384D23D
                                                                    SHA-256:B4C7BD0FDD3FAE338D692797A43CDF2316DF4AE303703373422D1D26B96A9420
                                                                    SHA-512:F2DFFD1019D910A09A067E459C9F3409675F90B5765BA0351882FB67FFF6F46796DB11942C55C812A3CC3BDEF78464DF859EFBB9D9497E2245F82F4DA7B519AB
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11641" V="0" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="3484" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <R T="2" R="11637" />.. <F T="3">.. <O T="NE">.. <L>.. <S T="2" F="2" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <TO T="4" I="5min">.. <S T="3" />.. </TO>.. <Etw T="5" E="241" G="{f762ce39-ac6c-4e1c-b55f-0e11586e6d07}" />.. <F T="6">.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <S T="5" F="StoreType" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="EQ">.. <L>.. <S T="5" F="LogStr" />.. </L>.. <R>.. <V V="15" T="U32" />.. </R>.. </O>.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T=
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):696
                                                                    Entropy (8bit):4.927767271855225
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdGz+4VzjfXS5dRDDHwpat5ti0cPA2KLEXByv2aGb8OrX/c//1OpONkMNOqHN9:2dGy4JmdRge9cRNW7
                                                                    MD5:E48AD6BA2E7E8DA3BE4EE62E5AF5A3B9
                                                                    SHA1:E9909A98CC925410AEBBCFBA4FAE9E24F3B20FA3
                                                                    SHA-256:7AFAD94DF3F8AA9504092CE1EA975C67BC92533854DF7D4BE0AD03395497329B
                                                                    SHA-512:8D0F2CDFED9C0A568F40EAC728F7B8C8BFFA9E70263D3B42A93CF65EFF20862E11776993A2750AFC306147BBB1318FDD8F89A172E0D6E0B0BAB3C6E65DB8C73E
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11642" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.GroupVisitsContentSyncLatency" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="300" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="11641" />.. </S>.. <C T="U32" I="0" O="false" N="NonZeroUnseenVisitCount">.. <S T="1" F="0" />.. </C>.. <C T="U32" I="1" O="false" N="NonZeroUnseenVisitSyncLatency">.. <U T="100nsToMs">.. <O T="SUB">.. <L>.. <S T="1" F="2" />.. </L>.. <R>.. <S T="1" F="1" />.. </R>.. </O>.. </U>.. </C>.. <T>.. <S T="1" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):805
                                                                    Entropy (8bit):3.961646487265531
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdGWfBfczPO+u/lOaNeLTOH/M//k5eNX/c//aNemfH/M///5eNpONQ5aMNO/Hb:2dGgyuXY6qTTfxq7
                                                                    MD5:69F3C5B599738F7FFEC592B6EB905B66
                                                                    SHA1:478D47AEA85BBF6DD508C1DCCB30C2923C8A165A
                                                                    SHA-256:1B48993B7CA638BFF78E21DC31FE31345EF348ADD5CDA1E5072EF5C879312985
                                                                    SHA-512:C9743EC917ADE9F12B709B23A45A63851335E6779A9A748DE3F204D129E496FC3ADDEE09BAC60B52729898491AF4FFB82C7FCEE88AB401D74339D43003D03127
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11643" V="0" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="241" G="{f762ce39-ac6c-4e1c-b55f-0e11586e6d07}" />.. <F T="2">.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <S T="1" F="StoreType" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="EQ">.. <L>.. <S T="1" F="LogStr" />.. </L>.. <R>.. <V V="15" T="U32" />.. </R>.. </O>.. </R>.. </O>.. </F>.. </S>.. <C T="F" I="0" O="false">.. <S T="2" F="MessageCount" />.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):792
                                                                    Entropy (8bit):5.108078659105838
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdG8VzjlPdRDDHwpatEUX2GeOSiMYQicih22uXHhSMj+UXswfXp931ZC/hEXNP:2dG8HdRgervLCjJ9b9lGY
                                                                    MD5:5E55AE1F0F9797B94D3B334AAA18A5E9
                                                                    SHA1:71530C677F6C15D063C75189636B0D04C840564A
                                                                    SHA-256:9D01CD8DDB5E550E7D7F46589BEA6A1C902815BC3BDD55E8ECA5D19D41FA2E09
                                                                    SHA-512:2B0EC534DAB221564CDC52A6F423738B90BA34159B6FA5367131D041470793D3A709CA7F1C6EAD8F8F2A891BF86D4CFFBC199D2DC6CBB75D57B12CB3184E4572
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11644" V="1" DC="SM" EN="Office.Outlook.Desktop.Groups.TotalSyncCount" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3459" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <R T="2" R="11643" />.. <A T="3" E="TelemetryShutdown" />.. <TI T="4" I="Daily" />.. </S>.. <C T="U32" I="0" O="false" N="TotalSyncCount">.. <C>.. <S T="2" />.. </C>.. </C>.. <C T="F" I="1" O="true" N="AvgSyncMessageCount">.. <A T="AVG">.. <S T="2" F="0" />.. </A>.. </C>.. <C T="U32" I="2" O="true" N="GroupAdviseFlightFlags">.. <A T="FIRST">.. <S T="1" F="FlightFlags" />.. </A>.. </C>.. <T>.. <S T="4" />.. <S T="3" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):596
                                                                    Entropy (8bit):5.246372126859281
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdG8Vzj8CMRiYdRDDHwpatEAT32GeOSc1NQnADirHaSMNOA/HNUlu:2dG8CCMRddRgetvLvqSP7
                                                                    MD5:E95A59C1371BC2EDC6438207E5E4EEFA
                                                                    SHA1:F8CBB23174007C506746DE287BCFD51F914E3389
                                                                    SHA-256:86A7C5A6E82E65EFC191E1E68FE20E7A38392282EFCE092E988E02D754525A77
                                                                    SHA-512:04E84D6CE531255D7D1A36B8378BC4838AC416BEF1CF1C9CE73A73CA9019685270D39B1A4CF86641BD6722BC18721D5838824A96433B949A3A9F70283BB03BB0
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11649" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.CountSuccessOfEnhancedGroupFollow" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3260" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="CountofSuccessEnhancedGroupFollow">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):687
                                                                    Entropy (8bit):5.126823146916047
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdGrVzj7ki4sdRDDHwpatEiHc1NQzDSSwOXnlfInwxCXHaSMNO5csu:2dGrSi4sdRge2qKtqnlvQu
                                                                    MD5:9A847FA4B6D8CE5FF25C39116ECBB6F6
                                                                    SHA1:70EBD99A3EF893AA22075F8211A330EE68CEB424
                                                                    SHA-256:FA642CCBA88219B8DAC4F931016412F9708C22C0C1FB3BEB6960FC747343B183
                                                                    SHA-512:89463AD7958638D45D9C87D7E4994F48D3250CC4695261577D98305EFFF41195A31953E0F5E9BCFFFA3CE31439B2832E5E4AE95009A9AE8CD8BD2AF641367226
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11651" V="0" DC="SM" EN="Office.Outlook.Desktop.SendToOneNoteAddin.ButtonClickTelemetry" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="19035" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="ItemType" />.. </S>.. </G>.. <C T="W" I="0" O="false" N="Type">.. <S T="1" F="ItemType" />.. </C>.. <C T="U32" I="1" O="false" N="ButtonClickCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):744
                                                                    Entropy (8bit):5.277491808508557
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdGH1VzjFzdRDDHwpat5DISeU8MbRyk+/XSpD/LWgONO2su:2dGH1nzdRgemSR1bRq
                                                                    MD5:6C473735DDE7FC149A8ADB47E9A88F6C
                                                                    SHA1:77331B90D0B09F12F99A63BED59B726A5B582BE8
                                                                    SHA-256:5BDA375FADB48365A9BF8F7030FFEBDD89E3AB6866B362D358F9CEA2338F1C05
                                                                    SHA-512:9F9BF87D5FD3724595F050C991FC36B4ACF32E4590329AD537FFE062D9E536ACD41E7CD24328ED621F3EFEE9E906A96AA01BC75103524EAEAA41CE3BD3A0CEA0
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11657" V="0" DC="SM" EN="Office.Outlook.Desktop.NullOutlmimeHeaderTableRow" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="1" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="163" G="{13967ee5-6b23-4bcd-a496-1d788449a8cf}" />.. </S>.. <C T="U32" I="0" O="false" N="MIMEPropertyContainerID">.. <S T="1" F="MIMEPropertyContainerID" />.. </C>.. <C T="U32" I="1" O="false" N="LoopIndex">.. <S T="1" F="LoopIndex" />.. </C>.. <C T="U32" I="2" O="false" N="HeaderRowIndex">.. <S T="1" F="HeaderRowIndex" />.. </C>.. <C T="U32" I="3" O="false" N="PropertyRowNumber">.. <S T="1" F="PropertyRowNumber" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):2264
                                                                    Entropy (8bit):4.614108140239659
                                                                    Encrypted:false
                                                                    SSDEEP:48:cG+efRgeSqJTLrQLYJLTf6V7thiA+ulMQ:VFfRge53rsY1Tf6V7mA+EMQ
                                                                    MD5:60B4C7E806CEA29568CD09B187789DF6
                                                                    SHA1:7162EEBDB33BF3510A5B958F941D03E625806EB9
                                                                    SHA-256:60AE6580182F624F79A43AE6731691D16CB82D0232FE93601341BE8EEB72BEC9
                                                                    SHA-512:5920991A47A4B5C45EBBDB5B61C7C7DC4E0F016704679EE1BBFB7FEFF77795E11D1242D54681B5DAF2CAA4C5475D885507A7670648D710A56B6300BB7F95B8EF
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11658" V="0" DC="SM" EN="Office.Outlook.Desktop.Social.PickerActivites" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="4051" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="MentionPickerActionType" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="MentionPickerActionType" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="MentionPickerActionType" />.. </L>.. <R>.. <V V="2" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="1">.. <F N="MentionPickerType"
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):428
                                                                    Entropy (8bit):5.3112013575014405
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdGDVzjon7dRDDHwpat5lkB9Je1zVhEXMNO2su:2dGDEdRge7E9fXk
                                                                    MD5:87D41D382120A6802A3BB2958687B53D
                                                                    SHA1:2951AABC5380E524126A94385E6F72B281859552
                                                                    SHA-256:12571CFDF73A7408D3D31D386E2572D1AC9BA843F3D67346496266E4F1EA990E
                                                                    SHA-512:A4365C6951D987F124A6B089EF965DCFBD2C36CEA2A6C882C1B074A7E226B73DCF3EBEA7D4C05178BE8EF1688497F9857A37765C4FFC7520EAEBD7EDF0F38607
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11659" V="0" DC="SM" EN="Office.Outlook.Desktop.Pst.BestBodyMarch2018" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="8" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="2001" G="{2adf8e23-0af9-43c9-ba4c-952ee130540d}" />.. </S>.. <C T="B" I="0" O="false" N="Enabled">.. <S T="1" F="Enabled" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):904
                                                                    Entropy (8bit):5.065926052144306
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdG5WhVzjzQIGdRDDHwpatyBHS1XFJicdDcgS/WP0MfZgS+/uSSO+M2CwfZ/ZE:2dG5WhhQIGdRgeiHSZvRm325Y
                                                                    MD5:0C2581E059676F1D4D2E072EEC4C819B
                                                                    SHA1:58A239F1A191559C07DE4B294DEFF073BE35B7A2
                                                                    SHA-256:8A81FC16187E01DAC227FC959F6482D276EF47185AF48457263C87EFABB699F2
                                                                    SHA-512:FD523AEE996B8F2602FD35D5B7F130332E720EAEEC7F1D13089ADE369B365FBF67E2BD8BB8335E7F2648CECE41EE197E5C05B4DF424AD40B560681889A9E1186
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11660" V="1" DC="SM" EN="Office.Outlook.Desktop.OutlmimePromptDetection" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DL="A" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="281" G="{13967ee5-6b23-4bcd-a496-1d788449a8cf}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Hourly" />.. </S>.. <G>.. <S T="1">.. <F N="Protocol" />.. <F N="MailProvider" />.. <F N="HRESULT" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="Protocol">.. <S T="1" F="Protocol" />.. </C>.. <C T="U32" I="1" O="false" N="MailProvider">.. <S T="1" F="MailProvider" />.. </C>.. <C T="I64" I="2" O="false" N="HRESULT">.. <S T="1" F="HRESULT" />.. </C>.. <C T="U32" I="3" O="false" N="CountPrompts">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1036
                                                                    Entropy (8bit):5.052888049355876
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdGMY0SVzjz8JJh8BdRDDHwpatbBiS1XFJicdDcgS/WP0MaNfZgS+/uSSO+M2k:2dGXh8l8BdRgediSZvR8+321C1YY
                                                                    MD5:D6BD8961C9DAF3AD04B7914231893953
                                                                    SHA1:5A2F487BF429DF9B8BCD5540A1C82AD27E9AB2C8
                                                                    SHA-256:A2A289DBB84A9895A59BD3491D423014CEADF18F14E34DFDA6006D858BA877BC
                                                                    SHA-512:CCC87B12CB96683383EDD06965B9CBBFCDBFF4BAAE1B3AB6AD1435FCA5441AF2249F4FD875A3E07B3EBDAA8252F0A192D1FFA924B250BB0D90ECBC114EDC197F
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11661" V="1" DC="SM" EN="Office.Outlook.Desktop.OutlmimeAuthenticationAttemptResult" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DL="A" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="282" G="{13967ee5-6b23-4bcd-a496-1d788449a8cf}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Hourly" />.. </S>.. <G>.. <S T="1">.. <F N="Protocol" />.. <F N="MailProvider" />.. <F N="HRESULT" />.. <F N="ResponseCode" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="Protocol">.. <S T="1" F="Protocol" />.. </C>.. <C T="U32" I="1" O="false" N="MailProvider">.. <S T="1" F="MailProvider" />.. </C>.. <C T="I64" I="2" O="false" N="HRESULT">.. <S T="1" F="HRESULT" />.. </C>.. <C T="U32" I="3" O="false" N="ResponseCode">.. <S T="1" F="ResponseCode" />.. </C>.. <C T="U32" I="4" O="false" N="AttemptCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="3"
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):691
                                                                    Entropy (8bit):4.343267265855362
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdG8HO62GeO+u+/WLMevH/M//K5eNUNf/0//cxhmMdrLnuBINO2su:2dGavLh+81rmBg
                                                                    MD5:FA2F7005514A4359173994EB38ACE452
                                                                    SHA1:03A2B872697DD679E42457CFB387A46F1E80B232
                                                                    SHA-256:04DCA68E6CDCD140BA57C4871C0C978CF36A73ADD2186DA3CDCB4894E0240FFC
                                                                    SHA-512:DD257FEFEDAF0C0555BCCA20526F325E376860C0454FFC86AC78893BD9C5B7AE283C1473FC0E9831DCB87CA996676ABBA7471C200020CD26BB91178CC57C4C38
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11662" V="1" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="1101" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. </S>.. <C T="I64" I="0" O="false">.. <O T="DIV">.. <L>.. <U T="100nsToMs">.. <O T="SUB">.. <L>.. <S T="1" F="TimeStamp100ns" />.. </L>.. <R>.. <S T="1" F="Last Updated" />.. </R>.. </O>.. </U>.. </L>.. <R>.. <V V="86400000" T="I64" />.. </R>.. </O>.. </C>.. <C T="W" I="1" O="false">.. <S T="1" F="OAB GUID" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1618
                                                                    Entropy (8bit):3.485346728988187
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdGcOi0cCS+u/Y//O5fX/c//4pONd+tNlOhH/eJfH/M//b5eNX/c//o//eJfHY:2dGBcC5udztZZ+7v4lmuj
                                                                    MD5:4822CD7D4F6D25DA04555FC192E7DB49
                                                                    SHA1:90E996E0C01639F38DF0EF1578A3DA7F5A4C3874
                                                                    SHA-256:A8E812D2AEBAA846838B76FA71C8E6E321890B6C29D6B2934525F3400B334B1F
                                                                    SHA-512:1EFBA9F124C486956456F905121E26DA09ACC9074463030D9457E6A97C262F0CBAA5BC15A73766851A99EDCBA19050A9210FAF98245ABDFC4F2E50D6AFF27D9E
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11663" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="11662" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="8" T="I64" />.. </R>.. </O>.. </F>.. <F T="3">.. <O T="AND">.. <L>.. <O T="GT">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="7" T="I64" />.. </R>.. </O>.. </L>.. <R>.. <O T="LT">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="30" T="I64" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="4">.. <O T="GT">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="29" T="I64" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false">.. <S T="1" F="1" M="Igno
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):801
                                                                    Entropy (8bit):5.183512479764439
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dGehRAKTdRgeLslmLFAOpAnABpAo+gj3:cGehxRRgeYgDWAqgj3
                                                                    MD5:D4E5008B04625E256C6017EAA1B03C65
                                                                    SHA1:D696CF5D98F85469EB3E37EEDC49DE3B156ACED9
                                                                    SHA-256:5B79FB719D8086B0CF706146CE30C3ECC6F4B04932B0BB039D6DD83F9E7F4D2D
                                                                    SHA-512:591932E414B9EC209E01B1B09F3F59E5CE2B5B956D7462A2221E55F8FF8BBFAC95A987C02D4000A125A5997A8573BDE35F8B46A95568853FC1E8BF6779B08E38
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11666" V="1" DC="SM" EN="Office.Outlook.Desktop.Search.FuzzyMatchContext" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="7142" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. </S>.. <C T="W" I="0" O="false" N="TraceId">.. <S T="1" F="TraceId" />.. </C>.. <C T="W" I="1" O="true" N="ReferenceId">.. <S T="1" F="ReferenceId" />.. </C>.. <C T="B" I="2" O="false" N="MatchRequested">.. <S T="1" F="MatchRequested" />.. </C>.. <C T="B" I="3" O="false" N="MatchReceived">.. <S T="1" F="MatchReceived" />.. </C>.. <C T="W" I="4" O="true" N="QueryAlterationType">.. <S T="1" F="QueryAlterationType" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1603
                                                                    Entropy (8bit):4.096573799634484
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdGhMVzjbXdtKdRDDHwpatli0cnSXFJiSKanDyXHBkn4iNxntDLNWyNmtOP/kF:2dGhMnQdRge/cqveC5KL9OSZabr6aA3
                                                                    MD5:EFF24E264A94BAB3AC5AC81C4A365126
                                                                    SHA1:1A27414CAC578093EC647E4619415AABE2B2FB8C
                                                                    SHA-256:69F4A0373E45D0AFCF61D1855DC40CAE97769B7475DF1CC49B44DACA80F6B3CB
                                                                    SHA-512:286767F526DBFB5ED6508C2F8C13B1B3894A28FBF51F07FBACB42F3C3BCC29C5C517E14F610449EE9754A1A1E2553108C9A328417E6EDFD7966BF6A0F4928C77
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11668" V="1" DC="SM" EN="Office.Outlook.Desktop.OABFreshness" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSP" xmlns="">.. <S>.. <R T="1" R="11663" />.. <A T="2" E="TelemetryShutdown" />.. <TO T="3" I="Hour">.. <S T="1" />.. </TO>.. </S>.. <G>.. <S T="1">.. <F N="0" />.. </S>.. </G>.. <C T="W" I="0" O="false" N="OAB_GUID">.. <S T="1" F="0" M="Ignore" />.. </C>.. <C T="B" I="1" O="false" N="IsFileAge_0To1Week">.. <S T="1" F="1" />.. </C>.. <C T="B" I="2" O="false" N="IsFileAge_1WeekTo1Month">.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </L>.. <R>.. <S T="1" F="2" />.. </R>.. </O>.. </C>.. <C T="B" I="3" O="false" N="IsFileAge_1MonthAbove">.. <O T="AND">.. <L>.. <O T="AND
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1235
                                                                    Entropy (8bit):4.7377046930203335
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dG/BdPdRgeaJuzvJt45v/s3VIiP1i8N11gunvuk:cGJ/RgeaJu9t4kdz7
                                                                    MD5:1E61C4F618449A751F5D0FDA23F7C5A8
                                                                    SHA1:8DE9A92DE523BC27946C2F1497C89806FB402CB0
                                                                    SHA-256:7EFD71797EB55D0AE75A8B3BB684CC590E378858850EC17E385481FA8AA3ED77
                                                                    SHA-512:2DCE7BA2B7DEE7E593DE5CAA879002F029527E50D4B5226B2C73D94A7C81EDF98EE87A186EF6186ACF985BDF8892334E1552BD5C530733CA5919050300AC2A2D
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11670" V="1" DC="SM" EN="Office.Outlook.Desktop.PreviewPlace.UserInfo" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="25" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3734" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <F T="2">.. <O T="NE">.. <L>.. <S T="1" F="SpecialFeature" />.. </L>.. <R>.. <V V="" T="W" />.. </R>.. </O>.. </F>.. <F T="3">.. <O T="EQ">.. <L>.. <S T="1" F="SpecialFeature" />.. </L>.. <R>.. <V V="" T="W" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="true" N="Audience">.. <S T="1" F="FlightAudience" />.. </C>.. <C T="B" I="1" O="false" N="MachineIDPopulated">.. <S T="1" F="MachineID" />.. </C>.. <C T="W" I="2" O="true" N="Build">.. <S T="1" F="ProductVersion" />.. </C>.. <C T="W" I="3" O="true" N="Channel">.. <S T="1" F="Channel" />..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):593
                                                                    Entropy (8bit):5.21375563156899
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdGnpvSVzjHC9dRDDHwpat5P4FasEXWdLUSCMfcSZNO2su:2dGnpadWdRgeJ7+kI
                                                                    MD5:C99837BEF7ABC9C6FE33FBAA8918CF28
                                                                    SHA1:0C5D73E4FBD55ECAB0DB15A775F5618F30A4FCD8
                                                                    SHA-256:502B418FB65648A13A463363B89A6D487691A71C4ED8DBCD78AA5D33EB4CFD04
                                                                    SHA-512:5A4967B29B4F7FF220C6C61CB0A82FDF058F1F6EEAF647D71DB747CAFB4D0D0F814204EF94D370196F81FE9D8FF896BD2D3270BD3A511E03D1FC6979671E6A83
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11671" V="1" DC="SM" EN="Office.Outlook.Desktop.PreviewPlace.ServiceCalls" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="25" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3735" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="W" I="0" O="true" N="Route">.. <S T="1" F="SARARoute" />.. </C>.. <C T="W" I="1" O="true" N="HTTPError">.. <S T="1" F="HTTPError" />.. </C>.. <C T="U64" I="2" O="false" N="HResult">.. <S T="1" F="HRESULT" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):535
                                                                    Entropy (8bit):5.300118517573922
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdGiVzjHCrx8dRDDHwpat5PbaGyMxupNmMdTFFSNO2su:2dGidqx8dRgeUGyM+X2
                                                                    MD5:CD298C1142DB1D07B4827D337A25FFE9
                                                                    SHA1:0318CCB538CF4F61B2CC354851860E9FD7A09858
                                                                    SHA-256:A4D6D5D66F3576274DCC0CEC3AE3A1AE9F155BD730A4A753164CB8146B238A95
                                                                    SHA-512:63843528FAA98FC36CBD861A955B5680B57EE68E89B42732152C318C67E6BA8C7572D9E38E2DA617A319112FBFDB64F839B45885CD37B1F3F8456F49F0C35D2F
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11672" V="0" DC="SM" EN="Office.Outlook.Desktop.PreviewPlace.FlightSetStatusEcs" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="25" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3736" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="W" I="0" O="false" N="FlightEcsOverrides">.. <S T="1" F="FlightName" />.. </C>.. <C T="W" I="1" O="false" N="Success">.. <S T="1" F="RegSetError" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):510
                                                                    Entropy (8bit):5.276756368324579
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdGLSVzjHCZzhdRDDHwpat5PWasuArybZ/ZNO2su:2dGLSdQldRgebgq
                                                                    MD5:92C0ED14E9F05FB4DBF2E0CFB35A21A0
                                                                    SHA1:697EF4E2DFA33D47FC70ADE7C7CB4C7FC3AA7777
                                                                    SHA-256:FBEB5AEFA68F205CCFEE428F3D884BFCE83F0935573A35C78DB7CC5BB8627FF7
                                                                    SHA-512:8CEDDA7C810A60A29A6C8DFE848AE7B12DE616384700338A5DA1C5AD2D74C012EE2534A2B8CEBE493AF289398C4FFB432B8252B27C9B965B881770693F97114F
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11673" V="1" DC="SM" EN="Office.Outlook.Desktop.PreviewPlace.HelpID" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="25" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3737" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="W" I="0" O="true" N="ArticleID">.. <S T="1" F="ArticleID" />.. </C>.. <C T="U64" I="1" O="false" N="HRESULT">.. <S T="1" F="HRESULT" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):524
                                                                    Entropy (8bit):5.309611572297989
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdGUVzjHCXd6dRDDHwpat5+qH161FZjXpNO2su:2dGUd4d6dRge5VCv
                                                                    MD5:5EABE55F261B90EB200FBDBAC73DF7A8
                                                                    SHA1:F54A61531259A65E7E9B002D4F6630561E617BBA
                                                                    SHA-256:0FD32D4F6C075FF8806EBA50ADBA5300A6EF53F9DE491EE005BB1A25F225F13B
                                                                    SHA-512:D1D332DA0E02AD316332FED6E9B2D6815512F73AA672E734CADC14974FAA1AB51B63CB3E5AEA3FD342D7A9B35858C9A869761CCF81DB7E4E1ACEEB364A9B31CA
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11674" V="0" DC="SM" EN="Office.Outlook.Desktop.PreviewPlace.SARAReturnedFlights" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="25" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="3738" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="U64" I="0" O="false" N="Success">.. <S T="1" F="HRESULT" />.. </C>.. <C T="U32" I="1" O="false" N="Amount">.. <S T="1" F="NumFlights" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):543
                                                                    Entropy (8bit):5.313779818888839
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdGj1VzjHCrxjCBdRDDHwpat5P56aGNFCqNpNmMdYSFSNO2su:2dGJdqxjIdRgeNGNFR3XY/
                                                                    MD5:6BAA1EA7E09C1A322FC8D73D2E43EB85
                                                                    SHA1:37C539988737DE8F06A69DCBAB043ED468F339AD
                                                                    SHA-256:548F231FB947AC58E41BDFE213EDED9CB5E19B60F7469F3B6A72146DA9627EFC
                                                                    SHA-512:4D4738D89E248BBCC8BC0F9E76D5F95663BAF6828D4D37DEFABBD8BB5336EC08F8898B1188C17DC123CAA06D49760398F04B24D52B79AE864082035DE7648C82
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11675" V="0" DC="SM" EN="Office.Outlook.Desktop.PreviewPlace.FlightSetStatusPreviewPlace" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="25" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3739" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="W" I="0" O="false" N="FlightPreviewPlace">.. <S T="1" F="FlightName" />.. </C>.. <C T="W" I="1" O="false" N="Result">.. <S T="1" F="RegSetError" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):653
                                                                    Entropy (8bit):4.969980962354719
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdGYVzjjT/i9dRDDHwpatler2/erzSOSNahnBicG297yFNHISMNO3XGHNS7lu:2dGYpTa9dRgeQr22ru5A8MOFsr
                                                                    MD5:6DE08C38A17666D25C49BA341D2E273C
                                                                    SHA1:855F7B5E20C9E15E94376B2566436772729A0EE7
                                                                    SHA-256:8376B176B7B136C36524BE7D2AC3D01C492CEC12190C0F24F299F564DE86DACC
                                                                    SHA-512:100DFA081B836CAC63C00774B36F80A42C8314ABA44773E46C49AFD9124C7F87EDCDFFD59FA49045002F0E7C65C5CDB7B4347D49E1B4FC969DE4AB850777D59C
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11678" V="0" DC="SM" EN="Office.Outlook.Desktop.Authentication.SignInDeadlockAvoidance" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSP" xmlns="">.. <S>.. <UTS T="1" Id="cm0bl" />.. <UTS T="2" Id="cl1qq" />.. <US T="3">.. <S T="1" />.. <S T="2" />.. </US>.. <A T="4" E="TelemetryShutdown" />.. <TI T="5" I="Daily" />.. </S>.. <C T="U32" I="0" O="false" N="NumberOfCancellations">.. <C>.. <S T="3" />.. </C>.. </C>.. <T>.. <S T="4" />.. <S T="5" />.. </T>.. <ST>.. <S T="1" />.. <S T="2" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):600
                                                                    Entropy (8bit):5.197656753208381
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdGv1VzjBOhdRDDHwpat5Cj2GeOX2MSy0fTpaANO2su:2dGv1POhdRge2vLPS1
                                                                    MD5:BAD0B2D26A8A5A361FF4016DB9872EAA
                                                                    SHA1:650083CE825CB0762CC27E077690D6D9CE659235
                                                                    SHA-256:6D8685303D3153C4387B8ABA4D20BEC36A6C3815E1A330224A9B5A4614219EC0
                                                                    SHA-512:048BC8820C283FF16C8D6ACEB8379AB65C5C9452B86DC11091E9855BFA5215C3F54A58CB4E15DA07A73C0A67E0B67524DE270E95AF55809E8AD411BBC1C911C4
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11679" V="0" DC="SM" EN="Office.Outlook.Desktop.SubmitMessage.CopyToMsgProblem" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="10" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="5021" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. </S>.. <C T="U32" I="0" O="false" N="MessageID">.. <S T="1" F="MessageID" />.. </C>.. <C T="U32" I="1" O="false" N="PropTag">.. <S T="1" F="PropTag" />.. </C>.. <C T="U32" I="2" O="false" N="SCode">.. <S T="1" F="SCode" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):4313
                                                                    Entropy (8bit):4.3773032940657846
                                                                    Encrypted:false
                                                                    SSDEEP:48:cGlGOx2RgeVwqdrK28uHesl85AKELnfwFlImLrGJ7XJ6GtFU:VYRgeqnueCfpLnfwfNfq5pU
                                                                    MD5:C7DA8A194363215C06C829B1327701A9
                                                                    SHA1:132B6E7AF5C922996CDC386FC1996765F226F3AF
                                                                    SHA-256:24CAA63EC7699ECADE0B5A7BB5FF114E43E97B74C3ABB07A1396B8D9A13CBDFB
                                                                    SHA-512:3A5205AA3F8DC5052F19FA20758D9CD2E5C896FB7ACB9CAA802D461C38CC0F7ED08469F55BD93BC5613BC28B6009577C64CF915206D3F4F0CE804C5CD4E2B97E
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11680" V="0" DC="SM" EN="Office.Outlook.Desktop.SubmitMessage.CopyToMsgStats" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="5021" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="2" E="5022" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="3" E="5001" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="4" E="5007" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <A T="5" E="TelemetryShutdown" />.. <TI T="6" I="Daily" />.. <F T="7">.. <O T="EQ">.. <L>.. <S T="2" F="HResOld" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="8">.. <O T="GE">.. <L>.. <S T="1" F="SCode" />.. </L>.. <R>.. <V V="2147483648" T="U32" />.. </R>.. </O>.. </F>.. <F T="9">.. <O T="EQ">.. <L>.. <S
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):506
                                                                    Entropy (8bit):5.203457606856901
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdGx3Vzjeul4sdRDDHwpat5aer7e/EDMd+EQMNO2su:2dG5zOsdRgefr7ecDw/f
                                                                    MD5:A6E11D4FA649872D59FD9757F86318BB
                                                                    SHA1:338C051F2D0408C15A24CAFD781A0B1DFADFF150
                                                                    SHA-256:7D0688BE24682D1AB41598387DCF368E9684B1E760DF44E5911A0CE88AFB537B
                                                                    SHA-512:290248EE1D4A989E43E70AAFE8FCED345022870F6DAF9001FB8160F72B0F70BB41D9C1181A19E541C907E8ABEB71C5004CB42E58820CDB877B21E3378CF79CFC
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11684" V="0" DC="SM" EN="Office.Outlook.Desktop.AutodiscoverServiceClient.ErrorDetails" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSP" xmlns="">.. <S>.. <UTS T="1" Id="coiol" />.. </S>.. <C T="W" I="0" O="false" N="ErrorLocation">.. <S T="1" F="ErrorLocation" />.. </C>.. <C T="W" I="1" O="false" N="ErrorDetails">.. <S T="1" F="ErrorDetails" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):440
                                                                    Entropy (8bit):5.334582931550476
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdG9VzjTLsKFdRDDHwpat5CkTslguRSNO2su:2dG9RAKFdRgeM2slO
                                                                    MD5:802E1235BBEB74166AF2EDB9B0FB4EA1
                                                                    SHA1:D14C30FE7AD3C47189F059E4AD8A9DDB2B9D1DD9
                                                                    SHA-256:ABE3E3D0F3D4422C24CDCB01F16EB8E718120CA29229C5BD370891E8CED5A671
                                                                    SHA-512:DFAA7E746CB4B6EE21C73119DF49052FC41CC45E854398EFF167FB98F895B85A2A3B12D28180442F0C88ADC8F771330718F8960C35B65A12C87E8CF0ACEC5C87
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11688" V="0" DC="SM" EN="Office.Outlook.Desktop.Search.FuzzyMatchClicked" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="50" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="7144" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. </S>.. <C T="W" I="0" O="false" N="ReferenceId">.. <S T="1" F="ReferenceId" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):678
                                                                    Entropy (8bit):5.197510052873043
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdGuaVzjx6pPdRDDHwpat5CFgmBn2yohS/EpeSpkdfZFayNO2su:2dGRvGPdRgeMug2VyAohwi
                                                                    MD5:A8F835F7292D079D85FA7E866EC31049
                                                                    SHA1:4D0A5346C86C418B2CD6E8EF49A33FD42F04EC04
                                                                    SHA-256:8230496BE302328304749F0B5695D64D03A86E86BA22E02FD9934086110C90C2
                                                                    SHA-512:2059637DDBECCC6871A36C7E5E146B230626005FA3E0E7EF598536D0B8A3B0E24843E6422B62D97F9ED166DF151EBE73D79A44DAAE44EBF8C50D45719BFE143A
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11689" V="1" DC="SM" EN="Office.Outlook.Desktop.ComAddin.BootInformation" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="50" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="3000" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="G" I="0" O="false" N="AddinId">.. <S T="1" F="GUID" />.. </C>.. <C T="U32" I="1" O="false" N="LoadBehavior">.. <S T="1" F="LoadBehavior" />.. </C>.. <C T="U32" I="2" O="false" N="BootTime">.. <S T="1" F="DelayTime" />.. </C>.. <C T="W" I="3" O="false" N="ProgID">.. <S T="1" F="ProgID" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):859
                                                                    Entropy (8bit):5.141910280583144
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdGu5Vzjx6pPdRDDHwpat5CFgmBn2ydLEZFaypthS/ETSpkN1DfXhxkxZ1NO2z:2dGyvGPdRgeMug2i6w2yZ610H
                                                                    MD5:E8218970143F2372A8F143D732115D00
                                                                    SHA1:9DB7AD67F6776E834D3691AFE61496B73201FD42
                                                                    SHA-256:9E1815722AEF1ECA4C49798C773D19BA329BFAEC9D3032796E06E32D15AC4D6A
                                                                    SHA-512:F8067FFD728049458AFDE2ADFD708524FA8D19DC58A0C92C333A94C43847EA703B7740AE2EBD8E5DA03E7E4B237427269C8C41449CB3A4A54A9B780B8D714B92
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11689" V="2" DC="SM" EN="Office.Outlook.Desktop.ComAddin.BootInformation" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="50" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="3000" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="G" I="0" O="false" N="AddinId">.. <S T="1" F="GUID" />.. </C>.. <C T="W" I="1" O="true" N="ProgID">.. <S T="1" F="ProgID" />.. </C>.. <C T="U32" I="2" O="false" N="LoadBehavior">.. <S T="1" F="LoadBehavior" />.. </C>.. <C T="U32" I="3" O="false" N="BootTime">.. <S T="1" F="DelayTime" />.. </C>.. <C T="U32" I="4" O="false" N="BootLoadTime">.. <S T="1" F="BootLoadTime" />.. </C>.. <C T="U32" I="5" O="false" N="OnStartupTime">.. <S T="1" F="OnStartupTime" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):3133
                                                                    Entropy (8bit):3.865714546088812
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dGB6PdRgeOvS8OHrTe6dwOSrTe6dcHrTe6e+rTe6Lk1bHx/1X:cGBORgeOvS8OXeO4eOcXeNqef1bHxdX
                                                                    MD5:AD6CABB80F294DFCE1F0BC67FEBA3293
                                                                    SHA1:7E524932530E56FC95D88DB79D7E8DE907A675E7
                                                                    SHA-256:1D12E1472C997F3E4AA768E815F603F2C83B67FFD93F15E475D7AD82D794B149
                                                                    SHA-512:790CD14239A103E7DA78E70DD3840342B65C98FA13610D2CA2308CFC5DE2B1751B90293B3F35DB21E0DCC9DA36DEF748BF21F6AC77847A714643D4285BF00022
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11695" V="2" DC="SM" EN="Office.Outlook.Desktop.Groups.DragDropToGroup" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="19036" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="EQ">.. <L>.. <S T="1" F="OpType" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="5">.. <O T="AND">.. <L>.. <O T="NE">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):2976
                                                                    Entropy (8bit):5.032236730295511
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dGSuaMdRgeEHgeqZyrirYFrZf1OVmRlNbmL6/lwZAuT38AeOFZqZHNgq6USf1np:cG5ZRgeNyGCZNOVmv9mYE3H5FsloRPB7
                                                                    MD5:F1E10E88036AB5750B021A6C00C32DB0
                                                                    SHA1:49D70B89CD6B2A905F2C194BB86E05335549F0CC
                                                                    SHA-256:927BD2D4CB827BEB947C66518F808BA1DDD23E736670B3F7AADBBB38643B1821
                                                                    SHA-512:3EF5971BA0DB483C6197157C44C400817C8F3C4DC90586F6C8DA1B33FE9A5F49DDF51FCD57DE5B40AF071A0E9D8E335C615CF78BF0C1ED48A6717DB991BBDB1C
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11698" V="3" DC="SM" EN="Office.Outlook.Desktop.AccountConfiguration.AccountCreationFailureDiagnosticsResult" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="20" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="493" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="2" E="491" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="3" E="8" G="{ad58872e-4df6-4b26-9841-5d7887a1c7a5}" />.. <Etw T="4" E="494" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. </S>.. <C T="W" I="0" O="true" N="AccountType">.. <S T="4" F="AccountType" />.. </C>.. <C T="W" I="1" O="true" N="AccountCreationResult">.. <S T="4" F="AccountCreationResult" />.. </C>.. <C T="W" I="2" O="true" N="RecoveryTitle">.. <S T="4" F="RecoveryTitle" />.. </C>.. <C T="B" I="3" O="false" N="TitleRetrieved">.. <S T="4" F="TitleRetrieved" />.. </C>.. <C T="B" I="4" O="false" N="ErrorMessageRetrieved">.. <S T="4" F=
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):3379
                                                                    Entropy (8bit):5.03456639262393
                                                                    Encrypted:false
                                                                    SSDEEP:48:cdN/C2RgegB/pjRpPPa0QQatevjOPSkaNvmsYQm6dLIZLKFDYDE7:8/RgegB/pjRp3a0Q3erBP1zmLKFDYDE7
                                                                    MD5:8128FC3D43D014B1817459A17EAA530A
                                                                    SHA1:2166F7C86E936A66A5639FCABF7F49FF1524F63C
                                                                    SHA-256:8DED8CBC88E55F941608705F5A992B48329C97914493CF2ED2AEFCAB09B54F46
                                                                    SHA-512:02917A6011B1D566664DDDBEFF28645A211409B072272C843EF701CBB31B324AAA2E8727448A2C4094B4EEF5AD5BE0EE0A722261A9566BDCB465DFB84626D931
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11700" V="2" DC="SM" EN="Office.Outlook.Desktop.AccountTypeDetectionResults" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="20" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3791" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="2" E="3792" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="3" E="3793" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="4" E="3794" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="5" E="3795" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="6" E="3796" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="7" E="3823" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="8" E="3824" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. </S>.. <C T="U32" I="0" O="false" N="TotalTimeForAccountTypeDetection">.. <U T="100nsToMs">.. <O T="SUB">.. <L>.. <S T="2" F="TimeStamp100ns" />.. </L>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1129
                                                                    Entropy (8bit):5.140935693060115
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dRV6dRgetvroWrxrorVAquDT2DTZ1If7:cRV2RgetvsWNkXIf7
                                                                    MD5:33F29D9D773542AB05C2A725A5AEBBD6
                                                                    SHA1:31275F20A0D0D7B1538AD3D4B7C1D4136F3B44CD
                                                                    SHA-256:DE1FD2D5D06581EA0CE4C315E27B7EC0B63B5B036B1D6015297B1E72B9A482FC
                                                                    SHA-512:DE6D6C3F93795F6D58766A74CDFC8B374FF975EDD62720CC54C2D96D3529F01716CC56D18148E1B10AAE7E78D2EDC6017ABE0486B5B12F49FEF305B153CEA3C5
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11701" V="1" DC="SM" EN="Office.Outlook.Desktop.Lpc.LokiOutboundEvents" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="1000" DL="N" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="b3g8r" />.. <UTS T="2" Id="b3g8s" />.. <UTS T="3" Id="9rfv2" />.. <SR T="4" R="(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)-(.|)(.|)(.|)(.|)-(.|)(.|)(.|)(.|)-(.|)(.|)(.|)(.|)-(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)">.. <S T="1" F="CorrelationId" />.. </SR>.. </S>.. <C T="W" I="0" O="false" N="RequestUrl">.. <S T="1" F="RequestUrl" />.. </C>.. <C T="U32" I="1" O="false" N="HttpStatus">.. <S T="1" F="HttpStatus" />.. </C>.. <C T="W" I="2" O="false" N="CorrelationId">.. <S T="4" F="Matched" />.. </C>.. <C T="U32" I="3" O="true" N="Milliseconds">.. <S T="2" F="Milliseconds" />.. </C>.. <C T="U32" I="4" O="true" N="ResponseSize">.. <S T="2" F="ResponseSize" />.. </C>.. <C T="U32" I="5" O="fal
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1028
                                                                    Entropy (8bit):4.708398065278194
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d/+WdRgejIirqJTAemjqwOaAemi6muXY7:c/xRgejnqJTAeAqQAeXuI7
                                                                    MD5:DD4BF297493CEE5D60AD9AB426858DA1
                                                                    SHA1:D53819D4A9BBB9260B808A24A99F08CF613376DE
                                                                    SHA-256:B910E99D7283AF42FD3010F8D28F995AF859F235D5FAAB65CDF602237773B529
                                                                    SHA-512:E1A6BAEDC8E0FDCF5EEAA0FE89379C368057E64D976B177E2643D72E1B25FBEF0CB5C0C08F68E3EEE93149F40297E975724AC8AC9F0C025B904078B0066C7148
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11702" V="0" DC="SM" EN="Office.Outlook.Desktop.SchedulingAssistantRecipFromEditControl" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="1020" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="fNewCell" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="fNewCell" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="NewCellCount">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="ExistingCellCount">.. <C>.. <S T="5" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1271
                                                                    Entropy (8bit):4.978455972588113
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dKLOPdRgeTlIicGIizIidgJJugQXuAB9gao:cKilRgehoG3RgJJwfXRo
                                                                    MD5:8BEF061B77604BF75FF655DEBDA5CE22
                                                                    SHA1:A8BBF5CC40CA4CC5B80BA441891774BEC3CE1C22
                                                                    SHA-256:752AD2BE6D92E5F2A02EECBED2F5EF388660B8DA76DA1DFCBEA04C09312F355A
                                                                    SHA-512:4E58C49C04CB19D53918758659A9422AF98BD4BDBC86369FDEB2D2FE3D2BB3F8FF291F24C273D7983BC09C50DBCC150CF6882A91DF21C719E1F84B883A06DBB2
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11703" V="0" DC="SM" EN="Office.Outlook.Desktop.SchedulingAssistantPeoplePickerHealth" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DL="A" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="1015" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <Etw T="2" E="1016" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <Etw T="3" E="1019" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <TI T="4" I="Daily" />.. <A T="5" E="TelemetryShutdown" />.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="GridColumn" />.. </L>.. <R>.. <V V="2" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="AttendeeSelectionFailedCount">.. <C>.. <S T="2" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="IsUpdatedCheckFailedCount">.. <C>.. <S T="3" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="EnterAttendeeValueExceptionCount">.
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):3171
                                                                    Entropy (8bit):4.706340035425865
                                                                    Encrypted:false
                                                                    SSDEEP:48:clERge5v4JIBY1U2ehBcYF9HRgs8Hr/Xs:JRge5hgzrfs
                                                                    MD5:D15475174EE7DB434C43EC8ED48B0373
                                                                    SHA1:6E1DEE8F9B3F932EBE3BA55BE39AE42161E09054
                                                                    SHA-256:8B333E949A2A85F70EFE1E46A81E631039671D6A1D8498106D325228C0203EC4
                                                                    SHA-512:90C823BC439314FFDEA79ADCF33999ACC9608C26072095711BB57A0A615F7F396F292438BC52DA25E91697AB85A91F98394CAF402CA86CC7E630F32828158D05
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11705" V="1" DC="SM" EN="Office.Outlook.Desktop.Lpc.LinkedInBindWorkflow" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" SP="CriticalUsage" S="100" DL="N" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="cmpda" />.. <UTS T="2" Id="cfzmw" />.. <UTS T="3" Id="cfzms" />.. <UTS T="4" Id="cfzmp" />.. <UTS T="5" Id="cfzmr" />.. <UTS T="6" Id="cfzmt" />.. <UTS T="7" Id="cfzmu" />.. <UTS T="8" Id="cfzmv" />.. <UTS T="9" Id="cfzqn" />.. <UTS T="10" Id="bd7ah" />.. <UTS T="11" Id="b3g8x" />.. <SR T="12" R="error=(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)">.. <S T="8" F="ErrorDescription" />.. </SR>.. <SR T="13" R="error_description=AADSTS([^@]|)([^@]|)([^@]|)([^@]|)([^@]|)([^@]|)([^@]|)([^@]|)([^@]|)%3a">.. <S T="8" F="ErrorDescription" />.. </SR>.. </S>.. <C T="W" I="0" O="false" N="Bind
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):631
                                                                    Entropy (8bit):5.23021248178263
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdaVzjw+dRDDHwpatUclPJe1zbhxBHOTWHyn/apx4MNO2su:2daC+dRgeUc98hXHqWHMk
                                                                    MD5:5A8A41CEE56BDDE6EA382C24CEA91908
                                                                    SHA1:95F861FDE1A01A29E3883218935D7543ADFE047A
                                                                    SHA-256:0667A234151FF3EA3F1E955206C4E2BAB64C4A9B0283171A6F4BDE4AEC971DAD
                                                                    SHA-512:7230661E9578C1B4BA6A94B45B0B3F1BCD8F2C9EDC93304F3717F21C2229B31D549E5BBED84216DD24610F83B6DB6838DBDBC3B078CD9E8756F91CABC86F319C
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11710" V="0" DC="SM" EN="Office.Outlook.Desktop.NdbCorruptionResult" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" SP="CriticalUsage" S="50" DL="B" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="368" G="{2adf8e23-0af9-43c9-ba4c-952ee130540d}" />.. </S>.. <C T="W" I="0" O="false" N="ReportingProcess">.. <S T="1" F="Process" />.. </C>.. <C T="B" I="1" O="false" N="CreateNewFile">.. <S T="1" F="CreateNew" />.. </C>.. <C T="U32" I="2" O="false" N="Consumers">.. <S T="1" F="Consumers" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1501
                                                                    Entropy (8bit):4.1314083035473805
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd+jVzjfPdRDDHwpatli0iXFJicoN+kXlO1OX/c//pleJfH/M//K5eNpONd+wo:2d+jVdRge/6vS8cxUwOfJyzxaeQ7
                                                                    MD5:E5FE0FAB52FEC3FE674F1ED97C43DF43
                                                                    SHA1:AAC9A4AD239C8152B8A86230061A7CD63C0BD3F2
                                                                    SHA-256:DE0E32E7DF5E4E6EE1788E01CE8107D23327A357CC38DB0A170C31B73C9ABBE3
                                                                    SHA-512:EED0C042D77C1528C70B50AB6F4F08471D6F8F8CE2112156600C848C5C4305CFAFA1362AC8FD3E1A2919056BDC6BE4D8020EE2914C2C58702609E1EC5FC92E2F
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11712" V="0" DC="SM" EN="Office.Outlook.Desktop.ContactCard2HoverCardWarmup" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSP" xmlns="">.. <S>.. <R T="1" R="11736" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="AND">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <O T="NE">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="3" T="U32" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="5">.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </L>.. <R>.. <O T="NE">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):587
                                                                    Entropy (8bit):5.187286281544145
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdjVzjSJdRDDHwpatlB3HR2GeOSXFJico2zWAWNc5XNO5AHNUlu:2djKdRgef3HRvLqvSI7B7
                                                                    MD5:EFE7AAD31D626E6E0E7151DD0D2175B2
                                                                    SHA1:18486D8911701C8FE583B28720B4193AC825B60E
                                                                    SHA-256:121678735B8867ECE0B4341B260D19D75465995F2E9426B1F469F6CBA02FEF02
                                                                    SHA-512:D3796CBFFBE3940E76BC6187E5FAB7FD35046A6243DF7636E7B3647B51F3069029054915D6E763C90C2D320EA65D8D1FEFF79028A6552261A93745626DA04ED0
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11715" V="0" DC="SM" EN="Office.Outlook.Desktop.OABDownloadThrottledTime" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="26150" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <C T="U32" I="0" O="true" N="TotalElapsedTime">.. <A T="SUM">.. <S T="1" F="ElapsedTime" />.. </A>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):6006
                                                                    Entropy (8bit):3.5879471064362303
                                                                    Encrypted:false
                                                                    SSDEEP:96:mu9VAaY0xEXKs4MBOfbA8OhgrWAmewYEAuG+dWZwB2hIh/H/2DzNl:DnfydABl
                                                                    MD5:528E0A4867B30F009233B4832EEA5381
                                                                    SHA1:4280DF2DB38D3934890075BC191C74917FFDA4AA
                                                                    SHA-256:ADDAC979CCD4E4D8679D8731F153363D041ABB2F1E680D87B17E9FDD6396A6CC
                                                                    SHA-512:CE40AB622CF02E6441407A82F0482C0F4D469CD6528F024762D4905F05B148AE4B4F2618BCD0ABB8339B9570B0FE8BE8E2ED4CA4029F4288CE30289E1D8C1E42
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11724" V="1" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3805" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <F T="2">.. <O T="NE">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="-2147168464" T="I32" />.. </R>.. </O>.. </F>.. <F T="3">.. <O T="NE">.. <L>.. <S T="2" F="HRESULT" />.. </L>.. <R>.. <V V="-2147168488" T="I32" />.. </R>.. </O>.. </F>.. <F T="4">.. <O T="NE">.. <L>.. <S T="3" F="HRESULT" />.. </L>.. <R>.. <V V="-2147168465" T="I32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="NE">.. <L>.. <S T="4" F="HRESULT" />.. </L>.. <R>.. <V V="-2147417848" T="I32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="NE">.. <L>.. <S T="5" F="HRESULT" />..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):6006
                                                                    Entropy (8bit):3.5880726682924546
                                                                    Encrypted:false
                                                                    SSDEEP:96:Qu9VAaY0xEXKs4MBOfbA8OhgrWAmewYEAuG+dWZwB2hIh/H/2DzNl:xnfydABl
                                                                    MD5:FBDA30AB466B37D36748966EFB942BCF
                                                                    SHA1:CF715601FEEB8C90FDCD45E5854FE980F2A35324
                                                                    SHA-256:A58CDF1E1B176D6083E0025D0954FFB2B54A05E650D2A447AA0880D243C61B0D
                                                                    SHA-512:A0D0634510D3C8EB93BF3E91C355F7D6792D895A4E99E53533FAE293F4975634C1184B4F621ED3BE5DED2CD7F10281AC6F70287928A14D07469525BD805906FA
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11725" V="1" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3806" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <F T="2">.. <O T="NE">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="-2147168464" T="I32" />.. </R>.. </O>.. </F>.. <F T="3">.. <O T="NE">.. <L>.. <S T="2" F="HRESULT" />.. </L>.. <R>.. <V V="-2147168488" T="I32" />.. </R>.. </O>.. </F>.. <F T="4">.. <O T="NE">.. <L>.. <S T="3" F="HRESULT" />.. </L>.. <R>.. <V V="-2147168465" T="I32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="NE">.. <L>.. <S T="4" F="HRESULT" />.. </L>.. <R>.. <V V="-2147417848" T="I32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="NE">.. <L>.. <S T="5" F="HRESULT" />..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):768
                                                                    Entropy (8bit):5.142151072181204
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdPVzjNv6dRDDHwpatEBMHPYHcoNBnzXHaSMPXuHhSMNOAdHNS7lu:2dPedRgekzvzWWr
                                                                    MD5:C8EF53FB9365514D0BA47571505FA30F
                                                                    SHA1:2BD8061D934F64F8C4887A436F43D1BE8364BF2E
                                                                    SHA-256:3CF87314ED0D03900FE97DF3794193E01809099B1940D4EECDB609FAA08A8DF2
                                                                    SHA-512:5D2A1A60011F5DE8B1AA244ADC694C2ED437B064B14CC97899C4177F760003A2FE745898BB635C0B9E7B3914082C35C94BE0DF6B58E07463E600231277B1166B
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11728" V="0" DC="SM" EN="Office.Outlook.Desktop.Calendar.SwapTZAndLabelChangeUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="22420" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="22421" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="3" I="Daily" />.. <A T="4" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="ButtonClickCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="NumUsersPriLabelChanged">.. <C>.. <S T="2" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="4" />.. </T>.. <ST>.. <S T="1" />.. <S T="2" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1506
                                                                    Entropy (8bit):4.6508051674056485
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dyul0JdBdRgekVqJT2W/wOa2WghJ2WGcJ7:cyuorRgekVqJT2gQ25J2hcJ7
                                                                    MD5:D1C1EBD24EB990964498B112B2FE4DAE
                                                                    SHA1:F4A5236731A66C45700C3DF437643D9F3029D7DB
                                                                    SHA-256:4D790BA268912F2EB85A87B547D86E41B1CE2F4148AE4D1CF9736DAFF4FD7F99
                                                                    SHA-512:67849DC18B1DDAD1119ECF3E0A624F630282E1158C78EC7E722D5EF3F4127175C7BCC8EA020BAE18C61FA2CAF9EE4726C9F5F4988649BF91EB09082A6FE6F7C9
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11729" V="1" DC="SM" EN="Office.Outlook.Desktop.Calendar.PresetTimeZoneSelectionUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="22422" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="NumTimeZonesSelected" />.. </L>.. <R>.. <V V="1" T="I32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="NumTimeZonesSelected" />.. </L>.. <R>.. <V V="2" T="I32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="NumTimeZonesSelected" />.. </L>.. <R>.. <V V="3" T="I32" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="Count_Calendar
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1265
                                                                    Entropy (8bit):5.068838819144208
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dkQrdRge7WqJT8X/VmLpbwOa8X/VmL3uWZ7:ckQJRge7WqJTgdmxQgdm757
                                                                    MD5:D1D4DC60041DB3C3DEFF8868F0EA993E
                                                                    SHA1:2C601D493D74A0EDFE6EC6C459C03EEA519CC61B
                                                                    SHA-256:2EBE23C74D5E7292D08D7C85B919479D2B398B291263D59CB5F85D488AE59990
                                                                    SHA-512:C5F13979D75907ACA27CBEA9DA5C2584EA61DF37143E2DF942C1D88BB82CC2B442641D92ECC599D7F8D78A7A2A08AA3E12A6C409C8474A9CEB7F3071E916B4FA
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11730" V="0" DC="SM" EN="Office.Outlook.Desktop.AutoDiscover.AutoDiscoverV2Request" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="615" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="ServerResponse" />.. </L>.. <R>.. <V V="{&quot;Protocol&quot;:&quot;SubstrateSearchService&quot;,&quot;Url&quot;:&quot;https://outlook.office365.com/search&quot;}" T="W" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="ServerResponse" />.. </L>.. <R>.. <V V="{&quot;Protocol&quot;:&quot;SubstrateSearchService&quot;,&quot;Url&quot;:&quot;https://outlook.office365.com/autosuggest&quot;}" T="W" />.. </R>.. </O>.. </F>.. </S>.. <C T="
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1041
                                                                    Entropy (8bit):4.7259754056208045
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdZVzjsKk6dRDDHwpatETGIqB2c1NQi+kXqNOfrX/c//bLMpONd+wsvXqNOfrY:2dZ2cdRgeQGIirqJTiiAwOaij/+7
                                                                    MD5:AD55A15C3A31032E1F253F24462F08E6
                                                                    SHA1:4508BA5918FF6A25874254CEF4771FB7F0DF7364
                                                                    SHA-256:84BD78D7909C7B09950AF25A94EEEB05CBB61738F6F7AE8E37C55B215872D3B0
                                                                    SHA-512:22EA087F80F9E9D8698C8544FC71B1E8FEFAC3F737DD53A3D4E826FA4023F495CEE896E8DC1CBC899B4BE4FE4D0B019FEFA77533B8761EFC8987FB17F02A054F
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11731" V="0" DC="SM" EN="Office.Outlook.Desktop.Reminders.AutoDismissalOptionsUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="834" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="OptionValue" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="OptionValue" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="CountFeatureTurnedOn">.. <C>.. <S T="5" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="CountFeatureTurnedOff">.. <C>.. <S T="4" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1214
                                                                    Entropy (8bit):4.819427131350566
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d22ycdRgeuTIirqJT4YpPiAwOa4YpPj+l7:c22nRgeuTnqJT4YpPQ4Ypb+l7
                                                                    MD5:9D3E63522F1772BB889670761BA9DE91
                                                                    SHA1:87C232D0FFC059621B6EBC8CEC1D9767CD1BDE5E
                                                                    SHA-256:AF8AD4ADFFDF777BFA4407B5AF2621B662C0095CD902E6924D397E3577E07308
                                                                    SHA-512:7FB1EC96543F09A1A08FB3123BB47737DAED840B981E46DBAC94850D990B1F62C9999837AD5D755246EFBCABDBA9C0CB6DC8437BCA92EA5D6EB91D0D45345416
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11732" V="0" DC="SM" EN="Office.Outlook.Desktop.Reminders.AutoDismissalUsageStatistics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="835" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="IsDismissedFromDialog" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="IsDismissedFromDialog" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="CountAutoDismissedReminders">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="CountAutoDismissedRemindersWithoutShowingInUI">.. <C>.. <S T="4" />.. </C>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1309
                                                                    Entropy (8bit):4.606942035174418
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdhWVzjrGMBdRDDHwpat5rTwb2GeOS+u/5lOj7X/c//7pONd+tNqNOBX/c//cj:2dhWR9dRgetMbvL5uwUt44nZpz73JCC1
                                                                    MD5:AFC7EB407F1A6F3E1EBE3130C48DE35C
                                                                    SHA1:AD22B1C50F6FE569D51DA045137C300D40E2500B
                                                                    SHA-256:2BC3ED832E96F004181576EB388AE97FAB9D959ECC14C67BF2CB466CFCDBE4FA
                                                                    SHA-512:559056DE12798F63F9E7D958AC20FEF892FE6557361003087B8D86D324BD49635E54D14314DEAA2195A946445CBC75DD0DD8132AABD966B0DBE808D2981FA190
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11738" V="4" DC="SM" EN="Office.Outlook.Desktop.StoreApis.RESTVerb_Execute_Online_Reliability" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="1000" DL="A" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9101" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <F T="2">.. <O T="NE">.. <L>.. <S T="1" F="VerbIdNew" />.. </L>.. <R>.. <V V="1000" T="U64" />.. </R>.. </O>.. </F>.. <F T="3">.. <O T="EQ">.. <L>.. <S T="2" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="U64" />.. </R>.. </O>.. </F>.. <F T="4">.. <O T="NE">.. <L>.. <S T="2" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="U64" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="3">.. <F N="CorrelationID" />.. </S>.. <S T="4">.. <F N="CorrelationID" />.. </S>.. </G
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1457
                                                                    Entropy (8bit):4.886477791787648
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dcT6dRgetpvLrvLGvLlUfJTGPn+X6sJBRsJiWY:ccqRgetV/kxUfJ7ygn
                                                                    MD5:DE34976C9A2929D4B031C0D014ABFDFD
                                                                    SHA1:63B93267B5BA45B68839E2032E0C3DA74B86D03D
                                                                    SHA-256:F83047BAA123BBA21AB0071675BE86FEF1D153A22AAD5553432FF7C5389C6188
                                                                    SHA-512:F027FAF5F6486FA08395AD5A6566842D4C978585CEC7ABE3A1605142EAC28CF342F2209787ACF172722673CB168C72C04FD339A243D5A49C3A57E6F4C379FF80
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11739" V="5" DC="SM" EN="Office.Outlook.Desktop.StoreApis.ContextReliability" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="1000" DL="A" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9005" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="2" E="9102" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="3" E="9502" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. </S>.. <G>.. <S T="1">.. <F N="ThreadId" />.. </S>.. <S T="2">.. <F N="ThreadId" />.. </S>.. <S T="3">.. <F N="ThreadId" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="StoreType">.. <S T="3" F="StoreType" />.. </C>.. <C T="G" I="1" O="falseNoError" N="CorrelationID">.. <O T="COALESCE">.. <L>.. <S T="1" F="CorrelationId" />.. </L>.. <R>.. <S T="2" F="CorrelationID" />.. </R>.. </O>.. </C>.. <C T="U64" I="2" O="false" N="ApiCtx">.. <O T="BITWISE
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):611
                                                                    Entropy (8bit):5.244867997063719
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdT2guVzjWdRDDHwpat5GgTu2GeOXrzfTTx6/x9MYXZNO2su:2dTvukdRgetSvLHPgf
                                                                    MD5:40FFF1935CB1D2EF95AA6B91357CA8F8
                                                                    SHA1:4CD6851EE44FF9901A5DEAE81A3F166A9622F80E
                                                                    SHA-256:352EFA58305CA584148B79DB884A248DA6D305B4EC093E9F0D0CA75E03892C6E
                                                                    SHA-512:EFF5E1EAE53D8ACC77C0F84A37EFF1A97241354CC677FDA2DA6DA5C52F5F14DBE6F97304E7E132FC404D1ED663AAD2011C3B32B18F5D8886A0C9D363A41015DA
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11740" V="3" DC="SM" EN="Office.Outlook.Desktop.StoreApis.HelperFailures" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="500" DL="A" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9501" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. </S>.. <C T="U32" I="0" O="false" N="StoreType">.. <S T="1" F="StoreType" />.. </C>.. <C T="U64" I="1" O="false" N="ApiMethodCtx">.. <S T="1" F="CONTEXT" />.. </C>.. <C T="U64" I="2" O="false" N="Failure">.. <S T="1" F="HRESULT" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1778
                                                                    Entropy (8bit):4.699554913428993
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d0WNWPndRgeAvLgbvLEe0BO0pzPAqtoRPi8P6E6PHQ1RB7h7:c0KWPdRge2gYeeO88O0R7
                                                                    MD5:D1D00C4507050D3A4B9EADD59DEE2FFB
                                                                    SHA1:0D6F2186E04C9DEA47A8DF4BAB19ED9DAA265F20
                                                                    SHA-256:281876D911162231BCF60A2513F1A7F5E546DFDFB2CF0ACEC2874F024B318969
                                                                    SHA-512:B18941975C8587CB48EA5B1F6C4FD6869D8BB10800C0AB5D2D47CFB0C5D6B14C57440BE5CD59B9F8D20C11F96CBE7FE4A960513E7163EAE7F6B39817D34C9874
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11741" V="4" DC="SM" EN="Office.Outlook.Desktop.REST.VerbExecutionMetrics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DL="A" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9102" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="2" E="9101" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <TI T="3" I="Hourly" />.. <A T="4" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="StoreType" />.. <F N="VerbIdNew" />.. <F N="SubVerbId" />.. <F N="HRESULT" />.. </S>.. <S T="2">.. <F N="StoreType" />.. <F N="VerbIdNew" />.. <F N="SubVerbId" />.. <F N="HRESULT" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="StoreType">.. <O T="COALESCE">.. <L>.. <S T="1" F="StoreType" />.. </L>.. <R>.. <S T="2" F="StoreType" />.. </R>.. </O>.. </C>.. <C T="U32" I="1" O="false" N="VerbId">.. <O T="COALESCE">..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):809
                                                                    Entropy (8bit):4.608239851250772
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdMPOOX2GeOq9s7WBSf/0//yMhmM19s7WBSf/0//whmMpxOxnZN1DRTTxNO2su:2dMPpvLusDBEsDwl193
                                                                    MD5:15084E45CFEEA65254FEB0074248C1E5
                                                                    SHA1:262948FF7A1D35944C500D4A203787FD6B9660F2
                                                                    SHA-256:02701EC9B77351E4C629DACD5CB30B49AD0CB005BF43AD4A18E5FB37367F6707
                                                                    SHA-512:674315E1CF42AE73DD60C1CEEDFB88CEDCDB60EE84623EF816FBEC7A11B35735C1C0B01E1BB3304FEA3F47923694A95B76C96E52D903C49E36D988E66545F102
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11749" V="3" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9502" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. </S>.. <C T="U64" I="0" O="false">.. <O T="BITWISEAND">.. <L>.. <S T="1" F="CONTEXT" />.. </L>.. <R>.. <V V="268369920" T="U64" />.. </R>.. </O>.. </C>.. <C T="U64" I="1" O="false">.. <O T="BITWISEAND">.. <L>.. <S T="1" F="CONTEXT" />.. </L>.. <R>.. <V V="65535" T="U64" />.. </R>.. </O>.. </C>.. <C T="U32" I="2" O="false">.. <S T="1" F="SessionType" />.. </C>.. <C T="U64" I="3" O="false">.. <S T="1" F="HRESULT" />.. </C>.. <C T="U32" I="4" O="false">.. <S T="1" F="StoreType" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):780
                                                                    Entropy (8bit):4.968177337830356
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdhtWVzjydRDDHwpat5GgTX2GeOS+u/5lOeX/c//cpONGrzfYTx6/69MYXQNOP:2dbW0dRgetbvL5uRZK5H
                                                                    MD5:98A42B8306E75462EAC045974B62E73B
                                                                    SHA1:81DB69C2C883B10E4CD254D2292B92ED95A41F6A
                                                                    SHA-256:A9B6FD341229927BE884E096D896159EE8CDFEBBC5DB184C78B4DAADB2866B39
                                                                    SHA-512:35FB5EF795DB0227FA1659F8949A2EAF37A18B7763D5E15F9D064619781A79C8DF5A3F239352AD475AD9E583B6CF632E1779351AA0CF0050E845DC2B0446E3BE
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11750" V="4" DC="SM" EN="Office.Outlook.Desktop.StoreApis.Failures" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="500" DL="A" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9502" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <F T="2">.. <O T="NE">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="U64" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="StoreType">.. <S T="2" F="StoreType" />.. </C>.. <C T="U64" I="1" O="false" N="ApiMethodCtx">.. <S T="2" F="CONTEXT" />.. </C>.. <C T="U64" I="2" O="false" N="Failure">.. <S T="2" F="HRESULT" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1739
                                                                    Entropy (8bit):4.341665904389952
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dBFdRgemSuqvlT0JwOaynJ0tVuuY1Wr9F:cBnRgeUqvlTGQIeuvGF
                                                                    MD5:6315D2E3B42D86BF3499DD2FBFFE1E56
                                                                    SHA1:E40A5D909CF00F5801C9470BA8077C219B14DF8D
                                                                    SHA-256:9C4990AF8F8B82A39D7BBB03616577D55ACAAA21BAC88C5546631520F9E988D1
                                                                    SHA-512:2D4D5F145A2F3C417A98A6A662F593F98B6544608A0728867AB805A7626D9459E7C46C79F29C612E6D192BB32397B8067B1E1F9F4F4ACDF9D9DE9DED0B2BDE33
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11751" V="2" DC="SM" EN="Office.Outlook.Desktop.StoreApis.MapiCalendarPermissions_Reliability" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DL="A" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="11749" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Hourly" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="33882112" T="U64" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="4" F="3" />.. </L>.. <R>.. <V V="0" T="U64" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="NE">.. <L>.. <S T="4" F="3" />.. </L>.. <R>.. <V V="0" T="U64" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="4">.. <F N="0" />.. <F N="1" />.. <F N="2" />.. <F N="4" />.. </S>.. <S T="5">..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1735
                                                                    Entropy (8bit):4.335945445005739
                                                                    Encrypted:false
                                                                    SSDEEP:24:2detdRgemSuqvlT0Q6wOaynJ0tVuuY1Wr9F:cevRgeUqvlTB6QIeuvGF
                                                                    MD5:7A894576292B078BA5E4BE1ED2778CBE
                                                                    SHA1:E674F8B151903D780553840C45DA366B6301871E
                                                                    SHA-256:EACE1A21ED2E51AE953E91B2C184B296D6D61B08515B9D50DD0ABACAC819ADF6
                                                                    SHA-512:A8AA947EC0D051539BDDF77F3A7397D202B3C3D0C15338D35F9C35E817C788E4244FB1D8F305CD03288D2C98951AF8DEB7CB9119EE9A01501168845FAC81E607
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11752" V="2" DC="SM" EN="Office.Outlook.Desktop.StoreApis.MapiCalendarSharing_Reliability" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DL="A" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="11749" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Hourly" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="33947648" T="U64" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="4" F="3" />.. </L>.. <R>.. <V V="0" T="U64" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="NE">.. <L>.. <S T="4" F="3" />.. </L>.. <R>.. <V V="0" T="U64" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="4">.. <F N="0" />.. <F N="1" />.. <F N="2" />.. <F N="4" />.. </S>.. <S T="5">..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1723
                                                                    Entropy (8bit):4.32085691396312
                                                                    Encrypted:false
                                                                    SSDEEP:24:2ddShdRge8SuqvlT0xwOaynJ0tVuuY1Wr9F:cdSLRgemqvlT+QIeuvGF
                                                                    MD5:C5DB3C4869A47FA352DD250EA2D534B0
                                                                    SHA1:E0DEFAF5BEBA5E175B639BD3691FE8754A58BDE6
                                                                    SHA-256:B3A6C636FD5B4B5C5FF45DE6C9B90564CA56F82226C574FAF6CAC2CFC36FEB6F
                                                                    SHA-512:8D572B435330CECF736C7FCFE03E1D9D8F77499BDF3E4F8672C41F9AF58F118EE01A8BA1577CEB0945B85D0FF6756FD698E3852AF6417B1487F59D688C8417E0
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11753" V="1" DC="SM" EN="Office.Outlook.Desktop.StoreApis.MapiCommonItem_Reliability" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="11749" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Hourly" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="34013184" T="U64" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="4" F="3" />.. </L>.. <R>.. <V V="0" T="U64" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="NE">.. <L>.. <S T="4" F="3" />.. </L>.. <R>.. <V V="0" T="U64" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="4">.. <F N="0" />.. <F N="1" />.. <F N="2" />.. <F N="4" />.. </S>.. <S T="5">.. <F N="0" />.
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1725
                                                                    Entropy (8bit):4.323360675578003
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dLgdRge8SuqvlT0YwOaynJ0tVuuY1Wr9F:cLYRgemqvlTHQIeuvGF
                                                                    MD5:BA5FF7F44BB22218C4F7CE77E890FDEF
                                                                    SHA1:E3B8EF7C8B95754F2BCBC48E4FB47D622B0EA7F0
                                                                    SHA-256:5E4C32D81403444C5A847A15FBFC4C1F7372CF11DD6687593BE145F2FCAD024C
                                                                    SHA-512:F92F09F1DF99DFC9737DBBA4158044CB27FD084385B1143284422B75A0B5AE4E43160E77E32CDC1589D4D07051AE03E0D1F04FB9C0F7B89F0620C6584A8319C6
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11754" V="1" DC="SM" EN="Office.Outlook.Desktop.StoreApis.MapiCalendarItem_Reliability" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="11749" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Hourly" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="34078720" T="U64" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="4" F="3" />.. </L>.. <R>.. <V V="0" T="U64" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="NE">.. <L>.. <S T="4" F="3" />.. </L>.. <R>.. <V V="0" T="U64" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="4">.. <F N="0" />.. <F N="1" />.. <F N="2" />.. <F N="4" />.. </S>.. <S T="5">.. <F N="0" /
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1724
                                                                    Entropy (8bit):4.3225776265618965
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dOJdRge8SuqvlT0kfwOaynJ0tVuuY1Wr9F:cOTRgemqvlTZfQIeuvGF
                                                                    MD5:A2BC2693B1794955DE5EC5813D405B30
                                                                    SHA1:24873043AAF24D58C4B92DB7BAAEA35FECCA5A54
                                                                    SHA-256:AE761A704DB41D57640E063DFAF8D4939BF47B17F42B002F7A87C4DBB10547EF
                                                                    SHA-512:D870ABAE833C5A2E624C7C53939411163D411F7C8995FC239CA9D487A23C5725FCEEF1678A25D8B981AC55CB6FF396C91AEFAD3427CDAC04204CABF93666448C
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11755" V="1" DC="SM" EN="Office.Outlook.Desktop.StoreApis.MapiMeetingItem_Reliability" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="11749" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Hourly" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="34144256" T="U64" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="4" F="3" />.. </L>.. <R>.. <V V="0" T="U64" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="NE">.. <L>.. <S T="4" F="3" />.. </L>.. <R>.. <V V="0" T="U64" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="4">.. <F N="0" />.. <F N="1" />.. <F N="2" />.. <F N="4" />.. </S>.. <S T="5">.. <F N="0" />
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1723
                                                                    Entropy (8bit):4.324253382941466
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dJNdRge8SuqvlT0TwOaynJ0tVuuY1Wr9F:cJPRgemqvlT0QIeuvGF
                                                                    MD5:32CFCBC0A2F536B6A6B6A3FD822E354F
                                                                    SHA1:DB7B913CE02D733B5BAAB7ABF100D655C8CB55AF
                                                                    SHA-256:FB2F037D6A7A9CE8912FE45F7F1F087E8CE39844F86FF8C60C8A1D9C43DFCEA5
                                                                    SHA-512:C8B8A7E893B8CB1B5576301B7395E4E4AF04C7F1DA3EDAB902116BCED7279F131B9738ABED8ECE3BB31354CBEEE6677DB50EE8D56A38D9B770A1B781F5FE1621
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11756" V="1" DC="SM" EN="Office.Outlook.Desktop.StoreApis.MapiAttachItem_Reliability" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="11749" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Hourly" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="34209792" T="U64" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="4" F="3" />.. </L>.. <R>.. <V V="0" T="U64" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="NE">.. <L>.. <S T="4" F="3" />.. </L>.. <R>.. <V V="0" T="U64" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="4">.. <F N="0" />.. <F N="1" />.. <F N="2" />.. <F N="4" />.. </S>.. <S T="5">.. <F N="0" />.
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1723
                                                                    Entropy (8bit):4.321111424743761
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dsQjsdRge8SuqvlT0x5wOaynJ0tVuuY1Wr9F:csQj8RgemqvlTU5QIeuvGF
                                                                    MD5:1CF09EC92E88EE8016078592FA61CE19
                                                                    SHA1:CBC38D75365D7B5D02286C2BBA7A2A28AFB7EE77
                                                                    SHA-256:D310A276E20D7449258D71FB1D4616434BC5966990644C75F5D6F075E398207E
                                                                    SHA-512:7909B5678DBFFD01E54E40725B0DF4FD40D9A9DFBC840342AC4B4BEA302389A91FD9262DA4EF811CA3FCB0A1D6E22EC5CA50F3A7C7A703BE0B22D905AC193C53
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11757" V="1" DC="SM" EN="Office.Outlook.Desktop.StoreApis.MapiRecurrence_Reliability" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="11749" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Hourly" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="34275328" T="U64" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="4" F="3" />.. </L>.. <R>.. <V V="0" T="U64" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="NE">.. <L>.. <S T="4" F="3" />.. </L>.. <R>.. <V V="0" T="U64" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="4">.. <F N="0" />.. <F N="1" />.. <F N="2" />.. <F N="4" />.. </S>.. <S T="5">.. <F N="0" />.
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1736
                                                                    Entropy (8bit):4.3319136824723925
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dmuXdRgemSuqvlT0XfwOaynJ0tVuuY1Wr9F:c9NRgeUqvlT2fQIeuvGF
                                                                    MD5:5E0D8FFF11D1C7B692C19C9EBDA87FB7
                                                                    SHA1:4770BAC803C4675D7F904D3528F4AFF806E01CF8
                                                                    SHA-256:C7A89B4954131B0481AAA5F3A782FF50E588853D254699706737DA684D5BBE4A
                                                                    SHA-512:874F87C81885430AD6B53D2AEFEC832B7188804896EC740F250D3391B58144E72ED6B47B289C460346BBA405995D3B3E64F393793A5C859FDF5D299AE134CB29
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11758" V="3" DC="SM" EN="Office.Outlook.Desktop.StoreApis.MapiFolderCollection_Reliability" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DL="A" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="11749" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Hourly" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="34340864" T="U64" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="4" F="3" />.. </L>.. <R>.. <V V="0" T="U64" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="NE">.. <L>.. <S T="4" F="3" />.. </L>.. <R>.. <V V="0" T="U64" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="4">.. <F N="0" />.. <F N="1" />.. <F N="2" />.. <F N="4" />.. </S>.. <S T="5">..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):2405
                                                                    Entropy (8bit):5.170990019698884
                                                                    Encrypted:false
                                                                    SSDEEP:24:2djkudRgeMQsclWyVzSyqjNnPGNCWGK84G3v+cvJILvwybNEfvLlEgs/JzWozqk7:cjkSRgeoyVGtRu8WGsG3v+6lGMs/J5F7
                                                                    MD5:C8FBC084A34D87E2DE868F772CA43C51
                                                                    SHA1:6B7CAEF31754F4A922FA57DDD342420682AAD3F7
                                                                    SHA-256:1B69FEB356AED03E3B34F4872EEFBB727F062BA344E05FD93A5625CF555780B4
                                                                    SHA-512:64C97B3A22F55350E5CF1C4AA25952B018213E1944A1CDDFBEE9E115956E84217950FF18299CDBC305FCD2A1BA29EEF6FA9A1B6CC72809A86C950F0B02ACE330
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11759" V="0" DC="SM" EN="Office.Outlook.Desktop.AccountConfiguration.AzureActiveDirectoryZeroConfigExchange" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="50" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="498" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="2" E="496" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="3" E="497" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="4" E="499" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. </S>.. <C T="I64" I="0" O="false" N="AddressDiscoveryHRESULT">.. <S T="4" F="HResult" />.. </C>.. <C T="I64" I="1" O="false" N="AddressDiscoveryTaskHRESULT">.. <S T="4" F="TaskHResult" />.. </C>.. <C T="B" I="2" O="false" N="FullNameRetrieved">.. <S T="4" F="FullNameRetrieved" />.. </C>.. <C T="B" I="3" O="false" N="PrimarySmtpRetrieved">.. <S T="4" F="PrimarySmtpRetrieved" />.. </C>.. <C T="B" I="4" O="false" N="UserPrin
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):2649
                                                                    Entropy (8bit):3.802109708779993
                                                                    Encrypted:false
                                                                    SSDEEP:24:2derVrumt4ZPjqTZ2DCNlwOaZ2DCdJZ2DCgz2DiPX2Diq/2DC0PWxVHnPWl9XVlQ:cehymt4tqTnQdJgCt9Xp
                                                                    MD5:B566F6C2DA0CF8CB9E711C9588F76ACE
                                                                    SHA1:61A26EE38863A45186779F55F779B6C1FDB66069
                                                                    SHA-256:B41138BA164326EA1A2F2D7C8DDE4182FA69AC9687D7ABBB6502236FA1F8577F
                                                                    SHA-512:1225F1FE1C4D1851CF3EE75D2EEC78588EBC33BAAE58FBCE55A5BF65C9D049E70B413E49AD40D89FB130D4E0ADF3F4056CBE8709E7E320BC0E573AB109903E06
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11767" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bmz0a" />.. <UTS T="2" Id="bmz0b" />.. <F T="3">.. <O T="EQ">.. <L>.. <S T="2" F="RequestSuccess" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="4">.. <O T="EQ">.. <L>.. <S T="2" F="HttpStatus" />.. </L>.. <R>.. <V V="401" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="2" F="HttpStatus" />.. </L>.. <R>.. <V V="403" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="2" F="HttpStatus" />.. </L>.. <R>.. <V V="404" T="U32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="2"
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):2153
                                                                    Entropy (8bit):3.605188552555672
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dULuQfXAt4yfXr5+7teoZ4e+FneC1PL4e0j5eAOeD:cOu2XAt4AXr5bj2z
                                                                    MD5:867D74FB75E911F06808693D549FC57A
                                                                    SHA1:E803911A4E5CB8016973839CFFDDB18E51998C3D
                                                                    SHA-256:2648C260B56EEABD9ACB4AEFE1501700712180A0517781D5F30FA0C46F1E7960
                                                                    SHA-512:8E4EC68AA57ADB1881CF1EF5A652E9B3FF3F7BE95E911CC3192676B87A854FC9CD4D97EE2B9BE98C255E7852E56CD623C638E53F20EEA48D39F58B7B2AE36C61
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11768" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="11767" />.. <F T="2">.. <O T="NE">.. <L>.. <S T="1" F="2" />.. </L>.. <R>.. <V V="4" T="I32" />.. </R>.. </O>.. </F>.. <F T="3">.. <O T="EQ">.. <L>.. <S T="1" F="2" />.. </L>.. <R>.. <V V="4" T="I32" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="2">.. <F N="0" />.. <F N="1" />.. </S>.. <S T="3">.. <F N="0" />.. <F N="1" />.. </S>.. </G>.. <C T="W" I="0" O="true">.. <S T="2" F="1" />.. </C>.. <C T="U32" I="1" O="true">.. <O T="ADD">.. <L>.. <A T="MAX">.. <S T="2" F="3" />.. </A>.. </L>.. <R>.. <A T="MAX">.. <S T="3" F="3" />.. </A>.. </R>.. </O>.. </C>.. <C T="U32" I="2" O="true">.. <O T="ADD">.. <L>.. <A T="MAX">..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):2798
                                                                    Entropy (8bit):4.187029908716092
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d2WsdRge8DvS8fbwOdIybGbkvbCbNvQe8LL8X1QJ5EcB7:c2JRge0vS8zgwU8gNE8lFQ
                                                                    MD5:651E78EAD579D2DC36429D12024DE5C2
                                                                    SHA1:E27CBE0E5DADB0485382F0301415994EDC7A5A77
                                                                    SHA-256:26BCA3417BC3B40E8EFCCC69433E5EAEF09018D90D6719FE1ECAE6AF5923F1DC
                                                                    SHA-512:25898DAD0AC61D507A8A36C8246CB9C3E58469C4D0A547AC57FBDA738BD840B495FD57880B24730A1D5C102B8706D67061AB2629C06B6140C7821DFDB94848CD
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11769" V="0" DC="SM" EN="Office.Outlook.Desktop.PcxAndOsfHttpStatus" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="11768" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="GE">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="LE">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="GE">.. <L>.. <S T="5" F="2" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="GE">.. <L>.. <S T="5" F="3" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):4634
                                                                    Entropy (8bit):4.601125821968251
                                                                    Encrypted:false
                                                                    SSDEEP:48:cge8jRgeLWvS8UNwR7dOhJz+701RsrMo7:a8jRgeCbUNwR7dOHry7
                                                                    MD5:07D1624FEEC8E1CBC56C4805F2CFC1AF
                                                                    SHA1:8E2C491B2D4BAFF981B8952110F8683B3EB815AD
                                                                    SHA-256:225EDF6F7FDEDC1FF49C540A2435D033F1253BC25B31E808C3E4DB4ABC33D9EB
                                                                    SHA-512:883B3B426AFDF05B8DF2AAE1F6BECCECA1EBA9A0032BAE5D10A0D39A939B17779DD362E4D9045E6BD874FDACF4682BE7C770DE6827FFBE3C39F940525B7477D4
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11770" V="0" DC="SM" EN="Office.Outlook.Desktop.PeopleSearchResultsReturned" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="cu5of" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="GE">.. <L>.. <S T="1" F="TotalResultsFound" />.. </L>.. <R>.. <V V="1" T="I32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="AND">.. <L>.. <O T="LE">.. <L>.. <S T="1" F="TotalResultsFound" />.. </L>.. <R>.. <V V="0" T="I32" />.. </R>.. </O>.. </L>.. <R>.. <O T="GE">.. <L>.. <S T="1" F="UnfinishedSources" />.. </L>.. <R>.. <V V="1" T="I32" />.. </R>.. </O>.. </R>.. </O>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):7262
                                                                    Entropy (8bit):4.292942473815119
                                                                    Encrypted:false
                                                                    SSDEEP:96:1RgegbwwwYwHA1yfiKqLAqrUmYuAbL+hWGL4Hf7:1Dgq1ycGL4/7
                                                                    MD5:E92DB98E314911DA51E04EFA313C4DC6
                                                                    SHA1:25A1988C58C2273ABFFE9D8039529370102BCD29
                                                                    SHA-256:678AA0A18F44A65DA8B857B58BD45E8A69D0B8026287A25C7BFF5DBC7866352F
                                                                    SHA-512:3E5588B7D2F6547CCBD5366099D512292F6ECE837C9BD109CF9BB617785EE5287A179EB9CED2E601CA853545E4270AB92CAAB786F95C4912BA829668B7804CFD
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11771" V="0" DC="SM" EN="Office.Outlook.Desktop.PeopleSuggestionsSessions" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="cwfnj" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="SelectionMade" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="4" F="StringLength" />.. </L>.. <R>.. <V V="0" T="I32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="4" F="StringLength" />.. </L>.. <R>.. <V V="1" T="I32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="4" F="StringLength" />.. </L>.. <R>.. <V V="2
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):2056
                                                                    Entropy (8bit):5.023105490945167
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dojsdRge02C0ibAOwOaYbJYg1cX5Cr9LfzHOx5p9GHG:coj8RgeQzQGJPT9rxHG
                                                                    MD5:4D14F934141F4077B282BF260D0EAB55
                                                                    SHA1:D0F8F0A72F206B66AB9B82AE56324B771D9DA911
                                                                    SHA-256:DE8BB531EB4A058C8B379E9EC804795B1A71F30FC345F60E085ACDF6C574D913
                                                                    SHA-512:EDCF47EAAB59889250F8D74CFFB5C466F334BD5EF0B0DD5D935E470B4BE58DE5A20CED3B390B9A1523ACC6D435F416DD537A82E42AB8DBB55811CB0AF1DFFCEA
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11772" V="0" DC="SM" EN="Office.Outlook.Desktop.Diagnostics.System.GetDiagnostics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="10" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="733" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="2" E="732" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="3" E="734" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="4" E="735" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <F T="5">.. <O T="EQ">.. <L>.. <S T="3" F="ControlName" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="3" F="ControlName" />.. </L>.. <R>.. <V V="2" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="ClosedView">.. <S T="1" F="CollectDiagnosticView" />.. </C>.. <C T="I64
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):771
                                                                    Entropy (8bit):5.261592979598644
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd3Vzjjq0dRDDHwpat5lil/q3TPZdLjSTFUST3tyxP2ZQSTCUSTGNO2su:2d380dRgeTjbXSTGSTIx+2ST/STW
                                                                    MD5:2115913299B74CA91CEA081B8D4DE545
                                                                    SHA1:71B5ABC026BDE0EC732B9ADBE7C1EF15F15CC4B8
                                                                    SHA-256:2C244A915753832973743C436A927356B8BCFED5FF707BD02039C9FB798B3214
                                                                    SHA-512:2BFAE2B49A1E697760AC66849973573D6850ABD61CF6A7FC8C58C437EAF31BC2DDA6752581B864A7AE6D5BE250D635F5935A3EEA6D0020BD6F2B7D284987C0C6
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11773" V="0" DC="SM" EN="Office.Outlook.Desktop.Diagnostics.System.GetDiagnosticsCompressFiles" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="20" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="736" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. </S>.. <C T="I64" I="0" O="false" N="HResultFilesCompressed">.. <S T="1" F="HRESULT" />.. </C>.. <C T="W" I="1" O="true" N="CompressedArchive">.. <S T="1" F="CompressedArchive" />.. </C>.. <C T="I32" I="2" O="false" N="FilesCompressed">.. <S T="1" F="FilesCompressed" />.. </C>.. <C T="U64" I="3" O="false" N="CompressedArchiveSize">.. <S T="1" F="CompressedArchiveSize" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):443
                                                                    Entropy (8bit):5.339981847676649
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdpVzjudRDDHwpat5DtqaUVLYfACkxNO2su:2dpAdRgebwYBk3
                                                                    MD5:850FDECBAC8158CEE24945F63A6DDD45
                                                                    SHA1:E42EB9F1D198EC6956F3528CEF7FABA1EB301854
                                                                    SHA-256:C19E688D0EB3AE9E92179A6EDD461539E1CA41E41C3BE34264F5F82A3E70A567
                                                                    SHA-512:DC4B2D302410F5D22618EEA5D1F6934D7408B41AAE237AD8C898059CC42EB186B1F00E5ADCA66BFD0923628535CFCB544EC5CAD15EF6532062B54D1A087B784A
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11775" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.ArrangementMetrics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="1" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="13032" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="U32" I="0" O="false" N="ArrangeType">.. <S T="1" F="ArrangeType" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1438
                                                                    Entropy (8bit):5.289843595247927
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d84MadRgeVWhU2yeKkmk8naAewVQngUnZJ:c84MWRgeVBnlegQ1ZJ
                                                                    MD5:FACCAD5A993E27229A39BA717674AEBA
                                                                    SHA1:1D21C7CCF5653F87FD7F165E346CC506B47DDBA1
                                                                    SHA-256:AFC69B98314A876669ED3B64814493886E27AFC06C69152DED5EB3E9D6612217
                                                                    SHA-512:33C2E882720D7EBFC33B369771ADF224EF79A9C61C5C875726ACB885912EEC67759EFAFF6B1D762AF47D1E53A372DA61474F6B2EB8B83B4B74F7D492D47A5EE6
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11780" V="1" DC="SM" EN="Office.Outlook.Desktop.InAppContactSupport.InitialScreenshot" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="739" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="2" E="740" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="3" E="741" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="4" E="742" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="5" E="743" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="6" E="744" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. </S>.. <C T="U64" I="0" O="true" N="ScreenshotCaptureHRESULT">.. <S T="1" F="HRESULT" />.. </C>.. <C T="U64" I="1" O="true" N="ThumbnailGenerationHRESULT">.. <S T="2" F="HRESULT" />.. </C>.. <C T="U64" I="2" O="true" N="ReconInvokedScreenCapturingHRESULT">.. <S T="3" F="HRESULT" />.. </C>.. <C T="U64" I="3" O=
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):452
                                                                    Entropy (8bit):5.345561286329968
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd10SVzjTqsdRDDHwpat5lSSslsaFaN1JyNO2su:2dGSRldRge1slDEi
                                                                    MD5:F6109E54AB82FED091808C53481C9435
                                                                    SHA1:120F3E2AB578397FE0D13BBB770B7005A00B32E2
                                                                    SHA-256:943AD6C16AEEFC5C3C36C945345CAC190595D4CFE18C29B24D3B9CC9D6C62783
                                                                    SHA-512:56F69C1A2E51DD195339A772252D4EF292EECE06731125AEA0B892BCDFA4195DA1E1A0861E73F18B83643DE0057371EBF47E4E719B3AEE43E8099F06A6A13B27
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11783" V="1" DC="SM" EN="Office.Outlook.Desktop.SearchQueryScopeAndGetterType" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="200" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="7002" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. </S>.. <C T="W" I="0" O="true" N="GetterTypeString">.. <S T="1" F="GetterTypeStr" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1011
                                                                    Entropy (8bit):5.004524873937057
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd2VzjSXdRDDHwpaty6ab2GeOSXFJicdDUTO+6O+S0MfrzfTTxWGfOxME/x9q8:2d2EXdRgeevLqvq+cPdmov1fu
                                                                    MD5:173069DDF69BC9E19FCC2FB5098BD6C7
                                                                    SHA1:551513B350D04F803607A7EBC3A409E5BCD707E4
                                                                    SHA-256:DB85ACB517242F2E174857BD665CE5119F8CEB60BA11442C2D1D46ADC4A8967C
                                                                    SHA-512:F96F7CA74DC9A6600A19454410130A32472FB18DA3B1FB99B427F11CA1BB6F018FBD769008D82CD711BB699FE1FCEDD2109C1B64F320C1ADFCDE85F213047871
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11787" V="0" DC="SM" EN="Office.Outlook.Desktop.Store.RestVerbFailures" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DL="A" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9001" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Hourly" />.. </S>.. <G>.. <S T="1">.. <F N="StoreType" />.. <F N="SessionType" />.. <F N="CONTEXT" />.. <F N="HRESULT" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="StoreType">.. <S T="1" F="StoreType" />.. </C>.. <C T="U32" I="1" O="false" N="SessionType">.. <S T="1" F="SessionType" />.. </C>.. <C T="U64" I="2" O="false" N="MethodCtx">.. <S T="1" F="CONTEXT" />.. </C>.. <C T="U64" I="3" O="false" N="Failure">.. <S T="1" F="HRESULT" />.. </C>.. <C T="U32" I="4" O="false" N="FailureCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. <
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):796
                                                                    Entropy (8bit):5.1074346506122446
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd/2YVzjpdRDDHwpaty6i2GeOSXFJicdD+S0Mr/x9cXZp7XHaSMNO5csu:2d+Y/dRgeovLqve/u
                                                                    MD5:6E2AC6E60ABAD69D35216E20CBD87B17
                                                                    SHA1:5C1332B702F222A951845CBE0FDBAAE6C839F6A6
                                                                    SHA-256:02B2D53D5EE5C083C102BC996C1883C225992729FA0304C64DC87390ADF967FB
                                                                    SHA-512:30B7EFDD7B8B41CBBAAE785BC26DE5D5531FF9C7F341CD157BC773D8FB77C7BCD0B2A9521CD7773879D7C5B7DAED7218A60E7A6643E8FC8B3140D5F93A594744
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11788" V="0" DC="SM" EN="Office.Outlook.Desktop.Store.RestVerbConvertHelperFailures" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DL="A" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9003" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Hourly" />.. </S>.. <G>.. <S T="1">.. <F N="CONTEXT" />.. <F N="HRESULT" />.. </S>.. </G>.. <C T="U64" I="0" O="false" N="MethodCtx">.. <S T="1" F="CONTEXT" />.. </C>.. <C T="U64" I="1" O="false" N="Failure">.. <S T="1" F="HRESULT" />.. </C>.. <C T="U32" I="2" O="false" N="FailureCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):790
                                                                    Entropy (8bit):5.096313992996928
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd3YVzjdIAdRDDHwpaty6X32GeOSXFJicdD+S0Mr/x9cXZp7XHaSMNO5csu:2do3IAdRgeBvLqve/u
                                                                    MD5:45DE7F16841201DD4C31F6C4D7D3FC68
                                                                    SHA1:9E018C9EFB512E4FE33A3A2AC0348C74AC8159F8
                                                                    SHA-256:79CFBBF31162CBF95AC41EAD2671210217759C91B4918D2723125C337DD330B6
                                                                    SHA-512:7C0524CB526F0B4E38163B3A22F2F73C6CDF9EC5F2EA53F18E9C20C178338EDA8790F3D06F3E23C13093410E9F9D67EA6D8A5254ED7CF812BA94C2FC4AEE546D
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11789" V="0" DC="SM" EN="Office.Outlook.Desktop.Store.RestVerbConvertFailures" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DL="A" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9004" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Hourly" />.. </S>.. <G>.. <S T="1">.. <F N="CONTEXT" />.. <F N="HRESULT" />.. </S>.. </G>.. <C T="U64" I="0" O="false" N="MethodCtx">.. <S T="1" F="CONTEXT" />.. </C>.. <C T="U64" I="1" O="false" N="Failure">.. <S T="1" F="HRESULT" />.. </C>.. <C T="U32" I="2" O="false" N="FailureCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1033
                                                                    Entropy (8bit):5.318046582182046
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdrVzj9KdRDDHwpat5auq36pq3sTqhAEJG/ZZ/rrP/Qnt9Dt2/eztanszaJAGu:2drmdRgeYxc2gUaqew+QQngin+
                                                                    MD5:51946DC35ED3BF5C6A318D148D73094D
                                                                    SHA1:0B3C9276E177AEB97C3C855F2162558E875497AF
                                                                    SHA-256:330FFD3951C9EBA271853EC5EDD736D1E6C5D8D369C7EC280A92E670DDD49DF6
                                                                    SHA-512:A380BB78BB9811076830EB7C9319B909B05B9B719AC4EF0F0E4EE90B1E68EFA72D6A65AC217C2E5502E4F983100CDD019C8D62014CA3AD6E41CDD86078F188B1
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11790" V="1" DC="SM" EN="Office.Outlook.Desktop.FeedbackPane.InitialScreenshot" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="753" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="2" E="754" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="3" E="755" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. </S>.. <C T="U64" I="0" O="true" N="FeedbackInvokedScreenCapturingHRESULT">.. <S T="1" F="HRESULT" />.. </C>.. <C T="U64" I="1" O="true" N="FeedbackEmbeddedThumbnailHRESULT">.. <S T="2" F="HRESULT" />.. </C>.. <C T="B" I="2" O="true" N="UserCheckedIncludeScreenshotBox">.. <S T="3" F="UserCheckedIncludeScreenshotBox" />.. </C>.. <C T="B" I="3" O="true" N="AddedDataCollector">.. <S T="3" F="ResolvedLoggingLocation" />.. </C>.. <C T="W" I="4" O="true" N="OutlookSession">.. <S T="3" F="OutlookSession" />.. </C>.. <T>
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):7022
                                                                    Entropy (8bit):3.789256707640678
                                                                    Encrypted:false
                                                                    SSDEEP:96:wRgenbY5CH/dKfF9feKHg+CjrQP87tPzu7:wDnihGtLu7
                                                                    MD5:E847D7DF616B3A0E027DE6EB8E6FF235
                                                                    SHA1:8EC93455D7C15AB5F896CB730E39F9B752F41313
                                                                    SHA-256:E2564AB6A484A9753453B93E173844D3FF3CE794BF3A28F39557CDBED1E2223E
                                                                    SHA-512:AB46DC4E28905E04036D72CD1C26B7D9FE24605A66F388A9954F201662A6CD0A62C470836E0A5C451A4CC8B7A597FE8526AE1E6CF1A2509250C53BA751C39E56
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11792" V="1" DC="SM" EN="Office.Outlook.Desktop.PeopleSuggestionsDisplayTimes" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSP" xmlns="">.. <S>.. <UTS T="1" Id="cwfnh" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="IsFirstInSession" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="LT">.. <L>.. <S T="4" F="ElapsedMsForSession" />.. </L>.. <R>.. <V V="100" T="I32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="4" F="ElapsedMsForSession" />.. </L>.. <R>.. <V V="100" T="I32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LT">..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1217
                                                                    Entropy (8bit):4.65026027684882
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dV5nx6dRgeLr3vS8dbwOa71EeEgFwEcF4ES7:cV5nx2RgeLLvS8hQ8S7
                                                                    MD5:DA668269FEE0A29C7ECCDE1A0358FB99
                                                                    SHA1:DE01DCF29DF053044E4DE5B30AA623AA8F8DA6C5
                                                                    SHA-256:C7F732A8FA1233F261CEC481AB65B93456EE6D9B55B2956E728BEC4A8DBDE070
                                                                    SHA-512:6C3AA373E3AFB4ABF2CF3A5BDA35C3C03CF010C515061591175442ED76ACFF51DBFD8A823EDF7050BFC80FA8508749BBF20E4C8EE6FBD63A7AE18AFF11BC5D3D
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11793" V="0" DC="SM" EN="Office.Outlook.Desktop.PeopleSuggestionsSearchStats" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="cwfni" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="GE">.. <L>.. <S T="1" F="Suggestions" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="Suggestions" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="CountSearches">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="CountSearchesWithSuggestions">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="CountSearchesWithoutSuggestions">.. <C>.. <S T="5" />..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1382
                                                                    Entropy (8bit):3.6365736385425627
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dsrXhomuyaPkI3t41ST1lwOa1XOP4POsPv0x8:csFomuyab3t4QTDQ/
                                                                    MD5:E52549C1D1538EDCA8579CBD6609F2EB
                                                                    SHA1:CF9C6D726FC627F576C026F782A09E98FB390502
                                                                    SHA-256:4DE0A3F26DE982FD5930E5F250B545EF928F7D3C63B542E582D287BBD1A57AC2
                                                                    SHA-512:73447D460ACC793630EE22095729CB6E6F34B94455417D52FBC02E030091F1BD7D1D8BCF106D07D2259B7CF443CCBA1E3CA7195C74659FBCFF81FDBB89559DF9
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11794" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="by7xb" />.. <F T="2">.. <O T="EQ">.. <L>.. <S T="1" F="valueName" />.. </L>.. <R>.. <V V="DefaultIMApp" T="W" />.. </R>.. </O>.. </F>.. <F T="3">.. <O T="EQ">.. <L>.. <S T="2" F="data" />.. </L>.. <R>.. <V V="Communicator" T="W" />.. </R>.. </O>.. </F>.. <F T="4">.. <O T="EQ">.. <L>.. <S T="2" F="data" />.. </L>.. <R>.. <V V="Lync" T="W" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="2" F="data" />.. </L>.. <R>.. <V V="Teams" T="W" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false">.. <O T="COALESCE">.. <L>.. <O T="COALESCE">.. <L>.. <S T="3" F="data" />..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):3286
                                                                    Entropy (8bit):5.129492498358063
                                                                    Encrypted:false
                                                                    SSDEEP:48:cHTRgezunfsLpw57LD7Q+o4e1XHdja7yf:sRgezEsLOqHdu2f
                                                                    MD5:5BCF913C003837AC915DCBCA2F2BCB02
                                                                    SHA1:4F7C2C00A5296F54B42AD5F9C477D1813786706E
                                                                    SHA-256:B0ADBAB65A26317E44D515FF7A7883F6BBF001546A3F29C18B1836DA4DF7F7E3
                                                                    SHA-512:83B6D45BEFA2962AF566EAC1940DA3B3C9618985D19DE70B1B0DB6791DBA80F1A4B86FAB84C2C112548775B1134E1311D68EA41F799B90C6327F115198180DDA
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11796" V="3" DC="SM" EN="Office.Outlook.Desktop.Diagnostics.System.WatsonCrashDeflectionsOnBootNovFork" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" SP="CriticalBusinessImpact" S="1" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="396" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="500" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="3" E="503" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="4" E="506" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="5" E="507" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="6" E="508" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <F T="7">.. <O T="EQ">.. <L>.. <S T="1" F="IsCrashTypeSet" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <C T="I64" I="0" O="true" N="BootComponentSuccessHRESULT">.. <S T="1" F="HRESULT" />.. </C
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1685
                                                                    Entropy (8bit):4.6711415976317605
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dHHVytwfxnC1hgg0K5HvYOdwT/2NVz2r:cH1YOxmhbbllwT/2L2r
                                                                    MD5:9C87C252D62194564E5282B647D4E8DC
                                                                    SHA1:6E26567F8EE04F5A971F3BF181CC0E3BA4F61CE3
                                                                    SHA-256:557426E09B2B48FBE1EDCF3990750AF01D732AAA7B338BF72324DA438382A47B
                                                                    SHA-512:51BF122E94DC1102B1AC0A37480F3C660D6E36E4C6186CDD3836E87E6DDFEA5BBFD3D32E07A6836026B07E87EFF0022AA7CCB16CFA98ADA7AFE3D48C822B8A21
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11798" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="1605" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. </S>.. <C T="B" I="0" O="false">.. <O T="LT">.. <L>.. <S T="1" F="cbRequested" />.. </L>.. <R>.. <S T="1" F="ulStreamSize" />.. </R>.. </O>.. </C>.. <C T="U32" I="1" O="false">.. <S T="1" F="ConnID" />.. </C>.. <C T="U32" I="2" O="false">.. <S T="1" F="ec" />.. </C>.. <C T="B" I="3" O="false">.. <S T="1" F="fReadCacheEnabled" />.. </C>.. <C T="U32" I="4" O="false">.. <S T="1" F="ServerConnectionType" />.. </C>.. <C T="B" I="5" O="false">.. <S T="1" F="fPackedCompressedEnabled" />.. </C>.. <C T="B" I="6" O="false">.. <S T="1" F="fAllowLargeBuffers" />.. </C>.. <C T="B" I="7" O="false">.. <S T="1" F="fReadCacheV2Enabled" />.. </C>.. <C T="U32" I="8" O="false">.. <S T="1" F="m_cbReadAheadBufSize" />.. </C>.. <C T="U32" I="9" O="f
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):2030
                                                                    Entropy (8bit):4.619617140501037
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dv4x6dRge/RuQuJth52h3VafmsUbAg7jNNfsG+ed:cv4x2RgepuZJr5M3cfmsUbJxNfsG++
                                                                    MD5:97D4B23FE5BFDE7ACB9CA5BCDDDA1514
                                                                    SHA1:C4B7A692ED41BE5EAA77DB65E364468537CCA742
                                                                    SHA-256:1CE34C2820D786F08BDB985A06858965BCC22F92790C039D77817FE177BA04D3
                                                                    SHA-512:177110DCBDE5AFC76F68B73AF44BF9C0540F727B645A64915279254B3270C1B64CEC2BB226F4836815595BA010821C43B2C54E0B50F5B93BFBEC447A54A61C30
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11799" V="0" DC="SM" EN="Office.Outlook.Desktop.StreamObjReadSummaryStats" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSP" xmlns="">.. <S>.. <R T="1" R="11798" />.. <F T="2">.. <O T="NE">.. <L>.. <S T="1" F="2" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <A T="3" E="TelemetryShutdown" />.. <TI T="4" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="0" />.. <F N="3" />.. <F N="4" />.. <F N="5" />.. <F N="6" />.. <F N="7" />.. </S>.. <S T="2">.. <F N="0" />.. <F N="3" />.. <F N="4" />.. <F N="5" />.. <F N="6" />.. <F N="7" />.. </S>.. </G>.. <C T="B" I="0" O="false" N="IsPartialRead">.. <S T="1" F="0" />.. </C>.. <C T="B" I="1" O="false" N="FReadCacheEnabled">.. <S T="1" F="3" />.. </C>.. <C T="U32" I="2" O="false" N="ServerConnect
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):796
                                                                    Entropy (8bit):5.179220776086826
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd+Vzj1u6dRDDHwpatE7A+KbSfA+KbSQicih22AxKOHaSMjncEb/HhSMNOAdHL:2d+jRdRge/JHwZbr
                                                                    MD5:88FDD5C4E51211380CBD8336C6A30F0E
                                                                    SHA1:C5E5342F6CF3376E26735D96B010D921F0C2D3CE
                                                                    SHA-256:FEC051E42DEDAD8B3414D57A8EDF46F3C5E2C954A059976BFB74335E3C17F71D
                                                                    SHA-512:35592F6593A84917E548A0F36781D0339258BF7BC1A2E3B5542AB0D481FAA75208E8C5D6BA322E17E1D77C383CD34EA0DFB0B4BC77D824C0990514E18453B3A9
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11800" V="0" DC="SM" EN="Office.Outlook.Desktop.StreamObjReadCacheV2Errors" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="1606" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <Etw T="2" E="1607" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <A T="3" E="TelemetryShutdown" />.. <TI T="4" I="Daily" />.. </S>.. <C T="U32" I="0" O="false" N="CountReadCacheV2AppendBufferFailed">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="CountCursorPosNotMappedInRopBufferDataChain">.. <C>.. <S T="2" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="4" />.. </T>.. <ST>.. <S T="1" />.. <S T="2" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):555
                                                                    Entropy (8bit):5.333822079764966
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdDVzjTLsKidRDDHwpat5az7slguRS31o+F1oCNO2su:2dDRAKidRge87slAjn
                                                                    MD5:5E1779D526A22FF145F58546B465F0EB
                                                                    SHA1:9E6C8E8FAD365FBBAFFE7DAA3C03C713CB40B210
                                                                    SHA-256:8DF184C50A95DD4E729907F91B570517C391C1BAF66994B7E81840E167ADFE45
                                                                    SHA-512:DBD1A7C55F856A9AD4788BAB2C99690369A11A1CA9FBC799FED0731F014D0CEA266251F71D9D2A67E3E952A11E16B4DCA6641DE8F01FC09A2B0027BA7EFE4AFC
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11801" V="0" DC="SM" EN="Office.Outlook.Desktop.Search.FuzzyMatchShownTime" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="7148" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. </S>.. <C T="W" I="0" O="false" N="ReferenceId">.. <S T="1" F="ReferenceId" />.. </C>.. <C T="I64" I="1" O="false" N="DisplayedDurationMillis">.. <S T="1" F="DisplayedDurationMillis" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):826
                                                                    Entropy (8bit):5.185561178399846
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdvVzjvCQPdRDDHwpat5liEBMA+KbX7dDeyW+ysfbOyQxMLiZ7cHbSPcHyN1Dr:2dvYQPdRgeTjBeHsTFQ+SlZ1cub
                                                                    MD5:39CF88120D3975C11207DF00F42BA0A5
                                                                    SHA1:0C4F1C3E584ECBAD159BA4ADF137FD559D077A03
                                                                    SHA-256:4C05FCCA6E1AC1EEF9ACED796EA9837D267FC7806DFE461CDCA6902CB66360E9
                                                                    SHA-512:65796D017E619D55AB7F0B4388831C41E1E0C47093C2DF7868920965A2ACF466B754A35F308986A7C1FD9FBAB5C121885EFAA3F6106DE6239E05F672159502E7
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11805" V="0" DC="SM" EN="Office.Outlook.Desktop.OpenMessageStore.FailedToConnect" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="20" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="2077" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. </S>.. <C T="U32" I="0" O="false" N="StoreLogonHelperID">.. <S T="1" F="StoreLogonHelperID" />.. </C>.. <C T="U32" I="1" O="false" N="CurrentState">.. <S T="1" F="CurrentState" />.. </C>.. <C T="U64" I="2" O="false" N="ResultErrorCode">.. <S T="1" F="HRESULT" />.. </C>.. <C T="U64" I="3" O="false" N="GlobalError">.. <S T="1" F="GlobalError" />.. </C>.. <C T="U32" I="4" O="false" N="CountOfRunAutoD">.. <S T="1" F="CountOfRunAutoD" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):918
                                                                    Entropy (8bit):5.181172050807619
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdOg4VzjvRdRDDHwpat5lilBF0A+KbX7dDeyW+ysfbOyQxMLiZ7cHbSPcHyN1J:2dO1ndRgeQFrBeHsTFQ+SlZ1cri
                                                                    MD5:D009139DEE8226683804CBF72295916C
                                                                    SHA1:D2FCF20E4975DC680FCBB333A4BAB5DECFB33AA0
                                                                    SHA-256:67C81689BE24B85BCC6570EE826038F2C240EFAED56B2B8BD51520370CD6B7A1
                                                                    SHA-512:2A61BDD8BB9313FDC3DD4DB8BBA68EB9751F8B1F9F5956C2EDB6B651F1CBC470208B62E789F074BE47A3B396C62C7232BAE363E654FB7368C97A40B00B024EF1
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11806" V="0" DC="SM" EN="Office.Outlook.Desktop.OpenMessageStore.RunAutoDAsync" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="20" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="2075" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. </S>.. <C T="U32" I="0" O="false" N="StoreLogonHelperID">.. <S T="1" F="StoreLogonHelperID" />.. </C>.. <C T="U32" I="1" O="false" N="CurrentState">.. <S T="1" F="CurrentState" />.. </C>.. <C T="U64" I="2" O="false" N="ResultErrorCode">.. <S T="1" F="HRESULT" />.. </C>.. <C T="U64" I="3" O="false" N="GlobalError">.. <S T="1" F="GlobalError" />.. </C>.. <C T="U32" I="4" O="false" N="CountOfRunAutoD">.. <S T="1" F="RunAutodiscover" />.. </C>.. <C T="B" I="5" O="false" N="IsFireAndForget">.. <S T="1" F="IsFireAndForget" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1301
                                                                    Entropy (8bit):5.176058544002295
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dENdRgeSIiVIiagevUOIeXct5MI8t0M6cNsF0dAULPwR:cEPRgeSpYUOWPF8CwNsgBPu
                                                                    MD5:812DC9CC1AC86317CCCE49A30A467CE1
                                                                    SHA1:02EBA0A3C875D80A4A80D36B02559117546FFBDC
                                                                    SHA-256:704422399B852A02C3E8C1E923010A92507F6E612A379991F856E96F2AB7E977
                                                                    SHA-512:A623A1A54FF6D16D22754CA25E2EEE4D5E247501AB6091054B3DE5D8E0BF2CCBA070E8F025225B0F8DF857A4C9EA3C0A541F71BE68B19B1E80D4F272E5276519
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11807" V="1" DC="SM" EN="Office.Outlook.Desktop.CalendarEndEarlyByDefault" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="10" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="906" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <Etw T="2" E="907" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. </S>.. <C T="U32" I="0" O="false" N="DefaultDuration">.. <S T="1" F="DefaultDuration" />.. </C>.. <C T="B" I="1" O="false" N="EndEventsEarly">.. <S T="1" F="EndEventsEarly" />.. </C>.. <C T="B" I="2" O="false" N="EndEventsEarlyGP">.. <S T="1" F="EndEventsEarlyGP" />.. </C>.. <C T="U32" I="3" O="false" N="EndEarlyShortDuration">.. <S T="1" F="EndEarlyShort" />.. </C>.. <C T="B" I="4" O="false" N="EndEarlyShortGP">.. <S T="1" F="EndEarlyShortGP" />.. </C>.. <C T="U32" I="5" O="false" N="EndEarlyLongDuration">.. <S T="1" F="EndEarlyLong" />.. </C>.. <C T="B" I="6" O="false" N="EndEarly
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):565
                                                                    Entropy (8bit):5.284114766191096
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdrVzjIdRDDHwpat5rFL2Jqt/wGqHneWXaNO2su:2drmdRgeHI8
                                                                    MD5:5B1C85AC89EF3080CEE22941979E72AE
                                                                    SHA1:8E4FD87B4700C4CB276BD039944987F2D5C9BFCA
                                                                    SHA-256:ED98A72360BEE7E07959D69B58DF70474084285B26FBE3A13A122F23482DE81A
                                                                    SHA-512:0449202951BE449AD2A923555951D6632295D09700450BB037744367B15F8A6F4BEB6049D0B3C0D8DE4289DFDD20823F9FFD1116CA6164AE5D4C90302375E140
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11809" V="0" DC="SM" EN="Office.Outlook.Desktop.ReadingPaneSelectItem" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="10" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="6218" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="B" I="0" O="false" N="ReadingPaneSelectItemOption">.. <S T="1" F="fReadingPaneSelectItemOption" />.. </C>.. <C T="B" I="1" O="false" N="FromReadingPane">.. <S T="1" F="fFromReadingPane" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):3122
                                                                    Entropy (8bit):4.385421737557271
                                                                    Encrypted:false
                                                                    SSDEEP:48:cx2RRgeft6vJQkpJkwukjvkd0sk/lL/GExtFnfaPbop6MiG:fRRgeGdl5RF/+bG
                                                                    MD5:9C7CEAF0E51F5D30EB90560B123EA71F
                                                                    SHA1:C069C542C27593C5D2F8F03B427CBFD43E893B40
                                                                    SHA-256:38D76229BC5756C5299FB9B9B903D44C828502F29C96A34667C7F63F7D8DADA7
                                                                    SHA-512:2C69494AEBB667D84A52916AA5F28BD921F990FF8486716B17A292E27E9FDFA0276AB6ECA25CF905D225CE85A306B1DD9ED8B26760E05F42847E5EC42536FC5A
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11810" V="0" DC="SM" EN="Office.Outlook.Desktop.Reminders.AutoDismissImpactStatistics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="20" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="834" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <Etw T="2" E="837" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <TI T="3" I="Daily" />.. <A T="4" E="TelemetryShutdown" />.. <F T="5">.. <O T="EQ">.. <L>.. <S T="2" F="RemindersDisplayedCount" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="2" F="RemindersDisplayedCount" />.. </L>.. <R>.. <V V="2" T="U32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="2" F="RemindersDisplayedCount" />.. </L>.. <R>.. <V V="3" T="U32" />..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):3245
                                                                    Entropy (8bit):4.267958950605029
                                                                    Encrypted:false
                                                                    SSDEEP:48:czCRgevT6vJQ5JOuzvAsm08rxYq/mqfyaxEUCCfUMbV7:1RgeUA4A4gihBfvj9Z7
                                                                    MD5:8AA67F3543B9544084593C1118267ECC
                                                                    SHA1:E5B529FB90A98A35A3D193FD46F4FDE808BE99BF
                                                                    SHA-256:9293665B2265EECC0ABC5223A1D4A68222C34E89BB6181EAAB2223D53DF925EF
                                                                    SHA-512:D14428D5FFA99AA7690CC63A8BD28F02B742BF040A14437403DE9BE449D97C5E55EE0251203386696D6113B45D4464603B7623D88061EE0FAA1CE23A998B6D59
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11812" V="0" DC="SM" EN="Office.Outlook.Desktop.Reminders.ReminderSourceStatistics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="838" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <Etw T="2" E="839" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <TI T="3" I="Daily" />.. <A T="4" E="TelemetryShutdown" />.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="SourceMessageClass" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="SourceMessageClass" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="1" F="SourceMessageClass" />.. </L>.. <R>.. <V V="2" T="U32" />.. </R>.. </O>.. <
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1463
                                                                    Entropy (8bit):4.90533255035527
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dsjRcdRgeNsxsVsO82gjzhfzPNqcPWKjBqk:csjWRgeqWyO82gjzhfxuCT
                                                                    MD5:002F4E2FB6CC9E35EFC663364AD9C5CA
                                                                    SHA1:F73E656BB342C1AE63BF2C3A2D1FA4F7707B4F91
                                                                    SHA-256:082DA1A833535AD8FB44846CE559CB17170F2D58AA2D7DA4BD5B10A5DE203D70
                                                                    SHA-512:B888B47ECBE626FDDC9349ADFB1F1FA0E70C4CF177CDE5C4AD68689A04BD9015ECBA3D5CEC6BF4DF22C845CA5567598709517CEA975803C6B1E5B989DFFD670D
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11813" V="0" DC="SM" EN="Office.Outlook.Desktop.SearchSuggestionHitHighlighting" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="7152" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <Etw T="2" E="7153" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <Etw T="3" E="7154" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <A T="4" E="TelemetryShutdown" />.. <TI T="5" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="SuggestionType" />.. </S>.. <S T="2">.. <F N="SuggestionType" />.. </S>.. <S T="3">.. <F N="SuggestionType" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="SuggestionType">.. <O T="COALESCE">.. <L>.. <S T="1" F="SuggestionType" />.. </L>.. <R>.. <O T="COALESCE">.. <L>.. <S T="2" F="SuggestionType" />.. </L>.. <R>.. <S T="3" F="Sug
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1398
                                                                    Entropy (8bit):4.729629546757337
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dosRdRge37vJwOaBvjqJ4c6AsnpsmrxsG:cocRgervJQBqJV+hh
                                                                    MD5:0CD366528765FE78F5BBBB844C881910
                                                                    SHA1:CFA4E6042D922CCB6C30E01BD17AEE5B435BAACA
                                                                    SHA-256:4A80852B3C97D86EBDF909A16AABFCAC5A8401B675CF753C5D7B15DEC359CDCF
                                                                    SHA-512:A51A8AE8DF6F3695C6A69892F2F7A80FBFD3D496511C6787E004157B22A6922EDB8AEB123928E3DF41016144C6BB96A5F561470DE7C3A9E0ED09449D92B15432
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11815" V="0" DC="SM" EN="Office.Outlook.Desktop.FolderBar.MobileBanner" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3742" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="3743" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="3" I="Daily" />.. <A T="4" E="TelemetryShutdown" />.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="IsInDraftsFolder" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="2" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="I32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="NE">.. <L>.. <S T="2" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="I32" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32"
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):710
                                                                    Entropy (8bit):5.182305722031781
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdfVzjf6bl6dRDDHwpat5DPHc1NQzD0MffDnXHaSM0DF/ZNO5csu:2dfsbodRgegqNLpH
                                                                    MD5:B0AD21C9DE626670E7ACBC468441F66E
                                                                    SHA1:858AE494032CC8DA3CE1EB6952BCEA6AE975C70B
                                                                    SHA-256:D67DFCE8004A25FD56F31924B4A23A6367597B558F92386D6C6A38BA892B7F86
                                                                    SHA-512:EF927288943CCAAE7FC7A26998E139E633E947A603FCAAF06F159E4B97DB81150B82B13E43F49C1E5B935B016C28A5405CE0EB3AE822ED3CFF123EDC9E083445
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11816" V="0" DC="SM" EN="Office.Outlook.Desktop.FolderBar.MobileBanner.Errors" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3743" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="HRESULT" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="MobileBannerClickCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="MobileBannerClickHRESULT">.. <S T="1" F="HRESULT" />.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):824
                                                                    Entropy (8bit):5.12526187702441
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdQVzjHdRDDHwpatE0HXFJicouD7/NOSfwxCfIymO9Gk7AWNAhNXnt6uIPSNOw:2dQNdRgetvSxCWN
                                                                    MD5:F56D9EB86EDD57B410CBB4558A7EB876
                                                                    SHA1:8CB3E55AD2789F5CE938927A13038587D3865533
                                                                    SHA-256:FE90D2F8AA5694150B38C1F27A037C77A961E5917290F0D8E4AED13D0DA20E9B
                                                                    SHA-512:A5028DF737C17232BCCD75BC65DD6475813B5CC1F87C19608BCAEDD93D06972DC9C6B80856C7CCFE1D3642FEE30D0EF09553BD769B89FA88AA1155F1770A4CEA
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11818" V="1" DC="SM" EN="Office.Outlook.Desktop.Groups.DragDropToGroupIncapable" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="19037" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="IsOwner" />.. <F N="Incapability" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="IncapabilityType">.. <S T="1" F="Incapability" />.. </C>.. <C T="U32" I="1" O="false" N="SumOfMessages">.. <A T="SUM">.. <S T="1" F="CountOfMsg" />.. </A>.. </C>.. <C T="B" I="2" O="false" N="IsOwner">.. <S T="1" F="IsOwner" />.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1254
                                                                    Entropy (8bit):4.653039335917695
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdNVzjuPdRDDHwpatEbHXFJicoN+kXqNOvTOX/c//0pONd+wsvXqNOvTOX/c/8:2dNUdRge8vS8TOabwOaOagK09Q5
                                                                    MD5:ACF7A36B03765D036F25EA097180D5FB
                                                                    SHA1:D2F9E4ACDBB2B077A4E41131B7EA9726E675F23F
                                                                    SHA-256:04C93B67B26D286E4962DF8A717BDE9609CFA9D10E0ACA97B78B11FE0C2AEB25
                                                                    SHA-512:87F6342C20BC2448835DAF2514B9E8DAA6D00D5C33396542721632A47C8673F07AC46BE933ABC6BB98F6DB712E5706475E101A11B9C5C9AA0CAD68C42092EB3E
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11819" V="1" DC="SM" EN="Office.Outlook.Desktop.Groups.DragDropToGroupUndo" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="19038" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="OpType" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="OpType" />.. </L>.. <R>.. <V V="2" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="1">.. <F N="IsOwner" />.. </S>.. <S T="4">.. <F N="IsOwner" />.. </S>.. <S T="5">.. <F N="IsOwner" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="UndoCopy">.. <A T="SUM">.. <S T="4" F="CountOfMsg" />.. </A>.. <
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):456
                                                                    Entropy (8bit):5.282923398064508
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdu2YVzjzmPdRDDHwpat5D74Ibpl9/NlmMNO2su:2du2Y9mPdRgetr9Xmk
                                                                    MD5:20733B1AF7963B7EAFC57B6ADAD5CBD3
                                                                    SHA1:3956A0DEA8FC0BE9DE0EFF1BC842580A5B28C965
                                                                    SHA-256:30E0400FA94DBCA73ED5BF4E287911B1FA74A113AA85889B85395238E2925C08
                                                                    SHA-512:FBBBC22A5CDD01BC0E8871AB9D97774550E6EDE5BE4FB67272619E1A421AAA68C2E7959BE0D06C7A209876F749C1C38F6F3A1E0B39DE5EF6488AD798862BB0F8
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11820" V="0" DC="SM" EN="Office.Outlook.Desktop.SelectedItemLocation" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="1" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="19042" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="I32" I="0" O="false" N="SelectedItemLocation">.. <S T="1" F="SelectedItemLocation" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):705
                                                                    Entropy (8bit):5.196671366165347
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHduYVzjmtdRDDHwpat5DF42W3fYvxn4Bi1XGIi3nty0r9NO2su:2dNQdRge4koKm
                                                                    MD5:B861265CFBEF37D04D046F31640CA901
                                                                    SHA1:64FC738C698FF72F6722076632A172B3F119AEC8
                                                                    SHA-256:8E561AAE2AFB2540B3CB54265EDEC790B9849DB89814FAE736EA212FE059789F
                                                                    SHA-512:269442FDCE90E58595ECCF42793FF4913C5D86616BC9B89A0AADC3A6E227B528EBDA2CCF3D479D57FA1B77257DE1388A1F34A9F01685136DBB05203507379122
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11821" V="0" DC="SM" EN="Office.Outlook.Desktop.MessageBodyFocusChanged" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="6" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="B" I="0" O="false" N="FocusGained">.. <S T="1" F="FocusGained" />.. </C>.. <C T="B" I="1" O="false" N="PreviewPane">.. <S T="1" F="PreviewPane" />.. </C>.. <C T="B" I="2" O="false" N="ReadOnlyCanvas">.. <S T="1" F="ReadOnlyCanvas" />.. </C>.. <C T="G" I="3" O="false" N="CorrelationID">.. <S T="1" F="CorrelationId" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1751
                                                                    Entropy (8bit):5.198686726421675
                                                                    Encrypted:false
                                                                    SSDEEP:24:2da43dRgeA4joYEwgZx8Q+pW101a63M7pGNJeA3n9v:ca4tRgeIx8C01TfeMn9v
                                                                    MD5:10D59D386F2D2F970902C47A4F20E183
                                                                    SHA1:6EBE85A63D27919A0BC776684E019D2C0D695362
                                                                    SHA-256:75B9CDBE1E76D0A6904452D8DFA9A2CBA7446EB865BF3F4A46CA72F2065E07A6
                                                                    SHA-512:5E5923DAC1A1A0B47751101E653528D08F45DACA463426EE69FE5B950F22A8F80ED68AAEF6BBB174A5CF45EABA9C59931EAFA6C97AAF9905BE63A67E6903DAA7
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11822" V="0" DC="SM" EN="Office.Outlook.Desktop.InAppContactSupport.RecoveryUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="30" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="701" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="2" E="702" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="3" E="42" G="{ad58872e-4df6-4b26-9841-5d7887a1c7a5}" />.. <Etw T="4" E="45" G="{ad58872e-4df6-4b26-9841-5d7887a1c7a5}" />.. <Etw T="5" E="46" G="{ad58872e-4df6-4b26-9841-5d7887a1c7a5}" />.. <Etw T="6" E="47" G="{ad58872e-4df6-4b26-9841-5d7887a1c7a5}" />.. </S>.. <C T="W" I="0" O="true" N="RecoveryName">.. <S T="5" F="RecoveryName" />.. </C>.. <C T="U32" I="1" O="true" N="Invoker">.. <S T="5" F="Invoker" />.. </C>.. <C T="U32" I="2" O="true" N="RecoveryTask_PrecheckStatus">.. <S T="1" F="Status" />.. </C>.. <C T="U64" I="3" O="true" N="RecoveryTask_PrecheckHResult">..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):5467
                                                                    Entropy (8bit):4.320907975816982
                                                                    Encrypted:false
                                                                    SSDEEP:96:48jfGRgekn38t3Aa38ttd38tyQ38tnu38t3A4Mf438ttDJV38tyvrrG38tnYITyJ:JfGDXCaGvwxMaYqyS9RaJT7hfgYbMHgN
                                                                    MD5:46BD397F3E5353D704F945C50E58E0F7
                                                                    SHA1:3A3BEE0CE58B33D491AE7F763D90376BD25ACF89
                                                                    SHA-256:E705E97CA24B93C3B32AB76F587EEE6A1CD1F0A4D1B293A2D1D45A802601AEEA
                                                                    SHA-512:9C53735DABF11BE70DF493B4171F27C31AD2C9B4C6A09DFB7502D75BF8B26EFB93C1BC1ED8E162F4B12217793756D648866000A5C56DDF13B8CAA3DA905DA5F5
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11825" V="0" DC="SM" EN="Office.Outlook.Desktop.SearchResultGetterStat" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="7157" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <Etw T="2" E="7158" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <A T="3" E="TelemetryShutdown" />.. <TI T="4" I="Daily" />.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="SearchResultsProvider" />.. </L>.. <R>.. <V V="4" T="I32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="SearchResultsProvider" />.. </L>.. <R>.. <V V="3" T="I32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="1" F="SearchResultsProvider" />.. </L>.. <R>.. <V V="2" T="I32" />.. </R>.. </O>.. </
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1165
                                                                    Entropy (8bit):4.771851921115038
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd1VzjFDdRDDHwpatEc6NXFJiFH+kXqNOPfX/c//wVrMpONd+wsvXqNO16X/c9:2d1fDdRgeyxvdTAvjqwOaZjh/3nMZ
                                                                    MD5:E45D7274BB0C85E79E3E19F144375616
                                                                    SHA1:EF2D105F0A5CF63F0F9116EC7EF2E20D542E3C04
                                                                    SHA-256:D72CF29DADE25EDF80CE0A10660D9B10C84E6B9ED451EBB8405593F7973D8DEA
                                                                    SHA-512:E5B70D1F0F7B1235DA4A30404B70079BE58A2F268037689508CC70E4BE6D1309673A97F615976A8D551B96EFFD0D3C70508D0646ABC2DD90481AF025053F45CC
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11829" V="0" DC="SM" EN="Office.Outlook.Desktop.Attachments.EmailSent" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <TI T="1" I="Daily" />.. <A T="2" E="TelemetryShutdown" />.. <Etw T="3" E="4306" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="3" F="HasCloudFiles" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="3" F="SentWithSharingErrors" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="Count_MailsSent">.. <C>.. <S T="3" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="Count_MailsSentWithCloudFiles">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="Count_MailsSent
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):2273
                                                                    Entropy (8bit):4.173928223889092
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d0jZdRgecvS83FMEwOPFMfHFMBSFMvHFMyIFM3cnz9Dcdg7:c0XRgecvS83fRUISmzIHT7
                                                                    MD5:D824AB4471D5D7C6B0DDBF39C4A85EE3
                                                                    SHA1:C6C84A216DE43F3EF9EC661114DFEED4CB1B9665
                                                                    SHA-256:0AF3EF738DBD0E832E616E6CECE75469779B72A98F0F4F163B49D831A6504C96
                                                                    SHA-512:22BEF986FA4F106E526B7B02D8303E6A14A608CDB155C4B4AC0004B2ECEF7F2240CE8CD4FB6D3ABAEE0794EFFE2F673C7E65AF63E3606492E750A016710A524A
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11833" V="0" DC="SM" EN="Office.Outlook.Desktop.EnhancedLocations.LocationFetchTime" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="6126" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="LT">.. <L>.. <S T="1" F="ElapsedTickCount" />.. </L>.. <R>.. <V V="500" T="U64" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="ElapsedTickCount" />.. </L>.. <R>.. <V V="500" T="U64" />.. </R>.. </O>.. </L>.. <R>.. <O T="LT">.. <L>.. <S T="1" F="ElapsedTickCount" />.. </L>.. <R>.. <V V="1000" T="U64" />..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1403
                                                                    Entropy (8bit):3.9857348097565484
                                                                    Encrypted:false
                                                                    SSDEEP:24:2duKWhdRge+AuMqrKH+aKDH+a8R0B+AOL:cuTRgeJuMVe9ezR0YAOL
                                                                    MD5:69D58B1B8AC1B0E51E20FE50352ABDAB
                                                                    SHA1:2DA03C9206E19389CE104C24F2940E39055C4E27
                                                                    SHA-256:C82B40E2804EFA42EE951193B75E9206544EB2F0AD1041ECEB91B082DF0BBFEC
                                                                    SHA-512:C443326DE313C42D436C1B6D0540CA80A10595D595B4BF7A70FB548CFCE63880AA6A4F3FC4D2CF1C251DFEEE752953518D64570D887C185449C4FCF55897BC7B
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11834" V="1" DC="SM" EN="Office.Outlook.Desktop.TcRebuild" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="500" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="617" G="{2adf8e23-0af9-43c9-ba4c-952ee130540d}" />.. <F T="2">.. <O T="AND">.. <L>.. <O T="NE">.. <L>.. <S T="1" F="Elapsed" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="OR">.. <L>.. <O T="EQ">.. <L>.. <S T="1" F="NIDType" />.. </L>.. <R>.. <V V="14" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="EQ">.. <L>.. <S T="1" F="NIDType" />.. </L>.. <R>.. <V V="16" T
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):438
                                                                    Entropy (8bit):5.2983359003737895
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdnVzjm6dRDDHwpat5DX26eUImpDMNO2su:2dnDdRgevtk
                                                                    MD5:DA7160E821EAA803DA2B1A7181C5A47A
                                                                    SHA1:6F117BF95A35AFC94A1336DA7CEED44A3B2E3AC0
                                                                    SHA-256:514603565C830E5F6378B2522EBFF165900AB9E4A53BFDEF4BBE2A644FD13FF7
                                                                    SHA-512:6155668B61D366BA13A5683D0937F2A9684B6A30F915CDD7F39DF92389D2825B13F03A4A0C4AF378957B083ADC1E17C1CCBB7593FB58366A6D8F724E48838CC4
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11841" V="0" DC="SM" EN="Office.Outlook.Desktop.DarkModeUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="1" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="8108" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="B" I="0" O="false" N="DarkModeEnabled">.. <S T="1" F="IsDarkModeEnabled" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):530
                                                                    Entropy (8bit):5.275584213761911
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd2HA4VzjhMdRDDHwpatlOHXFJTf0djuuOXNO/HNUlu:2d2g47MdRgemvr0JDf7
                                                                    MD5:BD204AD3264858CFED5FF0FD3EA98337
                                                                    SHA1:DE6ABB7CC77E77E281626C24D23FB146953EEFC4
                                                                    SHA-256:7E50B2E98CF4F348D3E5CA98855930F16F2389742945920BB2FB25ACA782A7B2
                                                                    SHA-512:15973ABC3DAF687D065A4A7214389066FF971D70546239AA8C5795FF296DF74CCF4E7BB7A194AD79607B1AD41B74CA1ACE6426C9F2CA1F6C694F51DCDBF79F65
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11842" V="0" DC="SM" EN="Office.Outlook.Desktop.RssHashPerf" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="385" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. </S>.. <C T="I32" I="0" O="false" N="RssHashPropMaxKB">.. <A T="MAX">.. <S T="1" F="RssHashPropKB" />.. </A>.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1460
                                                                    Entropy (8bit):4.666418817421043
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdWuVzjXTCN6dRDDHwpatl0A+KbSSeA+KbSSA+KbSNXahIn+wsvXlOpleJ0H/0:2dWudxdRgeEwOecSK77ODe
                                                                    MD5:FEDCCCD798E11E042E4C4D96897E106C
                                                                    SHA1:40464A636DCBF01E6E3C7EEB9F2286CB7A477970
                                                                    SHA-256:EF093D87908D5570D7716DC8F3E0F58148384448B895C8DE9E435B9CA4D00450
                                                                    SHA-512:FD7BF082F5A7EC16AC689BF82075C4FD2ADA5518C650545EE6C20624BFFEEC8EE1A7255FD06DA89B4D0D82EACC079EDED4254ED04BD54788D9126505CDFADADB
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11844" V="1" DC="SM" EN="Office.Outlook.Desktop.AuthXMSDiagnosticErrors" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="7090" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <Etw T="2" E="7092" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <Etw T="3" E="7094" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <US T="4">.. <S T="1" />.. <S T="2" />.. <S T="3" />.. </US>.. <F T="5">.. <O T="AND">.. <L>.. <O T="NE">.. <L>.. <S T="4" F="XMSDiagnosticsError" />.. </L>.. <R>.. <V V="4294967295" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="NE">.. <L>.. <S T="4" F="XMSDiagnosticsError" />.. </L>.. <R>.. <V V="4000000" T="U32" />.. </R>.. </O
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):790
                                                                    Entropy (8bit):4.979348876203387
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdyHMVzjtLZRdRDDHwpat5zT32GeOS+u/5lOeX/c//cpONwsPA4McJi2vy2i2S:2dUMPLZRdRgex7vL5uRNmA56D62Dhg
                                                                    MD5:2A0B16C54FC327A1603D4EFDB1A38149
                                                                    SHA1:3458EEECDB42C70DB89D18896B496F6421D9C2DC
                                                                    SHA-256:6DE56B9A9676A5162079031B9B4CDDD4E7919A09299FA070CD480E2FC5C4371D
                                                                    SHA-512:534535C30731E72947D56E419155DBF420261D414C045A282CB8DFE55A3A2F1BA66CF97968D8D47E91F35E3A0652881124D20EE91397C93134770C22F6EA383B
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11846" V="1" DC="SM" EN="Office.Outlook.Desktop.Rest.RequestExecutorBasicError" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DL="A" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9106" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <F T="2">.. <O T="NE">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="U64" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="true" N="RequestId">.. <S T="2" F="RequestId" />.. </C>.. <C T="U32" I="1" O="false" N="HttpStatus">.. <S T="2" F="HttpStatus" />.. </C>.. <C T="I64" I="2" O="false" N="HResult">.. <S T="2" F="HRESULT" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):4598
                                                                    Entropy (8bit):3.7786855921949014
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dVjhoo6mYdRge8SvS8OguwOmQt+q/m+aC2+tFb+v4R+xI/+jWOHAHiZHpyHFj1J:cVjKXRgexvS8Fu7ncCoVZvXC9/7
                                                                    MD5:5C21D3E92C8937A5A72DADDB1C66AB59
                                                                    SHA1:9BEAF466964A984EB81FDE704DB3BA327DD9A56E
                                                                    SHA-256:0647BFE6BDBC024FDA2F642E738EF4DE3C9DF4EB458BED1137A2445617441B4E
                                                                    SHA-512:DACA50E52FAE39F0945BB9931A4BAD810D1F231A950761D0125FA84D851CB381B0D52F86E7ED141F64C9E516DE56AE758B60FDDB76F2A654DE1942D2BF9D5108
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11847" V="0" DC="SM" EN="Office.Outlook.Desktop.OutlookBrowseGroupsDlgUIAllLoadBucketRule" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="10591" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="LT">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="250" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="250" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LT">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="500" T="U32" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="6">.. <
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):4634
                                                                    Entropy (8bit):3.808741357444101
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dqhoo6mDdRge8tvS8OguwOmQt+q/m+aC2+tFb+v4R+xI/+jWOHtHxZHYyHmj1fH:cqKWRgeWvS8Fu7ncCoVZLG7n77
                                                                    MD5:AC02080D31AA991E28F634D542BFFEA4
                                                                    SHA1:6AE27E9022B7F7A6DC4C25DC5BBD8442546E4D2F
                                                                    SHA-256:F1D4BDB3F96DCC7BEF09B48CE156A70A82458F69C0F3F0F20DFBC0B4C38C3E0F
                                                                    SHA-512:AFFDAB80C8B0E3BB8F3D1D04988F3C813600790717EC5FECC20DA203B876804912E2DE7982A48F3ACF667CBC47AAD1065E3BDB9851EB1CB1CD5D2B02353723E7
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11848" V="0" DC="SM" EN="Office.Outlook.Desktop.OutlookBrowseGroupsDlgUISuggestLoadBucketRule" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="10592" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="LT">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="250" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="250" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LT">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="500" T="U32" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="6">..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):4607
                                                                    Entropy (8bit):3.790425620953119
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d1hoo6m3dRge88vS8OguwOmQt+q/m+aC2+tFb+v4R+xI/+jWOHxHVZHUyHqj1fZ:c1K4RgevvS8Fu7ncCoVZbSNvV7
                                                                    MD5:840B771544EB1794F70C2AFC6B80EA02
                                                                    SHA1:903E6F5EDEDDF7A94A6A1336DC2AF799DC046050
                                                                    SHA-256:1A88B486E30D87D643E68A451D613721298CFED7600EEAF6A5508B5B518FDCBC
                                                                    SHA-512:EF101EB2F01F9AA5D8BD29FB0B6D75EB728A1127099E03ED8A8F476F273DF45AADDA3838571D7A204E6E5F6A668E8E4DF6501AF0623AB331E4BE29FF1D63227B
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11850" V="0" DC="SM" EN="Office.Outlook.Desktop.OutlookBrowseGroupsDlgUIJoinLoadBucketRule" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="10593" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="LT">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="250" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="250" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LT">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="500" T="U32" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="6">..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):4634
                                                                    Entropy (8bit):3.8047585304954845
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dAhoo6mtndRge8nvvS8OguwOmQt+q/m+aC2+tFb+v4R+xI/+jWOHW29HW4ZHWj1:cAKSdRge8vS8Fu7ncCoVZLANrj7
                                                                    MD5:D11E9438793EA06B2E99EE6B6FB4754D
                                                                    SHA1:47D5A68E57F06F54B668FD7C4725B1F91964076A
                                                                    SHA-256:11D846519EAFFBD9AF3EE92CA3957991656771314F065F7767D73FF2215E838A
                                                                    SHA-512:7A7ECB65B7981F819A2A23D3BD205EC882099289CDC0183B74258DEAB48C76DD02E1CDAF568FC03A334CA07EC112C44F338202119AC621CB04274FDA8F681A51
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11851" V="0" DC="SM" EN="Office.Outlook.Desktop.OutlookBrowseGroupsDlgUIDismissLoadBucketRule" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="10594" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="LT">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="250" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="250" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LT">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="500" T="U32" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="6">..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1694
                                                                    Entropy (8bit):5.088503698783867
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdXVzjzooAzm7dRDDHwpat5D0H6HHYHSH3HG4HiHxFHzU9THaSMb3dHhSMpuHE:2dXhoo6m7dRgerfMjZ9183d3Nw
                                                                    MD5:28CBA06F973AE07D2D5DE90E6E3AFE6E
                                                                    SHA1:158F7E777C4D92BF4B8E89A9E053B480E67AFA56
                                                                    SHA-256:985C667611B33DA1737B99EF8B2787D5C05E6F7A608626A201C0CEDFC3CF31C7
                                                                    SHA-512:58B9A11F9394A44D16AB7CF09EB5E14840C5533A3959F2CC813DDEB26E13035B28F52E27FBCF35070EAE0956B119A5E5388770326FF7DC69EE429D548213B887
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11852" V="0" DC="SM" EN="Office.Outlook.Desktop.OutlookBrowseGroupsDlgUIButtonHitsRule" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="18016" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="18017" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="3" E="18018" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="4" E="18019" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="5" E="18020" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="6" E="18021" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="7" E="18030" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="8" E="18054" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="9" E="18055" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="U32" I="0" O="false" N="NoOfSearchBtnClicks">.. <C>.. <S T="1" />.. </C>.
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):625
                                                                    Entropy (8bit):5.035874029828806
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdJVzjyBdRDDHwpatEerZXFJicouDP4b2dfAGqjBHaSMNO5csu:2dJQBdRgeLrFvS4Ndlr
                                                                    MD5:A5B1C31C7B2B6AB6C0B30869849F32DF
                                                                    SHA1:B4DB6968A5DDF065D59289678FA44A901218A9B4
                                                                    SHA-256:F489D3594494620F0E8E121778256CD97F14FA1FD2E71919A32890DDB7A557E6
                                                                    SHA-512:C32AD303E80F06D4E6242E64556AC80697EE07024B45BA81C112861CC217E565599987ADAA73F36CEA48D9788A356BC5484376D802423186DFF74E444FDB0736
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11854" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.CreateDlgExit" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="c5xgh" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="Action" />.. </S>.. </G>.. <C T="I32" I="0" O="false" N="ActionType">.. <S T="1" F="Action" />.. </C>.. <C T="U32" I="1" O="false" N="CountClicks">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):623
                                                                    Entropy (8bit):5.030376317205087
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdUVzjgdRDDHwpatEer3fXFJicouDP4b2dfAGqjBHaSMNO5csu:2dUydRgeLr3vvS4Ndlr
                                                                    MD5:4D50E1EF893A1810E4294A40E73FE452
                                                                    SHA1:9E47994F71F6EC67033B85D7817CAE3EF138F4A2
                                                                    SHA-256:0AA13C740C47CF810E619A42DCF1F48A4CE626D8CF937ED3BFED2365B4F9222B
                                                                    SHA-512:AD5EDDBEEC7B3E33CB6B76A15D3A0655CEAD3FD675F34E021778CA982E0663118E3156B9476B23BDE4280064041AA8F66E03B9CD9C4A57AE4A62E8ADB5966108
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11855" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.EditDlgExit" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="c5xgf" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="Action" />.. </S>.. </G>.. <C T="I32" I="0" O="false" N="ActionType">.. <S T="1" F="Action" />.. </C>.. <C T="U32" I="1" O="false" N="CountClicks">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1084
                                                                    Entropy (8bit):5.119538640545281
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdLVzjyYAdRDDHwpat5DerdC143AtOKIkxntEanxHWS5bSALHWS5ynHDqevAij:2dLQYAdRgesrItdGSFKSS/9KUiR2
                                                                    MD5:9643EEEAA5AA89FCEB0CF15A7C2BE045
                                                                    SHA1:944840765699F8506C0B35E48EEC665EB27D529C
                                                                    SHA-256:367115A2330B3A7EEC36BA1722B4498100542AABDCED7A0518B9E7C3377022D6
                                                                    SHA-512:E16EF8C73FB18544168FC5C00D499AF2F5AAD00EB2FD827B881A2C4B3C6801E05C3366C111975FEA84247A0363B4F4C74D7B56CAEEBAE9ACA6557AE841C45AD6
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11856" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.CreateDlgInfo" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="c5xgg" />.. </S>.. <C T="B" I="0" O="false" N="LanguageChange">.. <S T="1" F="LanuageChange" />.. </C>.. <C T="I32" I="1" O="false" N="PrivacyValue">.. <S T="1" F="Privacy" />.. </C>.. <C T="B" I="2" O="false" N="ClassificationChange">.. <S T="1" F="ClassificationChange" />.. </C>.. <C T="B" I="3" O="false" N="AutoSubscribedCheck">.. <S T="1" F="AutoSubscribedCheck" />.. </C>.. <C T="B" I="4" O="false" N="GroupIdEdited">.. <S T="1" F="GroupIdEdited" />.. </C>.. <C T="B" I="5" O="false" N="NamingPolicyEnabled">.. <S T="1" F="NamingPolicyEnabled" />.. </C>.. <C T="B" I="6" O="false" N="PrefixSuffixEnabled">.. <S T="1" F="PrefixSuffixEnabled" />.. </C>.. <C T="I32" I="7" O="false" N="BannedWordsCount">..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1681
                                                                    Entropy (8bit):5.031911578321207
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dmudRgesrZ0AzrUOUMKrv3S83SfaK/NQy62:cmSRges17zKrv3ZCfxn
                                                                    MD5:29657EC1CB41062647C5D7979F404071
                                                                    SHA1:7DE35DEFDB7FECA804B86D66D6960E3F74CA47D8
                                                                    SHA-256:91367A4F86F4DD9AB94DFD2724302CF70C79E141632FA99688AA0D16955CA2C4
                                                                    SHA-512:147A6227BD7779185C242F2C79192E2D77C61BC9476178441038CC6EF856C7B76B149F19B683AF639A29079BB3A2B4F9A19D07400356A82909DB81A7E2C15377
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11857" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.EditDlgInfo" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="c5xge" />.. </S>.. <C T="I32" I="0" O="false" N="MembersAdded">.. <S T="1" F="MembersAdded" />.. </C>.. <C T="I32" I="1" O="false" N="MembersRemoved">.. <S T="1" F="MembersRemoved" />.. </C>.. <C T="I32" I="2" O="false" N="MembersChangedAdmin">.. <S T="1" F="MembersChangedAdmin" />.. </C>.. <C T="I32" I="3" O="false" N="MembersChangedNonAdmin">.. <S T="1" F="MembersChangedNonAdmin" />.. </C>.. <C T="B" I="4" O="false" N="NameChange">.. <S T="1" F="NameChange" />.. </C>.. <C T="B" I="5" O="false" N="DescriptionChange">.. <S T="1" F="DescriptionChange" />.. </C>.. <C T="B" I="6" O="false" N="LanguageChange">.. <S T="1" F="LanuageChange" />.. </C>.. <C T="B" I="7" O="false" N="PrivacyChange">.. <S T="1"
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):805
                                                                    Entropy (8bit):5.174600923213037
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdNVzjTL9N6dRDDHwpatErsw2qswQicih22cUGS/HaSMxUPQ3HhSMNO3AHNS7w:2dNRKdRgeSsusLJVSDQdr
                                                                    MD5:68225C7CA3CEEBE522B8A543D87D8AD1
                                                                    SHA1:CB82B1D650208845E1FFBE4CDEC8C81D150E7BD1
                                                                    SHA-256:A6073057EAFB0D93785278A8C1BFE5D069ADD0D74D3D45097E4EBEBF054C8FEA
                                                                    SHA-512:85C6AA6C05570FDA17ADF74F973AA0D8118099F09412ABBFEB5B87ECE274197DA5DC0103583E5E7DD22480766BD53F25AA6B579A3575A2811A59535D51D6BDA0
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11858" V="0" DC="SM" EN="Office.Outlook.Desktop.Search.AdvancedSearchPaneUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9300" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <Etw T="2" E="9301" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <A T="3" E="TelemetryShutdown" />.. <TI T="4" I="Daily" />.. </S>.. <C T="U32" I="0" O="false" N="NumberOfTimesAdvancedSearchPaneShown">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="NumberOfTimesAdvancedSearchPaneSearchPerformed">.. <C>.. <S T="2" />.. </C>.. </C>.. <T>.. <S T="4" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. <S T="2" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):709
                                                                    Entropy (8bit):5.177355495915668
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdYVzjTL95dRDDHwpatEJswXFJicouDkXO8nYxDHaSMNOAjsu:2dYRzdRge8sEvS3F
                                                                    MD5:CABF65E8A2364D44532A218A0E1FCFC0
                                                                    SHA1:85877519C55CD224B284B2FB8A5CF80892825F59
                                                                    SHA-256:ADA3510F0DB5CC7661E764C840DDD9B4FF28DC5DFCF866DE19692F30AF8B05A4
                                                                    SHA-512:122AE550AF61B7931F5D2A672618F9D9513193D19BD37128DED68DA8350259C18CEF7877DE19EB10B7D7AA6147E780B492AB8318E6FBD1B84C213312C432886E
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11859" V="0" DC="SM" EN="Office.Outlook.Desktop.Search.AdvancedSearchOptionUsed" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9302" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="OptionName" />.. </S>.. </G>.. <C T="W" I="0" O="false" N="AdvancedSearchOptionName">.. <S T="1" F="OptionName" />.. </C>.. <C T="U32" I="1" O="false" N="NumberOfTimesOptionUsed">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):711
                                                                    Entropy (8bit):5.1708717056519955
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHda1VzjTL9OHhdRDDHwpatE2l7swXFJicouDkXO8nYxBHMfHaSMNOAjsu:2dcR4HhdRgeTsEvS3YHMw
                                                                    MD5:96DE31148FBC75BA29A77A21139DB8CA
                                                                    SHA1:67C371BE2133681E0F60B384D897A740C0E9CC75
                                                                    SHA-256:8D251CB71BA7E6CC3E63D123AD75757100578C8070E32A17ED1456A331E4FE2B
                                                                    SHA-512:C9B49483BF9BEFB6A49DB8B764A7FA36181793F682A67AD1FB0E04A558017EEEEA6D2344A25189D36155D67F5F972857C57F549FFF6D92299E145C2549AF0339
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11860" V="0" DC="SM" EN="Office.Outlook.Desktop.Search.AdvancedSearchOptionAdded" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9303" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="OptionName" />.. </S>.. </G>.. <C T="W" I="0" O="false" N="AdvancedSearchOptionName">.. <S T="1" F="OptionName" />.. </C>.. <C T="U32" I="1" O="false" N="NumberOfTimesOptionAdded">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):715
                                                                    Entropy (8bit):5.180933768367821
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd53VzjTL9CdRDDHwpatE3XswXFJicouDkXO8nYxWHaSMNOAjsu:2d53RgdRgeusEvS3c
                                                                    MD5:5F59869A6D41F2A3617937BDEAF8E825
                                                                    SHA1:99BA71CBFB4191FC1B80230BAF452D5EE69872F0
                                                                    SHA-256:9F719D920534856227D49E883AB3E1C01279ABD509E94954969EB78633E6A21D
                                                                    SHA-512:1D5F8E0E709C93040539D7DA1A0159505895216C84762341FAFE608CA17B427314ED774FE4170C1160D7FAA1E78FE3ADF9F8092CAB7D72538B9D3E440560BAE3
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11861" V="0" DC="SM" EN="Office.Outlook.Desktop.Search.AdvancedSearchOptionRemoved" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="9304" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="OptionName" />.. </S>.. </G>.. <C T="W" I="0" O="false" N="AdvancedSearchOptionName">.. <S T="1" F="OptionName" />.. </C>.. <C T="U32" I="1" O="false" N="NumberOfTimesOptionRemoved">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):2675
                                                                    Entropy (8bit):4.628239904225048
                                                                    Encrypted:false
                                                                    SSDEEP:48:cX4pRgeb3LJ8QwMJwbjuwGvwWfsin6TcyleoYGr:PRgeKJMWvbGYo3AXr
                                                                    MD5:D08C8AF94C5409038C46DAC6C323507C
                                                                    SHA1:6D229ACEA4B7C8BB9A4E00B3292202475723D6C9
                                                                    SHA-256:54FC859A8765843CFF13AEF38ADCFCA9AC0DF3C32FDDFDB8256CCD3D5DFA5BC6
                                                                    SHA-512:6BEA63CF22CBF4E1E417525A1E0A9B3F12765569672937F313F455234FE58D1435EF011DCDB3E78A2F917AB140C7EC28073B117388B0003BA89C326FFDE43786
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11862" V="1" DC="SM" EN="Office.Outlook.Desktop.SearchTellMeSuggestionsUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="7160" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <Etw T="2" E="7161" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <A T="3" E="TelemetryShutdown" />.. <TI T="4" I="Daily" />.. <F T="5">.. <O T="EQ">.. <L>.. <S T="2" F="SuccessResult" />.. </L>.. <R>.. <V V="0" T="U64" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="2" F="SuccessResult" />.. </L>.. <R>.. <V V="2147500037" T="U64" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="2" F="SuccessResult" />.. </L>.. <R>.. <V V="2147549183" T="U64" />.. </R>.. </O>.. </
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):747
                                                                    Entropy (8bit):5.21287995049897
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHde1VzjamH+6dRDDHwpatEcHXFJicouDPLfL+XHaSMGcvAWNO5csu:2de1YmBdRgepvS7gF
                                                                    MD5:710D9222529239A115762FD302DD28B0
                                                                    SHA1:DF5B11304E78B91E226C9BFFCE601933255311FE
                                                                    SHA-256:FDC5A983E99FC0B20BF510AF8F82D86F8A98EFBF359A427E92F56B92C3B1B4E5
                                                                    SHA-512:E113BB0F2C7F3CB4C9BA46B41BF31E419E349637B039E1F71FCC44F1D4AD698FDF172A38418EA7E5730EC9DB7C66DE619698A8A377E3E02AC0FF8E5796BD8637
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11864" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.SubscriptionButtonUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="19011" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="GroupsSubscriptionChangeAction" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="SubscriptionActionCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="SubscriptionActionID">.. <S T="1" F="GroupsSubscriptionChangeAction" />.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):816
                                                                    Entropy (8bit):5.130759637618822
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdSYVzjfA+dRDDHwpatEBaHc1NQzDdC00Mf3a/ICbYlfZr7XHaSMNO5csu:2dSY19dRgek1q1sw/lFu
                                                                    MD5:4A81778195DFDA6D9367BC18CAAFEF41
                                                                    SHA1:F86365A8B05ECF701F6E1C3304BE3BE68CC52319
                                                                    SHA-256:2FE6D98E9C7E31C72142D855FBADDDD7C3F360CAB03EC2896B9FF045983DEC10
                                                                    SHA-512:8BF5DC098CF7A7B4B61518CA88B242072CDED5F229F4A0F2AA7DB8C63BD9635F4D0A42D0F7FD877291601EFD3999DF1B1A35D066AED58DD09A29497989F81220
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11869" V="0" DC="SM" EN="Office.Outlook.Desktop.Pcx.Win10NotificationFailures" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="23407" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="NotificationAction" />.. <F N="HRESULT" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="ToastQuickAction">.. <S T="1" F="NotificationAction" />.. </C>.. <C T="I64" I="1" O="false" N="FailureType">.. <S T="1" F="HRESULT" />.. </C>.. <C T="U16" I="2" O="false" N="FailureCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1114
                                                                    Entropy (8bit):5.249517661765813
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdS1VzjKdRDDHwpat5rereMWasWWW+qDiVfuWSwieFUe3nlWfN1DS8BuM8BSuC:2dEgdRgeArT1ryndrm1m8BL8Br8ey8ed
                                                                    MD5:E6381445D5F708EB0E67A1043824CBC3
                                                                    SHA1:737D8C6A76D0E491A6FDDF46A074B2BCCB72D331
                                                                    SHA-256:B7D27713A41349EF08D9CE4C89CF02041AF7460B2C3D08E38B46366F595D30BE
                                                                    SHA-512:7346DA00663A90A543DFEC1ED74BECF8AE964EB43DCAC6E21ECCE5801B20CF08C15E2CBD49949A815CE033AE248A52D16F4178C821B98897901BC5BD1D01DA82
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11882" V="0" DC="SM" EN="Office.Outlook.Desktop.LokiSetAuthHeaderMetrics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="1000" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="c9vi3" />.. <SR T="2" R="(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)-(.|)(.|)(.|)(.|)-(.|)(.|)(.|)(.|)-(.|)(.|)(.|)(.|)-(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)(.|)">.. <S T="1" F="CorrelationId" />.. </SR>.. </S>.. <C T="W" I="0" O="false" N="CorrelationId">.. <S T="2" F="Matched" />.. </C>.. <C T="U32" I="1" O="false" N="FinalResultTag">.. <S T="1" F="FinalResultTag" />.. </C>.. <C T="I64" I="2" O="false" N="FinalResultExtValue">.. <S T="1" F="FinalResultExtValue" />.. </C>.. <C T="B" I="3" O="false" N="RetryRequired">.. <S T="1" F="RetryRequired" />.. </C>.. <C T="U32" I="4" O="false" N="FirstAttemptResultTag">.. <S T="1" F="FirstAttemptResultTag" />.. </C>.. <C T="I64" I="5" O="false" N="FirstAttem
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1085
                                                                    Entropy (8bit):4.619641857199903
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dpLVPPdRgeLrSovvS8TejqwOavTQjTFY7:cpLVPlRgeLOovvS8ToqQvWxY7
                                                                    MD5:A78CD05D4968E74803650E9616CB5D51
                                                                    SHA1:7D3B65A63702F71CE3F62D825DC468F09392321E
                                                                    SHA-256:7704B1884E9A26D7716C3DD838B96EABAFA5A5E5D30F14C82855B44DAC636391
                                                                    SHA-512:6F875F47D60B06AE032277760C4C10026D1EF69F3D6E604EF42250C902730B3CACE153F057E4E9CB6C55DA4FA74DAA0BC54C5DF557AA492DA6F7D45473E42101
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11890" V="0" DC="SM" EN="Office.Outlook.Desktop.Pcx.CCv2InCardNavigation" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="daprf" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="FoundCard" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="NavigatedToPersona" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="Count_Total">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="Count_FoundCard">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="Count_NavigatedToPersona">.. <C>.. <S T="5" />.. </C>.. </C>.. <T
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1586
                                                                    Entropy (8bit):4.326350329373209
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdL2Oi0hFNXFJiQjEcidVBy1NxMxOn14DRNyVLdKRXyd+spSNnnHxZyncPnMWS:2dL7hFxv5kDDwK9i+lHUpN/zt7
                                                                    MD5:9C8506468A07D06DE59B8AF4D1017227
                                                                    SHA1:739DCD3C5EE7A0F47CFCADDDB93B1D4120563055
                                                                    SHA-256:559578790ADD9E40CE0D7388EACC362FB2FA10709DC5E1700F266F98AC1668CD
                                                                    SHA-512:332DE477C226BBE0D71E1A78434E6890ADFADA9B39C942C92FB4D5E6126FE3B24D88FB5C6ACBEB45ED663C2D896A641B2490E566D506540F60BC5A119F3CB492
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="118916" V="4" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="110234" />.. <A T="2" E="TelemetryShutdown" />.. <A T="3" E="TelemetrySuspend" />.. <TI T="4" I="30s" />.. </S>.. <C T="U64" I="0" O="false">.. <S T="1" F="0" />.. </C>.. <C T="U64" I="1" O="false">.. <S T="1" F="1" />.. </C>.. <C T="U64" I="2" O="false">.. <S T="1" F="2" />.. </C>.. <C T="U64" I="3" O="false">.. <S T="1" F="3" />.. </C>.. <C T="U64" I="4" O="false">.. <S T="1" F="4" />.. </C>.. <C T="G" I="5" O="false">.. <S T="1" F="5" />.. </C>.. <C T="W" I="6" O="false">.. <S T="1" F="6" />.. </C>.. <C T="W" I="7" O="true">.. <S T="1" F="7" M="Ignore" />.. </C>.. <C T="B" I="8" O="false">.. <S T="1" F="8" />.. </C>.. <C T="B" I="9" O="false">.. <S T="1" F="9" />.. </C>.. <C T="B" I="10" O="false">.. <S T="1" F="10" />.. </C>.. <C T="B" I="11" O="false">.. <S T="1" F="11" />.. </C>.. <C T="
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1167
                                                                    Entropy (8bit):4.469051603181357
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd0VzjEGdRDDHwpatEDA+KbScDQi+kXjOaNeDNH/M//EYQ45eNX/c//aNeDNHi:2d0GGdRgeMJaOZP/TOZWyY
                                                                    MD5:6216D981DED0031BE61E18533B919568
                                                                    SHA1:83D3BFC747FC6DA322C880176E22BE1217C3C63B
                                                                    SHA-256:69D078EE0E02C71C4DD887182DF9645D32CB1EBADB5FBE8A0E52667307EB9A32
                                                                    SHA-512:17FD052048AD6E887E4D8FAE8A17DD5A955C70FC3E17C450DA24B2BED911609E4B4B610BF151CC49E9EE6BDD82E0DE36295B94E43BAE8A63526948328F086259
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11891" V="0" DC="SM" EN="Office.Outlook.Desktop.Emsmdb.InnerConnectFailure" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="4003" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <TI T="2" I="Hourly" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="OR">.. <L>.. <O T="EQ">.. <L>.. <S T="1" F="RequestMethod" />.. </L>.. <R>.. <V V="4" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="EQ">.. <L>.. <S T="1" F="RequestMethod" />.. </L>.. <R>.. <V V="14" T="U32" />.. </R>.. </O>.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="4">.. <F N="RetVal" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="ReturnValue">.. <S T="4" F="RetVal"
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1646
                                                                    Entropy (8bit):4.501749872221178
                                                                    Encrypted:false
                                                                    SSDEEP:24:2drtdRgeljTIilt44rZrwOanZdjqJnZdi+Z15JEHG:crvRgelvBt4mRQZ5qJZr37EHG
                                                                    MD5:D917FF305E7259C23AF991E567395B1C
                                                                    SHA1:D22F5F1F395B75B5D5E7401307D8D0B1A65BCC44
                                                                    SHA-256:BDAC19F96453AAFE8A523E7922BE09581F42FB02E2B2047757183BFE8E50A96F
                                                                    SHA-512:BE340F14458623686B50731EF72E570A83660ADA00CF98F971CBFFCA6A086CCC6EC7959DEA745EBF6C98BC22A774337F8BDFA67CB55E87DDFF99FFDDEE1562AF
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11892" V="0" DC="SM" EN="Office.Outlook.Desktop.CategorizedAllDayEventsMetrics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <Etw T="2" E="1023" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <F T="3">.. <O T="EQ">.. <L>.. <S T="2" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="I64" />.. </R>.. </O>.. </F>.. <F T="4">.. <O T="NE">.. <L>.. <S T="2" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="I64" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="3" F="isEventCategorized" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="3" F="isEventCategorized" />.. </L>.. <R>
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):576
                                                                    Entropy (8bit):5.330255518819447
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdGVzjNFbQ6dRDDHwpat5DBPUdtZVt7qEZoNO2su:2dGpdRgejgtntU
                                                                    MD5:99518DAAD956C03B13DC03532C63DAF2
                                                                    SHA1:1E16922BCEE7051DC9A25414120E8E382B744D93
                                                                    SHA-256:C025A9CBFFBE1FAD391806C79187FCB6A169CF6C7639E0A86F29A624B16B9FF1
                                                                    SHA-512:CEF5B1535701DE59535E890A0678C91F543AFBEB100914FBF65445C06E71956C2216AA2F07017F8FFE3097BAA75C9FCA179E5A4042D7C96C8C828B884AC4C7F4
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11893" V="0" DC="SM" EN="Office.Outlook.Desktop.Calendar.DynamicTimeZoneChange" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="1" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="22423" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="U32" I="0" O="false" N="NumTimeZonesDisplayed">.. <S T="1" F="NumTimeZonesDisplayed" />.. </C>.. <C T="U32" I="1" O="false" N="DynamicTimeZoneChange">.. <S T="1" F="DynamicTimeZoneChange" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):534
                                                                    Entropy (8bit):5.1430052843074945
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd3VzjXMIMdRDDHwpatEermSXFJico25XHaSMNO5AHNUlu:2d3CIMdRgeLrmqvSw07
                                                                    MD5:55772A7336D32364E51D4AE140EE9CA6
                                                                    SHA1:9B6B389F2873E6CFAF2124DF599C4F11845D6354
                                                                    SHA-256:BA09732BAFF9BC099B3A29DCC21E11D408C09580C952A5BC5BFFCB4D50C7C749
                                                                    SHA-512:FF88C78BEC91478151C85CC8553B254666E4C4718FE554300EFCC806BC764FCA7D34A04D174E1B00245AAB15AC16DC784581F692F0D8A5AE95A00891FF206892
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11896" V="0" DC="SM" EN="Office.Outlook.Desktop.LogFailedAutoDiscoverAttemptMetrics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="b7yhu" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <C T="U32" I="0" O="false" N="TotalFailureCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):822
                                                                    Entropy (8bit):4.819569964284182
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdzAYO3H36Hb6HnAD1W8/1WHN1WWXe//fDTNOAa//5jNUlu:2dVLgOXo
                                                                    MD5:56B1B613F15F30693DEADD776DABBF69
                                                                    SHA1:FE8EF06949471D77F9EBCA0CE496D88046222EA8
                                                                    SHA-256:86C758F5A712DF27565205857D1F06D3A2B13083AA1D0E7BEE247CE4472E9108
                                                                    SHA-512:DA144E573151F465B217208F0E666BEBAAB5E1135BEC896643C8B9581EC1675FC86D78F41DD1976583F97974F59E66C18D121D38AF77B07CAD436BB3EDBCC46E
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11898" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="15016" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="15014" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="3" E="15015" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="4" E="15017" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <G>.. <S T="1">.. <F N="CorrelationId" />.. </S>.. <S T="2">.. <F N="CorrelationId" />.. </S>.. <S T="3">.. <F N="CorrelationId" />.. </S>.. <S T="4">.. <F N="OldItem" />.. </S>.. </G>.. <C T="U32" I="0" O="false">.. <V V="1" T="U32" />.. </C>.. <T>.. <S T="3" />.. </T>.. <R>.. <S T="2" />.. <S T="4" />.. </R>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):861
                                                                    Entropy (8bit):4.650072505186062
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdMO+H+u/qNOHNX/c//wVrMpONdb6HnA8/1WHN1WWXe//fDPNOAa//jN7lu:2dDuyMJjnigODZ
                                                                    MD5:219922D315A8700F1EBD45AAE0627FF0
                                                                    SHA1:5287067A239B32A9D500C90EDB8053DB84A9ED26
                                                                    SHA-256:82980DC97302DC0D426E9CA460802ED71F9B782A5F8DF91FDBD4C22F08FFD460
                                                                    SHA-512:CFC76462ABB9A9B814710AE0708867243B889AA254E1DBEF36A2108B0656875A741F98D27D5D6B68DF1E08D5341B4A1D00F1A1843FD49B77297F25384EE19002
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11899" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="15013" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <F T="2">.. <O T="EQ">.. <L>.. <S T="1" F="ViolationsFound" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <Etw T="3" E="15015" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="4" E="15017" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <G>.. <S T="2">.. <F N="CorrelationId" />.. </S>.. <S T="3">.. <F N="CorrelationId" />.. </S>.. <S T="4">.. <F N="OldItem" />.. </S>.. </G>.. <C T="U32" I="0" O="false">.. <V V="1" T="I32" />.. </C>.. <T>.. <S T="3" />.. </T>.. <R>.. <S T="4" />.. </R>.. <ST>.. <S T="2" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1574
                                                                    Entropy (8bit):4.634281067119136
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdw4OYaHlHm6HM6HzHVH+rqNOONX/c//wVrMpONd+wqNOONX/c//bLMpONdRxi:2d/LFuRJjqvRJijxLWMU57
                                                                    MD5:0C7BDD76EA52B0A2B9C962BD58DD48E2
                                                                    SHA1:129353E9340FF53950998CDDDA055803CA80D005
                                                                    SHA-256:C76BFBCE79BF84FFA297A3D7E32F6720188C4EA06ABEEEA9A009E40A244F6124
                                                                    SHA-512:7AC27B60EF0F05B1677F94E2E62AF71943471B5561A0069824B8B1B732C68F7AED0DC90FFD78CCDC30D116F8C2FFA1EF318F840481BC72C87618D632396EA39E
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11900" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="15012" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="15013" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="3" E="15014" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="4" E="15015" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="5" E="15016" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="6" E="15017" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <F T="7">.. <O T="EQ">.. <L>.. <S T="2" F="ViolationsFound" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="8">.. <O T="EQ">.. <L>.. <S T="2" F="ViolationsFound" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. <SQ T="9" R="[5][7]([1]|)[8][4]" />.. </S>.. <G>.. <S T="5">.. <F N="Correlat
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1415
                                                                    Entropy (8bit):4.637564044096567
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdh4O+H36Hb6HSHOH+aqNOHNX/c//wVrMpONd+rqNOHNX/c//bLMpONdwchWXf:2dhbjJMJjquMJiqcHgQAcUR
                                                                    MD5:CA8331DBFB7D19C4BAF17E0A0F1D446E
                                                                    SHA1:640937C0D445ADCEE2B1B0233B052B7B18288D35
                                                                    SHA-256:FF0E53CC63CD9D6D49F03B312478BBDBF71C5E4D64E8242A718032EC86EF844A
                                                                    SHA-512:675C087703B373B5D001489A072E482F61E810C4E1B757BA49941BBF75D9A070BB74C858CB02839D5518177DF45AC4376035FCF8FFAD5A8B44A35E11B20C8698
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11901" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="15013" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="15014" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="3" E="15015" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="4" E="15016" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="5" E="15017" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="ViolationsFound" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="1" F="ViolationsFound" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. <SQ T="8" R="[6]([^[7]]|)[2][3]" />.. </S>.. <G>.. <S T="4">.. <F N="CorrelationId" />.. </S>.. <S T="6">.. <F N="CorrelationId" />.. <
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):554
                                                                    Entropy (8bit):5.1507704760790265
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdjjVzjhOlGm6dRDDHwpatEi09fc1NQnAoOlG2HaSMNOA/HNUlu:2dnTeb6dRge8oqNeo7
                                                                    MD5:9749168FA208AB7A24D0B98E59E635CA
                                                                    SHA1:4BF21E35C938B92E62F9C6B397A473E8C6973917
                                                                    SHA-256:F8353E611854570CE6833CCC6C25F400E4CBC0E8A890638C92BF22DF80898BA7
                                                                    SHA-512:45CBFCF763AAD9974445244F560CE6E44C4940D6BF4E0F79FEC57D99BBCB4221B3AD9282169B4F189E34629CB340FCBB82A0B674E4D1261CCE274B01F5026CE8
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11904" V="0" DC="SM" EN="Office.Outlook.Desktop.PACMailtip.CountMessagesSentToPACRecipients" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="11898" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="CountMessagesSentToPACRecipients">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):6233
                                                                    Entropy (8bit):4.001327044989029
                                                                    Encrypted:false
                                                                    SSDEEP:96:tRge3O6jMGFSF83VCD9KjFgfY57+OqAZ0tFrutkPfYjOyzl4ONhbJTWcocwXlfoi:tDqmiyJ3k86
                                                                    MD5:FED9B41C56A578ABEF6D2972A777616F
                                                                    SHA1:DC3AE5D7606B93CA4EEC8B35C9318BC7BB0D2E48
                                                                    SHA-256:261150E06FF0F8AF2F6BEF41429A30450D8758E8300E2E85A133F32B8E2587D4
                                                                    SHA-512:5E9EDABC0223633917F5E80DD1ED79FF56BE4F6154B1A3BEFDF4F54F4D540B1E64EDD5335FBBEB99DB0C2F2E6AE68BD21824006431524D64B247B9D0645D5F47
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11905" V="1" DC="SM" EN="Office.Outlook.Desktop.Sync.ConflictResolution" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="200" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="636" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="2" E="637" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="3" E="1200" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="4" E="4026" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <US T="5">.. <S T="3" />.. <S T="4" />.. </US>.. <F T="6">.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <S T="1" F="ContextId" />.. </L>.. <R>.. <V V="0" T="I32" />.. </R>.. </O>.. </L>.. <R>.. <O T="AND">.. <L>.. <O T="NE">.. <L>.. <S T="1" F="ContextValue" />.. </L>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):2816
                                                                    Entropy (8bit):4.308213423795027
                                                                    Encrypted:false
                                                                    SSDEEP:48:cF0RgeNEvS8To+QoKJonuoovo6so78oX/oyAPaS+7:lRgeGbc+PKyn1og6T7jXwAH7
                                                                    MD5:E04E5188D06A5DCF479FDE88D7FFE9A3
                                                                    SHA1:C7920E1F1D33BCF6184E7AECA42399CEA19FA7A4
                                                                    SHA-256:B8D5FB333B8622FE5AEDC29A4785C18EEB9E5DCFE16567EA6A12DC1B30023F87
                                                                    SHA-512:68BDED0CF7C1B030A2C4F74CECDAD4E546A7B116C3484DBF915A05E0DF3349B25258F06A194F09E0E4DC7FDFA73EA8A776019564B0E2B4091A0203DF5E2D93FC
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11906" V="0" DC="SM" EN="Office.Outlook.Desktop.SearchQueryCountAndStoreType" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="7157" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="StoreType" />.. </L>.. <R>.. <V V="Unknown" T="W" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="StoreType" />.. </L>.. <R>.. <V V="Primary" T="W" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="StoreType" />.. </L>.. <R>.. <V V="OnlineArchive" T="W" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="1" F="StoreType"
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):580
                                                                    Entropy (8bit):5.216588947185266
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdfhVzjhDy1CdRDDHwpatEi00c1NQnAoDy1ZHaSMNOA/HNUlu:2dfhTDMCdRge8dqNDM07
                                                                    MD5:602809311CD117BE9CE311CE8547D2DB
                                                                    SHA1:0E8713CE21627C5B5B4B07FBE34BAEC726DA5A93
                                                                    SHA-256:13C42166E1D220E7DB4CB2B490B501FAF7A4386EF96FABE84E91F60EFC4C722D
                                                                    SHA-512:46295D5C196891EC1B0DCFD8E024AAA168E41C50EFA181D8C0808D0FC59561CA14BF35EA02BDFF1DC083DB3FC1E8E845FEE47D087E77F15BB916BA5416A96CC4
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11907" V="1" DC="SM" EN="Office.Outlook.Desktop.PACMailtip.CountMessagesSentAfterPACMailtipEverDisplayed" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="11899" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="CountMessagesSentAfterPACMailtipEverDisplayed">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):902
                                                                    Entropy (8bit):4.965723974647843
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd7uVzjhCdRDDHwpatEi0bc1NQi+kXxH/O5fX/c//tpONGAoZHaSMZkxdHfSMV:2d7uTCdRge8CqJvu2kxh7
                                                                    MD5:E95D6B198AB318A4022CE1032FD6DA22
                                                                    SHA1:CDD2E272D9215C2B046172268C63F29C808340C1
                                                                    SHA-256:69FD33B068679D0563DE8B5AAE6194AF911F1EE82D2F34E6E1DAE162845FA439
                                                                    SHA-512:B04491523632F5DA693B54E723DDA5856FDAB93DA514E3AEB8C47DE475F76CA84640F27382165D46B2F8236EAA91CA5A64FD45F98294B756DBC559FF92C3766D
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11908" V="1" DC="SM" EN="Office.Outlook.Desktop.PACMailtip.CountMessagesSentWhereUserFixedAccessibilityAfterMailtip" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="11900" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="GT">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="CountMessagesSentWhereUserFixedAccessibilityAfterMailtip">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="MessagesWhereMailtipActivatedAccessibilityChecker">.. <C>.. <S T="4" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):580
                                                                    Entropy (8bit):5.19912151139074
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd3VzjhU3HPdRDDHwpatEi0Cc1NQnAoU3oHaSMNOA/HNUlu:2d3TU3vdRge8/qNU3V7
                                                                    MD5:279D5AA97B8BBC8F60BB8B9615BFD4D5
                                                                    SHA1:03C1CCAC32BBF2FA9167795E9279CD920DAF8E53
                                                                    SHA-256:115302424908245DCF36B428E136EB7DAF6C1BDEB3FA511CCEAD9DA71A631BDC
                                                                    SHA-512:EA72A76CDE6750F38DF964EDC655501D2C5EC5121BFEEB47B684C8322CA03E06E4B6F3AD1CB606065980F6A4DF6B60E61EE7FC40312664D944FA375076C8AC2F
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11909" V="1" DC="SM" EN="Office.Outlook.Desktop.PACMailtip.CountMessagesSentAfterUserRemovedPACRecipient" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="11901" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="CountMessagesSentAfterUserRemovedPACRecipient">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):778
                                                                    Entropy (8bit):5.143676367809366
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdaq4VzjKkhdRDDHwpatEq0F2HXFJnvMz/jujNXSMZ/AjNXp1M1fsjNXNO/HN9:2daq4lhdRgeZ8MvvAf04+F7
                                                                    MD5:DD2A4D131FAC16493B0AB0DF2B2B33AE
                                                                    SHA1:0918842F0DC9C21A2417412FCDAC0A58290AF289
                                                                    SHA-256:584E524945D63D44561EDC5BCC6053395466F8A3F6B3FF8667E16F976826091C
                                                                    SHA-512:FA0110365B9EE9E4A8CA1090B3151086BB80E8C21F8003802F4543CF9278678C3FD37172081C9B20C25E43C5C9AF4D0267ECACF99B2C5FCD7ED5C7DA04FE9B70
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11914" V="0" DC="SM" EN="Office.Outlook.Desktop.MessageListDimensions" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="13107" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="MessageListWidth_Max">.. <A T="MAX">.. <S T="1" F="Width" />.. </A>.. </C>.. <C T="U32" I="1" O="false" N="MessageListWidth_Min">.. <A T="MIN">.. <S T="1" F="Width" />.. </A>.. </C>.. <C T="U32" I="2" O="false" N="MessageListWidth_Avg">.. <A T="AVG">.. <S T="1" F="Width" />.. </A>.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1200
                                                                    Entropy (8bit):5.02429455280933
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dRJAKdRgezIJTma5b6EA1v7FSALVcxA7:cRCGRgekJTmgb64Ax0A7
                                                                    MD5:6407316FBAE79C9CB15A6C2FE2C6905A
                                                                    SHA1:133C8FDE49D7FEFF1141A9EDE15D798205807CD6
                                                                    SHA-256:4F4C5E90855BAAD3738DB7FA599A4ACC7FF4F054BD751CA3F0B1FC67CF787FF6
                                                                    SHA-512:0C63F22F74BC89AE070DF18A4A00AE0127C7F41F0B47AF45E40D3EB148755BB01EDF28A33EDF19597BC87B2321C6FF0DDF3D765D7C36ECD7DC02F058381CA16A
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11915" V="0" DC="SM" EN="Office.Outlook.Desktop.ExchangeSaraAuthDiagnosticsFallback" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="10" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="50" G="{ad58872e-4df6-4b26-9841-5d7887a1c7a5}" />.. <Etw T="2" E="7090" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="2" F="ConsumerType" />.. </L>.. <R>.. <V V="6" T="U8" />.. </R>.. </O>.. </F>.. <TI T="5" I="5min" />.. </S>.. <G>.. <S T="4">.. <F N="LogicalHttpRequestId" />.. </S>.. <S T="1">.. <F N="LogicalHttpRequestId" />.. </S>.. </G>.. <C T="U32" I="0" O="falseNoError" N="RequestResult">.. <S T="4" F="HttpResponseStatus" />.. </C>.. <C T="B" I="1" O="false" N="SecretKeySuccessfullySet">.. <S T="1" F="SetSecretString" />.. </C>.. <C T="B"
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):980
                                                                    Entropy (8bit):5.1221018502271
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdOVzjwe6dRDDHwpatE/q33DFIqB2DIqB2BicG2vHbbSbd/HaSMgARU/HhSMp/:2dOmBdRge7nDFIiOIi08QHhR4S9o
                                                                    MD5:9561D4B433FAF699DB72D0774C93B60C
                                                                    SHA1:F1CDC9E104162B9B22AB73C47617259A1C6D07CC
                                                                    SHA-256:436C65461B2A43AFAAF4EA586464653033E14FDABB8A49EADBBF76927EDD7B5C
                                                                    SHA-512:54112CD0E7B55BDB16D6E40AC3488E0E655B828E66CA2941EDAC94D6FBCD9629B6452D0B016E16DBBAAD8B1835A9F8DA6713CF4EE10C24132865FABA0E3F488E
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11916" V="0" DC="SM" EN="Office.Outlook.Desktop.OPX.RoomFinder.Errors" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="354" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="2" E="1024" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <Etw T="3" E="1025" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <A T="4" E="TelemetryShutdown" />.. <TI T="5" I="Daily" />.. </S>.. <C T="U32" I="0" O="false" N="WebHostingPageTransitionTimerFailedTotal">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="AddResourceAttendeeErrorTotal">.. <C>.. <S T="2" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="GetAppointmentDataErrorTotal">.. <C>.. <S T="3" />.. </C>.. </C>.. <T>.. <S T="4" />.. <S T="5" />.. </T>.. <ST>.. <S T="1" />.. <S T="2" />.. <S T="3" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):2547
                                                                    Entropy (8bit):4.682325925448918
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dTkndRgeU+88Nhgum3iAc1RaGus1gCt5Zf9Mgam190CWE60o:cTYRgeZ888umHi/usmmdJto
                                                                    MD5:888CBE316DACEDEBC303BBE8C2300C62
                                                                    SHA1:1AD5414C2BBEA9B9602FE6ECD04AD829F23DFEF5
                                                                    SHA-256:D108EBFD099EDA0F739C9932D7637E29F8F2B92135D2CD21DA441F7F5925714D
                                                                    SHA-512:B14ED629E5D5160BBE103992D52EE7C4544FFCE9A67286D617FD59813DBE9444BFEF9D243EC4416F9A8934D84BCBA064F3E82944AD600E9883F4FE9F32EBFD79
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11917" V="0" DC="SM" EN="Office.Outlook.Desktop.RopChaining.ParseResponseMetrics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="1608" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <Etw T="2" E="1609" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <Etw T="3" E="1612" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <A T="4" E="TelemetryShutdown" />.. <TI T="5" I="Daily" />.. <F T="6">.. <O T="NE">.. <L>.. <S T="1" F="RequestRop" />.. </L>.. <R>.. <V V="163" T="U32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="2" F="FMatchesCurrentChainedRopInfo" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. <F T="8">.. <O T="NE">.. <L>.. <S T="2" F="RequestResponseRop" />.. </L
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1204
                                                                    Entropy (8bit):5.035353445562176
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdXMVzjxBdRDDHwpatEqmHc1NQCwD1JQL+NcBiUcdqUYfwkNYgILtAC+Mp3BiO:2dXMJdRgeZ5qdEd+frtjvw51k3
                                                                    MD5:459E1FDC48A71470947341E1BA282180
                                                                    SHA1:8CC1F1C5CD25D3833ECF0778CB9ED7EB26CDF267
                                                                    SHA-256:F5231E381891E32A94884AC9BF10F2D8954BE574C43790837F25725694C313E2
                                                                    SHA-512:8A435BBF0092DD7B76A78B8DC3ECA2AA3871CE122D85B2E602D1BBB220209218FF361714C5062833125E654077C4A36B14CFE114517C46A6DFB2AF62B4709C9D
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11919" V="1" DC="SM" EN="Office.Outlook.Desktop.ClassicViewSettings" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="13100" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G I="true" R="TriggerOldest">.. <S T="1">.. <F N="ViewSetting" />.. <F N="ArrangeBy" />.. <F N="PreviewPaneSetting" />.. <F N="PreviewLines" />.. <F N="SpecialFolder" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="ViewSetting">.. <S T="1" F="ViewSetting" />.. </C>.. <C T="U32" I="1" O="false" N="ArrangeBy">.. <S T="1" F="ArrangeBy" />.. </C>.. <C T="U32" I="2" O="false" N="PreviewPaneSetting">.. <S T="1" F="PreviewPaneSetting" />.. </C>.. <C T="I32" I="3" O="false" N="PreviewLines">.. <S T="1" F="PreviewLines" />.. </C>.. <C T="U32" I="4" O="false" N="TotalFolderS
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1033
                                                                    Entropy (8bit):4.706841329449731
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd9aVzjNX/Nf6dRDDHwpat4AQiBk2GeOSc1NQi+kXqNOAIX/c//wVrMpONd+wZ:2d9arNSdRgevkvLvqJTKjqwOaKiWyEY7
                                                                    MD5:60101A2A5A97F01D44D6A95CDB2C2662
                                                                    SHA1:497D6F714144ECC69FCC5C6748BBE6B7C05020F4
                                                                    SHA-256:50328565B12D6087B7F1EAE0C799664670DF61AC948699C5FB1845EFA0538283
                                                                    SHA-512:61137413016481CE9A7CF97B154BF10A1C6097B205F5CFB7BCB3E076DE49ECBF7C1AAC7E338DA960747E827D5853AA71FDBBA7EACBB674846A45990F9675DA4C
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11920" V="1" DC="SM" EN="Office.Outlook.Desktop.Calendar.RESTCalOptInOutUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="210" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="isREST" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="isREST" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="OptInCount">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="OptOutCount">.. <C>.. <S T="5" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):2453
                                                                    Entropy (8bit):4.076699783445814
                                                                    Encrypted:false
                                                                    SSDEEP:48:cjuaLyRgeLuuhjRrt475qT6qtNrx2O5F7:daLyRgeKujrlphn7
                                                                    MD5:6021C9F2F4155A66791BD1B399544EED
                                                                    SHA1:E2606D61E40772D8CCBD8F5BB2B0B28E5051F34C
                                                                    SHA-256:D5766B3FF3AFFF8D2804D1A605E305DD752AC9748EBA1787B4F44272B54CC076
                                                                    SHA-512:920397ADB0E650831A9FEF638E7451F4196E7FDEBC1F83E4219A8DA165FF346CE5FB0B89278F48DAB80A2D149BAE1ACC2837EAFB2B2A08B670F7673608D6F562
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11922" V="0" DC="SM" EN="Office.Outlook.Desktop.CountDifferentAccountsUsedInRNCards" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="dd9jp" />.. <F T="2">.. <O T="AND">.. <L>.. <O T="AND">.. <L>.. <S T="1" F="CardIsInOutlook" />.. </L>.. <R>.. <S T="1" F="IsReactNativeSupportedForContactTypeAndTab" />.. </R>.. </O>.. </L>.. <R>.. <O T="AND">.. <L>.. <S T="1" F="hasReactHost" />.. </L>.. <R>.. <O T="EQ">.. <L>.. <S T="1" F="IsCardCustomized" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="3
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):2618
                                                                    Entropy (8bit):3.9553280275926457
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dekdRgeLriuh/vbq+UkCDDRQWPCQt47djqTYjqwOfIyzTrtyG2OJX/oUF7:ceURgeLuuh/aRrt475qT6qtNrx2OdF7
                                                                    MD5:C7D1DCB899019DB1444BE9F52891422A
                                                                    SHA1:BE8A2CBF117D187726DF6B4A75D33175C4B68660
                                                                    SHA-256:1DCE0C9C67250A679D639D0B6D87B8D514B5F4EE85139804803BD6BDF7DD62F9
                                                                    SHA-512:0FB55B815FD30A43F81627373346D26E42A65DA2759AF79175B9C3740FAA70A29FCE0305658D039A422F9669A0D451F26E5C890B8FDA9570CFC9BC308957808F
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11923" V="0" DC="SM" EN="Office.Outlook.Desktop.CountNoReactHost" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="dd9jp" />.. <F T="2">.. <O T="AND">.. <L>.. <O T="AND">.. <L>.. <S T="1" F="CardIsInOutlook" />.. </L>.. <R>.. <S T="1" F="IsReactNativeSupportedForContactTypeAndTab" />.. </R>.. </O>.. </L>.. <R>.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <S T="1" F="hasReactHost" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </L>.. <R>.. <O T="EQ">.. <L>.. <S T="1" F="IsCardCustomized" />.. </L>.. <R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1513
                                                                    Entropy (8bit):4.487551712145366
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dk7CdRgeLriuyYPjqt4aQWvjqTKbtiAwOa1kiV2OZicF7:ckyRgeLuuyYbqt4afqTSQd2OccF7
                                                                    MD5:A5FCD6B63CBC703D6613068D76DA505F
                                                                    SHA1:2A9B7FCE63665DEFA1F34A5605565AB5B58FECDB
                                                                    SHA-256:3C2AF55ED9C8A88BE582D879A360248BDF9EFD7CB947B4B931A9A92C1208731A
                                                                    SHA-512:DD1FCC0F8887F73373CAEE4B695B0A6946062C47463BD10F5D5F0890D6A540FF3F999CB6CAFC4C8F7096F2250513F04AC9E36AF66C6A235BD685814775BD4B79
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11924" V="1" DC="SM" EN="Office.Outlook.Desktop.CountCausesFailedToOpenRNCard" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="dd9jp" />.. <F T="2">.. <O T="EQ">.. <L>.. <S T="1" F="CardIsInOutlook" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="3">.. <O T="EQ">.. <L>.. <S T="2" F="IsCardCustomized" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="4">.. <O T="EQ">.. <L>.. <S T="2" F="IsReactNativeSupportedForContactTypeAndTab" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="2" F="hasReactHost" />.. </L>.. <R>.. <V V="false" T="B" />..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1363
                                                                    Entropy (8bit):4.743779778491043
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd4PVzjGuUHu6dRDDHwpat5Ddpq3+u/jOg+rOX/c//oehSH/M//K5eNpONLHNX:2d4PwxdRgecOu2raAGaHVZtmmHs/
                                                                    MD5:B64E2BB5D1950451902BAD92260B79C3
                                                                    SHA1:08F6CB3BFD9FD34E769ECFA927B4CDB6A2D1617A
                                                                    SHA-256:B5A8607750E30DADA2B0A4952DC6FACA9930F8823923CB54D6274E903CEF2F9A
                                                                    SHA-512:E3091675047978868F90CB7CA75498601C6576841EC433CE87130767B3A72D94D2A8A47737CE3619606FCBA6972C155D1AD3C02F7829907B84A5F62CB3E182FC
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11925" V="8" DC="SM" EN="Office.Outlook.Desktop.OPX.TransitionErrors" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="350" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <F T="2">.. <O T="OR">.. <L>.. <S T="1" F="IsFinalWebHostingState" />.. </L>.. <R>.. <O T="GE">.. <L>.. <S T="1" F="Result" />.. </L>.. <R>.. <V V="3" T="U32" />.. </R>.. </O>.. </R>.. </O>.. </F>.. </S>.. <C T="G" I="0" O="true" N="ControlId">.. <S T="2" F="ControlId" />.. </C>.. <C T="G" I="1" O="true" N="WebHostingSessionId">.. <S T="2" F="WebHostingSessionId" />.. </C>.. <C T="U32" I="2" O="false" N="Result">.. <S T="2" F="Result" />.. </C>.. <C T="B" I="3" O="false" N="IsVisible">.. <S T="2" F="IsVisible" M="Ignore" />.. <
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):704
                                                                    Entropy (8bit):5.122881156884214
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdJVzjzJ5x6dRDDHwpatEdYHc1NQCwDVffd2ycfHaSMNOAjsu:2dJhJ5sdRgeyfqtAE
                                                                    MD5:EAF46BFFF22ECED66E92503F502A8990
                                                                    SHA1:C3B70641B475370A70E773B31B7D3E5C5BE5A639
                                                                    SHA-256:3556F97DEA588A60A205BED670A72CF72E30208D17B48924DF3F89B1E6B77EE5
                                                                    SHA-512:090587CCC3AB505D774A508BFA2E2F4982C08AB251AED900914D5E4879AC20999593FA668A7CFC10BDE8F034CADDCCA78E08FC18C46403103272B28D842AC5C5
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11928" V="0" DC="SM" EN="Office.Outlook.Desktop.OutllibDialogETW" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="13200" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G I="true" R="TriggerOldest">.. <S T="1">.. <F N="DialogID" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="DialogID">.. <S T="1" F="DialogID" />.. </C>.. <C T="U32" I="1" O="false" N="TotalDialogsInitialized">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1212
                                                                    Entropy (8bit):4.305751169482486
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dXrVr3r8ghrbzwJQkGqzGnZGn3zGnnGqzGnMFh:cX5rbhMJQkGqGZGjGnGqGMFh
                                                                    MD5:CB85564EFD221EA611E0CB0E4DC0B4F4
                                                                    SHA1:DFCC5D8936EAF3CECEF5CE9206EBAEE5621F6FE5
                                                                    SHA-256:D94AEF86117BC93E5FF076CDCE1765DF5478AE7DB14F5372761B883522A1F0FA
                                                                    SHA-512:BE02D932409309E5750E6FC3312671A5A1A5E80967280D84C368F6290D669CD691ABB6A9D518A7CFB96C4F5063B6AED458C2F288491337A5A572D19E688A4AD3
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11930" V="0" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <UTS T="1" Id="dfds5" />.. <UTS T="2" Id="dfds6" />.. <UTS T="3" Id="dfjbr" />.. <UTS T="4" Id="dfjbs" />.. <TO T="5" I="30s">.. <S T="1" />.. </TO>.. <A T="6" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="Id" />.. </S>.. <S T="2">.. <F N="Id" />.. </S>.. <S T="3">.. <F N="Id" />.. </S>.. <S T="4">.. <F N="Id" />.. </S>.. </G>.. <C T="U32" I="0" O="falseNoError">.. <O T="SUB">.. <L>.. <S T="4" F="TimeSinceEpochJS" />.. </L>.. <R>.. <S T="1" F="TimeSinceEpoch" />.. </R>.. </O>.. </C>.. <C T="U32" I="1" O="falseNoError">.. <O T="SUB">.. <L>.. <S T="2" F="TimeSinceEpoch" />.. </L>.. <R>.. <S T="1" F="TimeSinceEpoch" />.. </R>.. </O>.. </C>.. <C T="U32" I="2" O="falseNoError">.. <O T="SUB">.. <L>.. <S
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):569
                                                                    Entropy (8bit):5.08920233705384
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdzVzj3dNPdRDDHwpat5ai0csr8/ByMhvNxpJNEuONO2su:2dz5PdRgeQcRmF
                                                                    MD5:9AFF37E01EB10E158F597EA6E1200EE8
                                                                    SHA1:C4264A3DBFC3AD5405E12F04F281C2D33D412AEE
                                                                    SHA-256:05FA8A5BC0784F487B1706D63380E2B3B0F34AEE574674D310078D2DF8AB7C61
                                                                    SHA-512:44116B0E2AF4F5EFE16A1CF57BF24B40680743888B1EDA11C9370E18E35A9EB9DDAEBA6BCB63FE462C72FDD913174ACC6A257155B153400862FF5619FDC6AE99
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11931" V="0" DC="SM" EN="Office.Outlook.Desktop.RNCardTimeToRender" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSP" xmlns="">.. <S>.. <R T="1" R="11930" />.. </S>.. <C T="U32" I="0" O="false" N="TimeToRenderInitial">.. <S T="1" F="0" />.. </C>.. <C T="U32" I="1" O="false" N="TimeToRenderContainer">.. <S T="1" F="1" />.. </C>.. <C T="U32" I="2" O="false" N="TimeToRenderPlaceHolder">.. <S T="1" F="2" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):3232
                                                                    Entropy (8bit):3.668625032816456
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d8sBdRge/cvvS8OrwOm6+Qr/Qt+qCm+aF2+yPwUUqbR1R97:c8WRge0vvS8U7ron/aoUUgfz7
                                                                    MD5:558FA25A780A9E5DE8ED13A75878734B
                                                                    SHA1:1C145DA0088A919E275021518112AEA0329590E4
                                                                    SHA-256:341A12CAF0766CD590E3928288C2CECFE1F1141428CB74A429A51FBA348716F6
                                                                    SHA-512:0F2376926E2BFEFA007BE39B5199D63EF0CFD0FA50DC170F5E1C1AC9203D5B0D73A0465475EABEA5F3E74C2BBF3BCA2EC3D2EA54424CAE97A74F611A6F75397E
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11932" V="0" DC="SM" EN="Office.Outlook.Desktop.RNCardTimeToRenderInitialBucketed" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSP" xmlns="">.. <S>.. <R T="1" R="11930" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="LT">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="100" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="100" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LT">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="250" T="U32" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="6">.. <O T="AND
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):3343
                                                                    Entropy (8bit):3.7999978378778105
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dxQBdRgeQrzvS8/UvwOHU2PUQHaUQZPU+LUKPUOsU6PUWaU8UUqbR1R97:cxyRgeQvvS8ODHU1zC4UUgfz7
                                                                    MD5:D8461954EBFB716661E5BDF2FCAECA18
                                                                    SHA1:B332465A784172E7FAFB36D8104D516C91216B7B
                                                                    SHA-256:EEE0C229D39D77830C70AA685C3045446B05CA060542B7FA9DD596A230115833
                                                                    SHA-512:D6FF65A7CF38783130FCAA5BF6EBD891777E77167F16A39647FC8D2A62322D48B86B853B301AC11E1399F715A3F31AB1DD895DD3659901E140F5379B2E2BF36D
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11933" V="0" DC="SM" EN="Office.Outlook.Desktop.CCV2TimeToRenderInitialBucketed" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSP" xmlns="">.. <S>.. <UTS T="1" Id="dfds4" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="LT">.. <L>.. <S T="1" F="Milliseconds" />.. </L>.. <R>.. <V V="100" T="I32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="Milliseconds" />.. </L>.. <R>.. <V V="100" T="I32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LT">.. <L>.. <S T="1" F="Milliseconds" />.. </L>.. <R>.. <V V="250" T="I32" />.. </R>.. </O>.. </R>.. </O>.. </
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):692
                                                                    Entropy (8bit):5.118026988954907
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdfVzj7RBdRDDHwpatEerN/XFJicouDCY2bPYHf4ZjzAIHaSMNO5csu:2dfF3dRgeLrNPvSZYSYHgo
                                                                    MD5:43012D6BF297C1BFE84236A092004A50
                                                                    SHA1:4F23B57FAB8E45C815A98BD6D565FD35CA0136AC
                                                                    SHA-256:B8C191C64060AF6E32A9AE559CEE97260FC5F27DFA8FFE3C2F30454A11B3AA47
                                                                    SHA-512:73B349A9E341591FE0F2840A64C9C6C6AC4F682F62EE2AB06203CAAFE69572FAF441D43F27389A9341184659DE1C9942EB2FA2CB0372ADF6694CEA1FAF5C9E66
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11935" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.CLPGuestsDisabledInfo" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="93uka" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="GuestsAccessDeniedFlag" />.. </S>.. </G>.. <C T="I32" I="0" O="false" N="GuestsAccessDeniedFlagType">.. <S T="1" F="GuestsAccessDeniedFlag" />.. </C>.. <C T="U32" I="1" O="false" N="CountGuestAccessDenied">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):654
                                                                    Entropy (8bit):5.237577883627452
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdoVzjPWdRDDHwpat5DertnSMnS31Rur1RlA9ntpYZU7NO2su:2do4dRgesrIb1RA1ROR
                                                                    MD5:6C4CCDD0E1B3D064B84446263F132472
                                                                    SHA1:24C266C590E93F235753F777853BAE022C3A50A4
                                                                    SHA-256:DD0AE757A8831C13355CB95D6D282E99782E08D6FAB2B85B5BC6FC54B11A391A
                                                                    SHA-512:BC34F98E3DB482142BD6057ACCCE22BA9A1BFD6360F9E99F2EB1981C9AEF47868D39FB854A356A3B97F8945C00E5F8C8B1B225974BE952870A79E84476A3A23E
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11936" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.CLPSensitiveLabelInfo" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="93uj9" />.. </S>.. <C T="B" I="0" O="false" N="ClassificationPolicyEnabled">.. <S T="1" F="ClassificationPolicyEnabled" />.. </C>.. <C T="B" I="1" O="false" N="SensitivePolicyDataExists">.. <S T="1" F="SensitivePolicyDataExists" />.. </C>.. <C T="B" I="2" O="false" N="SensitiveLabelsExist">.. <S T="1" F="SensitiveLabelsExist" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1456
                                                                    Entropy (8bit):4.609599678025888
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d2CcdRgeVIirqJTqL5a/wOaqL5aghJqL5a5nqdzoZdJ7:c2pRgeVnqJTqNMQqNVJqNELJ7
                                                                    MD5:D3FA94873D89CAF3E0DC512160ABB784
                                                                    SHA1:B0456568040EE18730406D0A9A5F5D401C0863E0
                                                                    SHA-256:3D62586F1F73D22EBF85CAE417F5F0E4C9D127172850F458699D7361082B2CA6
                                                                    SHA-512:4A7777B75390ADB600CB079B36AF61C3D4E5E9063874D45AED4C975CA8B212E3FB74C15D3EF2CC704430EE131006802995D08F16744A54185DEE74D38DB3AA48
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11938" V="0" DC="SM" EN="Office.Outlook.Desktop.Calendar.JoinOnlineFromToDoBar" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="1026" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="OnlineSessionType" />.. </L>.. <R>.. <V V="1" T="I32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="OnlineSessionType" />.. </L>.. <R>.. <V V="2" T="I32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="OnlineSessionType" />.. </L>.. <R>.. <V V="0" T="I32" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="CountJoinOnlineButtonPressed">.
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):410
                                                                    Entropy (8bit):5.24802525642993
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdbVzj9xdjdRDDHwpat5aerkDr8/MbNO2su:2db7dRgefrQx
                                                                    MD5:29B4742E3E9098FBBDA01AA24762F903
                                                                    SHA1:2188097389FCFE2AF0A7E39D3BE58A78AEBA44CF
                                                                    SHA-256:83836DD02393239B51B179D9AC516EFA1416AC5292AA09BB49454645535DD458
                                                                    SHA-512:DD119321EA9B63CD3092D06118C70F1F0E45DFEB505021E7F7DE4D60335B31A149427C12EA9DB73778B9569FC7156E1D056E003A78F348162B13AEB0247AE838
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11939" V="0" DC="SM" EN="Office.Outlook.Desktop.CCV2TimeToRenderInitial" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSP" xmlns="">.. <S>.. <UTS T="1" Id="dfds4" />.. </S>.. <C T="U32" I="0" O="false" N="TimeToRenderInitial">.. <S T="1" F="Milliseconds" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):2564
                                                                    Entropy (8bit):5.120412466327161
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d4GdRge6AtH1qS1B1613MB91y1u4vOyDsOhHHf/CNzffuicwEMYmETEq:c4KRgeSE6fQZui4l
                                                                    MD5:666C483A33B473397C31C2AE9D2FBDB3
                                                                    SHA1:6B1AC0C817939DC0068E13DC2A1FC93B61F81E76
                                                                    SHA-256:6774161A7D5651F86286A6D45A568735C244ACAFDF9D2EECEE2D01BD75B0524F
                                                                    SHA-512:B6236647406E9A2A16F216DA3E33DFECE2FAF577F20F59A55517E3DB0F58643DB9864D42F1F14C73C81BF9F1BC14195F5B3B66DBB09F6FC2CC2BD25FB4834E57
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11940" V="7" DC="SM" EN="Office.Outlook.Desktop.OPX.Performance" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="356" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. </S>.. <C T="G" I="0" O="true" N="ControlId">.. <S T="1" F="ControlId" />.. </C>.. <C T="G" I="1" O="true" N="WebHostingSessionId">.. <S T="1" F="WebHostingSessionId" />.. </C>.. <C T="I32" I="2" O="false" N="CreateWebViewElapsedTime">.. <S T="1" F="CreateWebViewElapsedTime" />.. </C>.. <C T="I32" I="3" O="false" N="ConfigTokenAcquisitionElapsedTime">.. <S T="1" F="ConfigTokenAcquisitionElapsedTime" />.. </C>.. <C T="I32" I="4" O="false" N="TryNavigationToNavigateCompleteElapsedTime">.. <S T="1" F="TryNavigationToNavigateCompleteElapsedTime" />.. </C>.. <C T="I32" I="5" O="false" N="TryNavigationToGetConfigElapsedTime">.. <S T="1" F="TryNavigationToGetConfigElap
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):781
                                                                    Entropy (8bit):5.09359922095744
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdeSVzjk2S2dRDDHwpatlFfnXFJicouDQPbSfpNAff+b9pIXHaSMNO5csu:2dznS2dRgebXvSLbxmbIu
                                                                    MD5:BAEC21F0C30BF264FF26C8A5751737B3
                                                                    SHA1:15C8990C1AF86CBEB35B63D8D889723CD45E11C9
                                                                    SHA-256:6BF02A41126C4937EE480E567059DF3C1F55B3AB4C5317163DEC0BC5780A7AB1
                                                                    SHA-512:BBFC6C00B323AA7BBE2A5CEB3EBB6B1652C9F7D59A5FEE56FEAFF45F7ABEF8F3532BDAD537F4E33836E513221BA2B25CE8942DE6C5A5B84115B89D2F43EAEA53
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11941" V="1" DC="SM" EN="Office.Outlook.Desktop.Mapi.ProviderDllLoad" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="633" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="KnownMapiDLL" />.. <F N="SCODE" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="DllEnum">.. <S T="1" F="KnownMapiDLL" />.. </C>.. <C T="U32" I="1" O="false" N="SCODE">.. <S T="1" F="SCODE" />.. </C>.. <C T="U32" I="2" O="false" N="DllScodeComboAmount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):756
                                                                    Entropy (8bit):5.202160271633777
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd+H4VzjGhdRDDHwpat5DersnSMnS31Rur1RlA9ntpY2U7nkYq/UqpNO2su:2d+H4MdRgesrbb1RA1ROHJf
                                                                    MD5:E1122B57E287C1877FA5315D9BBF69A6
                                                                    SHA1:3074795ABA811348349F03B901612F6DDAD5AE13
                                                                    SHA-256:7D1688B0D9262DF123FD483568DD0E57A9DD41C943524CF57863B04CA7D4DED4
                                                                    SHA-512:8E5FA31DEB789604CE517D998815350704001F8E6425A15607326E468AC57BD2338479CFCA872250EE2CDA48601B5945C89B29F120BEE2970B6289579BA3ABA0
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11942" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.EditDlgMIPInfo" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9348a" />.. </S>.. <C T="B" I="0" O="false" N="ClassificationPolicyEnabled">.. <S T="1" F="ClassificationPolicyEnabled" />.. </C>.. <C T="B" I="1" O="false" N="SensitivePolicyDataExists">.. <S T="1" F="SensitivePolicyDataExists" />.. </C>.. <C T="B" I="2" O="false" N="SensitiveLabelsExists">.. <S T="1" F="SensitiveLabelsExist" />.. </C>.. <C T="B" I="3" O="false" N="SensitiveLabelsChanged">.. <S T="1" F="SensitiveLabelsChanged" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):631
                                                                    Entropy (8bit):4.405615805083732
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd34ferslNerQuxfh3drYfh3pxb8OKX/c//fpONkMNO/HNUlu:2dprslYrQ8fhNkfhWE7
                                                                    MD5:25254D7ABE472DE6031DE7BD706A418F
                                                                    SHA1:7BB1C3AC2BE6A9D24C1D58F7EA991ADFDC66EAFD
                                                                    SHA-256:99FB31F55785E7EF651718044BF81F08980F60612E46DBE2656D790B2DF9B33D
                                                                    SHA-512:F8959DBD060099798EC3314C86AEAB9C4E7EEE6477ABD98FDED76282A17D33E647A1AEF6BCD6FC5457B514D15A85E294855B2FCD3F20B74EABC9483446CF3AC2
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11943" V="0" DC="SM" T="Subrule" DCa="PSP" xmlns="">.. <S>.. <UTS T="1" Id="a1dp6" />.. <UTS T="2" Id="a1dqe" />.. </S>.. <C T="W" I="0" O="false">.. <S T="1" F="ScenarioName" />.. </C>.. <C T="W" I="1" O="false">.. <S T="2" F="ScenarioName" />.. </C>.. <C T="U32" I="2" O="false">.. <U T="100nsToMs">.. <O T="SUB">.. <L>.. <S T="2" F="TimeStamp100ns" />.. </L>.. <R>.. <S T="1" F="TimeStamp100ns" />.. </R>.. </O>.. </U>.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1087
                                                                    Entropy (8bit):4.862865929474717
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd75uVzjIHFY6dRDDHwpat5D+q3cDQi+kX4ORSX/c//PbpON+WX2CHbO8SMH/j:2dlusTdRge3ZJwmgoH1KHXfQ7
                                                                    MD5:FF81F3CA8A56494C6A3E5D4565AC8516
                                                                    SHA1:B45684CAA68938A6060041DA1738A405A1CDCAA6
                                                                    SHA-256:05D0BE526FEBB984EC3EBC8217364E10F5A119201E3CBA9A9364168B8698FED6
                                                                    SHA-512:339F02B5A5E4B992D7B7C0661900A20E742E04D0A6EE19AAFF5369B0F16B20A0CE89CE635277D5B5D32100F8A4B3948D62796446835D58656C0AE40CDA1BCB8C
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11944" V="3" DC="SM" EN="Office.Outlook.Desktop.OPX.WebView2Errors" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="357" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <TI T="2" I="Hourly" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="GE">.. <L>.. <S T="1" F="Result" />.. </L>.. <R>.. <V V="2" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="4">.. <F N="ControlId" />.. <F N="WebHostingSessionId" />.. <F N="Result" />.. </S>.. </G>.. <C T="G" I="0" O="true" N="ControlId">.. <S T="4" F="ControlId" />.. </C>.. <C T="G" I="1" O="true" N="WebHostingSessionId">.. <S T="4" F="WebHostingSessionId" />.. </C>.. <C T="U32" I="2" O="false" N="Result">.. <S T="4" F="Result" />.. </C>.. <C T="U32" I="3" O="false" N="TotalCount">.. <C>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1029
                                                                    Entropy (8bit):4.709873309115686
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdxVzjfXWt6dRDDHwpatEs1nc1NQi+kXqNOAnX/c//wVrMpONd+wsvXqNOAnXT:2dxdXWQdRgevWqJT9jqwOa9iNEYEF7
                                                                    MD5:9E5FF3D3F1E264B2A77BB1183A5330FA
                                                                    SHA1:C584EC185628FAE3633C066080907C20C138ECFD
                                                                    SHA-256:D8EC66E15E8C9049C48032559B04B95E1CEEA42396097B95E5CEEB10C774198B
                                                                    SHA-512:FB7421E1BE697AC637439FAA36B8ABBA408684A67DCB4ED4F286CD3AAD3C43A9287D690E04A9BF130FC26F70441AB8542E7E2F78C6455732A4E0C2335CD5A476
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11946" V="0" DC="SM" EN="Office.Outlook.Desktop.OABBrowseAndSearchUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3402" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="isOffline" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="isOffline" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="CountSearchOABOffline">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="CountSearchOABConnected">.. <C>.. <S T="5" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>.. <ST>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1286
                                                                    Entropy (8bit):4.941151920409955
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dM8x6dRgebAuyRDu4Vcwgeg+6Kp5cTIBDR/B+SrCFG:cM8x2RgeMuyRS4VxQdIliFG
                                                                    MD5:CE9B8DB9494922C8E502F0C849945E4F
                                                                    SHA1:D1483FA4700903E0F8E99810F361EF8BC2621340
                                                                    SHA-256:B15CE7950544B1699E8390054CC55E8D0F95DDBDECD043C1D16E22D2326AAC6D
                                                                    SHA-512:BDC7FC89783ED7D1E12E19CAEA8CF94B08A83FB649579C7DD278385B8887397AAB497BD12F7227543978657B8AFAC5F6DE1EB5A94BACD328343E7FD829739282
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11950" V="0" DC="SM" EN="Office.Outlook.Desktop.Ndb.OpenedStats" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="800" G="{2adf8e23-0af9-43c9-ba4c-952ee130540d}" />.. <F T="2">.. <O T="EQ">.. <L>.. <S T="1" F="ErrorCode" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G I="true" R="TriggerOldest">.. <S T="2">.. <F N="LocalStoreFullFilePath" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="NdbVersion">.. <S T="2" F="StoreVersion" />.. </C>.. <C T="U32" I="1" O="false" N="FileTypeMagicNumber">.. <S T="2" F="LocalStoreFileType" />.. </C>.. <C T="U64" I="2" O="false" N="FreeSpaceInFile">.. <S T="2" F="FreeSpaceWithinLocalStore" />.. </C>.. <C T="U64" I="3" O="false" N="FileSize">.. <S T="2" F="LocalStoreFileSize" /
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):610
                                                                    Entropy (8bit):5.238735860448927
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd+VzjFu6dRDDHwpat5DDq5HE9KHbXbxw9lSZNO2su:2d+JdRgeUtHiI
                                                                    MD5:2EE4B1704D2B9448D7D668E8B6DAE167
                                                                    SHA1:8811A1C2BA5FBEF5C0554B37470AA04D274A5C90
                                                                    SHA-256:838E64973E4A10B67D3B0A1A94F9826E799F1427FD48431335B5000B6D5F41A0
                                                                    SHA-512:7839B4F312011669342EBD5EB2C3A3D3B3E95F26F3D46E7C258B16443C2EC0A8D525575D8E38CF22129DD28B5B79034F77E4DEC9C7225EEC74F21C408718A175
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11952" V="0" DC="SM" EN="Office.Outlook.Desktop.OPX.ConnectionErrors" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="358" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. </S>.. <C T="G" I="0" O="true" N="ControlId">.. <S T="1" F="ControlId" />.. </C>.. <C T="G" I="1" O="true" N="WebHostingSessionId">.. <S T="1" F="WebHostingSessionId" />.. </C>.. <C T="I64" I="2" O="true" N="Result">.. <S T="1" F="HRESULT" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):487
                                                                    Entropy (8bit):5.215584085516877
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdpVzjfVKpdRDDHwpatEerCPXFJnAjxeHaSMNO/HNUlu:2dp7adRgeLrCfvh7
                                                                    MD5:F623887B1E1DE93617A4F8D5FC5311EC
                                                                    SHA1:9547D43413583997D31AE8026DFC56F6EF83908C
                                                                    SHA-256:B850FC4A6D9D777B2BD0F1AF86C0745C23459902263C869A420D45CACF012E91
                                                                    SHA-512:A525411A0CF47E1D76634DCDBE044C31D4435A09E35EE88E2D2F1786B1EC2640399A6424D6F35B62617E710E91B18E6E3E07C12DEF4D397C84599A989720A84D
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11959" V="0" DC="SM" EN="Office.Outlook.Desktop.CountOfAddGroupMemberDialogGetDpi" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9zwv2" />.. <A T="2" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="CountGetDpiCalled">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):9172
                                                                    Entropy (8bit):3.925558248923313
                                                                    Encrypted:false
                                                                    SSDEEP:96:YRgekavWxFhxVAx/DxgxAax/qxVTxffsxJVx9e1H5IprdxyNYO2DrHv:YDkc6fDb
                                                                    MD5:FA851A2B33EDD754B355B8B4F81D6B12
                                                                    SHA1:1FC7E50DE3F59A6FAD36D36E04286FC0579D98C9
                                                                    SHA-256:8D829F4CB237FCA8FB3CBE49F58F45681BBE844A7149F24A631C79D82E4DCA21
                                                                    SHA-512:A63E963FEDE605EE0F2E742D62752D323FE88E820C461EA7B2C107409F530436D0CFF399BD5D2B4888F1EF2B3FD35A1169791E3F678D8BA5581156EE1A9A90E6
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11961" V="0" DC="SM" EN="Office.Outlook.Desktop.OpenMessageStore.EmsLogonHelperErrorCodeResults" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="2066" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="OR">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="2147483648" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="GE">.. <L>.. <S T="1" F="HResultRun" />.. </L>.. <R>.. <V V="2147483648" T="U32" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <O T="BITWISEAND">.. <L>.. <S T="4"
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):8429
                                                                    Entropy (8bit):3.9531412413732308
                                                                    Encrypted:false
                                                                    SSDEEP:96:1GmRgeka/lWxFhxVAx/DxgxAax/qxVTxffsxJVx9e1H5IprdxyNYO6Ub6ZIgRjqc:ZDko616k
                                                                    MD5:230BC7859C03FBB09F24EA9FDF3F93F7
                                                                    SHA1:E366F4D2FE911930801D2C86D16C2D318D599CE4
                                                                    SHA-256:79A45A8E36F2A2FCCB967E5B1C328945DEF848F313BEB90A224AE9844348204E
                                                                    SHA-512:670E3F124BD4959B346C899766BAC13F3AF16DF59219331DF2EE790B979A4154B4092A8733D377205BBE148C0211D20E71F72F97D79566EDC6E516C43879D8D9
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11962" V="0" DC="SM" EN="Office.Outlook.Desktop.OpenMessageStore.EmsLogonHelperEcGlobalError" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="2066" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="NE">.. <L>.. <S T="1" F="EcGlobalError" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <O T="BITWISEAND">.. <L>.. <S T="4" F="ulStoreInfoDataBytes" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <O T="BITWISEAND">..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):725
                                                                    Entropy (8bit):5.253946454742253
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd1jVzjp2w6dRDDHwpat5CkerMme/1yIEJopK0fvAIxnz6C/I1dNO2su:2d5bSdRgeMrrMmedfGEX1UCg
                                                                    MD5:3BE3BA16A95DF160733E232316647C6F
                                                                    SHA1:17A57D2D4EDDA899CCFA0B7BC5D6170EC30268DA
                                                                    SHA-256:6B37EC6FCC1C2661F7982799F452F3AD97299B9DD64AC1C263FEBFC669753069
                                                                    SHA-512:766731FCED3B205E31CF9D2B3ADEE6232948793D477CAAB1D285AAF2A2798DF247D6542110F8CEB2A00610C35B102262CF7B5EBFF46E927B70C9D4A3BF56AF65
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11964" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.MigratedCreateUnifiedGroupDialogUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="50" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9zg8g" />.. </S>.. <C T="U64" I="0" O="false" N="DialogVersion">.. <S T="1" F="DialogVersion" />.. </C>.. <C T="U32" I="1" O="false" N="DescriptionLength">.. <S T="1" F="DescriptionLength" />.. </C>.. <C T="U32" I="2" O="false" N="GroupType">.. <S T="1" F="GroupType" />.. </C>.. <C T="B" I="3" O="false" N="IsByDefaultAutoSubscribeOn">.. <S T="1" F="IsByDefaultAutoSubscribeOn" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):506
                                                                    Entropy (8bit):5.286616073715708
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdEVzjp24kKdRDDHwpat5CkerMKe/1yf87SZNO2su:2dEbrPdRgeMrrRedx7I
                                                                    MD5:DB54B30581DD2DB341E2B3586346D231
                                                                    SHA1:879A7418F3B8E295882506CF1243416FDC50AA89
                                                                    SHA-256:232A05CF9341D7181092A5AF1552469F1AD925B21A7FBDBAC76D9CFE60024253
                                                                    SHA-512:C2071EA18C026A1FD3356407DD410A15883B32D29B77702823445D19AC020BBE8B6C8165A216DDF00DD026A3B60CCF72303F442475D1FBEE96EA5BB34D4A1287
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11965" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.MigratedCreateUnifiedGroupDialogHealth" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="50" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9zg8e" />.. </S>.. <C T="U64" I="0" O="false" N="DialogVersion">.. <S T="1" F="DialogVersion" />.. </C>.. <C T="I64" I="1" O="false" N="Hresult">.. <S T="1" F="HRESULT" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):521
                                                                    Entropy (8bit):5.284810778509163
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd7Vzjp2dN6dRDDHwpat5CcTerpKe/1yf87SZNO2su:2d7bldRgeMc6rpKedx7I
                                                                    MD5:D552E7B4F302A1D60E65CF54581A09ED
                                                                    SHA1:CF197B29FF87811BDACF1408375549A38B482657
                                                                    SHA-256:CF0679FF2CCD262B41E632ADEEA82BA3140D9FC7FE5F2FC188E33B5FF37C6CE2
                                                                    SHA-512:96FD4B5FB7F4DC265E815614862EE5E9029A64D018AA3C918ED4CF056EC2A09439783A8A310C0CF3361B9C60B5A512B3F6CD5109548BE5472F76664E516D376D
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11966" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.MigratedCreateUnifiedGroupDialogServerResponse" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="50" DL="A" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9zg8d" />.. </S>.. <C T="U64" I="0" O="false" N="DialogVersion">.. <S T="1" F="DialogVersion" />.. </C>.. <C T="I64" I="1" O="false" N="Hresult">.. <S T="1" F="HRESULT" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1012
                                                                    Entropy (8bit):4.693424474775187
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd23Vzjp2KY3kKdRDDHwpatEerPc1NQi+kXqNOgdX/c//wVrMpONd+wsvXqNO9:2d23bGPdRgeLreqJTjjqwOajiY/Y7
                                                                    MD5:04D7FB0C5837D3D88EE00714E91C3C36
                                                                    SHA1:1CD948BB0F911B97A339427CE48C990FAA7EE38D
                                                                    SHA-256:C8DBCC9687A2D76DC57E9D289926F5640EDA624E7419F23C6EA14BAA83446075
                                                                    SHA-512:1ADC7946FF4AFED0A8C8D88D1AF1BD3740B42E7624574E6945369C412D0589CD97E97B36E54BE66D99F5E8EE1310DAD4D29ED9A393961C531DF94E0986F1F589
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11967" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.MigratedCreateUnifiedGroupDialogAdvancedSettingsHealth" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9zg8c" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="IsSucceeded" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="IsSucceeded" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="Success_count">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="Failure_count">.. <C>.. <S T="5" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. <
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):5915
                                                                    Entropy (8bit):3.8679735216721216
                                                                    Encrypted:false
                                                                    SSDEEP:48:c9b1lRgeLqvS83SdlE44YzcxWPLJ5VZzjmRgfeBlOMnw:CbRgeubiAucUhVffaEMw
                                                                    MD5:29863DB9317D0807F97B869B8A3010E1
                                                                    SHA1:19B84334C40BEBCCE0C0C4EFBD75040EDE4463F3
                                                                    SHA-256:3C5F1DABFD0C7E405510556B4FAA36ECCB2A20E31A9FA15E9D56BD2CC42F6F98
                                                                    SHA-512:E07193831ED8F100147C144DDEB952DEDC53DB1AA0297B65C6970E3D05B167C4F78C20E088477A246D12D52E68DE8316B4A3714C2590371FB4E93BB88D224FD5
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11968" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.MigratedCreateUnifiedGroupDialogDialogDuration" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9zg8b" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="LE">.. <L>.. <S T="1" F="OpenDialogDuration" />.. </L>.. <R>.. <V V="2000" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="AND">.. <L>.. <O T="GT">.. <L>.. <S T="1" F="OpenDialogDuration" />.. </L>.. <R>.. <V V="2000" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LE">.. <L>.. <S T="1" F="OpenDialogDuration" />.. </L>.. <R>.. <V V="5000" T="U32" />.. </R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):655
                                                                    Entropy (8bit):5.099623030102572
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdIVzjp23dRDDHwpatEer9XFJicouDP4b2dfAGqjBHaSMNO5csu:2dIbmdRgeLrhvS4Ndlr
                                                                    MD5:61D604FE9C10A79D895445C388AEF8ED
                                                                    SHA1:99F1790396119C8BC4623E8496D95BBA8CD69476
                                                                    SHA-256:D3CC089E9610A61E4D025180E0D5B4203FFBACEAB493746DD3685696FE61A7AD
                                                                    SHA-512:4C201A724CE48F0D29D48990A9947F8B8FEDE1E3BB6562B6C7802E631EA3463EA58BABD630F7BFA2603788DA119852C6CF2F747DB1AB98D4D73A0929A05FE51C
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11969" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.MigratedCreateUnifiedGroupDialogExitActions" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9zg8a" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="Action" />.. </S>.. </G>.. <C T="I32" I="0" O="false" N="ActionType">.. <S T="1" F="Action" />.. </C>.. <C T="U32" I="1" O="false" N="CountClicks">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):785
                                                                    Entropy (8bit):5.133376137351738
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdd4Vzjp2JfH+6dRDDHwpat5CkerJferADmfW8/mfR10M14n+w/bMMPe/1yNOQ:2dd4bYfBdRgeMrrJWrR3eUjvedi
                                                                    MD5:DD91A12BDA190B323116AA48DB4AD9B0
                                                                    SHA1:FB22048F433031D02E411A7C04BA2B28D3C4118C
                                                                    SHA-256:2D09AB06E29F58A711DB98A92F8CDA1C274D4C973E1DCC621F83C022A19AE721
                                                                    SHA-512:0D4C6DA6A2167A62F0DE202EE6FB757B7B9B93F830AA9003752D0E822EB314C9ADCB07CE2A8D1268FAE1340790BA9D9FEE225B2A931661075B8E1121C00137CC
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11970" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.MigratedCreateUnifiedGroupDialogClassificationUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="50" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9zg78" />.. <UTS T="2" Id="9zg77" />.. </S>.. <G>.. <S T="1">.. <F N="UniqueID" />.. </S>.. <S T="2">.. <F N="UniqueID" />.. </S>.. </G>.. <C T="U64" I="0" O="false" N="ShowDialogSucceed">.. <S T="1" F="ShowDialogSucceed" />.. </C>.. <C T="B" I="1" O="true" N="ShowClassification">.. <S T="2" F="ShowClassification" />.. </C>.. <C T="U64" I="2" O="false" N="DialogVersion">.. <S T="1" F="DialogVersion" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1120
                                                                    Entropy (8bit):5.155222805182783
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHddVVzjp2c0QdRDDHwpat5DerWkC143AtOKIkxntEanxHWS5bSALHWS5ynHDqk:2dXbj0QdRgesrWtdGSFKSS/9KUiR2
                                                                    MD5:080F8B0FF36E8B69CF754D2D69DE4D67
                                                                    SHA1:1EB72E631B5E4FB7800DBEA205AA2C9200213320
                                                                    SHA-256:1B842848ED8923C151CE45C25676BEEF93F2737ED77B57B52C02BF720B4DC99E
                                                                    SHA-512:70AFC546556EF2B049B8955E7CF163DBB1C849B54A355904092F47E382FFA4BE15ACB8E1723C39DF0024B0CA40A04E6D034629B72DFA7FAF5DD81E0EAD954C32
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11971" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.MigratedCreateUnifiedGroupDialogGroupCreationInfo" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9zg79" />.. </S>.. <C T="B" I="0" O="false" N="LanguageChange">.. <S T="1" F="LanuageChange" />.. </C>.. <C T="I32" I="1" O="false" N="PrivacyValue">.. <S T="1" F="Privacy" />.. </C>.. <C T="B" I="2" O="false" N="ClassificationChange">.. <S T="1" F="ClassificationChange" />.. </C>.. <C T="B" I="3" O="false" N="AutoSubscribedCheck">.. <S T="1" F="AutoSubscribedCheck" />.. </C>.. <C T="B" I="4" O="false" N="GroupIdEdited">.. <S T="1" F="GroupIdEdited" />.. </C>.. <C T="B" I="5" O="false" N="NamingPolicyEnabled">.. <S T="1" F="NamingPolicyEnabled" />.. </C>.. <C T="B" I="6" O="false" N="PrefixSuffixEnabled">.. <S T="1" F="PrefixSuffixEnabled" />.. </C>.. <C T="I32" I="
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):5907
                                                                    Entropy (8bit):3.864357021842609
                                                                    Encrypted:false
                                                                    SSDEEP:48:cAzclRgeLgxvS83SdlE44YzcxWPLJ5VZzjmRgfeBlOMnw:vwRgeCbiAucUhVffaEMw
                                                                    MD5:B0C9F347594B94FBC48B49F15E9CA0E2
                                                                    SHA1:844BF589FFE0A5634759EE427006780BEF940026
                                                                    SHA-256:4732E5257F4E2F14245B5343D52E90076FDD7C9C42D336FF1CBBC782AA14E8DB
                                                                    SHA-512:A67DBED2FFBA44CBC000EE8AB2BC71510C8749B741E0DCE49334B17F2915CADE006E848E5425B865AE12283FD927865191F1D0C12B92EB0314E8F1CDBE6A1D8D
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11972" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.MigratedEditGroupAfterCreationDuration" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9zg73" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="LE">.. <L>.. <S T="1" F="OpenDialogDuration" />.. </L>.. <R>.. <V V="2000" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="AND">.. <L>.. <O T="GT">.. <L>.. <S T="1" F="OpenDialogDuration" />.. </L>.. <R>.. <V V="2000" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LE">.. <L>.. <S T="1" F="OpenDialogDuration" />.. </L>.. <R>.. <V V="5000" T="U32" />.. </R>.. </O
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):941
                                                                    Entropy (8bit):5.094054980247312
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd1VzjbuMv7d6dRDDHwpat5CkerYerOerSDmfW8/mfWHNmfR10M14dEfIxnt99:2d1RuWAdRgeMrr/rhrr3e6cQEQzIk
                                                                    MD5:531E6081F18CC5320370AC8586CB9220
                                                                    SHA1:586FBC63288A8433928D0BB960BCA2F34EBFB812
                                                                    SHA-256:C1C6D813B9E969A0C6FAA8170C905808D193EE50013E7903806E93ED27960593
                                                                    SHA-512:730ECAB3E963A2149C0381D5691227536C04ABA95D096C9032EF3BB756DBAC14547419525E3C28F5434F144C2C1DCE59D5C3EB09C92A605B92AD13794DD2E545
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11973" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.MigratedAddUnifiedGroupMembersDialogUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="50" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9zg7y" />.. <UTS T="2" Id="9zg7v" />.. <UTS T="3" Id="9zg7z" />.. </S>.. <G>.. <S T="1">.. <F N="UniqueID" />.. </S>.. <S T="2">.. <F N="UniqueID" />.. </S>.. <S T="3">.. <F N="UniqueID" />.. </S>.. </G>.. <C T="U64" I="0" O="false" N="ShowDialogSucceed">.. <S T="1" F="ShowDialogSucceed" />.. </C>.. <C T="W" I="1" O="false" N="DialogType">.. <S T="1" F="DialogType" />.. </C>.. <C T="B" I="2" O="true" N="ShowEditPrivacy">.. <S T="2" F="ShowEditPrivacy" />.. </C>.. <C T="B" I="3" O="true" N="ShowClassification">.. <S T="3" F="ShowClassification" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):626
                                                                    Entropy (8bit):5.2687844045623775
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdkjVzjbuMv7FVKLFsdRDDHwpat5DerIkkpAGgCiEGpsOXMZlMNO2su:2dkjRuWvYFsdRgesrIdjTWcY
                                                                    MD5:6DB84A1957751410766FC2EB671391F5
                                                                    SHA1:431D04E45FC4DFF05690234ADA6A33FD669E1F45
                                                                    SHA-256:9CB015C8FEAA90824E8E3992684170576C73C5ADCD2656FAB9EDA8116C0F4652
                                                                    SHA-512:1DB706C5FF842C0CB22A71CE474CC46CCBBD8AE61662022F63BC70C76E912545EF68D1452236E9C1A2ED4D3130939915EB58BE14D8148CA61B3ABF52E317B010
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11974" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.MigratedAddUnifiedGroupMembersDialogBulkAddGroupMemberActionData" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9zg7w" />.. </S>.. <C T="B" I="0" O="false" N="ActionSucceed">.. <S T="1" F="ActionSucceed" />.. </C>.. <C T="U32" I="1" O="false" N="EWSErrorCode">.. <S T="1" F="ErrorCode" />.. </C>.. <C T="U32" I="2" O="false" N="MemberCount">.. <S T="1" F="MemberCount" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):658
                                                                    Entropy (8bit):5.109562528870546
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdRVVzjbuMv7xdRDDHwpatEerFXFJicouDP4b2dfAGqjBHaSMNO5csu:2dRVRuWxdRgeLrpvS4Ndlr
                                                                    MD5:26320703594403DA31BABF5692F2D842
                                                                    SHA1:044B79B6A0CCFACDED71767DA2F1A866F5306330
                                                                    SHA-256:F6A14666B64A961D2E3A37D0B06288606266380F017AB2D0E1C9F875F9D8460E
                                                                    SHA-512:2D539C4A77A86907431CF50F1FC4A40544194DB0B128032035FBD38DBF726EEA7151F357EA02CAFD46BBA8F5B01E0081116C0E528D9AF8D278548FBCA622B55E
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11975" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.MigratedAddUnifiedGroupMembersDialogExitAction" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9zg7t" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="Action" />.. </S>.. </G>.. <C T="I32" I="0" O="false" N="ActionType">.. <S T="1" F="Action" />.. </C>.. <C T="U32" I="1" O="false" N="CountClicks">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1277
                                                                    Entropy (8bit):5.069243664148278
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dURuW7xsdRgeMrrHrf3e5qYdrZxrvq+p+npfM:cURORgesrziq0rZxrvqfi
                                                                    MD5:10C3B32210DC96137147105352EC3C0F
                                                                    SHA1:3CCA9701D40E56411F96680418B890C1DCB6D503
                                                                    SHA-256:633BBEB3BECBFD43320EEE5FFBCF1AF7AD23B03ECDBF391D94E6BE974D15C027
                                                                    SHA-512:9FBDD3AB23C4322156DD216ED4079F8D36F7E812AA59114A06380F88FEE78B359ABC68C2EDE9BFFDDB0E2C45F76BA80DE0C9D5A9A08FA1405EA6D2A34364A4FE
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11976" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.MigratedAddUnifiedGroupMembersDialogEditGroupActionData" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="50" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9zg7q" />.. <UTS T="2" Id="9zg7m" />.. </S>.. <G>.. <S T="1">.. <F N="UniqueID" />.. </S>.. <S T="2">.. <F N="UniqueID" />.. </S>.. </G>.. <C T="U64" I="0" O="false" N="ActionResult">.. <S T="2" F="ActionResult" />.. </C>.. <C T="B" I="1" O="true" N="AccessTypeChange">.. <S T="1" F="AccessTypeChange" />.. </C>.. <C T="B" I="2" O="true" N="NameChange">.. <S T="1" F="NameChange" />.. </C>.. <C T="B" I="3" O="true" N="DescriptionChange">.. <S T="1" F="DescriptionChange" />.. </C>.. <C T="B" I="4" O="true" N="AutoSubscribeChange">.. <S T="1" F="AutoSubscribeChange" />.. </C>.. <C T="B" I="5" O="true" N="LanguageChange">.. <S T="1" F="LanguageCha
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):872
                                                                    Entropy (8bit):5.126905660124621
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dJRuWqdRgeMrrRWro3e5qYdrZfXmrwD0:cJRqRgesI4iq0rZ/mD
                                                                    MD5:833BDF9FF151747B2E2F8CEDC1BDFA2B
                                                                    SHA1:CFBC8A5B48B47D2F9507B74C9D6CC77D8A7C18A0
                                                                    SHA-256:E3C1C251FBA2940EC9F340F2998137AF98999FCB2B5EAACFB46FB975CF6A0737
                                                                    SHA-512:0B2C402EE1B6792B0072962EACB83F0397C343074FF5D3F7D9B99852DE6023DA306482D0D219FDD35D5ADBCA54C6B3A5FA8325257AEA33517D8E4B0740D31977
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11977" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.MigratedAddUnifiedGroupMembersDialogEditGroupMember" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="50" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9zg7p" />.. <UTS T="2" Id="9zg7l" />.. </S>.. <G>.. <S T="1">.. <F N="UniqueID" />.. </S>.. <S T="2">.. <F N="UniqueID" />.. </S>.. </G>.. <C T="U64" I="0" O="false" N="ActionResult">.. <S T="2" F="ActionResult" />.. </C>.. <C T="W" I="1" O="false" N="OperationType">.. <S T="2" F="OperationType" />.. </C>.. <C T="U32" I="2" O="false" N="TotalChangedMemberCount">.. <S T="1" F="TotalChangedMemberCount" />.. </C>.. <C T="U32" I="3" O="false" N="GuestCount">.. <S T="1" F="GuestCount" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):956
                                                                    Entropy (8bit):4.868383145752248
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdaVzjbuMv7FVKr9PdRDDHwpatEerzXFJicoN+kXqNOoGJX/c//bLMpONGPDXs:2daRuWvw9PdRgeLrLvS8TwNicDQs3y7
                                                                    MD5:D5D0D6FB40B55FE7207BDD1261715FDF
                                                                    SHA1:41AA942B5F85D47DC685A1258175BE88920698A5
                                                                    SHA-256:55D282F4A5A3FE83F02D12465E266757FDE286AC15610BB6ED6A3578EB7E9F2F
                                                                    SHA-512:AA799F051F7058A422235BE6E3AE2D50F9A2F584EDDD3C3803DE6838D1F5D00D3157189B192D2A6CBB19CF6ACFFE3835BF169A1F5B709FEAA5A477301B6C3578
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11978" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.MigratedAddUnifiedGroupMembersDialogAddGroupMemberEmailValidation" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9zg7j" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="ActionSucceed" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="GuestCount">.. <A T="SUM">.. <S T="1" F="GuestCount" />.. </A>.. </C>.. <C T="U32" I="1" O="false" N="FailureCount">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="TotalCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):752
                                                                    Entropy (8bit):5.0180794961343524
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd1VVzjHw6dRDDHwpatEerBXFJicouDP4/2vt/AGqMPGZpMVXHaSMNO5csu:2dPZdRgeLrNvS4UUtFXeYVu
                                                                    MD5:D246744886F012EE5E32F94A6783D0EC
                                                                    SHA1:73F1B96C797D85CBED01920C2BAF4B5406766B23
                                                                    SHA-256:D9B93901326A5782EFDEFAF82D2632804ABCC1A75B1ACD13C8AF1AE04CEC5F42
                                                                    SHA-512:D5768241AD6A786067BD28305E7C2B1DFBB5A2D7A7A7E1E23395A8E624FDFCACB21849F5A485A409278D36B66D5AE074170BDFC367FDA6ED229A25F6E7790F6F
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11979" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.MigratedDeleteGroupDialogUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9zg7h" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="Action" />.. <F N="ResultCode" />.. </S>.. </G>.. <C T="I8" I="0" O="false" N="Action">.. <S T="1" F="Action" />.. </C>.. <C T="U64" I="1" O="false" N="ResultCode">.. <S T="1" F="ResultCode" />.. </C>.. <C T="U32" I="2" O="false" N="ActionsCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1107
                                                                    Entropy (8bit):5.00784820344696
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dbzjDodRgets1zfYrGrRhr5WrDVtIZF+:cbzjDARge0zfYalhInV+ZF+
                                                                    MD5:2E1FBF3A1C0C423AD11151651544A55D
                                                                    SHA1:5E6D59971529DC0103C8E8484283250F39D6D19E
                                                                    SHA-256:77C89E571062F497E4799AE6D65D4F349D0534E21A422290635CF73C3C45C1C3
                                                                    SHA-512:6A2FF06D21BDE9CAD21772FCE4F255B5D09DAE675BBE59984502CC90C9CA8CFB7D6A1BF89A0E841AA3322C7D63272869761FB149DC123655540760BD25E9BBE1
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11980" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.UnwarrantedDialogsLoads" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" SP="CriticalExperimentation" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <UTS T="3" Id="9zb0h" />.. <UTS T="4" Id="9zb0j" />.. <UTS T="5" Id="9zb0l" />.. <UTS T="6" Id="9zb0n" />.. </S>.. <C T="U32" I="0" O="false" N="CountOfIllegalCallToUnifiedGroupErrorDialog">.. <C>.. <S T="3" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="CountOfIllegalCallToDeleteUnifiedGroupDialog">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="CountOfIllegalCallToCreateUnifiedGroupDialog">.. <C>.. <S T="5" />.. </C>.. </C>.. <C T="U32" I="3" O="false" N="CountOfIllegalCallToAddUnifiedGroupMembersDialog">.. <C>.. <S T="6" />.. </C>.. </C>.. <T>.. <S T="1" />.. <S T=
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):487
                                                                    Entropy (8bit):5.203053398959187
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdOVzj5d7jdRDDHwpatEerCefXFJnArQd7cHaSMNO/HNUlu:2dOPd7jdRgeLrCevvld7o7
                                                                    MD5:8507C9CED3B6414E8F14B25E1555927B
                                                                    SHA1:86A1E9B5331695D595BB7E4200DDCEBA6158709F
                                                                    SHA-256:E0D836D4FA2CDB90B7D8930B43142500BA226A8D95EB91C238ED0396433F3CA8
                                                                    SHA-512:0BD8108426058B10051B1BB679AB8D7BA0AD2ADBAA92F689751DD2B24DC19072DA1BB6E5733A4BB986F34227F236A6063D1BCF14D4A175A51B942E567BEBA979
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11981" V="0" DC="SM" EN="Office.Outlook.Desktop.CountOpenOutlookPropsDialog" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9zwv1" />.. <A T="2" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="CountOutlookPropsDialog">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):895
                                                                    Entropy (8bit):5.150260960535219
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdYVVzj8yDMBdRDDHwpat5l7+FUEXIlMnxy//Ih5MpIA1nkISnHD76pXIO6bSD:2dIaQ6dRgeGB8/W1i6VY
                                                                    MD5:9A129952A56076F0520EBD235195DC7B
                                                                    SHA1:F5DA019E82A8B0C7F702553951B497504C173CAF
                                                                    SHA-256:E5CE06758483C0F4C7FFDB0F8EDF6CA03B7C8FE0CADB45C786524FB2C5DD07CB
                                                                    SHA-512:49921F6EE711B3F66F501746C8D89DF7715EBB46734BF275DE40ED010132DD397866EB650D08AE5C89AA4891BD2DBA83929579B824C6CA0A13F6744621452202
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11987" V="0" DC="SM" EN="Office.Outlook.Desktop.AttachmentPreviewPerformance" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="200" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="4307" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="U32" I="0" O="false" N="AttachmentCount">.. <S T="1" F="Count" />.. </C>.. <C T="B" I="1" O="false" N="IsOfficeFileExtn">.. <S T="1" F="IsOfficeFileExtn" />.. </C>.. <C T="U32" I="2" O="false" N="AttachmentMethod">.. <S T="1" F="AttachMethod" />.. </C>.. <C T="B" I="3" O="false" N="IsSuccess">.. <S T="1" F="IsSuccess" />.. </C>.. <C T="B" I="4" O="false" N="IsReadingPane">.. <S T="1" F="IsReadingPane" />.. </C>.. <C T="U32" I="5" O="false" N="ElapsedTime">.. <S T="1" F="ElapsedTime" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):2151
                                                                    Entropy (8bit):4.471184011582431
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dSTdRgedGIiGIiOvJwOagOiAJgOjqu1OiAv1OjVN3uNkWNaN5NEN/PEN3/NYI95:cSRRge4y6vJQgkJgYqu1kv1YndSY
                                                                    MD5:393632731A4B18D83A19046C47F5B765
                                                                    SHA1:714CF03294CE099D564627CD2FE5719E685B577E
                                                                    SHA-256:FE9BC082E9804C2BC60099D34AE67605CB9574BB4E4073EA486DDEE002A62516
                                                                    SHA-512:6401E3C54F405F260725F9CAC5FD04A501308AD692FC243A0B7FA03D72BA7D9D8F89C1C4ACFACD82D28540D2E697182BEA7D2741DD2FAA99AF7DE574FE4D03DE
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11988" V="1" DC="SM" EN="Office.Outlook.Desktop.Calendar.EventPeekOpenUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="430" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <Etw T="2" E="607" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <TI T="3" I="Daily" />.. <A T="4" E="TelemetryShutdown" />.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="IsMeeting" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="IsMeeting" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="2" F="IsMeeting" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):700
                                                                    Entropy (8bit):5.2050849295587565
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdWVzjDdRDDHwpatEMuJe1zjFP9Asf5+AQxpbe/py4IMSe/jMSkNO2su:2dWxdRgeruEAsx+AQHehgejM
                                                                    MD5:A6C4CF6994B6E5731403968AC85C282D
                                                                    SHA1:6D2C8CC03EABE3162A4D0D6FD624337B971908FB
                                                                    SHA-256:CE604316D3B48AF632D17E4E8DE9D769AD33E0D958A0BE8B2E0A0FCC98F05A09
                                                                    SHA-512:556B01FB783C6E1D163509B4305E499199DCD246434147DF2F76192415509245A8B1277C7A7C8F305301D7DC41136A234E6C9AE8765C6B4509F80FFB3129F72D
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11989" V="0" DC="SM" EN="Office.Outlook.Desktop.NDBCorruptStoreRuleSampled" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="319" G="{2adf8e23-0af9-43c9-ba4c-952ee130540d}" />.. </S>.. <C T="U32" I="0" O="false" N="Context">.. <S T="1" F="Context" />.. </C>.. <C T="U32" I="1" O="false" N="NdbType">.. <S T="1" F="NdbType" />.. </C>.. <C T="U32" I="2" O="false" N="Version">.. <S T="1" F="Version" />.. </C>.. <C T="U32" I="3" O="true" N="CreatedWithVersion">.. <S T="1" F="CreatedWithVersion" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1044
                                                                    Entropy (8bit):4.993396824578967
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdGaVzjH8HRdRDDHwpat4AQiTHc4FHQicih2uD9NfW8/9Nf87PNWQRNff/0//1:2dJN8HRdRgeCJqN3VNkP3N3ON4IRpB
                                                                    MD5:D45E832799C97EF7C7F009C9B4253BA6
                                                                    SHA1:36449FD50540496200125065B00BB287BD247FC6
                                                                    SHA-256:FC91BF1DE6C4FFD3B2911459174B86AF2A7267C1380366A1C29F1BA29ADCACFC
                                                                    SHA-512:56809D8E610F1F30A14C47937E57C38A8D0C176C00A9DFFDDCE9959775BF1265736FE330A57191333835F232B40DB04B51A12D8A23716ED2E4584D581FB53F22
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11990" V="1" DC="SM" EN="Office.Outlook.Desktop.ReadSendMailEngagedUser" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="19045" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="19046" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="3" E="TelemetryShutdown" />.. <TI T="4" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="AccountUID" />.. </S>.. <S T="2">.. <F N="AccountUID" />.. </S>.. </G>.. <C T="G" I="0" O="false" N="AccountUID">.. <O T="COALESCE">.. <L>.. <S T="1" F="AccountUID" />.. </L>.. <R>.. <S T="2" F="AccountUID" />.. </R>.. </O>.. </C>.. <C T="U32" I="1" O="false" N="ReadMailCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="SendMailCount">.. <C>.. <S T="2" />.. </C>.. </C>.. <T>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1899
                                                                    Entropy (8bit):4.862540150008505
                                                                    Encrypted:false
                                                                    SSDEEP:48:ciGGuRgeL+hpWl79EVqAJo6fwAJ0Wc9wYFg3PvpkYsY4qYBm4:AGuRgeaDLfw80Wc9vF8vpzj49BL
                                                                    MD5:83B1DA95E45E4F977BF1242B8E3CFE9F
                                                                    SHA1:5D0628F1D7DAE6CAE095AA48F08607EB03AC6B16
                                                                    SHA-256:2E0ACFFAB4675F886DBF1891CDC2C896E30276353668252A29B9A0F98576FDB9
                                                                    SHA-512:37C33E0AA9882A281A5F6CBDC1C6740C93FE7C42EC96032599FF1C1C54585BCB587C48D71B13AC1B7663A10F5D2929CE6A542911A650988790AF17BCEA6E30EC
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11992" V="0" DC="SM" EN="Office.Outlook.Desktop.EmailTranslatorMgrMetrics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9y3sq" />.. <UTS T="2" Id="9y3sp" />.. <UTS T="3" Id="90jqt" />.. <UTS T="4" Id="90jqs" />.. <UTS T="5" Id="90jqr" />.. <UTS T="6" Id="90jqp" />.. <UTS T="7" Id="9y0my" />.. <UTS T="8" Id="9xohn" />.. <UTS T="9" Id="90jqq" />.. <A T="10" E="TelemetryShutdown" />.. <TI T="11" I="Hourly" />.. </S>.. <C T="U32" I="0" O="false" N="NeverTranslateLanguageStampEmptyErrorCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="AddNeverTranslateLanguageErrorCount">.. <C>.. <S T="2" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="TriggerServiceTranslationRequestErrorCount">.. <C>.. <S T="3" />.. </C>.. </C>.. <C T="U32" I="3" O="false" N="CheckTargetLanguageEmpty
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):860
                                                                    Entropy (8bit):4.960956486784933
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdXVzjUP0dK7dRDDHwpatEern/er5erHfBicHSXHaSMCzboXHhSMp7XHISMNOL:2dXiPJ7dRgeLr2rkrJ4tzsJao
                                                                    MD5:BB9DDC2E6CD1B7BFDE7075C9CE7A08F4
                                                                    SHA1:DBD0DA74E5CE7789D607DD411A5178E5592557FB
                                                                    SHA-256:54457F58DBECE89DEDAAA3590F5509C6F0AA64614589EE9076B43A83BBEE8D64
                                                                    SHA-512:AD1428922AC811982685DF415A275EE326345C96B26416CCC81DF8D4DFC124839AEA65B1B500915CA3828E4ACC8A3593EBE1EC050001811885A189843D89AE3D
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11993" V="0" DC="SM" EN="Office.Outlook.Desktop.EmailTranslatorMetricsCoreMetrics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9x7n3" />.. <UTS T="2" Id="9x7n4" />.. <UTS T="3" Id="9x7n5" />.. <A T="4" E="TelemetryShutdown" />.. <TI T="5" I="Hourly" />.. </S>.. <C T="U32" I="0" O="false" N="LogOperationFailedToStartCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="CantStartTelemetryCount">.. <C>.. <S T="2" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="LogOperationFailedToCompleteCount">.. <C>.. <S T="3" />.. </C>.. </C>.. <T>.. <S T="4" />.. <S T="5" />.. </T>.. <ST>.. <S T="1" />.. <S T="2" />.. <S T="3" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1025
                                                                    Entropy (8bit):4.931847309173289
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdUVzj0ugXdRDDHwpatEerOerGerzerQaicgL9hnXHaSMgRnoXHhSMpLYN3PXD:2dUqldRgeLrhrZrarlI9oZYN/yZbFU
                                                                    MD5:B4C156D0C2FD62D147879749E23C1AE5
                                                                    SHA1:AE6FDD3FB575C91B8078B8AB92224296CEAB550A
                                                                    SHA-256:5D4203C453A7A707FBC55CBD76388BDCCAB9D5A155F9426939BCF7497D76D01A
                                                                    SHA-512:7B77F91D07A1B4A023FB4F3BBF8C348482FED952239EAD583E9096D89701218204F1A81E2D8DE5DCD88159E5A0DB4F5F73279023E1FF1DC9B12753D79E187611
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11994" V="0" DC="SM" EN="Office.Outlook.Desktop.OlkTranslatorCloudSettingsMgrMetrics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9y3sb" />.. <UTS T="2" Id="9y3sc" />.. <UTS T="3" Id="9y3si" />.. <UTS T="4" Id="9y3sk" />.. <A T="5" E="TelemetryShutdown" />.. <TI T="6" I="Hourly" />.. </S>.. <C T="U32" I="0" O="false" N="TargetKnownLanguagesFromCloudCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="UnknownExceptionReadingJsonCount">.. <C>.. <S T="2" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="TranslationModeFailedCount">.. <C>.. <S T="3" />.. </C>.. </C>.. <C T="U32" I="3" O="false" N="SetCloudSettingsFailedCount">.. <C>.. <S T="4" />.. </C>.. </C>.. <T>.. <S T="5" />.. <S T="6" />.. </T>.. <ST>.. <S T="1" />.. <S T="2" />.. <S T="3" />.. <S
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1998
                                                                    Entropy (8bit):4.787853391214786
                                                                    Encrypted:false
                                                                    SSDEEP:48:cAeHrRgeLS0NW1IPhxpUilpt2w72JNRiQ369mr:ERgebNtEwyJ2N9o
                                                                    MD5:F54E3E5401E75B3B203737E67A1ADEA8
                                                                    SHA1:9D16ADE5DAB0009BD17557F0C58A399E3BAD535E
                                                                    SHA-256:C96EB4511421CC58A0C382EF74F909059AB4CE41AFD6DA70A2C34D06CF08BA55
                                                                    SHA-512:7183C22A760357B5071D666450E3DDB3EEF2B80661F54A8D35567C60DD382C8609A1E5F9008A9DD32C56BC9B44EE7DBD5DB401CFBC9FCBF0777F2E8E9A3D2725
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11995" V="1" DC="SM" EN="Office.Outlook.Desktop.TranslationInfoBarUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9ze0i" />.. <UTS T="2" Id="90kwx" />.. <UTS T="3" Id="90kww" />.. <UTS T="4" Id="9xohl" />.. <UTS T="5" Id="9w7ob" />.. <UTS T="6" Id="9w7oa" />.. <UTS T="7" Id="9w7n9" />.. <UTS T="8" Id="9w7n8" />.. <UTS T="9" Id="9ujt1" />.. <UTS T="10" Id="9ujt0" />.. <A T="11" E="TelemetryShutdown" />.. <TI T="12" I="Hourly" />.. </S>.. <C T="U32" I="0" O="false" N="OfficeCenterOpenFailedCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="InvalidEmailTranslationStateCount">.. <C>.. <S T="2" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="HandleSetSuggestTranslationStateTargetLanguageEmptyCount">.. <C>.. <S T="3" />.. </C>.. </C>.. <C T="U32" I="3" O="false" N
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1346
                                                                    Entropy (8bit):4.879166875723504
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dmQTdRgeLruiYrJGrwrrbV2rCurhyZHVhgNH1ZjeA9Rm+:cm0RgeLGwYA3l6yZCwRm+
                                                                    MD5:968FBBA18A6C2E60D0327882D8AD5F84
                                                                    SHA1:023FB10815905A9FD23F1F58AC885D16F0D3613B
                                                                    SHA-256:795B4FEEC00C6097D86F6B68C840DB03D24B96BDDC6C7188CFAC0C755F36E159
                                                                    SHA-512:445FC05175CCE0383D79CEFF23895FC3DEABE582E15410C6A0B65DB53341BE21EFF46A96C69E792981992454EC08FFD6F91C93E18F87C203C44F711F3C42D34C
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="11996" V="0" DC="SM" EN="Office.Outlook.Desktop.TranslatorSettingsMgr" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9zh7y" />.. <UTS T="2" Id="9zh72" />.. <UTS T="3" Id="9zh71" />.. <UTS T="4" Id="9zh70" />.. <UTS T="5" Id="9zh7z" />.. <UTS T="6" Id="9y3r8" />.. <A T="7" E="TelemetryShutdown" />.. <TI T="8" I="Hourly" />.. </S>.. <C T="U32" I="0" O="false" N="SupportedLanguagesFailedSessionCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="SupportedLanguagesFailedFromOgmaCount">.. <C>.. <S T="2" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="AddKnownLanguageUnsupportedCount">.. <C>.. <S T="3" />.. </C>.. </C>.. <C T="U32" I="3" O="false" N="SetKnownLanguageUnsupportedCount">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U32" I="4" O="false" N="PreferredLanguageUns
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):965
                                                                    Entropy (8bit):4.89769768385691
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdA1VzjXWoQKdRDDHwpat5Ckn+A+KbS+u/qNOyX/c//eHs7pONd+tN5lO0pX/B:2dA1koQKdRgeMmfuyfgtht2VHRQ
                                                                    MD5:A30ED30F074DBFD1415267263B941EFC
                                                                    SHA1:8CE63E9213BC9D85EE086B273E38404BF06FD3D9
                                                                    SHA-256:27DF729E076E5E328D24D310E1CEECB5FC98D560544A4E8497CDACD9CD861F1A
                                                                    SHA-512:58A41FFF6E724E297A1B982D4916E31E6DC0704305D95E2198D9DA588E7CB6BB492309C90318BC43152440BCE19AD4A095346B6B248896A757CCEBFBEFF34219
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12001" V="0" DC="SM" EN="Office.Outlook.Desktop.RopChaining.ParseResponseReplaySize" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="50" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="1612" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <F T="2">.. <O T="EQ">.. <L>.. <S T="1" F="ROP" />.. </L>.. <R>.. <V V="163" T="U32" />.. </R>.. </O>.. </F>.. <F T="3">.. <O T="NE">.. <L>.. <S T="2" F="RequestSize" />.. </L>.. <R>.. <S T="2" F="ResponseWrittenSize" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="WriteStreamExtended_RequestSize">.. <S T="3" F="RequestSize" />.. </C>.. <C T="U32" I="1" O="false" N="WriteStreamExtended_ResponseWrittenSize">.. <S T="3" F="ResponseWrittenSize" />.. </C>.. <T>.. <S T="3" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1028
                                                                    Entropy (8bit):4.877012501918166
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d0QNbHsdRgeLror0Wrrr+XN2iOeNoYOPNoYOpN2iObFU:c0ebcRgeLEpvSd2itPcPa2i2FU
                                                                    MD5:32C176C66F4FE4F6B802C6C36394013B
                                                                    SHA1:3BF4833ACCF528812601D2A93A5BD0C24732DD0F
                                                                    SHA-256:C44D6C6C90B628261055ED022BE65B4AB140DAFE5050322B904EB049DB673B55
                                                                    SHA-512:2392A8FD1B11B498A77BB4ADAF624026A36FEF44170E65F27B053151D8891A1F718FE92FF6CD8CB4008AA9BDD9277534EE2C6A58D3ACA534AE77ADBBFB389537
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12003" V="0" DC="SM" EN="Office.Outlook.Desktop.TranslationDataMetrics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="94el1" />.. <UTS T="2" Id="94el3" />.. <UTS T="3" Id="94elv" />.. <UTS T="4" Id="94elt" />.. <A T="5" E="TelemetryShutdown" />.. <TI T="6" I="Hourly" />.. </S>.. <C T="U32" I="0" O="false" N="SetTranslationStatusPropErrorCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="SetTranslationDataPropErrorCount">.. <C>.. <S T="2" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="ParseTranslationDataPropErrorCount">.. <C>.. <S T="3" />.. </C>.. </C>.. <C T="U32" I="3" O="false" N="ParseTranslationStatusPropErrorCount">.. <C>.. <S T="4" />.. </C>.. </C>.. <T>.. <S T="5" />.. <S T="6" />.. </T>.. <ST>.. <S T="1" />.. <S T="2" />.. <S T="3" />..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1170
                                                                    Entropy (8bit):5.017256271785813
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHduVzjgIFdRDDHwpatE3lnXFJicouD876uW+4TDYFbJixmnfXynt5v1I4KP4eY:2duPdRgeCXvSfcuYEV1aINIX
                                                                    MD5:DF1CEB3A2429615C0120AFCCDBD70DBD
                                                                    SHA1:8E15CE922A2D7DF794F23AD5B124F78FB3729C4A
                                                                    SHA-256:34AD2CD8C31F37CFD6BE485BA7296C810423FFE3A86D7005F86D4590CAE8CE87
                                                                    SHA-512:E4EEF8F6252F12C199DE3976621EE9E0CE1B273A45A6DF4E670A0C50E832962AA45262EE1023057608BDBD141297B367D77C14F918598DBDB0FDAEEDC9087AD1
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12004" V="1" DC="SM" EN="Office.Outlook.Desktop.AutoDv2.ServiceRequestOutcomePerScenario" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3894" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="Scenario" />.. <F N="BestEffort" />.. <F N="Succeeded" />.. <F N="ResponseStatus" />.. <F N="O365SettingsCheck" />.. </S>.. </G>.. <C T="I32" I="0" O="false" N="Scenario">.. <S T="1" F="Scenario" />.. </C>.. <C T="B" I="1" O="false" N="BestEffort">.. <S T="1" F="BestEffort" />.. </C>.. <C T="B" I="2" O="false" N="Succeeded">.. <S T="1" F="Succeeded" />.. </C>.. <C T="I32" I="3" O="false" N="ResponseStatus">.. <S T="1" F="ResponseStatus" />.. </C>.. <C T="U32" I="4" O="false" N="Count_Results">.. <C>.. <S T="1" />..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):694
                                                                    Entropy (8bit):5.072560269547965
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdA4VzjUN2E7dRDDHwpatEeriXFJicdDNN2LwOfgN2lEFN2LwxVN2lXHaSMNOw:2dViN2UdRgeLr6vhN2LwRN2yFN2LwnNV
                                                                    MD5:B65E778D0867CF13D611163172DD1250
                                                                    SHA1:2924989C8CD2B2A6742035D544C7453523E8826B
                                                                    SHA-256:8FCBDB5FEF2333D719367199FBF2836205E1C238FF8B79F2FBD87C6C1039B3C6
                                                                    SHA-512:48FEF5483984668717BCC18C3EBF0F83C7FE7D41DC7CF3FAB7FA657C8987CFB2A96F8AABAAF183470D5BA30021AC85B02E7A3061EC37256C63287C57DC20C154
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12006" V="0" DC="SM" EN="Office.Outlook.Desktop.EmailTranslationStateMetrics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9w7n7" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Hourly" />.. </S>.. <G>.. <S T="1">.. <F N="EmailTranslationState" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="EmailTranslationStateCode">.. <S T="1" F="EmailTranslationState" />.. </C>.. <C T="U32" I="1" O="false" N="EmailTranslationStateCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):684
                                                                    Entropy (8bit):4.999114195125101
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdgVzjmNmM6dRDDHwpatEerJferjQicitLFYUpoXHaSMqpoXHhSMNOAdHNS7lu:2dgQNmfdRgeLrJWrsYBYooJoDr
                                                                    MD5:8B713BDC4B5966D0971AE7C5C6553FBC
                                                                    SHA1:B91C9ED85B343B8A26B7B5AF25562AD1BCDF4364
                                                                    SHA-256:401E2042D7FFFC0196B56B5CE3304397F1642E971AF5E62C63C159713EBCB7C1
                                                                    SHA-512:E0924C6F1D7CFF1014C6407C8C947BAF5C05A7FC11D06CFBE2FB60B0633C391B71B0BB1BA933DA41C01BA408F0C0D0279C5F3E96C2894FD4A4B978685438B52C
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12007" V="0" DC="SM" EN="Office.Outlook.Desktop.TranslationContextMenuUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9w7oc" />.. <UTS T="2" Id="9w7od" />.. <A T="3" E="TelemetryShutdown" />.. <TI T="4" I="Hourly" />.. </S>.. <C T="U32" I="0" O="false" N="TranslateClickedCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="ShowOriginalClickedCount">.. <C>.. <S T="2" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="4" />.. </T>.. <ST>.. <S T="1" />.. <S T="2" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):999
                                                                    Entropy (8bit):3.7018389810195864
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdMPOO+QMfXFJFfcJfikfGvX4OjPNeJH/M//a5eNX/c//fezPNuc3/8//lSJud:2dMP4QevWRQrPGOZPzqhH
                                                                    MD5:0847565B252C325B0F3F4B65DDBF8CC2
                                                                    SHA1:BBAE496C74DD0952DE4CFC8A2F86FD0A8A9BB3B8
                                                                    SHA-256:0534C65211D5503B490BEED86790EE243C5DA900EADA1B419D593C90EE082A9E
                                                                    SHA-512:D53981BFDDF765CA9E4544744A234B7FEF266DFA85700E51523E52D784B4EE955A670DA22A549EE53BCCDC4D2CE5A9007EC793A732202AB143DB6F27317C98FB
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120100" V="3" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryStartup" />.. <A T="2" E="TelemetryResume" />.. <TI T="3" I="30s" />.. <R T="4" R="120100" />.. <TH T="5">.. <O T="GE">.. <L>.. <O T="COALESCE">.. <L>.. <S T="3" F="TimeStamp100ns" />.. </L>.. <R>.. <S T="2" F="TimeStamp100ns" />.. </R>.. </O>.. </L>.. <R>.. <O T="ADD">.. <L>.. <O T="COALESCE">.. <L>.. <S T="4" F="TimeStamp100ns" />.. </L>.. <R>.. <V V="1" T="FT" />.. </R>.. </O>.. </L>.. <R>.. <V V="864000000000" T="U64" />.. </R>.. </O>.. </R>.. </O>.. </TH>.. </S>.. <T>.. <S T="1" />.. <S T="5" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):2180
                                                                    Entropy (8bit):4.4661937782352386
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dCdgIqmBrerZWianT2lPBPzaonzPbcPeHsK6P4P49XCJYP4PVdwiJW/+fikA9GR:cCawSEi4TghV/xakIGR
                                                                    MD5:0BB16110449C6AD9F7E87A10F5B5976D
                                                                    SHA1:907AFA5DAEA114422780FB2906930CB30017B450
                                                                    SHA-256:C0513E3644466F11FE50B1434090E96D07966030BCD00E293506C763B6C6B7C9
                                                                    SHA-512:8528BDB42A797D656FDA2F2BD061FDAAD38F74C4FF40FE79023E196A120D4A521C8C4375E91A3CE668DFAF3F2A0EA5C69A481DAB4F38C91AB31EBB9E7551F592
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120107" V="6" DC="SM" EN="Office.System.SystemHealthDesktopSessionLifecycleAndHeartbeat" ATT="cd836626611c4caaa8fc5b2e728ee81d-3b6d6c45-6377-4bf5-9792-dbf8e1881088-7521" SP="CriticalCensus" DL="A" DCa="PSU" xmlns="">.. <RIS>.. <RI N="Lifecycle" />.. </RIS>.. <S>.. <UTS T="1" Id="awjb7" />.. <UTS T="2" Id="a14x3" />.. <SS T="3" G="{68442bc6-3519-4b08-a80c-e0a68fc8cda3}" />.. <TI T="4" I="Hourly" />.. <TR T="5" />.. <R T="6" R="120107" />.. <F T="7">.. <O T="NE">.. <L>.. <S T="1" F="Event" />.. </L>.. <R>.. <V V="3" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <C T="FT" I="0" O="false" N="Time">.. <O T="COALESCE">.. <L>.. <S T="2" F="SessionStartTime" />.. </L>.. <R>.. <S T="5" F="TimeStamp100ns" />.. </R>.. </O>.. </C>.. <C T="U8" I="1" O="false" N="State">.. <O T="COALESCE">.. <L>.. <S T="2" F="Event"
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1012
                                                                    Entropy (8bit):4.7979606654893825
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d0cbdJpIqGvlYrptc7XwzPbqVctTP1u7:c0On3mYtyAvj+
                                                                    MD5:EF1D0AD755895588ADD7990A34BF5E96
                                                                    SHA1:F084B03C5AEE3FD758DC41F60C5009E65307B9CA
                                                                    SHA-256:68A4BA764A5160151D1742ECD989F845C99D913B1C6482B1706FA72C7C8F9C19
                                                                    SHA-512:8A0AF04E08A873A2C5E046B19E858E4D1E46B5639BB6AF7E3E9BE3BABCE2264CB509B4684382D66C475166C4F1F3F2D21579CAC8F18D4DF8E9B23A4419744A7C
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120110" V="4" DC="ESM" EN="Office.System.SystemHealthEssentialMetadataAllIdentities" ATT="cd836626611c4caaa8fc5b2e728ee81d-3b6d6c45-6377-4bf5-9792-dbf8e1881088-7521" SP="CriticalCensus" T="Upload-Medium" DL="A" DCa="PSU" xmlns="">.. <RIS>.. <RI N="Metadata" />.. </RIS>.. <S>.. <UTS T="1" Id="4v5ai" />.. <R T="2" R="120100" />.. <R T="3" R="120110" />.. </S>.. <G>.. <S T="1">.. <F N="IdentityUniqueId" />.. </S>.. <S T="3">.. <F N="1" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="IdentityType">.. <O T="COALESCE">.. <L>.. <S T="1" F="IdentityType" />.. </L>.. <R>.. <S T="3" F="0" />.. </R>.. </O>.. </C>.. <C T="G" I="1" O="true" N="IdentityUniqueId2">.. <O T="COALESCE">.. <L>.. <S T="1" F="IdentityUniqueId" M="Ignore" />.. </L>.. <R>.. <S T="3" F="1" />.. </R>.. </O>.. </C>.. <T>.. <S T="1" />.. <S T="2" />..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):707
                                                                    Entropy (8bit):4.925273258562081
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdNTogoPln55QPwYHyj39Kmlwy+QMfiuficglVb5E7PNWXf/0//TfhmMNO/HNK:2dNkbd5yIqGvlMQ0HgPtEPQ7Y
                                                                    MD5:9304104F8C87FCEC2DB52A8C8042FC9E
                                                                    SHA1:EC55DC4144677CB28A90ADE379D0C1AC73F9ECF1
                                                                    SHA-256:64082DD943016E01DCDAEE511DA17ADC5B9F8AD29C3FD7A929365D366887FD4D
                                                                    SHA-512:E15DACA1D32B05D45A98AD89EA3697DD1CF7A32959F9001DABAD25257169583D4AD44277B01FDB9081A58CA2F4B44DBA41F76870D2C4AB2D59DED5C5F15C54D2
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120112" V="1" DC="ESM" EN="Office.System.SystemHealthSessionStartTime" ATT="cd836626611c4caaa8fc5b2e728ee81d-3b6d6c45-6377-4bf5-9792-dbf8e1881088-7521" SP="CriticalCensus" T="Upload-Medium" DL="A" DCa="PSU" xmlns="">.. <RIS>.. <RI N="Metadata" />.. </RIS>.. <S>.. <A T="1" E="TelemetryStartup" />.. <R T="2" R="120100" />.. <R T="3" R="120112" />.. </S>.. <C T="FT" I="0" O="false" N="SessionStart">.. <O T="COALESCE">.. <L>.. <S T="1" F="TimeStamp100ns" />.. </L>.. <R>.. <S T="3" F="0" />.. </R>.. </O>.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. <S T="3" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1330
                                                                    Entropy (8bit):4.555072319833569
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dfdXaIqmlXeWrZr2Q6P4Pv9kCkP4P/wd5ijh:cfQyOWthh
                                                                    MD5:502142DA94231A63C8DDA56CABB73744
                                                                    SHA1:523E38AA9296209FC88DCE6E36210B58CE5B4557
                                                                    SHA-256:0AB960FF92024AD83697E463441B9C44AC129D5EFE988A5099C1D7A56D86BAB2
                                                                    SHA-512:1A695C552B00DB8C697E754FCA14A9543F47000A5695417A72874B55FDAA48C304A565F4F651244B914AA46741643118F61777E43FF2DCA64D801961020AA1E3
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120119" V="0" DC="SM" EN="Office.System.SystemHealthRollbackSessionMetadata" ATT="cd836626611c4caaa8fc5b2e728ee81d-3b6d6c45-6377-4bf5-9792-dbf8e1881088-7521" SP="CriticalCensus" DL="A" DCa="PSU" xmlns="">.. <RIS>.. <RI N="Metadata" />.. </RIS>.. <S>.. <R T="1" R="120100" />.. <UTS T="2" Id="awjb7" />.. <UTS T="3" Id="a14x3" />.. <R T="4" R="120119" />.. </S>.. <C T="W" I="0" O="true" N="PreviousBuild">.. <O T="COALESCE">.. <L>.. <O T="COALESCE">.. <L>.. <S T="3" F="PreviousBuild" M="Ignore" />.. </L>.. <R>.. <S T="2" F="PreviousBuild" M="Ignore" />.. </R>.. </O>.. </L>.. <R>.. <S T="4" F="0" M="Ignore" />.. </R>.. </O>.. </C>.. <C T="U32" I="1" O="true" N="InstallMethod">.. <O T="COALESCE">.. <L>.. <O T="COALESCE">.. <L>.. <S T="3" F="InstallMethod" M="Ignore" />.. </L>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):861
                                                                    Entropy (8bit):4.821523960139548
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd0kogoPliPPwYHyj3HerHqHfiq/i7uiX7PNWAPJNf/0//4fhmMRiX7PNWQAJL:2dIbdEIqrrHqEuiLPRPrwLPQJ7
                                                                    MD5:8D39954AFC108812A81C00AA5376FAB6
                                                                    SHA1:C439F0F0D35E2B22D0C5146D52F4054ACC9EC197
                                                                    SHA-256:B262EBD864E32F4C8BB835DD2FA444CB526AA48C0A7920D6D0F52FF17F8250F4
                                                                    SHA-512:40CCABA74CA166AE729DA5497831B410B40023BD58E0FF002E4BB09F550BF25061CEB761B0C5E6674C7452201707266045479141D43A588704226E740BD9E579
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120120" V="0" DC="ESM" EN="Office.System.SystemHealthEssentialIdentityCount" ATT="cd836626611c4caaa8fc5b2e728ee81d-3b6d6c45-6377-4bf5-9792-dbf8e1881088-7521" SP="CriticalCensus" DL="A" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bisbj" />.. <R T="2" R="120120" />.. <R T="3" R="120100" />.. </S>.. <C T="U64" I="0" O="false" N="ValidIdentityCount">.. <O T="COALESCE">.. <L>.. <S T="1" F="ValidIdentityCount" />.. </L>.. <R>.. <S T="2" F="0" />.. </R>.. </O>.. </C>.. <C T="U64" I="1" O="false" N="AllIdentityCount">.. <O T="COALESCE">.. <L>.. <S T="1" F="AllIdentityCount" />.. </L>.. <R>.. <S T="2" F="1" />.. </R>.. </O>.. </C>.. <T>.. <S T="1" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):935
                                                                    Entropy (8bit):4.629259990506597
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdvn7PwYHyj3vAQ2Kmlwyi0s+u/qNO5fX/c//wVrMpONdiO+kXqNObfX/c//wT:2d/7IqhvlXjuy0j4TqjG/6
                                                                    MD5:979E3FF46A7D2602886C228E39D2595E
                                                                    SHA1:5D982F346BFF2E5F2107BDD34F299BABD1C26E1A
                                                                    SHA-256:C98FE8CC8AC28470223B863E007BEDA512346337DB24026E07D4141A59872CC6
                                                                    SHA-512:A7BD4589F36478412A256F4405E6E1FBE8820CDB86C807A640506A5E7B08F222CF22F9347F3F8268FFC4476F83E622A6C20E681B14C2A372EE31C45EB7B266A9
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120125" V="0" DC="SM" EN="Office.System.IdentityChanged" ATT="cd836626611c4caaa8fc5b2e728ee81d-3b6d6c45-6377-4bf5-9792-dbf8e1881088-7521" SP="CriticalBusinessImpact" T="Upload-Medium" DL="A" DCa="PSU" xmlns="">.. <RIS>.. <RI N="Metadata" />.. </RIS>.. <S>.. <R T="1" R="120126" />.. <F T="2">.. <O T="EQ">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <R T="3" R="120127" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="3" F="0" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. </S>.. <C T="B" I="0" O="false" N="IdentityChanged">.. <V V="true" T="B" />.. </C>.. <C T="B" I="1" O="true" N="TimerDetectedChange">.. <S T="4" F="0" />.. </C>.. <T>.. <S T="2" />.. <S T="4" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1660
                                                                    Entropy (8bit):3.4777365974062833
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdjYberNmO+u/jOzeKNug3/8//AcJuNH/M//KNuxvsK3/8//AcJuN5eNX/c//p:2djhrCuA1xDl+2KApxD+zK8
                                                                    MD5:01FF27391C5C91A0302D567138A2FF6F
                                                                    SHA1:F4BC4EF3E41DF635589E8E67A4BE15041C92C11A
                                                                    SHA-256:761B7BE0A558FDF74491FBEE8458DADAFF42943660AEA8F118FFE4C7F5AD0AC1
                                                                    SHA-512:E92B3B25EB103CC8CED1A4EFC5FC2F24CCD9D55065157A43D0F550BFD08FCAAAA3098C5CD7BA8C675E3F00FB161CD5946EF62CAAE573CE9493D5DC64EB7CC4DB
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120126" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <UTS T="1" Id="b14a4" A="awuw3" />.. <F T="2">.. <O T="OR">.. <L>.. <O T="OR">.. <L>.. <O T="EQ">.. <L>.. <V V="EventProfileAdd" T="W" />.. </L>.. <R>.. <S T="1" F="IdentityEvent" />.. </R>.. </O>.. </L>.. <R>.. <O T="EQ">.. <L>.. <V V="EventProfileRemove" T="W" />.. </L>.. <R>.. <S T="1" F="IdentityEvent" />.. </R>.. </O>.. </R>.. </O>.. </L>.. <R>.. <O T="OR">.. <L>.. <O T="EQ">.. <L>.. <V V="EventProfileSwitch" T="W" />.. </L>.. <R>.. <S T="1" F="
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1172
                                                                    Entropy (8bit):3.719006786338845
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdjAbermer/erG+kXjOaNese4H/M//J5eNX/c//aNese4H/M//fw5eNpONd+wf:2djpr5r2r1axewZTxewwtwOaAPfHMs6B
                                                                    MD5:A71CA3F2C426C3F3F8DD5CE7BDC8FC49
                                                                    SHA1:4D478FE45EDF72F679225C68D40963E31348A62F
                                                                    SHA-256:83C74EB9B3BB7FD30EA3114ABFFAFDFF9F1E9CFB33223EF7B86AB8A3F2C36FBA
                                                                    SHA-512:E26A68B9F08EEB3389CF258CE9D9AB2703256F95056F06312F5D87558F518B31F2AB1BA9BF51DDFB00A9E0C8F6C86D7B7352DF01D1A164CAC8D4F8F1A29E0240
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120126" V="8" DC="SM" T="Subrule" xmlns="">.. <S>.. <UTS T="1" Id="a3wen" />.. <UTS T="2" Id="bhq2o" />.. <UTS T="3" Id="cc3ox" />.. <F T="4">.. <O T="OR">.. <L>.. <O T="EQ">.. <L>.. <S T="1" F="UserDecision" />.. </L>.. <R>.. <V V="1" T="U8" />.. </R>.. </O>.. </L>.. <R>.. <O T="EQ">.. <L>.. <S T="1" F="UserDecision" />.. </L>.. <R>.. <V V="2" T="U8" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <O T="COALESCE">.. <L>.. <S T="3" F="AuthCategory" M="Ignore" />.. </L>.. <R>.. <V V="" T="W" />.. </R>.. </O>.. </L>.. <R>.. <V V="ActiveIdentityChanged" T="W" />..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1177
                                                                    Entropy (8bit):3.9234314786976854
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd/bc3fXFJFfiOzOeF/iweu5xlWLPNmjOP/k//bPN2Lx//U//cBGNx2Nf/0//y:2d+vvVFUbPnsPyXcPiSMPSM
                                                                    MD5:ED13EBF74891256A27A40043EA092AF8
                                                                    SHA1:DBB348E21C4594D671532454F9C13B37CB3829B9
                                                                    SHA-256:B1E34D9BBBCA1E5686F5996E126986F2B8D511CA6AC28835C1DB5E79D16E2E1D
                                                                    SHA-512:B8BECC70F271BD970752EF9DF7E7DBA7568ACE680A285ABB6663C700978542D96A54A5BA2C4057F6EC0C9200E0040D4D43117EB0334D97A6F61D21A01A5E2EAE
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120127" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <TI T="1" I="30s" />.. <A T="2" E="TelemetryResume" />.. <R T="3" R="120127" />.. <SS T="4" G="{1a6b5bd0-2f17-420c-8ba0-ee01132ee441}" />.. <R T="5" R="120100" />.. </S>.. <C T="B" I="0" O="false">.. <O T="NE">.. <L>.. <O T="COALESCE">.. <L>.. <S T="3" F="1" />.. </L>.. <R>.. <O T="COALESCE">.. <L>.. <S T="4" F="UserCid" M="Ignore" />.. </L>.. <R>.. <V V="" T="W" />.. </R>.. </O>.. </R>.. </O>.. </L>.. <R>.. <O T="COALESCE">.. <L>.. <S T="4" F="UserCid" M="Ignore" />.. </L>.. <R>.. <V V="" T="W" />.. </R>.. </O>.. </R>.. </O>.. </C>.. <C T="W" I="1" O="true">.. <O T="COALESCE">.. <L>.. <S T="4" F
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):657
                                                                    Entropy (8bit):5.176719630355306
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd89Xx1PwYHyj3vAQ3mlwyerNbx+/oVrz6+/ntW+/CNO2su:2d01IqVlYrzFoJX
                                                                    MD5:ED758634CBCD2030942B20CEC7235E2E
                                                                    SHA1:03DA3F778A321C513CE21A82C0C2835C17AEFD03
                                                                    SHA-256:671FBCE6FFD82EED19F5DC867435A92FAD7D92290F3632195992B0E39F2CC3DE
                                                                    SHA-512:369503745FFDE8EB0BA57B660E5D7DF8A0D80382A72E6F276332C227995D192C3E20B6C950ACA4A74FDFCA5AAC3FCE272C081E35CBF47DFBEF6C36510BBF4E7A
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120128" V="0" DC="SM" EN="Office.System.UserChangedDiagnosticLevel" ATT="cd836626611c4caaa8fc5b2e728ee81d-3b6d6c45-6377-4bf5-9792-dbf8e1881088-7521" SP="CriticalBusinessImpact" DL="A" DCa="PSU" xmlns="">.. <RIS>.. <RI N="Metadata" />.. </RIS>.. <S>.. <UTS T="1" Id="c4qbn" />.. </S>.. <C T="B" I="0" O="false" N="UserChangedDiagnosticLevel">.. <V V="true" T="B" />.. </C>.. <C T="I32" I="1" O="false" N="OldDiagnosticLevel">.. <S T="1" F="OldLevel" />.. </C>.. <C T="I32" I="2" O="false" N="NewDiagnosticLevel">.. <S T="1" F="NewLevel" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):2849
                                                                    Entropy (8bit):4.395501028116881
                                                                    Encrypted:false
                                                                    SSDEEP:48:cs/cRgeklevS8TiqQCJrqufvCqsaq8Sq/1YPX9zLeXvmXjrqXtpXsF7:MRgekEbB7AONickX9XeXvmXjGXtpXI7
                                                                    MD5:3D5BFEDF8BFF08FC1FD30CFD1FDEAC72
                                                                    SHA1:4BAE9BA25B0C1B71B01DA4C55D3CCE747260C7A0
                                                                    SHA-256:B703EE5EC52A956EE64A68B0FB744245E6782ECA8D7091A2A35EB1D7974D47BC
                                                                    SHA-512:D84CBC7625E204CB976F2D8321512F0AE07287645B0BB7B9BA962680A3AC05EF2BE8959A541F4BB4DCD797A01C7C99BB56871B77090F3650ED45192E50DC9720
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12014" V="0" DC="SM" EN="Office.Outlook.Desktop.FreeBusy.AddressLookupSuccessAndSourceMetrics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="27129" G="{d8d0510d-3f14-4da9-a096-b9c7ad386da0}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="FoundSmtpAddress" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="FoundSmtpAddress" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="LoadedProps" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):3083
                                                                    Entropy (8bit):4.403352684363651
                                                                    Encrypted:false
                                                                    SSDEEP:48:cYeaRgelg+lheuLPqvLrsVkPq8VkFtj/YRSTPmdJnsdR:7RgeG3PGPgRSjR
                                                                    MD5:145B9F6DDA1A8391E1BE436203A04976
                                                                    SHA1:DDE04509A01ACD2690A14B8DD7DC3A13987085EA
                                                                    SHA-256:E789B7C98BC4D61281659D384C9A01009D48DCB759DB19B3470457A3C30B24D2
                                                                    SHA-512:BD4D0FF91FA40E2B39E2131D16D656173AD356994FF1362C18B8F7495EFA3F3F9DD3909D2A47CDA74CA48ED47FE14BBB3BFF47D5823DCB45EC8FE5EC71F9FBE2
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12015" V="1" DC="SM" EN="Office.Outlook.Desktop.TranslationDataErrorOutput" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Hourly" />.. <UTS T="3" Id="94ely" />.. <UTS T="4" Id="94el9" />.. <UTS T="5" Id="94elr" />.. <UTS T="6" Id="94elv" />.. <F T="7">.. <O T="EQ">.. <L>.. <S T="3" F="TranslationDataPropEmpty" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="8">.. <O T="EQ">.. <L>.. <S T="3" F="TranslationDataPropEmpty" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. <F T="9">.. <O T="EQ">.. <L>.. <S T="6" F="TranslationDataPropEmpty" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1297
                                                                    Entropy (8bit):4.59458386608663
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dwMYfoyux6dRgenvS8TfDlwOaf+vM86PtWWRMa:cwM6oNx2RgenvS8T7lQGU7l1
                                                                    MD5:8974B169D2882FF799B09DF1B6A1B336
                                                                    SHA1:9F88221565B3A83CC042B8857707FF1F2261E23C
                                                                    SHA-256:D64931BA1749F3964201C9A6989E36722791D706FF54144EF11DA094EFD2DD86
                                                                    SHA-512:1CA6F252ADE67FCC666C5B375B4F7956F59561B733C7C173D0CD5FF258926202F985DBA7267593024EE90861BA4F054E38373905FBC1BBBE46878035C76A1656
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12018" V="1" DC="SM" EN="Office.Outlook.Desktop.RopWriteStream.FailureStats" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="363" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="ROP" />.. </L>.. <R>.. <V V="45" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="ROP" />.. </L>.. <R>.. <V V="163" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="4">.. <F N="Result" />.. </S>.. <S T="5">.. <F N="Result" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="Failure_Result">.. <O T="COALESCE">.. <L>.. <S T="4" F="Result" />.. </L>.. <R>.. <S T="5" F="Result
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):3816
                                                                    Entropy (8bit):3.60180606792738
                                                                    Encrypted:false
                                                                    SSDEEP:48:csPRgeauyLxQtV7h6HOHQLhBLibB6HOHGQdqJpwXEw5N7:HRgeausxQ7hMLh2Byx4XPj7
                                                                    MD5:B557233CC8A2123D0D7819B3EB935A10
                                                                    SHA1:B44B6DBA5591617D012A00178F4DCA4811A1E6A3
                                                                    SHA-256:B15B0D6B64FB488FCE0A853F9789D2390543ACCDDD822076B2A37DB62B98F6CB
                                                                    SHA-512:B03F13FAD4E04CF90483D833C1B446056E74984F6C9B9B9C25382FD737655464CD70C60A81E9AD598FAD4C44D7796413B13A6782D10088BF133AC5174ACCEFF1
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12019" V="1" DC="SM" EN="Office.Outlook.Desktop.Pst.FileTypeUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" SP="CriticalUsage" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="802" G="{2adf8e23-0af9-43c9-ba4c-952ee130540d}" />.. <F T="2">.. <O T="EQ">.. <L>.. <O T="BITWISEAND">.. <L>.. <S T="1" F="Provider" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="3">.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <O T="BITWISEAND">.. <L>.. <S T="1" F="Provider" />.. </L>.. <R>.. <V V="256" T="U32" />.. </R>.. </O>.. </L>.. <R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):2640
                                                                    Entropy (8bit):4.9348078745429325
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d8d4A0Iqs2QYrAlKh4WApCt4BzAoJE9PfrZ1zY05GwsMOnvFEizIUhNySELwHOY:c84L8kgwt4BPJ4bzlfOtrICsCHtH894f
                                                                    MD5:F999CB328321A7D4F1AB28F60CFA1595
                                                                    SHA1:A4DCAB4B0B8A7A07A722574792E11D03772ED2F0
                                                                    SHA-256:37CC50DCC7D7707DD913FFAF7AF093F0C06EC1E091E10C205724D4EF416141A5
                                                                    SHA-512:DA89B1710740ACFD1DEAD546C7863C682004772F4CAF620C854C19D6DC0BD59C8403A2DB00882FAA9737053A510187D9B6082EBAC5869E2FB1063F1A4039A6E5
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120201" V="14" DC="SM" EN="Office.System.SystemHealthUsage.ClickStream" ATT="cd836626611c4caaa8fc5b2e728ee81d-3b6d6c45-6377-4bf5-9792-dbf8e1881088-7521" SP="CriticalUsage" DCa="PSU" xmlns="">.. <RIS>.. <RI N="Usage" />.. <RI N="CommandUsage" />.. </RIS>.. <S>.. <UTS T="1" Id="bb9uz" A="bb9ve bb9vg bcijr bcijp bgmnl bgmnr bgmnt bgmnx bgmnz bgmn1 bgmn3 bgmn5 bgn2k bgn2m bgn2o bgn2q bgn2s bgn2u bgn2w bgn2y bgn21 bujz1 bunl0 ide6g b0mo1" />.. <UCSS T="2" C="Command Usage" S="Medium" />.. <F T="3">.. <O T="EQ">.. <L>.. <S T="1" F="ULS_Category" />.. </L>.. <R>.. <V V="Scope Summary" T="W" />.. </R>.. </O>.. </F>.. </S>.. <G I="true">.. <S T="3">.. <F N="ScopeInstance" />.. </S>.. <S T="2">.. <F N="UserActionID" />.. </S>.. </G>.. <C T="FT" I="0" O="false" N="StartTime">.. <S T="3" F="TimeStamp100ns" />.. </C>.. <C T="I32" I="1" O="falseNo
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):3029
                                                                    Entropy (8bit):4.783329374973241
                                                                    Encrypted:false
                                                                    SSDEEP:48:c7fsfEt4BX79qPJ4sUbVn1VO50TOtrICsL:IKE+X5kKVpYrIDL
                                                                    MD5:D368219CDF254E91CB793F73251F4B0B
                                                                    SHA1:F9AA8AB421EF6C3BEAD105EA6047194D83C70F15
                                                                    SHA-256:451FA7E073B8BC6AB481CE14F2FA487701033BA564E9669476094D7CCAA0BF95
                                                                    SHA-512:18D86D448B75CEC121BCBC91EAB5FC54000816F08503A66CDAF54DB7A50C0E26C5032AC6452580FE258CF51371A882DCD3C0DD0FA9522CE280542F21A527E9B1
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120205" V="11" DC="SM" EN="Office.System.SystemHealthUsage.NonTCIDClickStream" ATT="cd836626611c4caaa8fc5b2e728ee81d-3b6d6c45-6377-4bf5-9792-dbf8e1881088-7521" SP="CriticalUsage" DCa="PSU" xmlns="">.. <RIS>.. <RI N="CommandUsage" />.. </RIS>.. <S>.. <UTS T="1" Id="bb9uz" A="bmmfb bb9ve bb9vg bcijr bcijp bgmnl bgmnr bgmnt bgmnx bgmnz bgmn1 bgmn3 bgmn5 bgn2k bgn2m bgn2o bgn2q bgn2s bgn2u bgn2w bgn2y bgn21 bix8b bix8d bix8f bix8h bix8j bix8l bojix bk8ux bcss8 c5n49" />.. <UCSS T="2" C="Command Usage" S="Medium" />.. <F T="3">.. <O T="EQ">.. <L>.. <S T="1" F="ULS_Category" />.. </L>.. <R>.. <V V="Scope Summary" T="W" />.. </R>.. </O>.. </F>.. <F T="4">.. <O T="NE">.. <L>.. <V V="" T="W" />.. </L>.. <R>.. <O T="COALESCE">.. <L>.. <S T="2" F="TelemetryId" M="Ignore" />.. </L>.. <R>
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1103
                                                                    Entropy (8bit):5.081116538822298
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdxVzj2DWl6dRDDHwpat5DyTIqB2MpqwDoW8/CHbOMN7PNWuOf/0//ughmMz7O:2dx8dRgewIi3AtKHHPw5Z7
                                                                    MD5:67F53BA2499E56DA352E2C2EFD8437CA
                                                                    SHA1:7DC5E335AC07D8C2D1D5398ACD835A8AFF90B312
                                                                    SHA-256:54E201B18A1CCBDCEC63388EED110DCA398992E33213F1DD8A280C8015063958
                                                                    SHA-512:467543DDFF11BB43A8C1E548C825A4BE46BA80E66E640B2D163720F896354EB70BC3DC7A9F7AE4E462E997F1CC1FB7FDCD65E425B1D819A0338F56A17E25FFFA
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12020" V="0" DC="SM" EN="Office.Outlook.Desktop.MeetingInsights.MIUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="908" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <Etw T="2" E="356" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. </S>.. <G>.. <S T="1">.. <F N="DiagnosticId" />.. </S>.. <S T="2">.. <F N="WebHostingSessionId" />.. </S>.. </G>.. <C T="G" I="0" O="true" N="DiagnosticId">.. <O T="COALESCE">.. <L>.. <S T="2" F="WebHostingSessionId" />.. </L>.. <R>.. <S T="1" F="DiagnosticId" />.. </R>.. </O>.. </C>.. <C T="I32" I="1" O="false" N="CompleteLoadToUpdateResultTime">.. <S T="2" F="CompleteLoadToUpdateResultTime" />.. </C>.. <C T="I32" I="2" O="false" N="InsightsCount">.. <S T="1" F="InsightsCount" />.. </C>.. <C T="B" I="3" O="false" N="RetryMode">.. <S T
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):819
                                                                    Entropy (8bit):5.14360472471183
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdlA4Vzj656dRDDHwpatEFxnXFJicouDUrSaq/SfAseHaSMULft9ntf+iS+/9n:2dlA4W6dRgeyXvS3sLFPvP
                                                                    MD5:6640500C2D446B3AD9F910BA0D1CB52B
                                                                    SHA1:0C104506BA45EE5E5A0C6ED26C58F4D28025B5EB
                                                                    SHA-256:E054602ACC0F456434EDA7F786F76954BB8E196376EDABDBEC42722358BFD107
                                                                    SHA-512:7665C4416715F71EE59858C8BA5FBC594EB29E1E1AE2D29B6BE7B0910FEBD7E7DDDBD83D0E177E7319DFE7107940831986C996680B277A355DAD8F1166AF9146
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12026" V="0" DC="SM" EN="Office.Outlook.Desktop.HomeRealmDiscoveryLookupResults" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="639" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="HrdResult" />.. <F N="FromCache" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="CountIdentityChecks">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="DeterminedIdentityType">.. <S T="1" F="HrdResult" />.. </C>.. <C T="B" I="2" O="false" N="IdentityFromCache">.. <S T="1" F="FromCache" />.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1037
                                                                    Entropy (8bit):4.719768372527338
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd81Vzj8hRdRDDHwpatEj0A+KbSXFJicoN+kXqNOIKPX/c//wVrMpONd+wsvXd:2dqahRdRgeNvS8TpKfjqwOapKfi/U17
                                                                    MD5:5A1A55F9AB590A554C379440E390C440
                                                                    SHA1:B7F766CBF58B4B75EA4C37E06A929427A22A2564
                                                                    SHA-256:CF5123EFC558D9CB658BD2E85C68616F4B6C9765EE0BF79F9F2B59C13DDCEBD1
                                                                    SHA-512:5140927D079E9782951641420267DB422FF268283D02F7C522BA65EBFEBF5676EAFEAE6843C9F266D77B9B9C2BDD72A8758DC1FE62E74BC85FC1B7A587CE0736
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12027" V="0" DC="SM" EN="Office.Outlook.Desktop.NegotiateClientAckHeader" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="743" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="ValidAckHeader" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="ValidAckHeader" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="CountValidAckHeaders">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="CountNotValidAckHeader">.. <C>.. <S T="5" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1003
                                                                    Entropy (8bit):5.035943950062749
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdyYVzjyMhdRDDHwpatERHXFJicouDgO0M7/7hNfbfXTxcZ/Zt6uIPSRKIhMNR:2dyYkMhdRgeOvSpurP1HGru
                                                                    MD5:ACBE3C99DEF2187CF360D010FF6DE411
                                                                    SHA1:8B7C96CB493208F331337E3C66E698DA4193B3EC
                                                                    SHA-256:8CBB76E5C9410A2D25628D8FF58BF63CEBB4A537D6AF29A8CCBDB53E5B9A808D
                                                                    SHA-512:4E8C8234A2A6F39379DED45995C371EFF7BB424F8F47989432DEAA536DA222B8BECBF9B57A9FBF43803BE950AE155928336FC67FEC54DE994AA41ED06B292748
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12028" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.DragDropToGroupGeneric" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="19036" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="OpType" />.. <F N="HRESULT" />.. <F N="IsOwner" />.. <F N="CountOfMsg" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="OpType">.. <S T="1" F="OpType" />.. </C>.. <C T="U32" I="1" O="false" N="HRESULT">.. <S T="1" F="HRESULT" />.. </C>.. <C T="I32" I="2" O="false" N="IsOwner">.. <S T="1" F="IsOwner" />.. </C>.. <C T="U32" I="3" O="false" N="CountOfMsg">.. <S T="1" F="CountOfMsg" />.. </C>.. <C T="U32" I="4" O="false" N="DragDropEventCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1305
                                                                    Entropy (8bit):4.616495117342903
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdbYVzjzff6dRDDHwpatEoIqB2c1NQi+kXqNO2X/c//wVrMpONd+wsvXqNO2X/:2dkMdRgeLIirqJTnjqwOaniraPr/e71a
                                                                    MD5:3D5CC7261BEB03DF98E09805E92AB8BC
                                                                    SHA1:51DE75F2E4ED56F633B8E0AFC2DC952A8ED76C0F
                                                                    SHA-256:3FB69863D20FE36A95700B8B1A91DE48029C4B677B9B0E5712CDD41A103CF832
                                                                    SHA-512:3F86FB08D12CA9A584710EB974E875259E1F198D88F881315EED7B96C366E237544883433AD55B7C983EC014307DF476393481706CDD438B5553D577E797020A
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12029" V="0" DC="SM" EN="Office.Outlook.Desktop.MeetingAttendeeGrid.ExpandCollapseUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="1028" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="Collapsed" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="Collapsed" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="4">.. <F N="GroupId" />.. </S>.. <S T="5">.. <F N="GroupId" />.. </S>.. </G>.. <C T="U64" I="0" O="false" N="GroupID">.. <O T="COALESCE">.. <L>.. <S T="4" F="GroupId" />.. </L>.. <R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):961
                                                                    Entropy (8bit):4.4482435960164395
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdmObxpSEXKudrU0x/x7PNWUZtZf/0//ExhmMspS7PNWUMTf/0//ahmMp1xpS8:2dmwXKWQwPp/VNZPpMD11uP+x
                                                                    MD5:3787458C2166D70089625D4295174043
                                                                    SHA1:28BB8699390C79FCB6E9CC0E6CCACF33986AB27B
                                                                    SHA-256:712F1F4EECEBA02722D95218CC8CD1388D39EB59312D47560F849E8B817389AA
                                                                    SHA-512:FBDB5FE328998F24270192E27A6FD7E379CF4EBB9ECB8A0EE94CD17F6B095A3F5E0F2F69AD2EE4EA198AB0573337A33A9B6A3ECD2B56DEF4FFB855763C7BCB09
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120300" V="3" DC="SM" T="Subrule" xmlns="">.. <S>.. <UACS T="1" S="Unexpected" />.. </S>.. <C T="U16" I="0" O="true">.. <S T="1" F="ETW_EventId" M="Ignore" />.. </C>.. <C T="W" I="1" O="false">.. <S T="1" F="ULS_Category" />.. </C>.. <C T="TAG" I="2" O="false">.. <O T="COALESCE">.. <L>.. <S T="1" F="ETW_TrackbackTag" M="Ignore" />.. </L>.. <R>.. <S T="1" F="ULS_Tag" />.. </R>.. </O>.. </C>.. <C T="I32" I="3" O="true">.. <O T="COALESCE">.. <L>.. <S T="1" F="ErrIdOptional" M="Ignore" />.. </L>.. <R>.. <S T="1" F="SH_ErrorId" M="Ignore" />.. </R>.. </O>.. </C>.. <C T="I32" I="4" O="true">.. <O T="COALESCE">.. <L>.. <S T="1" F="HROptional" M="Ignore" />.. </L>.. <R>.. <S T="1" F="SH_ErrorCode" M="Ignore" />.. </R>.. </O>.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1453
                                                                    Entropy (8bit):4.684191125363692
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdRYoPlR6VPwYHyj3vAQMm2Ni0G+u/5lOrX/c//l4pONdc8BjEaCw8/Lg5/e1N:2dRzdyIqG2X1uQYbF4M6PapU3ZbBT9
                                                                    MD5:3919CC7F5FE2DFF74BDD02FBD0483AEC
                                                                    SHA1:19F386B069290EA2DDF22993722DBE4C99C7F29E
                                                                    SHA-256:8392211A244794F86556E3D17415175079B96D7D33D72A6E905D3FB73B91C3BD
                                                                    SHA-512:DC71343A2FC50FEB3722F24C495DF03AEB77F8849CA05455E6FBA2F584610FA2D3B68416A972416D6987C33B6A279268FF70C424317BAD1E03CF062DD4EFC4A5
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120305" V="3" DC="SM" EN="Office.System.SystemHealthErrorsWithTag" ATT="cd836626611c4caaa8fc5b2e728ee81d-3b6d6c45-6377-4bf5-9792-dbf8e1881088-7521" SP="CriticalBusinessImpact" DL="B" DCa="PSU" xmlns="">.. <RIS>.. <RI N="Error" />.. </RIS>.. <S>.. <R T="1" R="120300" />.. <F T="2">.. <O T="NE">.. <L>.. <S T="1" F="2" />.. </L>.. <R>.. <V V="6034006" T="U32" />.. </R>.. </O>.. </F>.. <TI T="3" I="10min" />.. <A T="4" E="TelemetrySuspend" />.. <A T="5" E="TelemetryShutdown" />.. </S>.. <G I="true" R="TriggerOldest">.. <S T="2">.. <F N="1" />.. <F N="2" />.. <F N="3" />.. <F N="4" />.. </S>.. </G>.. <C T="FT" I="0" O="false" N="EndTime">.. <A T="MAX">.. <S T="2" F="TimeStamp100ns" />.. </A>.. </C>.. <C T="W" I="1" O="false" N="ErrorGroup">.. <S T="2" F="1" />.. </C>.. <C T="TAG" I="2" O="false" N="Trackback">.. <S
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1249
                                                                    Entropy (8bit):4.749564309320366
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdqoPlr0PwYHyjLm2NVcefQjEBi+wsvX5lO8xX/c//PpON+PvXcOp1lVYFjuDs:2dtdr0IqR2nYOJwOfVqrPaQUsv2Bv
                                                                    MD5:5A306F55B8BE6297FA735159DF791E43
                                                                    SHA1:AF012DDBC1DBCAB6888769225A720289972038BD
                                                                    SHA-256:89E8A3E12159A3000300FDD5EFBFD646FF4AC951F39D6BE243061E40D9CB1105
                                                                    SHA-512:3189327E37645477AA59D358E24730EFEABBA38DEA4A4770217B426EA826127DD25426B4EB1F0B72DC3187D24F1F596462596826469BCF2094CF2317422F257D
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120307" V="1" DC="SM" EN="Office.System.SystemHealthAsserts" ATT="cd836626611c4caaa8fc5b2e728ee81d-3b6d6c45-6377-4bf5-9792-dbf8e1881088-7521" DL="B" DCa="PSU" xmlns="">.. <RIS>.. <RI N="Error" />.. </RIS>.. <S>.. <UACS T="1" S="Assert" />.. <TI T="2" I="30s" />.. <A T="3" E="TelemetrySuspend" />.. <A T="4" E="TelemetryShutdown" />.. <F T="5">.. <O T="NE">.. <L>.. <S T="1" F="ULS_Tag" />.. </L>.. <R>.. <V V="508441857" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="5">.. <F N="ULS_Category" />.. <F N="ULS_Tag" />.. </S>.. </G>.. <C T="FT" I="0" O="false" N="EndTime">.. <A T="MAX">.. <S T="5" F="TimeStamp100ns" />.. </A>.. </C>.. <C T="W" I="1" O="false" N="ErrorGroup">.. <S T="5" F="ULS_Category" />.. </C>.. <C T="TAG" I="2" O="false" N="Trackback">.. <S T="5" F="ULS_Tag" />.. </C>.. <C T="U32" I="3" O="false" N="
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):790
                                                                    Entropy (8bit):5.066114171630968
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd+VzjzmsdRDDHwpatENIqB2c1NQzDa/tFNMS+ZXpdGXHaSMNO5csu:2d+7dRgeuIirqyQGu
                                                                    MD5:82EDF3245A18BE14633A08FF2669CE66
                                                                    SHA1:7A30FCC4B62792AD1B6B199A8D4E1D6CC2E8E7AA
                                                                    SHA-256:AFB6DF9AD06596A2A657BAB39DEF302E2D87498B2D85EBE50B618BAC0863CD91
                                                                    SHA-512:EF7C5ECC21C9C8D1911CC28F4062468339AA15977E66FF7A6E32E9F0C2254A01D23FCC91564F3649E16A64696B3B83A80AF9CA0F69FD33F9E5EBA42D704FC569
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12030" V="0" DC="SM" EN="Office.Outlook.Desktop.MeetingAttendeeGrid.UpdateAttendeeType" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="1029" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="From" />.. <F N="To" />.. </S>.. </G>.. <C T="U64" I="0" O="false" N="FromGroupID">.. <S T="1" F="From" />.. </C>.. <C T="U64" I="1" O="false" N="ToGroupId">.. <S T="1" F="To" />.. </C>.. <C T="U32" I="2" O="false" N="UpdateAttendeeTypeCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):652
                                                                    Entropy (8bit):5.062451879967685
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdHjVzjmN0H+6dRDDHwpatEerQdfXFJicdDP4fcQiSAGqJQzXHaSMNO5csu:2dHjQN0BdRgeLrMvvLduxu
                                                                    MD5:1D5536237275326B5AC0E005CE32C5AE
                                                                    SHA1:3AA4BBA942C81B315EB0A580B8046514266C4759
                                                                    SHA-256:024531FCE9538B88C7E4000E07E9E873A5CEC5389691F2932DCFF11001DBE4C3
                                                                    SHA-512:F3210FF95CC91106AD5A6091400EA2E0CB7CA02BFCA74234A40CF6C82623A36C6728D59B55B4EE11D423932F42657A2E8928AD3061ABBBC4940E2448374A45FA
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12031" V="0" DC="SM" EN="Office.Outlook.Desktop.TranslationRibbonUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9t591" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Hourly" />.. </S>.. <G>.. <S T="1">.. <F N="Action" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="RibbonInvokeActionCode">.. <S T="1" F="Action" />.. </C>.. <C T="U32" I="1" O="false" N="RibbonInvokeActionCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):692
                                                                    Entropy (8bit):5.146636101488893
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdVVzj0uDu6dRDDHwpatEerxXFJicdD0MA1+aDYSZK1+aD2OOXHaSMNO5csu:2dVqkRdRgeLr9vy1eb18OOu
                                                                    MD5:C2531E60CD2D5A0FE6E61334C8F8E1CC
                                                                    SHA1:818368D9D0D43A78BB4A278173A1CCFD8536BF8B
                                                                    SHA-256:D483B579DEBB420807041F14848F45546BFBE7D6FF5DBBDEF3DE9B43D0AED4EA
                                                                    SHA-512:B4804439697777CD4B244F7D8EBD1AF3652B1875752132680A8F895623089F9D4F2ADF88516AA5AC569EAAFC519B0BA5B8F959DC5521980AD70DCAF1FFDA16F7
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12032" V="1" DC="SM" EN="Office.Outlook.Desktop.OlkTranslatorCloudSettingsMgrHResultErrors" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9squ3" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Hourly" />.. </S>.. <G>.. <S T="1">.. <F N="HRESULT" />.. </S>.. </G>.. <C T="I64" I="0" O="false" N="GetCurrentAccountErrorHResult">.. <S T="1" F="HRESULT" />.. </C>.. <C T="U32" I="1" O="false" N="GetCurrentAccountErrorHResultCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):2467
                                                                    Entropy (8bit):4.218494123729328
                                                                    Encrypted:false
                                                                    SSDEEP:48:cvERgeLTvS8TYovpiqxOYs60s59lf0sA7:5Rgenb0gpik/s60sVf0sA7
                                                                    MD5:23E79EA4B5CFF67F704A6D0D21B7BEDF
                                                                    SHA1:C1B2D11601C0D966E9D28EDCD5F051D120CF4F80
                                                                    SHA-256:5E21DDC819BEBE7D9574474C0A7126FA0C4635CD8016074D7FA49C33822D0191
                                                                    SHA-512:739B3BB95F8922D68ACDE537E66BCEC47A699AB1E07099FC88E6F6FB09EA99CC1E3261212962EC99411B4E0FCE61602F4A140CD13E38F2A5CAB5A047CC497E07
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12035" V="0" DC="SM" EN="Office.Outlook.Desktop.Pcx.IsExchangeAddressBook" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9trqk" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="HasAddrBook" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="AND">.. <L>.. <S T="1" F="HasAddrBook" />.. </L>.. <R>.. <O T="EQ">.. <L>.. <S T="1" F="LoadedSearchPath" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="6">.. <O T="AND">.. <L>.. <S T="1" F="LoadedSearchPath" />.. </L>.. <R>.. <O T="EQ">..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):775
                                                                    Entropy (8bit):5.124181478867032
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd4VzjOEVH9dRDDHwpatEFuHZYHQicih22ZLuXHaSM21XHhSMNO3AHNS7lu:2d4jVH9dRgeTJau/19r
                                                                    MD5:6260C679EA48A67F6C8099EC8845CEF7
                                                                    SHA1:EB98BC722730EC7D53ADAF59602A800051A51CF4
                                                                    SHA-256:8FF1C62B23B62C8C06008EC19F28EEC86B18CAEB899B4D09D8180399F12D8145
                                                                    SHA-512:94A51D5237F9847758A99E7E71946AF9FD2DF8AC94BA479AB63AAD2ACAA3A26C37D02393DBE1891FC0B9F5164A640C8D7C66DFE173F0FFBFAD8B584ED722D2C8
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12036" V="0" DC="SM" EN="Office.Outlook.Desktop.EnhancedLocations.PrefetchandRecurrence" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="6127" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="6128" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="3" E="TelemetryShutdown" />.. <TI T="4" I="Daily" />.. </S>.. <C T="U32" I="0" O="false" N="PrefetchResultShownCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="RecurrenceDataCount">.. <C>.. <S T="2" />.. </C>.. </C>.. <T>.. <S T="4" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. <S T="2" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):3787
                                                                    Entropy (8bit):4.955693169986947
                                                                    Encrypted:false
                                                                    SSDEEP:48:cMoMLaYeYg05WdhSsw0zeQgNg8NgRkUlrtvzxEd0NiRgiR3Si:nzQg5EhS+ZvzRUX3F
                                                                    MD5:5B2225D394303EEAD121834886DEF8CE
                                                                    SHA1:6F1A7E6379A0B17DF6269B744564C85B853C27E3
                                                                    SHA-256:05A0A5628BEA491A045AE43C66D2D1F377145214E11F596B95F60AD7B889B3CF
                                                                    SHA-512:36E56D0E1408AF2764DE788221ADA49971B08F76D00DDD793AB2CD36F13FFA0077EBC1F7C1A23F26DF277DD684475729541DB00F7F3455C50DF16A90B16B391C
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="120402" V="21" DC="SM" EN="Office.System.SystemHealthUngracefulAppExitDesktop" ATT="cd836626611c4caaa8fc5b2e728ee81d-3b6d6c45-6377-4bf5-9792-dbf8e1881088-7521" SP="CriticalCensus" DL="A" DCa="PSP" xmlns="">.. <RIS>.. <RI N="Crash" />.. <RI N="Metadata" />.. </RIS>.. <S>.. <UTS T="1" Id="824rc" />.. <SS T="2" G="{68442bc6-3519-4b08-a80c-e0a68fc8cda3}" />.. <TR T="3" />.. </S>.. <C T="FT" I="0" O="false" N="DetectionTime">.. <S T="3" F="TimeStamp100ns" />.. </C>.. <C T="FT" I="1" O="false" N="CrashedProcessSessionInitTime">.. <S T="1" F="CrashedSessionInitTime" />.. </C>.. <C T="G" I="2" O="false" N="CrashedProcessSessionID">.. <S T="1" F="CrashedSessionId" />.. </C>.. <C T="U8" I="3" O="false" N="CrashType">.. <S T="1" F="CrashType" />.. </C>.. <C T="W" I="4" O="true" N="PreviousBuild">.. <S T="1" F="PreviousBuild" M="Ignore" />.. </C>.. <C T="U32" I="5" O="true" N="InstallMethod">.. <S T="1"
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):663
                                                                    Entropy (8bit):5.099263620692954
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd4VzjmNxLu6dRDDHwpatEer5XFJicdD8f7wE7gyXHaSMNO5csu:2d4QNlRdRgeLrlvuJEyu
                                                                    MD5:C3092D3B811AC7FA0EFD684200A9590B
                                                                    SHA1:28EA34D0EBDF0984B7D37EE55EE9B79A91371A5E
                                                                    SHA-256:24C9F91FCABC7853FA3510FF0511D65853D30A6BB204E1F4A15D90A24598EEBF
                                                                    SHA-512:D786BEAFD6CDD7ACB61F134F6D4B311250737B1E6E0752842A70F442FC7542590E60CBFBD03DD0E853B405DA12BD87CD0C5660437F5A80B5B6CF9FE0EA6E21C3
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12043" V="0" DC="SM" EN="Office.Outlook.Desktop.TranslationInfoBarFlexUIHResultErrors" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9sqvv" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Hourly" />.. </S>.. <G>.. <S T="1">.. <F N="ErrorTag" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="FlexUIErrorTagCode">.. <S T="1" F="ErrorTag" />.. </C>.. <C T="U32" I="1" O="false" N="FlexUIErrorTagCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):743
                                                                    Entropy (8bit):4.990664509358685
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdI1VzjLUsdRDDHwpatEeriNc1NQzDKuOjbPSf3exn2Iqnp6zMDHaSMNOAjsu:2dI1pdRgeLrVqiuiSG9
                                                                    MD5:F14F9A0EB8A7410AA025D156961DF7A2
                                                                    SHA1:49A93444CE4429B7A7A34E33B35893B366ED38EE
                                                                    SHA-256:777AE1E18ACCCB59C1C5C4F41AFC705F362AADAC8BBC2E234DF2A71BBE17737F
                                                                    SHA-512:6F56937AC04B1869C45E5BA757681910B96FA7B72666544CAC5A9D609DF979B114DCB058DEFB004D39C1B1413F903EED61AA6E9B40ADC263687405230181E8ED
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12045" V="0" DC="SM" EN="Office.Outlook.Desktop.Pcx.CountCardType" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="crzmp" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="CardType" />.. <F N="IsHosted" />.. </S>.. </G>.. <C T="I32" I="0" O="false" N="CardType">.. <S T="1" F="CardType" />.. </C>.. <C T="B" I="1" O="false" N="IsHosted">.. <S T="1" F="IsHosted" />.. </C>.. <C T="U32" I="2" O="false" N="CountCardTypeAndIsHosted">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1690
                                                                    Entropy (8bit):4.748737190020795
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dLCQPdRgeBIirqJTnIwOZH5xQNk5xQNkC5xQNNpRL5FpvuKQlXoNW:cLFlRgeBnqJTI5xDxixGRN3vuKQh1
                                                                    MD5:FEA20A72BD4FB9A9AFF5563D7859382A
                                                                    SHA1:2D9E361B1CA6FD6377A2A74A0C3F3E84379F0AFB
                                                                    SHA-256:128CD2AC3F3953D28C8773F4734FCF17EF7C9BF2EFE438979561A437409B9963
                                                                    SHA-512:B24F0B7DEF9759EB0DC9DDD09F31421350488E2D510A156896569962F14E3A96DA02BDA48032DB290280636435504C7BD7D6EB3B4A7E6C9AFDBB3D6F8B874907
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12046" V="2" DC="SM" EN="Office.Outlook.Desktop.Calendar.JoinOnlineOnCalendar" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="1030" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="NE">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="1">.. <F N="OnlineSessionType" />.. <F N="JoinOnlineLocation" />.. <F N="AccountID" />.. </S>.. <S T="4">.. <F N="OnlineSessionType" />.. <F N="JoinOnlineLocation" />.. <F N="AccountID" />
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):619
                                                                    Entropy (8bit):5.027977889714664
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdL4VzjOKdRDDHwpatEerBac1NQzDVXSNL/dEXHaSMNOAjsu:2dcEKdRgeLrNq1SBdEY
                                                                    MD5:43E5D7CDC5F02DDEF3AA8170021D4AB2
                                                                    SHA1:8A16729FBD2E1284E1BE8ED04CCF8003C15B2FC9
                                                                    SHA-256:532DF1D02C4E3F272A90CF9B50D51C94BE53783FEAB97BC15DB694563409AF8D
                                                                    SHA-512:9C4F3752BC4AF3025D0AEDD82C231CB3BADF946E24BA307E78357B08BE04B386202E73ECEE69B3F526572418C9251999090B76A658E135F9020DB92957845A78
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12050" V="0" DC="SM" EN="Office.Outlook.Desktop.Pcx.LpcOpenning" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9s74g" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="Source" />.. </S>.. </G>.. <C T="W" I="0" O="false" N="Source">.. <S T="1" F="Source" />.. </C>.. <C T="U32" I="1" O="false" N="LpcOpeningsCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):759
                                                                    Entropy (8bit):5.103131962399642
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdRVzjpJuYBdRDDHwpatEerKXFJicouD0Mye/1yf87SZpWuYYEXHaSMNO5csu:2dRbJPdRgeLrCvSpedx7nSEu
                                                                    MD5:02ABDF2616BA2A23A1306F1B266D33AC
                                                                    SHA1:F8B306457E1C428EA1FEAB1EFC3840D68AFE2294
                                                                    SHA-256:91152E7AB658B26F69FF4B731283507141F9CDBD4F3D20B337D4A04C7BA1AFEB
                                                                    SHA-512:B6E882BDAEF6623E4054C8F4019AEF8378AFA4AE7140E1D62C9F900FF96A9EF663D479F57D7BE5FC2EDF170CDB40D22A27E5E215AC3E58BC2DB2A40F112375CE
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12051" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.MigratedCreateGroupGetGroupSettings" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9uax1" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="HRESULT" />.. </S>.. </G>.. <C T="U64" I="0" O="false" N="DialogVersion">.. <S T="1" F="DialogVersion" />.. </C>.. <C T="I64" I="1" O="false" N="Hresult">.. <S T="1" F="HRESULT" />.. </C>.. <C T="U32" I="2" O="false" N="CreateGroupGetGroupSettingsCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):755
                                                                    Entropy (8bit):5.108187898032485
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd+3Vzjf6iJuYBdRDDHwpatEerT/XFJicouD0Mye/1yf87SZpG5uYYEXHaSMNR:2dOzJPdRgeLrbvSpedx7/SEu
                                                                    MD5:088E9768342AF72158DCF7B62AD7912A
                                                                    SHA1:56D34F57EAC7742B6EFD4F070313EC17DB9B8532
                                                                    SHA-256:A39641CB1942E938790245D3BC0650B36FF3B7D6DE88B98BB040C6F67BF99CF2
                                                                    SHA-512:F3B7CAB0EC0B10D7F0690595F5A0E641C1F908B42EEC2FC78504A64F6A71C7838226B76EE410925C4907A2B1C319767328BF367618D95519D9BC797509C3D68D
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12052" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.MigratedEditGroupGetGroupSettings" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9uax0" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="HRESULT" />.. </S>.. </G>.. <C T="U64" I="0" O="false" N="DialogVersion">.. <S T="1" F="DialogVersion" />.. </C>.. <C T="I64" I="1" O="false" N="Hresult">.. <S T="1" F="HRESULT" />.. </C>.. <C T="U32" I="2" O="false" N="EditGroupGetGroupSettingsCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):751
                                                                    Entropy (8bit):5.110882330608996
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdTVzjkTdRDDHwpatEerSXFJicouD0Mye/1yf87SZpV/OOXHaSMNO5csu:2dTedRgeLrqvSpedx7S/OOu
                                                                    MD5:07487D6B44AFA1AF380E65BBC5367474
                                                                    SHA1:C7D7F16F5EDB8FFB715B2DA773DE5A9001D56F86
                                                                    SHA-256:99AB9B8310391F678BEE2358D75C62FDE661B35D5ED010DC93945225526D3FC8
                                                                    SHA-512:7942117D615B6960005DDB9D5A8A698D2F19F4660EF04C9D66F085ABD024BF117B71BDC97FC78EF971DA2ABEE47DEB4D26F24E32D7FCF538EE1F8E435D1216C8
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12053" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.MigratedGetMembershipTaskResult" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9uaxy" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="HRESULT" />.. </S>.. </G>.. <C T="U64" I="0" O="false" N="DialogVersion">.. <S T="1" F="DialogVersion" />.. </C>.. <C T="I64" I="1" O="false" N="Hresult">.. <S T="1" F="HRESULT" />.. </C>.. <C T="U32" I="2" O="false" N="GetMembershipTaskResultCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):755
                                                                    Entropy (8bit):5.106600457843894
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdIVzjRAKdRDDHwpatEerxfXFJicouD0Mye/1yf87SZpV/6OOXHaSMNO5csu:2dIMKdRgeLrxvvSpedx7S/6OOu
                                                                    MD5:86ADED024E71BFC513174DBEBA697BCB
                                                                    SHA1:E67EDF048C9D98B6FA499EDC39C329C54A426FCB
                                                                    SHA-256:E9C3DCBA31D341FFDE6B0363750FEAF151960B1104F49EEEC2E1ECDE3A9BE8A3
                                                                    SHA-512:EB382CB2AABC71BAEF560BDD157E5EF378FA244FB7E73A9637C00F8FE1E0463076F868D19B538E46C4BF919EAD1D9202E14E2055A8A83F43FF416AD8D873B847
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12054" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.MigratedGetGroupDetailsTaskResult" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9uaxz" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="HRESULT" />.. </S>.. </G>.. <C T="U64" I="0" O="false" N="DialogVersion">.. <S T="1" F="DialogVersion" />.. </C>.. <C T="I64" I="1" O="false" N="Hresult">.. <S T="1" F="HRESULT" />.. </C>.. <C T="U32" I="2" O="false" N="GetGroupDetailsTaskResultCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):670
                                                                    Entropy (8bit):5.113702506511761
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd9VzjCl+dRDDHwpatEerywOc1NQzDznex4nnLanhd4dXHaSMNOAjsu:2d9I+dRgeLrywDqLT2D4dY
                                                                    MD5:EFD4F950979DB9E888C3629DF0DF113F
                                                                    SHA1:365ED92368E8AF71358AFD735ED517906707D599
                                                                    SHA-256:C34684A334E8C966327C7BA0DF09D8F1F0EA65E9FCE7E2E1AFCD55824CA6FA48
                                                                    SHA-512:2D06D35461176F4FA3747C0A2C1ECC0AD167BC0EA3C277349E71968A6BC91A5C1941206703A7DD8BBAFE757AF17D7AF69E536CC68AE08C5BF6B8E5E1925CE1B8
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12055" V="0" DC="SM" EN="Office.Outlook.Desktop.Pcx.MediumCardOpenedFromTimerOrChevron" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9ma03" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="ChevronClicked" />.. </S>.. </G>.. <C T="B" I="0" O="false" N="ChevronClicked">.. <S T="1" F="ChevronClicked" />.. </C>.. <C T="U32" I="1" O="false" N="MediumCardShownCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):4781
                                                                    Entropy (8bit):3.8026096011369317
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d83CdRgeUIimvS8I3NOwOl6NJWHN45YNak2NvfRNkmGOi8TX1ux9Pj:c83eRgeUCvS8/a1pp4Ci8Tlur
                                                                    MD5:4FDD7E5642D1441098146B4F17D739F6
                                                                    SHA1:FA3092438C0DA5C3FB83DA4C77EAE312195415B5
                                                                    SHA-256:D63E03EAC8F1365C389C2C0B981914FDE793ED7C12178886172C7E2DC3E2D23B
                                                                    SHA-512:CCD56C4F362860988BCC41176C19BA3244D8AFB6AB6E4B3F0A783EE952A6287700BE3B11809D9D4BAE7E01808F5E2BD74088F19693F4018288B0D106F11F716D
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12058" V="0" DC="SM" EN="Office.Outlook.Desktop.MeetingInsights.NativeMailUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="910" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="LoadTime" />.. </L>.. <R>.. <V V="0" T="I32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LT">.. <L>.. <S T="1" F="LoadTime" />.. </L>.. <R>.. <V V="1000" T="I32" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="5">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="LoadTime" />.. </L>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):995
                                                                    Entropy (8bit):4.961679196780908
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd1jVzjzwKdRDDHwpat5rF2GeOSHA+KbSQi+kXqNO7OX/c//npONdcEsWXpFtL:2d1jNwKdRgefvLZJTma26EA1v7F1R
                                                                    MD5:F85E6CC629072DC5F6F4EE8D9792116D
                                                                    SHA1:C2EFDD2423D483A43418497F29B987A030C08DC1
                                                                    SHA-256:36E3E1EE6B90B1515C1622D4273FECEF054ED79010CAB73C96690B781339D79E
                                                                    SHA-512:8C209363281F463A76E6030B5B8D857B73700FB6619498B045B23BDBD2F50AA50CC50FE8AC0E5F2E7AA25660AD212A1A00FFD720CAEB13D4E50ECAF540A069F3
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12059" V="0" DC="SM" EN="Office.Outlook.Desktop.EwsAccessTokenFallback" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="10" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="354" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <Etw T="2" E="7090" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="2" F="ConsumerType" />.. </L>.. <R>.. <V V="7" T="U8" />.. </R>.. </O>.. </F>.. <TI T="5" I="5min" />.. </S>.. <G>.. <S T="4">.. <F N="LogicalHttpRequestId" />.. </S>.. <S T="1">.. <F N="LogicalHttpRequestId" />.. </S>.. </G>.. <C T="U32" I="0" O="falseNoError" N="RequestResult">.. <S T="4" F="HttpResponseStatus" />.. </C>.. <T>.. <S T="4" />.. <S T="3" />.. </T>.. <R>.. <S T="5" />.. </R>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):2128
                                                                    Entropy (8bit):5.104787639829218
                                                                    Encrypted:false
                                                                    SSDEEP:24:JdJdHjIqUlsGjPvy3iFcKaXbPICtKuQqo1ZKTvCkqy8qGHwxF0soh/N0aeZ44L:3JrMsGjPvy3IMLt4MTIaGj4L
                                                                    MD5:C0CD509AF6E12FC3D2A441B81F550999
                                                                    SHA1:732988232E7D2CFF964008A510C5F58034E45C89
                                                                    SHA-256:C3C7819FE42F83FAF7508BBB4A184B429C0DC8926050D5BECB20FF4F73E1782A
                                                                    SHA-512:BAE01A8FE637DDF65503DDB0B67FA16C7BF4FBC45B023DDB5E5BD916A775D63F9E49A2E3E6E099EC6577E7EAC0C0FDAEC3F443162D6AED9D06BBCAEFE37DA9BB
                                                                    Malicious:false
                                                                    Preview:.<?xml version="1.0" encoding="utf-8"?>..<R Id="120603" V="8" DC="SM" EN="Office.System.SystemHealthMetadataApplicationAdditional" ATT="cd836626611c4caaa8fc5b2e728ee81d-3b6d6c45-6377-4bf5-9792-dbf8e1881088-7521" SP="CriticalBusinessImpact" E="false" DL="A" DCa="PSU" xmlns="">.. <RIS>.. <RI N="Metadata" />.. </RIS>.. <S>.. <SS T="1" G="{c3d2f3fc-0f86-43ac-b7a3-007bf524f38f}" />.. <SS T="2" G="{1f59c07e-f223-4c7f-aa23-df28da66734b}" />.. <SS T="3" G="{dd5250a9-3404-43b0-9b7a-6f4eaea6497d}" />.. <SS T="4" G="{1a6b5bd0-2f17-420c-8ba0-ee01132ee441}" />.. <SS T="5" G="{6b5515e4-c848-4ef0-92d4-747ecc491c7b}" />.. <R T="6" R="120100" />.. <R T="7" R="120607" />.. </S>.. <C T="FT" I="0" O="true" N="FirstRunTime">.. <S T="1" F="FirstRunTime" M="Ignore" />.. </C>.. <C T="W" I="1" O="true" N="Alias">.. <S T="3" F="Alias" M="Ignore" />.. </C>.. <C T="B" I="2" O="true" N="IsLabMachine">.. <S T="3" F="IsLabMachine" M="Ignore" />.. </C>.. <C T="B" I="3" O=
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):856
                                                                    Entropy (8bit):5.000732911812472
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdjWguVzjBeB+6dRDDHwpatPEc6NXFJiertwHNP4+ffn/KGqdPbSK6yp3yFNHm:2dqgubeBhdRgeaxvVr2FtiG6ZgFLD0
                                                                    MD5:347134F81CBA37E407A2C1530F670526
                                                                    SHA1:A4CE47423473C4F6A398587FF043611ED8E2D619
                                                                    SHA-256:C946D774C5F2AADCDAC02EF92869EC2866878CD83F97319F7F35BD44FDA3B2E3
                                                                    SHA-512:485A6DB40BBE107D5F021463486CB95C400FF069032A18D4D4304A767417FD65317A89798EE164F51BD07A650365E28E1F035B10515F7C34E71AD89742A5F668
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12103" V="3" DC="SM" EN="Office.Outlook.Desktop.MetaOS.HubBarAppUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" SP="CriticalUsage" DCa="PSU" xmlns="">.. <S>.. <TI T="1" I="Daily" />.. <A T="2" E="TelemetryShutdown" />.. <UTS T="3" Id="66fmh" />.. </S>.. <G I="true" R="TriggerOldest">.. <S T="3">.. <F N="Action" />.. <F N="AppId" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="AppAction">.. <S T="3" F="Action" />.. </C>.. <C T="W" I="1" O="false" N="AppId">.. <S T="3" F="AppId" />.. </C>.. <C T="U32" I="2" O="false" N="TotalAppActions">.. <C>.. <S T="3" />.. </C>.. </C>.. <C T="G" I="3" O="false" N="AccountUID">.. <S T="3" F="AccountUid" />.. </C>.. <T>.. <S T="2" />.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):807
                                                                    Entropy (8bit):5.040926084996233
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdTVzjBe2UdRDDHwpatEc6NXFJierR7wHNFL7lfoi/6WTQGadp/7yFNHISMNOi:2dTbezdRgeyxvVrRwrvCiC0jFQ
                                                                    MD5:28E43FE8DDB488AEF5014682706E7BCE
                                                                    SHA1:EFFB41C8E602248E1EBB927709F2B6DBDAE68CA5
                                                                    SHA-256:F7EFCAA525600D9145125CB1747CE06CF1E09C797C3672AC54A368B91AA228BD
                                                                    SHA-512:307F20CBEB6B07983F250B11EEF3B5D9607CFEB0E6C5CE550B86C5819F53708573346EBC01C8C3F9E942905E32C485E7763EDF3411DDF6B725D8FE4C4B9569FC
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12104" V="1" DC="SM" EN="Office.Outlook.Desktop.MetaOS.HubBarModuleContextMenu" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <TI T="1" I="Daily" />.. <A T="2" E="TelemetryShutdown" />.. <UTS T="3" Id="7muce" />.. </S>.. <G I="true" R="TriggerOldest">.. <S T="3">.. <F N="ContextMenuOption" />.. <F N="ModuleId" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="ContextMenuOption">.. <S T="3" F="ContextMenuOption" />.. </C>.. <C T="U32" I="1" O="false" N="ModuleId">.. <S T="3" F="ModuleId" />.. </C>.. <C T="U32" I="2" O="false" N="TotalContextActions">.. <C>.. <S T="3" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):874
                                                                    Entropy (8bit):5.023254209008374
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdhuVzjBe+dRDDHwpatPEc6NXFJierlpwHNP4+ffoi/KGqdPbSK6yp/7yFNHIP:2dhube+dRgeaxvVrcFOiiG6ZQFLD0
                                                                    MD5:9139BC1D0D2581443D89AF542C605C14
                                                                    SHA1:3EA1A5325D03D82FF32E386D887B3BE6ADF16DCA
                                                                    SHA-256:7318A6F0B8E131047D3CCFB80C661FC12200E8292B46F469BC46D2850B41DE76
                                                                    SHA-512:1B314B8AE9DA93AE65E3AF23DC2085F9432E3BD2D13102CAF6359EB5C46FDF0FCDE022E8BD0912DF134C3BD2416ED9429FD92E572BCE44B132A9385399C71607
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12105" V="3" DC="SM" EN="Office.Outlook.Desktop.MetaOS.HubBarAppContextMenu" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" SP="CriticalUsage" DCa="PSU" xmlns="">.. <S>.. <TI T="1" I="Daily" />.. <A T="2" E="TelemetryShutdown" />.. <UTS T="3" Id="66fmf" />.. </S>.. <G I="true" R="TriggerOldest">.. <S T="3">.. <F N="Action" />.. <F N="AppId" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="ContextMenuOption">.. <S T="3" F="Action" />.. </C>.. <C T="W" I="1" O="false" N="AppId">.. <S T="3" F="AppId" />.. </C>.. <C T="U32" I="2" O="false" N="TotalContextActions">.. <C>.. <S T="3" />.. </C>.. </C>.. <C T="G" I="3" O="false" N="AccountUID">.. <S T="3" F="AccountUid" />.. </C>.. <T>.. <S T="2" />.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1079
                                                                    Entropy (8bit):4.9438852795403365
                                                                    Encrypted:false
                                                                    SSDEEP:24:2duj9+8TPdRgeqFIiKIitJ8wOasTJjYmrXDgr:cI9+CRgeGWxJ8QiXQr
                                                                    MD5:DA20AAF6A7F57742FF43F9304BF7CCEC
                                                                    SHA1:25431F71218299FEC18732174405A67CD194C242
                                                                    SHA-256:E2E4899A1DECB832DA1966F320909EC28D49A73652189F15682F1BFAC0D4E1C1
                                                                    SHA-512:5B15B36D73A1E3099D2D09FB405D7A5483DE3FB62CA96F5C2C6C003A166506E2C827A36D32EFF53CE1280FD850ED5AE0655FE5713412FE1DE87A11A4D10C499C
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12106" V="0" DC="SM" EN="Office.Outlook.Desktop.Calendar.HideAttendeeList" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="912" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <Etw T="2" E="913" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <A T="3" E="TelemetryShutdown" />.. <TI T="4" I="Daily" />.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="fHideAttendeeList" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="Count_HideAttendeeListOptionAvailable">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="Count_HideAttendeeListUIShown">.. <C>.. <S T="2" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="Count_HideAttendeeListChecked">.. <C>.. <S T="5" />.. </C>.. </C>.. <T>.. <S T="4" />..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):4120
                                                                    Entropy (8bit):4.167494694263229
                                                                    Encrypted:false
                                                                    SSDEEP:48:cfPLRge0uyN8t4NKTNoXAQNQBJNhuNmvNnsNk8Nq/NlfyNcFN/IN2h22eyITVxlJ:WRge0uZTMAvJjx3bTfzjBU1VxB17
                                                                    MD5:8C27A62FD55E500FA43B07026B4764BF
                                                                    SHA1:8E857C1B99970E91BCC49AED0D2BDA839529FBAA
                                                                    SHA-256:022D7E00196598188A3D99220ECF5CA7F1832D918A0EBBFF834A95B89875661B
                                                                    SHA-512:9DDF1F9F68941BA67B2CA56D37D0073889BF9052FDCC124D4C3D7005DF5A38A1576942BC648640460F36A2F10371CE95FEECEE14A922C06C1FAA9BCCE4F84D01
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12108" V="1" DC="SM" EN="Office.Outlook.Desktop.OPX.OWAComponentUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="363" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <F T="2">.. <O T="EQ">.. <L>.. <S T="1" F="OWAComponent" />.. </L>.. <R>.. <V V="1" T="I32" />.. </R>.. </O>.. </F>.. <F T="3">.. <O T="EQ">.. <L>.. <S T="1" F="OWAComponent" />.. </L>.. <R>.. <V V="3" T="I32" />.. </R>.. </O>.. </F>.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="OWAComponent" />.. </L>.. <R>.. <V V="4" T="I32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="OWAComponent" />.. </L>.. <R>.. <V V="5" T="I32" />.. </R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1154
                                                                    Entropy (8bit):5.132404728649547
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d4s6dRgecIi2geveO6YC/5M4YGwdAULPk:c4s2RgecseOW/54hBPk
                                                                    MD5:2215A58CEEA55D244BD0AF5CB32A9D43
                                                                    SHA1:192F5A39682110816BEAE0D084CA5E14F475CE92
                                                                    SHA-256:00D1E7459DF43A8F3227B59921F166076D759001507F2DCC36584D84F3A52C78
                                                                    SHA-512:79BB9CC990158A90D488C3C555FFF80D9D39A4D0796AA5B9D627DBD936C9B5A7B74B95C128DA86DC9FF00ADC007B86E46BF47E2B0B3E7A1EC6CA71B9A5662486
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12115" V="0" DC="SM" EN="Office.Outlook.Desktop.Calendar.ShortenEvents" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="10" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="1031" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. </S>.. <C T="I32" I="0" O="false" N="DefaultDuration">.. <S T="1" F="DefaultDuration" />.. </C>.. <C T="I32" I="1" O="false" N="ShortenEventsType">.. <S T="1" F="ShortenEventsType" />.. </C>.. <C T="B" I="2" O="false" N="ShortenEventsTypeGP">.. <S T="1" F="ShortenEventsTypeGP" />.. </C>.. <C T="I32" I="3" O="false" N="ShortenEventsShort">.. <S T="1" F="ShortenEventsShort" />.. </C>.. <C T="B" I="4" O="false" N="ShortenEventsShortGP">.. <S T="1" F="ShortenEventsShortGP" />.. </C>.. <C T="I32" I="5" O="false" N="ShortenEventsLong">.. <S T="1" F="ShortenEventsLong" />.. </C>.. <C T="B" I="6" O="false" N="ShortenEventsLongGP">.. <S T="1" F="ShortenEvents
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):341
                                                                    Entropy (8bit):5.393363672425984
                                                                    Encrypted:false
                                                                    SSDEEP:6:TMVBd7zzDkhOVzjqJm/R/tYR/3IbqBdRijeDHwp1MTZ5lkHperhnKOn2sby:TMHdvzjVzjqJm/NtYN4GdRDDHwpat5lO
                                                                    MD5:075306B623ED6678444EAFA8C8A6D9EF
                                                                    SHA1:CFE5825581589202A2B25E07BDE26BFE0201C2AD
                                                                    SHA-256:F38DAAF7815CDF84A9F578104505672DE200C1C3E7ACEFB379B0CCCA10E79F50
                                                                    SHA-512:6CD8E25CA58B5C94EA6FC4B03EB42AF6DE4E4F296576FCE2CB7BC83CB690A7EF35692018ED8ECF673613EDF8E90F7E7C04ADE2DAD79C7BF3833D5C4DB37E9744
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12116" V="0" DC="SM" EN="Office.Outlook.Desktop.InlineTranslation.TranslationDataLanguageStampEmpty" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="200" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9t6w3" />.. </S>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1441
                                                                    Entropy (8bit):4.7858043786112665
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dDgZodRge/OuyGmfXAt4GmlAnHX5HgHETBwb1lZSQZZ4:cDWARge2uyGkXAt4GsAn35pTBwRlZSQE
                                                                    MD5:D4D810D19BC342330C998A7C4A9B156C
                                                                    SHA1:AADC38E853FDAF5E6D7677BAF442E3BEE4EC21A5
                                                                    SHA-256:53601B626E1B47CE3E6FECACA1510AD0FBB64CB8C50093453C4C981A9DD86B06
                                                                    SHA-512:EA7EEA7A18E3ED0838A10211E133F9BF6D4DC0D34979253980E9ADE051AB8BBE7937993B7AA5ADB587E345ED278A64AE1FFCEDECDC6A138DDC9D4D2C3515F7A3
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12117" V="1" DC="SM" EN="Office.Outlook.Desktop.OPX.WebHostJSMemoryUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="369" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <F T="2">.. <O T="EQ">.. <L>.. <S T="1" F="Result" />.. </L>.. <R>.. <V V="4" T="I32" />.. </R>.. </O>.. </F>.. <F T="3">.. <O T="EQ">.. <L>.. <S T="1" F="Result" />.. </L>.. <R>.. <V V="5" T="I32" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="2">.. <F N="ControlId" />.. <F N="WebHostingSessionId" />.. </S>.. <S T="3">.. <F N="ControlId" />.. <F N="WebHostingSessionId" />.. </S>.. </G>.. <C T="G" I="0" O="true" N="ControlId">.. <S T="2" F="ControlId" />.. </C>.. <C T="G" I="1" O="true" N="WebHostingSessionId">.. <S T="
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):2747
                                                                    Entropy (8bit):5.139514887863295
                                                                    Encrypted:false
                                                                    SSDEEP:48:cTuRgeax3nTqjOb55AQ4Q5mQlkAQIze2cqW6kQbSbFUpo7:3RgeaxWjg55A92m2rE6kOo7
                                                                    MD5:1AEAC3E99B1A88068254E464DE80B277
                                                                    SHA1:692421C40B1D9094840B3DA1DB12F242B59C44EE
                                                                    SHA-256:E30F3C88AE951BD2C0D85CA9C2A5B32785F3108093DF9ECC40AC8C43DEE93616
                                                                    SHA-512:9536DF4EF7BB47E32A17E166991558150C831F96436EB205E678787428D815F8B97E29FD85EEFB327F168A22F5B57A531D1B4B35C854E6CAC8BAAD7F032A69AC
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12118" V="2" DC="SM" EN="Office.Outlook.Desktop.OPX.MemoryUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="50" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="327" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="2" E="328" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="3" E="364" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="4" E="366" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. </S>.. <C T="U32" I="0" O="false" N="SystemMemoryLoad">.. <S T="1" F="MemoryLoad" />.. </C>.. <C T="U64" I="1" O="false" N="TotalCommittedMemoryLimit">.. <S T="1" F="TotalPageFile" />.. </C>.. <C T="U64" I="2" O="false" N="SystemTotalVirtualMemory">.. <S T="1" F="TotalVirtual" />.. </C>.. <C T="U64" I="3" O="false" N="TotalCommittedMemoryUsed">.. <S T="1" F="PageFileUsed" />.. </C>.. <C T="U64" I="4" O="false" N="SystemTotalVirtualMemoryUsed">.. <S T="1" F="Virt
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):654
                                                                    Entropy (8bit):5.063052154049238
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHddVzjhEqjdRDDHwpatEerzc1NQzDdX6HfWX6Gs66jNDHaSMNOAjsu:2ddvjdRgeLr6qlvv
                                                                    MD5:BE6F2624D0921E997D94D32B06927D8E
                                                                    SHA1:0BD06C7E06A90A07720FBF97FC5E83369836C989
                                                                    SHA-256:6EB1A8533FEF08CBB7251C82FAE67DE006C2D6D8155D747B201D1C2FA73FC6FE
                                                                    SHA-512:613EB539B014D65CD1D445DA55AD6CD83EF738C5293584B264904A381EB018A646FABF61F948B8D257FF08C5AE59EBB6BC44513970174BEB8AFC61F55EB634D3
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12121" V="0" DC="SM" EN="Office.Outlook.Desktop.Pcx.PersonaPhotoLoadSuccess" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9udxm" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="PhotoSourceId" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="PhotoSourceId">.. <S T="1" F="PhotoSourceId" />.. </C>.. <C T="U32" I="1" O="false" N="CountLoadSuccess">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):643
                                                                    Entropy (8bit):5.2105352782281535
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdFVzjVgPdRDDHwpatUk62GeOXrzfTTxZcv8tgA9M3gSzuSNNO2su:2dFIPdRgeUfvLHPnNqAq
                                                                    MD5:60C78FB579BDF7FDA5446C2A3FD9CC91
                                                                    SHA1:4D832AAD5069A076DF8FE9F18E780BA2902658E0
                                                                    SHA-256:4C1801B9F0BFAA190DA5FFBDF422F9702F65680D537FECDF5F5D85974AE2F0E1
                                                                    SHA-512:1EF36B3870883148A919C736267EFFCE17910E63D6F4E601CA0DB9BE26B6824FCCAD95B47A29A921D4127083405278A4EF5B0964EB0B5CC49331DF41188A1D3C
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12124" V="1" DC="SM" EN="Office.Outlook.Desktop.Store.InvalidProtocols" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" SP="CriticalUsage" S="50" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="7011" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. </S>.. <C T="U32" I="0" O="false" N="StoreType">.. <S T="1" F="StoreType" />.. </C>.. <C T="U64" I="1" O="false" N="SavedProtocols">.. <S T="1" F="SavedProtocols" />.. </C>.. <C T="U64" I="2" O="false" N="ProtocolsToUse">.. <S T="1" F="ProtocolsToUse" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1622
                                                                    Entropy (8bit):4.640539355427191
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dxykdRgelfywOaqIJqbuqgplwOm1udQNH:cxyURgelfyQbJIuNl8uQNH
                                                                    MD5:95707CAB5D81F73C4FDB7EC24C272C7E
                                                                    SHA1:DDD7C87257DE4FA6C28F7A8C3772DD8278C41AC5
                                                                    SHA-256:A45209A73819868632AC2485E89F9D1F2AEA8314264A4F59EB6EF77090A612B7
                                                                    SHA-512:EDF6235DE301928E9724550A44CF94FE8475C9C1547CF19BF4DA345D439365DBC6D47C6F1C9929D006CC7C184D07864DF75E5415ED0B0FFABAE950445B9A83B2
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12125" V="0" DC="SM" EN="Office.Outlook.Desktop.SuggestedReplies.GeneralUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <Etw T="3" E="23500" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="4" E="23501" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <F T="5">.. <O T="EQ">.. <L>.. <S T="4" F="Position" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="4" F="Position" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="4" F="Position" />.. </L>.. <R>.. <V V="2" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0"
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):2382
                                                                    Entropy (8bit):4.478168140757753
                                                                    Encrypted:false
                                                                    SSDEEP:48:cqwx2RgeqqJTBrYQ4wJ48quBrRvBr07w07w17wu7wf7wZQrg7U1l0:jRgehFrYvwazSrRZr+w+wdwMwjwZeSU8
                                                                    MD5:4A5E13830CDC3C1E60BDD10363B4FD8C
                                                                    SHA1:1A4C0F915E158CB113BB64E891F8527B9AD477E5
                                                                    SHA-256:19C91EB9D30F787E9AAC688A6E2BC17D56BD8D8EC9805C1E2D3CAEDF0BB1B22A
                                                                    SHA-512:8F998600EF550442BFF13210475F4614FF884782E6C17AB109A7F3D652779F474B54CC6378BFA42945365CD4E0123A156917E230C8AAB5CFD6654744E1CDD2AB
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12127" V="1" DC="SM" EN="Office.Outlook.Desktop.Outllib.OutllibItemCRUDStats" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="3600" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="UserOperationType" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="4" F="IsItemEverSaved" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="4" F="IsItemEverSaved" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1085
                                                                    Entropy (8bit):5.038011908816117
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dZhJGqax6dRgevavFN3VNkP3N3ONwlsfqq7:cZ3ax2RgevavFpVYcMzQ
                                                                    MD5:0B8F9E20C2D6B8BA528AF9B8D5E6D01D
                                                                    SHA1:A5B98C65AF43AE69D47FC0938188EF83D9C82612
                                                                    SHA-256:43421BF91E371DFCB724210392CB439A3BC0B1C3098D70874A15333546A8F1C4
                                                                    SHA-512:605500307673B10AF31DFA0C99B5851538A236EE196AAC16DEEB7AB60F9487828D933B9E0A877DB824CC718FCE90386000AD879777F9FAE1A27D6F224F0B5C6C
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12128" V="1" DC="SM" EN="Office.Outlook.Desktop.Outllib.CreateFolderandFocusedInboxStats" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="23409" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="23410" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="3" I="Daily" />.. <A T="4" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="AccountUID" />.. </S>.. <S T="2">.. <F N="AccountUID" />.. </S>.. </G>.. <C T="G" I="0" O="false" N="AccountUID">.. <O T="COALESCE">.. <L>.. <S T="1" F="AccountUID" />.. </L>.. <R>.. <S T="2" F="AccountUID" />.. </R>.. </O>.. </C>.. <C T="U32" I="1" O="false" N="CreateNewFolderCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="ActivatePivotFocusedInboxCount">.. <C>.. <
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1448
                                                                    Entropy (8bit):4.719937168644355
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d8dmux6dRgeoIirqJTqPjqwOaqPifNy9AyNy9ACWNy9ArNV9VAiEuU:c8dBx2RgeonqJTqbqQq30zR
                                                                    MD5:3D76C8E3AF7DCD298D9A12F8A405F76B
                                                                    SHA1:5E4F78E6AAECFAF7905A14CB49369D5EE412263F
                                                                    SHA-256:5C844C7CBFDD7D5068FEB3C8583A7AB1A987111BA4971B0BAA6EE03800BA8127
                                                                    SHA-512:C1FCA7A00D05F84BA322F6E49E7D454ED5080009329F76105E5B093EA0F748225FC92F9DBBAAFB02CACE18975466D58FC63DA20EC081A58782C29FE46886DAB4
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12129" V="1" DC="SM" EN="Office.Outlook.Desktop.Calendar.ViewUsageStats" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="423" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="IsHomeView" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="IsHomeView" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="1">.. <F N="AccountID" />.. <F N="CalendarMode" />.. </S>.. <S T="4">.. <F N="AccountID" />.. <F N="CalendarMode" />.. </S>.. <S T="5">.. <F N="AccountID" />.. <F N="CalendarMode"
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1423
                                                                    Entropy (8bit):4.858270460123539
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dfhJ4vx6dRgeUjgFN3VN6zNkP4PHNneNkTRNyxwmq4A:cfwvx2RgeUjgFpVAzzcyR4yV
                                                                    MD5:7E0A51589D9A8B7305D87CF7EDB474F0
                                                                    SHA1:9A72A2F0C886760E3280F0BC2AFC172903F7E899
                                                                    SHA-256:EF62A9203A6947EC340DBAC2978683D6532562698F16E8507C85B8D95B2BCEEE
                                                                    SHA-512:09BB5816BA07E1BD20C8E10B491A9D76E13758627DD8AB6167AD3A6438CA5BF04CB48912A318CF48D951E13287E05AB023FBAA7D860766EFFA8CDFE8DB2E75D4
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12131" V="1" DC="SM" EN="Office.Outlook.Desktop.Outllib.MessageTaggingStats" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="19008" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="19010" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="3" E="23411" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="4" I="Daily" />.. <A T="5" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="AccountUID" />.. </S>.. <S T="2">.. <F N="AccountUID" />.. </S>.. <S T="3">.. <F N="AccountUID" />.. </S>.. </G>.. <C T="G" I="0" O="false" N="AccountUID">.. <O T="COALESCE">.. <L>.. <O T="COALESCE">.. <L>.. <S T="1" F="AccountUID" />.. </L>.. <R>.. <S T="2" F="AccountUID" />.. </R>.. </O>.. </L>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1272
                                                                    Entropy (8bit):4.71489936713762
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d1ahJTTx6dRgevJ1qJTOaIwOaOa3NbNkNNTNi2a:c1arTx2RgevzqJTOrQO2ZkJG
                                                                    MD5:CF98688029B3A7B85A8C1A3E544271C8
                                                                    SHA1:038C2C10269F6CD2DD65FD3E876C686E3298C4CE
                                                                    SHA-256:318F72133F73F09CE0D86F3EB8C7E220C589947370DD448C2F1EF35540404388
                                                                    SHA-512:E5150A1B64FC62DBDD3170263C5393F9A6F8D6D15EC9FDE25EC9754009B02B5E988E7386EE1493D63E52EE7D1347781FD8B95D3D39E757925A89BF2FA3A95E96
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12132" V="1" DC="SM" EN="Office.Outlook.Desktop.Outllib.CopyandMoveMessagesStats" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="23412" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="OpType" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="OpType" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="1">.. <F N="AccountUID" />.. </S>.. <S T="4">.. <F N="AccountUID" />.. </S>.. <S T="5">.. <F N="AccountUID" />.. </S>.. </G>.. <C T="G" I="0" O="false" N="AccountUID">.. <S T="1" F="Accou
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):744
                                                                    Entropy (8bit):5.094230261637117
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd8NVzjqJm/N0cnAdRDDHwpat5Gger5IrsLDCNWUFN2LwOf/0//nbhmMnWNzIz:2dO4JqNrnAdRgeAryrqOpFN2LwqoGNnU
                                                                    MD5:4190727D47C7E595FC653F10EF2D7460
                                                                    SHA1:DEEEF9D1EE69115480AC71FD3EA6642425D6C71B
                                                                    SHA-256:A56DEF334DFCEC38B7155BB9EA6AF5C12BBEFEF41C11E1C1B7488F62C03F8D36
                                                                    SHA-512:29E39E72079154B0DB0B38A40283962B0B6EC98873EED88B8742F3596747CC85C96FE138B841FC8A659FED0FCECD847A229273D450D186C9E8881DA2C8CB7495
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12133" V="2" DC="SM" EN="Office.Outlook.Desktop.InlineTranslation.InfobarUsageGroupedMetrics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="500" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9w7n7" />.. </S>.. <C T="B" I="0" O="false" N="IsTranslateButtonClicked">.. <O T="EQ">.. <L>.. <S T="1" F="EmailTranslationState" />.. </L>.. <R>.. <V V="2" T="U32" />.. </R>.. </O>.. </C>.. <C T="B" I="1" O="false" N="IsAutomaticTranslationEnabled">.. <S T="1" F="IsAutomaticTranslationEnabled" />.. </C>.. <C T="W" I="2" O="true" N="MessageId">.. <S T="1" F="Id" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):4071
                                                                    Entropy (8bit):4.4210348649292
                                                                    Encrypted:false
                                                                    SSDEEP:96:JRgedbWr5Y4RDmy/VMl1CDy/yyyZyEybyuyCyPy2K3seD:JDdXj
                                                                    MD5:E43B0513EBD9AD67FFA50381F2241A0B
                                                                    SHA1:8E11B58C0B574AFF2631B2FA3D001B435139F63D
                                                                    SHA-256:71BCBE7C19A77850100EB7915D6B2D916BBB300121EF42D130260086F089790D
                                                                    SHA-512:9D80F58A8A1FEBB33E5ADD3A8DF20D7DAE1663BC47B7A348A602A1CAC343CE557FA6283D1AF561835B797EB8F2F1D9B1928658053F4DAA5175288EA81594820C
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12136" V="0" DC="SM" EN="Office.Outlook.Desktop.Attachments.UploadToCloud" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="4163" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="StorageHostType" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="StorageHostType" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="StorageHostType" />.. </L>.. <R>.. <V V="2" T="U32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="1" F="StorageHostTyp
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1040
                                                                    Entropy (8bit):4.976728441101618
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d5hJQx6dRgevUAqJTZd0ANdDJ0qNINYJ0x0FV:c5ox2RgevUAqJTwkmquim+f
                                                                    MD5:662EF54AC7597A1181CC86F8DFD51468
                                                                    SHA1:30EA3C158DE667AA5CC06BE7F9B60224B7A0705D
                                                                    SHA-256:E8B9C7AF95AF70922C57F8DCBEDA5AC35F22C85A315260FD4A647A8FE20C1126
                                                                    SHA-512:D4A3D38F966A4CCDC52941F7632CAB77F78ECE031F1E1C323DF6A77B2F635B57128E1D0DB90447134FFA7640E5BFA2714EA8B3D4735FD3BAAFBFDBCE6F208B22
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12137" V="1" DC="SM" EN="Office.Outlook.Desktop.Outllib.FolderSwitchStats" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="22860" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="ModuleTypeBefore" />.. </L>.. <R>.. <S T="1" F="ModuleTypeAfter" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="4">.. <F N="ModuleTypeBefore" />.. <F N="AccountUID" />.. </S>.. </G>.. <C T="G" I="0" O="false" N="AccountUID">.. <S T="4" F="AccountUID" />.. </C>.. <C T="U32" I="1" O="false" N="ModuleTypeBefore">.. <S T="4" F="ModuleTypeBefore" />.. </C>.. <C T="U32" I="2" O="false" N="FolderSwitchCount">.. <C>.. <S T="4" />.. </C>.. </C>.. <T>.. <S T
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):2312
                                                                    Entropy (8bit):4.9291671976958025
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d+3gbdRge5tHAoivFIPlexnSNC9ohKjKXZJ+Arijs7A:c+3CRge8oivFIPDQ9guiur
                                                                    MD5:68B5F6197A445D2D94861FD875018BF8
                                                                    SHA1:AF04C1B8CAB680C5CEF1D1F2A89D6E54ADD0F9C3
                                                                    SHA-256:98190BD1EB99699137491C89FB114075A10BA126D943F1122E81D29D9A96E734
                                                                    SHA-512:D8BE57E2F080B6DF95551EBF37DAF4C29F5E8670A111D52547886BA1F985C6AADCCAADC135EFAC9612DA9BAF90937CBE0F7E1CE64705BBEDF2F5339373B8BE1A
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12139" V="0" DC="SM" EN="Office.Outlook.Desktop.OPX.WebHostJSPerformanceTimings" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="370" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. </S>.. <C T="G" I="0" O="true" N="ControlId">.. <S T="1" F="ControlId" />.. </C>.. <C T="G" I="1" O="true" N="WebHostingSessionId">.. <S T="1" F="WebHostingSessionId" />.. </C>.. <C T="D" I="2" O="false" N="ConnectEnd">.. <S T="1" F="ConnectEnd" />.. </C>.. <C T="D" I="3" O="false" N="ConnectStart">.. <S T="1" F="ConnectStart" />.. </C>.. <C T="D" I="4" O="false" N="DomComplete">.. <S T="1" F="DomComplete" />.. </C>.. <C T="D" I="5" O="false" N="DomContentLoadedEventEnd">.. <S T="1" F="DomContentLoadedEventEnd" />.. </C>.. <C T="D" I="6" O="false" N="DomContentLoadedEventStart">.. <S T="1" F="DomContentLoadedEventStart" />.. </C>.. <C T="D
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):825
                                                                    Entropy (8bit):5.19676780938152
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdCVzjIHtNCusdRDDHwpat5aOzq5HE9KHbXbxdy9ve/cyRtSIs9N1DaESIt9N7:2dCg4usdRgeotHTmeUeUD1R1z
                                                                    MD5:6A47156F9640688805C6AE9E98BEC251
                                                                    SHA1:73537CE1DB5207EBDD1D255903A5B5697E3DF7E4
                                                                    SHA-256:718D23B210C063DC2B4AD282F04A18F5D35303F9B5D898995F3CE679BE4F5A21
                                                                    SHA-512:141030297EAC6E96DFAB7319E8273CFECADA49D97CC9125AC4171E8661304FD43C5D111367A8D27842B56554C395C19119A5CED704D407FC89D8A8B98C8A9DB0
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12140" V="0" DC="SM" EN="Office.Outlook.Desktop.OPX.WebHostOWAData" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="371" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. </S>.. <C T="G" I="0" O="true" N="ControlId">.. <S T="1" F="ControlId" />.. </C>.. <C T="G" I="1" O="true" N="WebHostingSessionId">.. <S T="1" F="WebHostingSessionId" />.. </C>.. <C T="W" I="2" O="true" N="OWAVersion">.. <S T="1" F="OWAVersion" />.. </C>.. <C T="U32" I="3" O="false" N="CountResourceRequests">.. <S T="1" F="CountResourceRequests" />.. </C>.. <C T="U32" I="4" O="false" N="CountScriptRequests">.. <S T="1" F="CountScriptRequests" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):841
                                                                    Entropy (8bit):4.955964770430341
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd3Vzj06dRDDHwpatEeryer4ermcih2NanA0hGSHaSMj0h3SHhSMp60hh/HISx:2d3JdRgeLrlrfrtgfTm7Uo
                                                                    MD5:888E924DD69E831D3AB1C6DE3A4F37C7
                                                                    SHA1:602CFB5BFFD9C211AE3084DE5BE13FFCDAC78248
                                                                    SHA-256:E13AFBD957239816FD3E3F4C10EDA58D37066C181224FE794464558420D5CA64
                                                                    SHA-512:FE1AFFE748BF5681552B182B54A0A4937BF820A17D8A9B4980147AA150EEAA83816A17AE6F68D7212CA9123ABA9E38058C0DFCD444A780FD9ADEE8A66A8CC62C
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12141" V="0" DC="SM" EN="Office.Outlook.Desktop.Pcx.LpcReactHostErrors" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="8ys2d" />.. <UTS T="2" Id="8ys2c" />.. <UTS T="3" Id="8ys2b" />.. <TI T="4" I="Daily" />.. <A T="5" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="CountLpcReactHostError">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="CountLpcReactHostConsoleError">.. <C>.. <S T="2" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="CountLpcReactHostJsException">.. <C>.. <S T="3" />.. </C>.. </C>.. <T>.. <S T="5" />.. <S T="4" />.. </T>.. <ST>.. <S T="1" />.. <S T="2" />.. <S T="3" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1192
                                                                    Entropy (8bit):5.024386106000472
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdf4VzjGx6dRDDHwpatEJA+KbSXFJicouDKp6fw9OOXHaSMCMgp7SAhoRXscFK:2df4wx6dRgekvSBH9OOtCR9F3ARzfFf
                                                                    MD5:A05ECBD001AD8D30D6A66D039B9F47E9
                                                                    SHA1:6E4C882CAB091A03DA26600B73287F0BCAB70185
                                                                    SHA-256:38EFA30673B5A29B8EEF905930819B20EC155CDA2E7296CFDD3B86A8ED58C218
                                                                    SHA-512:B03B5FB7D68DDBBB41EE4A5416579621E6D907C0A0A398C8C8F75A6387B769D1804A8E3F98B16E01494785AB936CC1669D347129530001D05DE448BDC32453FC
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12142" V="0" DC="SM" EN="Office.Outlook.Desktop.Authentication.AuthenticatedServiceTicketResults" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="744" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="CallerId" />.. <F N="AuthError" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="TicketResultCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="CallerId">.. <S T="1" F="CallerId" />.. </C>.. <C T="U32" I="2" O="false" N="AuthError">.. <S T="1" F="AuthError" />.. </C>.. <C T="U64" I="3" O="false" N="AvgElapsedTickCount">.. <A T="AVG">.. <S T="1" F="ElapsedTickCount" />.. </A>.. </C>.. <C T="U64" I="4" O="false" N="MaxElapsedTickCount">.. <A T="MAX">.. <S T="1" F="ElapsedTickCount" />..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1972
                                                                    Entropy (8bit):4.508920368337709
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dVvdRgeWvJwOanIkIu4Itm/BiXYRY1whF9s/TRm1n/T45:cVFRgeWvJQIduRIZiXYRY1ijsbYnbU
                                                                    MD5:A4B2BADA9859C035155A71EE588032AB
                                                                    SHA1:1C345A08CB9693290DFE1BAE675509A60D17D2E5
                                                                    SHA-256:B843F9886442C2333B4681D07F7FCB69039EBB127109302CC6321821DB42E1BB
                                                                    SHA-512:57FB23B355A44D98BE91309FADAD928E3C1502927305BF185CAF373165AD41DF25C09148A59E5C31B524A9BA87B6542070F2DAF1B0B2881204106E093D9A37C7
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12143" V="0" DC="SM" EN="Office.Outlook.Desktop.Calendar.WeatherPeekUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="399" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="400" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="3" I="Daily" />.. <A T="4" E="TelemetryShutdown" />.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="NE">.. <L>.. <S T="1" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="2" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="8">.. <O T="NE">..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1355
                                                                    Entropy (8bit):4.6355442203324095
                                                                    Encrypted:false
                                                                    SSDEEP:24:2drVCdRgeLrkvqJTSbiwO8biJSbcAR9z7:crVeRgeL4vqJTSmymJSXz7
                                                                    MD5:FB79522887D8EC95F6FBD411355F4622
                                                                    SHA1:31D91405135F28F323998BFBE717E82743486E3B
                                                                    SHA-256:2F90611B0932EADE9D612AEEBB57B19A096AC5FD1C5152002B3854796259A170
                                                                    SHA-512:85BCA8BE19BD7FB79892A6D6EDD56743D3983AFAA97149E893E7F061C20134C16077FDF490539EB78F49FDC9C8489E878D1FD163B7CEDBC4BA1C1A52E5915E1D
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12145" V="0" DC="SM" EN="Office.Outlook.Desktop.Pcx.DefaultAccountLpcMetrics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="86ql6" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="HostOffice365AccountId" />.. </L>.. <R>.. <V V="default" T="W" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="NE">.. <L>.. <S T="1" F="HostOffice365AccountId" />.. </L>.. <R>.. <V V="default" T="W" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="HostOffice365AccountId" />.. </L>.. <R>.. <V V="" T="W" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="CountLpcInstancesWithDefaultAccount">.. <C>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):457
                                                                    Entropy (8bit):5.333279936974253
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd0Vzj2DWg/rUdRDDHwpat5lilr5IqBr1DuNxNO2su:2d0MTUdRgeq5IipDq3
                                                                    MD5:FE61D33F3D575204126EA44A2838C1F8
                                                                    SHA1:5763C43162DD8D3DF63A98A6D58062AECDF8AE98
                                                                    SHA-256:D23543769BF60611AA36FE0A5E36B469434D160A61599F573586A4FB02CF13DE
                                                                    SHA-512:B82602179C30A7DD27FFEF05A0E1A2B9E3FFDFA07C45FF8BE590C2D0C0D253C78D7817E89887D84D8F8B119C0B6A60A91C291C09AEC50BF9F78BE0D20A1455A7
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12146" V="0" DC="SM" EN="Office.Outlook.Desktop.MeetingInsights.Direct3SPaneRenderTime" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="20" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="914" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. </S>.. <C T="U32" I="0" O="false" N="RenderTimeInMs">.. <S T="1" F="RenderTime" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):2689
                                                                    Entropy (8bit):4.135602363895752
                                                                    Encrypted:false
                                                                    SSDEEP:48:cQmKrRgesvu3FztVPzOpRYFYVAzZIPHh8:TRgesvuVzPz2LVCZIfG
                                                                    MD5:AB423D6F80619B71FCEBF9BF2F5903C2
                                                                    SHA1:150C13FECD74DAFB231E209DA5EFCE75F9D59F3B
                                                                    SHA-256:3CC22B8578DDCD7BDD8CD2324E1E8A288133927D47E10A56A22922D378ED2FC2
                                                                    SHA-512:9D400E1C4FC51922892225FEBD65BBD35004777371BE64E20D7DB6A3CA1A6D166AE66752B8DD8C24A26643031B128C10CE6C6A644C053DBB140B2FB2E88FCA6E
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12148" V="2" DC="SM" EN="Office.Outlook.Desktop.ShareToTeamsMultiWindow.Usage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" SP="CriticalUsage" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="23414" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <F T="2">.. <O T="OR">.. <L>.. <S T="1" F="IsSTTMWLaunchSuccessful" />.. </L>.. <R>.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <S T="1" F="IsSTTMWFeatureEnabled" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </L>.. <R>.. <S T="1" F="IsSTTAgaveLaunchSuccessful" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="3">.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <S T="1" F="IsSTT
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1330
                                                                    Entropy (8bit):5.151852989240321
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dvmEHhdRgeTMgYVR5r1R+LlJOjSJPpEAEP9oU6Ui:cvm+RgeT/q8LlJOjmZrUy
                                                                    MD5:6A0D492980745804FC9D0CDE71B9E128
                                                                    SHA1:F50A2800FBF8E7893B9EDEDF3C94740FB2400EFE
                                                                    SHA-256:64B0664250CAA8EFB01E919F5B8497A3A7927FAEC2737EDB298A751A282DCCBD
                                                                    SHA-512:4167BC6C97C0FFF9F4EAFACFF556394013190C7AE864F26DB9363AD13F3D20ED7AAE2852F019A9DF703A968A023790F75A5EAB8A49AF3BA89F91A856FE5F6E97
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12149" V="0" DC="SM" EN="Office.Outlook.Desktop.ShareToTeamsMultiWindow.LaunchInfo" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="23413" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="I32" I="0" O="false" N="OperationResult">.. <S T="1" F="HRESULT" />.. </C>.. <C T="G" I="1" O="false" N="CorrelationID">.. <S T="1" F="CorrelationID" />.. </C>.. <C T="U32" I="2" O="false" N="AttachmentCount">.. <S T="1" F="AttachmentCount" />.. </C>.. <C T="U32" I="3" O="false" N="CloudAttachmentCount">.. <S T="1" F="CloudAttachmentCount" />.. </C>.. <C T="U32" I="4" O="false" N="CappedDeeplinkLength">.. <S T="1" F="CappedDeeplinkLength" />.. </C>.. <C T="U32" I="5" O="false" N="UncappedDeeplinkLength">.. <S T="1" F="UncappedDeeplinkLength" />.. </C>.. <C T="U64" I="6" O="false" N="ClickTime">.. <S T="1" F="ClickTime" />..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1031
                                                                    Entropy (8bit):4.708430785093056
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dUVqdRgeiIimvS8TRhajqwOaRhaiuJE7:ckmRgeiCvS8TR+qQRoJE7
                                                                    MD5:A4844B1B6D2DC1EF5E5D2D74B65C5209
                                                                    SHA1:3EDD8DBC37513218B2BB51450A520D007D7C6E6A
                                                                    SHA-256:3131D265BB6F8983DFEB4448DD79B6AF88734694116046C32552ADD612285DB6
                                                                    SHA-512:85EFA9A80BE91F259587BB9298F5B43DC174015027A4340115CE48632B82B65A7704286580FEE385A0E7E4B720C3108A8E4E8791C2D8FF00929509B3CEF798E1
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12155" V="0" DC="SM" EN="Office.Outlook.Desktop.Calendar.ToggleEMOSetting" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="848" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="EMOSettingState" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="EMOSettingState" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="CountEMO_Enabled">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="CountEMO_Disabled">.. <C>.. <S T="5" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):788
                                                                    Entropy (8bit):5.112021796527143
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdbVzjNW7dRDDHwpatEiiGIqB2c1NQzD0M+SfRcSZGx9p6gCclXHaSMNO5csu:2dbS7dRgef5IirqkfVlu
                                                                    MD5:5FE5820D254EDD082FCA849E9153DFA9
                                                                    SHA1:78F030BBE199731441021447E14639BC030B3F86
                                                                    SHA-256:DA87098A7E112792DD693801FD8F0700101F8A89A9F10EA72715363C27F3EBB4
                                                                    SHA-512:64362E03DA8ED13E0CD79BA45EB3969F75969418E086A45687A0A1EE326EAF9A5829B941122E799DFD623370D1350842AD36558CCC4D07F6462E2B41881CFF84
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12156" V="0" DC="SM" EN="Office.Outlook.Desktop.Calendar.WriteEMORegistryError" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="850" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="HRESULT" />.. <F N="CONTEXT" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="HResult">.. <S T="1" F="HRESULT" />.. </C>.. <C T="U32" I="1" O="false" N="Context">.. <S T="1" F="CONTEXT" />.. </C>.. <C T="U32" I="2" O="false" N="CountEMOWriteFailure">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):852
                                                                    Entropy (8bit):5.146587954935496
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd2VzjNHcdRDDHwpatE2IqB2c1NQzDGNtvxfxuE+MnBxOstvxyp6gG0CHaSMNR:2d2YdRgePIirquD+wKG0R
                                                                    MD5:9E9094B652816FD20035EF7562B72D7A
                                                                    SHA1:B1CDA5DED7A6CD31D3621E3F853F9F088A5AFF11
                                                                    SHA-256:D646D165C7485A8C0833CFF4A11BB2B1C888E5F9C49B4D51446ECD9F8F7F8156
                                                                    SHA-512:6DE1D7A337629AAB04E2551AA6C02037218796479F849AFC326F70C4FB926A6C3E36E657C69F4D4CCB25AFAEE3D09FF984928FB7CC39FC016AFB6E119C44C3A4
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12157" V="0" DC="SM" EN="Office.Outlook.Desktop.Calendar.EMOSettingVisible" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="849" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="EMOFlightEnabled" />.. <F N="minTeamsVerInstalled" />.. </S>.. </G>.. <C T="B" I="0" O="false" N="IsEMOFlightEnabled">.. <S T="1" F="EMOFlightEnabled" />.. </C>.. <C T="B" I="1" O="false" N="IsMinTeamsVerInstalled">.. <S T="1" F="minTeamsVerInstalled" />.. </C>.. <C T="U32" I="2" O="false" N="CountEMOSettingVisible">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):583
                                                                    Entropy (8bit):5.217204375358035
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdsVzjNG6dRDDHwpatENHc1NQnvjEXHaSMNO5AHNUlu:2dstdRgeLqvjE07
                                                                    MD5:36E8461CDFD0C360E80164D19D076493
                                                                    SHA1:473F23571FBE168C8CE7BA2BFEC9DA33D829B9AD
                                                                    SHA-256:77F746198E8A7C4C17E4FD73698DB5E331E116F72BB3C03172CC0077D4654C5F
                                                                    SHA-512:AA56D55623CA47F4D36A2D6DFF48C4B8CF45111A26821BAD25040072D0A3DB7AC8114A5A2FCF573B4CCAB854D75D8FFE496B30C03259023D23381FBF9CD428A6
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12160" V="0" DC="SM" EN="Office.Outlook.Desktop.Calendar.WeatherLocationPickerUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="386" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="WeatherLocationChangeCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1832
                                                                    Entropy (8bit):4.6361679992123035
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dr8gdRgeIvS8TR+aIwOaR+abJR+aghN5NiNNjNpNb8u5U1u9F:crTRgeIvS8TR+rQR+YJR+9D+Z7hqGF
                                                                    MD5:82908D07E121BC91D47FDBEB4CC68A72
                                                                    SHA1:94D4F306BB4E44B929412E2430C75E7B5E2FCF71
                                                                    SHA-256:3BCF9DBB5FE1DDB2DED6EF0AC0B414FBC98B37D910C467E6B8E65FDD5A40F1DB
                                                                    SHA-512:869A82657C012E44D5819B739EDD755FAB7639376645F893987BDB4597919B8FEE6A989149A63D731F1FD183B461EDFC08F4B1B484CEC1E04C5CC1D35FA72709
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12161" V="2" DC="SM" EN="Office.Outlook.Desktop.LinkHandling.OpenOfficeUrl" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="4309" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="ExtensionType" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="ExtensionType" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="ExtensionType" />.. </L>.. <R>.. <V V="2" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="1">.. <F N="AccountUID" />..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1284
                                                                    Entropy (8bit):4.530359527050665
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dedsJdRgeLr9qJTlspIwOalspbksp7bO9z7:ceCTRgeLBqJTaiQaNLUz7
                                                                    MD5:E91F51346A5385C7D1D604249B221305
                                                                    SHA1:887723C955EEC12B94455443127E3F534F853A4E
                                                                    SHA-256:42C98E67458EA7E61E7D95F3170069DD12B9FBA8A9800BC1C1777774468369DB
                                                                    SHA-512:17A647C7B7A08B53D200C4D35132DE6D71A7E610B3931FE869343B537808802CC8DED52721579E3501A8E524D9BDC9C1F57745C8DD00783ACDC06B732D5D0D63
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12162" V="0" DC="SM" EN="Office.Outlook.Desktop.Pcx.ComplianceEnvironmentLpcMetrics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="8qpmh" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="ComplianceEnvironment" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="ComplianceEnvironment" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="GT">.. <L>.. <S T="1" F="ComplianceEnvironment" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="UnknownCount">.. <C>.. <S T="4" />.. </C>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):2491
                                                                    Entropy (8bit):4.770504797029131
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d2BmmN6dRgeTvuXLgyzKsIiCD4gSeNQf1xou1KH+PwRwJR5UzZHNe/HfIKIQ:c2mU2RgeTvuXgBtNC9qbtKMZb7Q
                                                                    MD5:573FA5483D1EBDB868FE455483C71BC6
                                                                    SHA1:ACA1C1300819480D14D33368D7D89301A9A5ABA9
                                                                    SHA-256:ECBFB41474FE0695A305400741E4BEFFED3E390C2DC99A8EF31A2AB9C7886DDD
                                                                    SHA-512:C724B4F96AFF89A20A9DD1798E4DA59F6DAD16D8E757E0C811BB387728DAE4912106BA39ADAAA65B798AD179E2EDCC378DC67516053F7A595297F29DA84AB368
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12170" V="1" DC="SM" EN="Office.Outlook.Desktop.ShareToTeamsMultiWindow.FailureContexts" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="23414" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <F T="2">.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <S T="1" F="IsSTTMWLaunchSuccessful" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </L>.. <R>.. <O T="OR">.. <L>.. <O T="EQ">.. <L>.. <S T="1" F="IsSTTAgaveLaunchSuccessful" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </L>.. <R>.. <S T="1" F="IsSTTMWFeatureEnabled" />.. </R>.. </O>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):829
                                                                    Entropy (8bit):5.101942169050815
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdKVzjFw516dRDDHwpatEerzc1NQzDhw3yNftXHaSMndi+HKpZMGE+SBMNO5cz:2dKnw516dRgeLr6qhNvV
                                                                    MD5:7C153DA1DA229614448960C278CDB3CA
                                                                    SHA1:DF3FDC96B754AA266787FA19A83B5D7A771EC485
                                                                    SHA-256:CD52F3607B55144F15DB386600C6724649E74B078B118E138844E9D3C8BDD9E4
                                                                    SHA-512:EF3623C9586357CA8064941E5318B64DEEFCD235B5D9A78C7DA2C35A0700CAA6EDC2FFD98A0F536E8A2C52F2CC959B3E2526CEAABE42843B72A05E4144A1A9AF
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12171" V="0" DC="SM" EN="Office.Outlook.Desktop.OneDriveTransportGetLinkInfoRONodeAttempts" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="8prv3" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="HadToUseRWNode" />.. <F N="Read Only Node Retries" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="FunctionCallCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="B" I="1" O="false" N="HadToFallBackToRWNode">.. <S T="1" F="HadToUseRWNode" />.. </C>.. <C T="U32" I="2" O="false" N="RORetriesBeforeFallback">.. <S T="1" F="Read Only Node Retries" />.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):455
                                                                    Entropy (8bit):5.367488168268504
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd9VzjIHtN0dRDDHwpat5DVdqGKa8xOI/a8xyNO2su:2d9gedRgekWht
                                                                    MD5:4F9B5727DD7A1BBD46ED780E2B47A7C9
                                                                    SHA1:13421235AC57E9B6E16179302DAB8B698F1945BF
                                                                    SHA-256:3E7CAA6ABE95D00948E66278CCA908A7AA774C5843A7A40202CB0361C85794AA
                                                                    SHA-512:8FC65BC73AA1A4B976389FCA0CB0223928473A21A46685345E9E82E44B0B457D4C905DE4E482CC5B4F42AD24C26C185AF34B2128BB1170011F20658F7E97B9CC
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12172" V="0" DC="SM" EN="Office.Outlook.Desktop.OPX.WebHostingEnvironment" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="1" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="372" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. </S>.. <C T="B" I="0" O="false" N="IsWebview2Installed">.. <S T="1" F="IsWebview2Installed" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):556
                                                                    Entropy (8bit):5.255743111025562
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd+uVzjNXzLdRDDHwpatpBj2GeOJjILTMLNLNO2su:2dXrdRge7jvLG6n
                                                                    MD5:710DCDE6B90B91F71736A9D69BDA4C78
                                                                    SHA1:6FFAF330E9CA7ACF45AEEC8C777F4F21A1A84442
                                                                    SHA-256:545ED21B171CBE2C5CE5D6AB9A559741BAEFB41AEB10150568B71D240948B6C9
                                                                    SHA-512:47663FDC7D3398F370EB1220B588C100BAEE031108D50D657CCB79E9D897BBF2338BE5E511C0A1322492AFD6A5D1A15AFF5F457310D38BA7DE2F6414217432EE
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12175" V="1" DC="SM" EN="Office.Outlook.Desktop.Calendar.RESTCalendarEnabledSource" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" SP="CriticalUsage" S="1" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="211" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. </S>.. <C T="B" I="0" O="false" N="IsRESTEnabled">.. <S T="1" F="IsEnabled" />.. </C>.. <C T="U32" I="1" O="false" N="RESTEnabledSource">.. <S T="1" F="Source" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):862
                                                                    Entropy (8bit):4.958715800579393
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdRYVzjMO7dRDDHwpat4AQi+ic1NerUerdOerXXRXHISMCXHfSMpiXHfOSMNOB:2dm+0dRgeEfYrbrPrxVW02
                                                                    MD5:31046DC166A680F2D236EA862E4D94DF
                                                                    SHA1:C261AF530A6691A4ADA540F6E792BD8CC8D53F84
                                                                    SHA-256:4803C51AB490362043BB2B219D0C65079AFC8552EF60ACB23718C424984651A2
                                                                    SHA-512:C6A0DF770DFB98F247FB25135F8BEDF482E5B13A6F7E2EFDA7011C6D166FCB3B084494D0327A343231AB7E8A67107B344733E4EC51CF3E901F2E45566CA818A4
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12180" V="0" DC="SM" EN="Office.Outlook.Desktop.Pcx.CCHeaderButtonClickedUnsampled" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <UTS T="3" Id="blek8" />.. <UTS T="4" Id="blek9" />.. <UTS T="5" Id="blela" />.. </S>.. <C T="U32" I="0" O="false" N="ButtonIMClickCount">.. <C>.. <S T="3" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="ButtonPhoneClickCount">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="ButtonVideoClickCount">.. <C>.. <S T="5" />.. </C>.. </C>.. <T>.. <S T="1" />.. <S T="2" />.. </T>.. <ST>.. <S T="3" />.. <S T="4" />.. <S T="5" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1822
                                                                    Entropy (8bit):4.296109398778628
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dgYY24dRgeFJqJTUsNZb4wOaUsNZoNJUsNZHMSYvROMOY7:cLY2QRgeFJqJTLUQLgJLy5n7
                                                                    MD5:3869BCC783B800DD292715287B133C22
                                                                    SHA1:D12ED834F84298AEFB3E4D953675F8F2DEE90DDB
                                                                    SHA-256:A8D6A3F626E92ACAE8021681052BA9F3393BE0DDEA012E91C39F6FBC2D401F2A
                                                                    SHA-512:C3C24B36B783386CBE2FF90A8BFD66EE937A68E72CDA338ABF3968D4AC9DD6C7B1F671797940CE314272A305F617BCB96398FBD969C2FBDD9A6BD18853020E1C
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12181" V="0" DC="SM" EN="Office.Outlook.Desktop.Accessibility.A11yCheckerImpOptions" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="15021" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <O T="BITWISEAND">.. <L>.. <S T="1" F="AccCheckerMode" />.. </L>.. <R>.. <V V="64" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <V V="64" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <O T="BITWISEAND">.. <L>.. <S T="1" F="AccCheckerMode" />.. </L>.. <R>.. <V V="128" T="U32" />.. </R>.. </O>.. </L>.. <R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):4672
                                                                    Entropy (8bit):4.1334781714402995
                                                                    Encrypted:false
                                                                    SSDEEP:48:cUY0bLRgeyqJTLPn0QLMJLmuMq6+sJqJ0/wqfXuFV5qlF0BaJWGJwkdkWJ6+RPJB:Y+RgeZfsWMhmmzDiPf+c1BwkGi6wF/7
                                                                    MD5:0E515453A47F9BC47D537F3922D13542
                                                                    SHA1:B91BB53EB2D61FE7B18CF63A558F95A3A4EF734A
                                                                    SHA-256:BAD8DD5A2474160DD9342C1D6D1EDCEF2319E9F7AA2F60F8CC4D16291AC28A5F
                                                                    SHA-512:29A0A6FEF51B547809D779F0E348C523EC71AA3C1D0D30F2876208E200FDEE51E8792C5846204B71BC9506EA6C567AE06F9CC6CE8A1E7B7A9CE87D5D84D83082
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12182" V="0" DC="SM" EN="Office.Outlook.Desktop.Accessibility.A11yCheckerImpUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="15022" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <O T="BITWISEAND">.. <L>.. <S T="1" F="AccCheckerMode" />.. </L>.. <R>.. <V V="4" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <V V="4" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <O T="BITWISEAND">.. <L>.. <S T="1" F="AccCheckerMode" />.. </L>.. <R>.. <V V="8" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <V V=
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):5680
                                                                    Entropy (8bit):4.0572764861361135
                                                                    Encrypted:false
                                                                    SSDEEP:48:cLCrRge6JJyuJvEsN7fTG2/KfyHFVcIVVinTGqrdic0i5GWEVOU:LrRgeAYacETbCfKHckViTrwc3n3U
                                                                    MD5:43D8B0799AB021D1D16E61E95B4E62DE
                                                                    SHA1:0FF48C463605A43E7632A0ED6B4AE11BE8A24AE8
                                                                    SHA-256:33379BDE2FE26F37EF6FF8C8993F90AA9BE89DBCD339AFA937EDCD739F3AA954
                                                                    SHA-512:58DED32166A49805F10FF6A1AC1F15057A8D15A55ED615BF2146DDB9636E1951CD86C85D9E214CFF65A53AD2524D64C5E265AC9C9A4719D9E5984930F08971F3
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12184" V="1" DC="SM" EN="Office.Outlook.Desktop.TeamsIntegration.ButtonUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="337" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. <Etw T="2" E="339" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. <Etw T="3" E="341" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. <Etw T="4" E="342" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. <A T="5" E="TelemetryShutdown" />.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="ButtonId" />.. </L>.. <R>.. <V V="102" T="U64" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="1" F="ButtonId" />.. </L>.. <R>.. <V V="103" T="U64" />.. </R>.. </O>.. </F>.. <F T="8">.. <O T="EQ">.. <L>.. <S T="1" F="ButtonId" />.. <
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):587
                                                                    Entropy (8bit):5.210740491167509
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdXVzjNJKmdRDDHwpatEOqFIqB2c1NQnAtKF/HaSMNO5AHNUlu:2dXomdRge2IirqFFs7
                                                                    MD5:9635D5FFAB1C2E78287F4DDADD841639
                                                                    SHA1:DB96D9F5E559B51511989F983ACA434214BD2933
                                                                    SHA-256:74C03E20FA763F4F5AEEE6A1461293C62DF23B0897CEA73977DB78E80C11C4A8
                                                                    SHA-512:A1A34BDD9F24FAE6A1337911358B86DEEA06BC0D32467CDFDBD42922B491C3A397FA79E228A19AB9E3BAD1E1979CF8061D394507FC8DFD27776A8E34A585D904
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12185" V="0" DC="SM" EN="Office.Outlook.Desktop.Calendar.ShortenEventsInfotipShown" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="1032" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="CountShortenEventsInfotipShown">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):765
                                                                    Entropy (8bit):5.144724565226951
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdPYVzjN9+6dRDDHwpatEQIqB2c1NQzDyOfUfHxjZcHaSMNO5AHNUlu:2dAJhdRgezIirqqFPX/7
                                                                    MD5:BABB601FBE23C7219CF821F3D9BAA200
                                                                    SHA1:174C2B1F708D678B6F65DE286787A0A0FE94C6EB
                                                                    SHA-256:7741CF83DBB62BBA5BC2522ABFC0193CD94E591536B706C928C696E0779BE2E8
                                                                    SHA-512:F60F2084EF66539782960E132BDC3C21B84F7B42DBD05CC049F0106E0AB363809B1016365B79EE6A5F4090BC87A7747065D39E95859E401A159BCA0BEF9AF386
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12186" V="0" DC="SM" EN="Office.Outlook.Desktop.Calendar.ShortenEventsInfotipUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="1033" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="controlType" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="ShortenEventsInfotipControlType">.. <S T="1" F="controlType" />.. </C>.. <C T="U32" I="1" O="false" N="CountShortenEventsInfotipClicks">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):806
                                                                    Entropy (8bit):5.112760209784194
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdeVzjNNR4KdRDDHwpatEV1DXFJicouDi6qObWIxN9lnTofsQxpw/OnXHaSMNR:2deAKdRgeivSPVLIxLxToRUou
                                                                    MD5:B339E8632BAF12EB6BB450AB53DC7EEF
                                                                    SHA1:A37D7EF691409D7F8D2176A7129A864CFCC69DB7
                                                                    SHA-256:78A797300D97239B64663CD61D969455C8B5857B6998D9AF06A2B4374DF90924
                                                                    SHA-512:D031368F5CAAE15310922DE95F3E515BF26D52EFB890D63DE83806C0865EB36862564D5244C53EFDC180F906512DBFC9649DA410D2FE822BB8B2CFAAD36E8E12
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12188" V="0" DC="SM" EN="Office.Outlook.Desktop.Calendar.LogNetUIDatePickerResizing" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="1202" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="Columns" />.. <F N="Rows" />.. </S>.. </G>.. <C T="I32" I="0" O="false" N="DatePickerColumns">.. <S T="1" F="Columns" />.. </C>.. <C T="I32" I="1" O="false" N="DatePickerRows">.. <S T="1" F="Rows" />.. </C>.. <C T="U32" I="2" O="false" N="DatePickerResizeCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):685
                                                                    Entropy (8bit):5.158310709665532
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdcVzj9dRDDHwpatEerPOc1NQzDKdffA0hh/HaSMdpO9yNOAjsu:2dcHdRgeLrPDqidf7ypcA
                                                                    MD5:4313C4D9BF3EF0E96C123836CC518ACC
                                                                    SHA1:040C6B64D75F2579F93E8CAE68549DF45CFA489B
                                                                    SHA-256:DCE4F71AA06789BD0E5CDCCBEAE6B1350088B51C52652D6B074127677C8CE001
                                                                    SHA-512:A2A401C77489A6F04E6E38EF4B2AB5CD8383460E12706A94B5569F4AF62A2867D470BE70E65F51C08E9C976A05314E00D72067674F2EE143A12AA746282FA957
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12199" V="0" DC="SM" EN="Office.Outlook.Desktop.Pcx.LpcReactHostJsExceptionCallstacks" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="7mzcq" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="Callstack" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="CountLpcReactHostJsException">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="W" I="1" O="false" N="LpcReactHostJsExceptionCallstack">.. <S T="1" F="Callstack" />.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):833
                                                                    Entropy (8bit):5.174399237244438
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdISVzjbdRDDHwpat5lSdYdqqeWOA6ydnGhFxfh3tB1/JMneacSJ9d+DhfCdN7:2dtNdRge2qLJGh7fhlBB4f+BE
                                                                    MD5:346C86818A1A8F921F9C391E726A651E
                                                                    SHA1:C0960225DCF8042332BD95DF7998ADCC52251F4B
                                                                    SHA-256:4DFD8CFD1E723F778E179113C956AAC8439AC5957961F5D6D7195756EFF61284
                                                                    SHA-512:C654E606E35BCF6BDD74E76D13A28090D4CE878F36F73B3B6D6CD58E9D2F11CA819BF68B6DE913F70AFBF61E931EDA28D4CAA58DA6A75613835268F83816FE4B
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12201" V="1" DC="SM" EN="Office.Outlook.Desktop.MetaOS.AppHostStopScenario" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="200" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="818" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. </S>.. <C T="W" I="0" O="false" N="AppHostAppID">.. <S T="1" F="AppId" />.. </C>.. <C T="W" I="1" O="false" N="AppHostStopScenarioName">.. <S T="1" F="ScenarioName" />.. </C>.. <C T="I32" I="2" O="false" N="AppHostStopScenarioDuration">.. <S T="1" F="Duration" />.. </C>.. <C T="B" I="3" O="false" N="AppHostStopScenarioResult">.. <S T="1" F="Result" />.. </C>.. <C T="W" I="4" O="false" N="AppHostStopScenarioSessionId">.. <S T="1" F="SessionId" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):841
                                                                    Entropy (8bit):5.205592853036668
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdxVzj35ldRDDHwpat5lSPdqqeWOA6ydnk5fhFxfh3tBk5i/JMak5OmNE2d+DG:2dxNDdRgeI0qLJk1h7fhUIB6Ee+2UE
                                                                    MD5:E186E299A24EBC00FB6B6F6EFFD40C0E
                                                                    SHA1:4764D03AF4F4494FF5524A8C830427EE3EBF4182
                                                                    SHA-256:3D44E10156E78F5A24138D8D4783567A4BB63BEE3A97E5801C562AEE405F2FB6
                                                                    SHA-512:9B4F5FFD489BC81C2BC2AD619F708EA3424134D2A7F7AEAB72ACE24559378AEAEF1679F9B0B0D661DBAB13A7654EDC2D909367BD36ED198C824DE23498CC2E68
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12202" V="2" DC="SM" EN="Office.Outlook.Desktop.MetaOS.AppHostFailScenario" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="200" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="819" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. </S>.. <C T="W" I="0" O="false" N="AppHostAppID">.. <S T="1" F="AppId" />.. </C>.. <C T="W" I="1" O="false" N="AppHostFailScenarioName">.. <S T="1" F="ScenarioName" />.. </C>.. <C T="I32" I="2" O="false" N="AppHostFailScenarioDuration">.. <S T="1" F="Duration" />.. </C>.. <C T="U32" I="3" O="false" N="AppHostFailScenarioErrorEnum">.. <S T="1" F="ErrorEnum" />.. </C>.. <C T="W" I="4" O="false" N="AppHostFailScenarioSessionId">.. <S T="1" F="SessionId" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):796
                                                                    Entropy (8bit):5.177964682243065
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdjVVzj2DW6BdRDDHwpatEtNXswbswcoNBnVWVXHaSMiWMXHhSMNO3AHNS7lu:2dRUdRgeuXsGs0v+R9r
                                                                    MD5:C8983474381807819DB4D57B25CC5F37
                                                                    SHA1:10A43E15DD5EB65DCD079FA5FE3089AAE7428578
                                                                    SHA-256:65001455E3E34B89AE96A230601FD13E251C2136121B65C9B929D5D39D23A524
                                                                    SHA-512:19071CAE83DFF6238FE4FD7E92142C9CAA75A4FB8D3BD4D6F1CAC8E0F7443F1CE91E53DDDF914AA0D6709CFECBBF85CEB37B4AE1FB6657FD342A5781EE255AB8
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12208" V="0" DC="SM" EN="Office.Outlook.Desktop.MeetingInsights.PrefetchCallReliability" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="7188" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <Etw T="2" E="7189" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <TI T="3" I="Daily" />.. <A T="4" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="InsightsPrefetchCallSuccessCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="InsightsPrefetchCallFailureCount">.. <C>.. <S T="2" />.. </C>.. </C>.. <T>.. <S T="4" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. <S T="2" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1260
                                                                    Entropy (8bit):4.685064576431716
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dml3dRgeIvS8TRjqwOaRiqosbdfPwYOa:cmltRgeIvS8T1qQ5/bdfPV
                                                                    MD5:5A2768987F6533758F0D59EEB3F01868
                                                                    SHA1:8D8B6690D6855222E5FBFC3DF9AC665C511D693E
                                                                    SHA-256:A712F291193BF9CDAE69FF334FEBE3DD12D33659A87A8CCD44B394CD93FEED37
                                                                    SHA-512:54F6E63691049EC97BC2A42FA6D2BA60BE2491BFA6CA3C63A43F53488632B4CA39E82B32D1B71CBBB8DBCD967D3043C4D86E2DCE81BE3026057511C62277CC12
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12210" V="0" DC="SM" EN="Office.Outlook.Desktop.Groups.OpxNotificationResultUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="19049" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="isSuccess" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="isSuccess" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="4">.. <F N="Scenario" />.. </S>.. <S T="5">.. <F N="Scenario" />.. </S>.. <S T="1">.. <F N="Scenario" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="ScenarioNumber">.. <S T="1" F="Scenario" />.. </C>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):2024
                                                                    Entropy (8bit):4.72870948370223
                                                                    Encrypted:false
                                                                    SSDEEP:48:cL3hRgeZTqJT6mqQ6eJJmizEBSUOJ6n+zlir:ShRgeWW5reHze+Y
                                                                    MD5:FDAF3F16CB7979C3660C6316DC04EE68
                                                                    SHA1:D5AAB3B6E8047B768C993FDD91308AEC50E63677
                                                                    SHA-256:0439EDF1EC789BD77ED644323FB27875792C4AABFEBFE8A85B3EB72CBC245A87
                                                                    SHA-512:B549DF11480BC9642165C7C64D6BCFA2FC1DAC002AB5690C5C6FE607C6D1508AF744B388AA4F339B2006574BB440AFC18CAE162EC08A059D1793812C0FB8F3F7
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12211" V="0" DC="SM" EN="Office.Outlook.Desktop.Authentication.EwsFallbackAuthenticator_AuthErrors" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="355" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="StartedRefreshInFallback" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="StartedRefreshInFallback" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="5" F="EndedRefreshInFallback" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="1">.
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):525
                                                                    Entropy (8bit):5.276476372202683
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdjVzj2DWwkdRDDHwpat5Gp3IqBr2aAGbI/JMNO2su:2djbdRgeCIiSWcBk
                                                                    MD5:AE4BEA0D342EFA31276D45560E749D91
                                                                    SHA1:DBEE1DBAFFC1D15A438174EDEFF7C31C82879623
                                                                    SHA-256:DFA6000EFE34F7C08589C02240287799C8B2F9F3DA7B7D684BBB2E0D0158F30D
                                                                    SHA-512:1290C36BAFF141B11614467EE41C759968924145D2ECBD725E07423121213C430558F54C43A54F35434E65EFC69763F23E39FB70E636C10EE3BDF9664F2AAFCD
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12219" V="0" DC="SM" EN="Office.Outlook.Desktop.MeetingInsights.PerfMetrics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="500" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="916" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. </S>.. <C T="U32" I="0" O="false" N="ActionArea">.. <S T="1" F="ActionArea" />.. </C>.. <C T="U64" I="1" O="false" N="Duration">.. <S T="1" F="Duration" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1127
                                                                    Entropy (8bit):4.426830692305313
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdVOOnVPn+tNqNOcSX/c//tpONd+kXxH/OcSX/c//tpON+D4fW8/4fWHN4fWWk:2dzN+t4RmIymd3Q6y6fPJmI
                                                                    MD5:8A4530BF828677E682966B0E26ABE836
                                                                    SHA1:FFFEEFED45442B9125EE3BE454F54F4FDFE66749
                                                                    SHA-256:30FEB30E7FA828C828D08EC0B03FE0578F035379BD5A07035716CE65B99F5F9E
                                                                    SHA-512:D40402A22091958FCA541324B92FEFA82A980817949212BD5794D484B31B79A6B9833CB0A93A58ADA186AF8EFB0D9532E699AC8A40A7EF5C6C2FC891E6D62242
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12224" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="436" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <Etw T="2" E="432" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <F T="3">.. <O T="EQ">.. <L>.. <S T="2" F="HResult" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="4">.. <O T="GT">.. <L>.. <S T="2" F="HResult" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="1">.. <F N="AutoDiscoverTaskID" />.. </S>.. <S T="2">.. <F N="AutoDiscoverTaskID" />.. </S>.. <S T="3">.. <F N="AutoDiscoverTaskID" />.. </S>.. <S T="4">.. <F N="AutoDiscoverTaskID" />.. </S>.. </G>.. <C T="U32" I="0" O="false">.. <O T="COALESCE">.. <L>.. <S T="1" F="AuthenticationScheme" />.. </L>.. <R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):2130
                                                                    Entropy (8bit):4.207237673456777
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dqrdRge8rvS8T0IwOa0bJ0gFu0f0v0gs0cIcTAZR96m1pFzccJy7:cqJRgeovS8TNQiJXu60vVstIcmHbx07
                                                                    MD5:AE79CD78EE01F7A6FDB571C20662AA91
                                                                    SHA1:68634C4DE9381C6FD4D527CC2F00B6CCC318FF68
                                                                    SHA-256:4072C55C3419CD74AB23C047520ED1586810FE1E9EE1CE4A0C53BAFA0C488E7A
                                                                    SHA-512:57419AD4A0D5287395AD7E4BFA4A02EAD062BC6724F618FB9BCAF8F888162EF81D6E4D5C4C7AC569D85DE2660DD6B730B226AA674295BEDE12199DB7AB1B2D39
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12225" V="0" DC="SM" EN="Office.Outlook.Desktop.AutoDiscover.AutoDv1LegacyAuthScheme" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="12224" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="2" T="U32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="4" T="U32" />.. </R>.. </O>
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1627
                                                                    Entropy (8bit):4.556074356631637
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdhiOjn+u/qNObX/c//tpONd+tNxH/ObX/c//tpON+D4fW8/4fWHN4ffDG6b9d:2dhR+uykItCd3Q6y1QVEQ1EBCq/aMzrX
                                                                    MD5:2521F3AF0E1469332CF0C3E62656BA50
                                                                    SHA1:C1F2303C87738B07BA48FE24BCDFE1B3FCF04DB9
                                                                    SHA-256:221DBF903A00B022073149D834E9FED51C5C20109EA7055C1E4B41717B0E4591
                                                                    SHA-512:F4F2D560A399247CE09F713A43DE1BC3CAE667CE7FD40A117FAC5C43D3C40669F4D2FEC6E2A6A14C9245DFA5434432CD11A754342F9A862FF59220B4BB7E6005
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12229" V="2" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="583" G="{6b6b571b-f4e3-4fbb-a83f-0790d11d19ab}" />.. <F T="2">.. <O T="EQ">.. <L>.. <S T="1" F="hrReturn" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="3">.. <O T="GT">.. <L>.. <S T="1" F="hrReturn" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="1">.. <F N="AutoDiscoverTaskID" />.. </S>.. <S T="2">.. <F N="AutoDiscoverTaskID" />.. </S>.. <S T="3">.. <F N="AutoDiscoverTaskID" />.. </S>.. </G>.. <C T="U32" I="0" O="false">.. <S T="1" F="hrO365Priority" />.. </C>.. <C T="U32" I="1" O="false">.. <S T="1" F="hrScp" />.. </C>.. <C T="U32" I="2" O="false">.. <S T="1" F="hrRoot" />.. </C>.. <C T="U32" I="3" O="false">.. <S T="1" F="hrAutodis
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):3455
                                                                    Entropy (8bit):4.069742234768909
                                                                    Encrypted:false
                                                                    SSDEEP:48:cp8LRgetvJt4NTiQjJQuZv+sww88/1fyKFthhlWg2BJr457:DRgetRU+EKM2cftfPJT2/rM7
                                                                    MD5:2700FD7B0E03E4DDAFDA492D9FF60D0C
                                                                    SHA1:87A9A8E6B94E330635D796281B40A6FB359FF957
                                                                    SHA-256:B7F2577F7424E9BB1E6FCFB2FDF8E44B54F2D1232B96748F9CE74FF49C8F44FE
                                                                    SHA-512:1B83A5F052A9533098E3DEC20C30AF3D93080AD3A134AB62E31474CD722D1D7ADF23C4C46A521443A1F8704662E101C1F3F3103501EB3ABF0D338B1E68EF7A30
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12230" V="1" DC="SM" EN="Office.Outlook.Desktop.AutoDiscover.AutoDv1StepUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="12229" />.. <A T="2" E="TelemetryShutdown" />.. <F T="3">.. <O T="EQ">.. <L>.. <S T="1" F="0" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="1" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="2" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="3" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):596
                                                                    Entropy (8bit):5.229538628324169
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdrVzjNFFHF6dRDDHwpatE+ic1NOFIqBrA0wHISMNOS/HNClu:2drHHIdRgelfAIijpZ
                                                                    MD5:D555885721852CEF3EB6B3AC5A7C406D
                                                                    SHA1:F1432C8EE6C6DD578BFE05547F4BFD2EACED9F0D
                                                                    SHA-256:7BBD03A85AF040AFC1DA825AA419D2F4839138FE1071CA7DFD9DB29F93E0CF35
                                                                    SHA-512:E39B5B652C85E0AAF3DD34F216E42E15EBBCFF92DDF055B3709D592481525F49FFC24DE8DCBCF786F468B86C6A471BAB7FD46C11EFD19805F494BCA6E54486E3
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12237" V="0" DC="SM" EN="Office.Outlook.Desktop.Calendar.DisplayReadOnlyResponseModeUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <TI T="2" I="Daily" />.. <Etw T="3" E="432" G="{02cac15f-d4be-400e-9127-d54982aa4ae9}" />.. </S>.. <C T="U32" I="0" O="false" N="Count_DisplayReadOnlyResponseMode">.. <C>.. <S T="3" />.. </C>.. </C>.. <T>.. <S T="1" />.. <S T="2" />.. </T>.. <ST>.. <S T="3" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):514
                                                                    Entropy (8bit):4.539174219385522
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdTOqY1D+u/qNOD7X/c//5mMpONGDkNO/HNUlu:2d7buyYbu7
                                                                    MD5:845B6FA277B39062E38FB080805246D3
                                                                    SHA1:2FAF9AF44A21D37D068CE05D344EA6F3EFCEED1B
                                                                    SHA-256:8B54DEF7EF9BB95CC818B7559F295F713582AA22072B5266D850E5BFF810DE46
                                                                    SHA-512:93BCCBE4BF86F795F6828AB5E1D6C5FF5AC6ACF0939AC3708CD881F611C9AE0355D7F226C5D3E1A0877FFD47AB85529E9AE542EBE912D0A9CE09E7B3E2F5FE8B
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12240" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="1310" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. <F T="2">.. <O T="EQ">.. <L>.. <S T="1" F="Reason" />.. </L>.. <R>.. <V V="ribbon-FailureToQuit" T="W" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false">.. <V V="0" T="U32" />.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):6198
                                                                    Entropy (8bit):4.559969880489392
                                                                    Encrypted:false
                                                                    SSDEEP:48:cbbxRge97uySeTN2SwB/9fyUFnIardLvK3u+dyUfvmGNlezEcJNGjIL/kzks2d/2:kxRge5ueASwBVfxtxrIoUXmGjc1uHl
                                                                    MD5:79E98EDC710B8A010D1E7C740ECF81F4
                                                                    SHA1:EF7B789BDF3847F3458F5529A8DFB45A42160383
                                                                    SHA-256:873CA5AED2BDCF903A758B50767B58F665F0C4DD6F04F0BFFB98258E2054373E
                                                                    SHA-512:F3C84A0B8DDF4815D61AD1D8A625BEA49808BD276D3458522D582F8212159793AC35940AFFA7CEF250A6EF4D5DEA6D6B4041F4151F988CB13AB11B93DBD09A1F
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12241" V="3" DC="SM" EN="Office.Outlook.Desktop.Monarch.ToggleFunnelData" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" SP="CriticalUsage" S="32" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="1306" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. <F T="2">.. <O T="EQ">.. <L>.. <S T="1" F="ToggleFlightEnabled" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. <Etw T="3" E="1307" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="3" F="NewOutlookInstalled" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. <Etw T="5" E="1308" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. <F T="6">.. <O T="LT">.. <L>.. <S T="5" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="I32" />.. </R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1407
                                                                    Entropy (8bit):4.551544748408868
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d24OdRgeTbvLqvS8TbjqwOarjqJamFj8QsuEP9J7:c/yRgevOvS8TPqQfqJLxp0lJ7
                                                                    MD5:D67A1568D0A315E275884052D6A0B09C
                                                                    SHA1:2F9701FD8DA6079404B10A927F09EF90A90BBEB0
                                                                    SHA-256:E446B09050FB5DE3092D864565A51543BBD5EA6E01FD68581F93DAB25BC921C0
                                                                    SHA-512:B768080EAAC9DEF2A9E7A12CAA82D2B65526D3AAC1070076502DCD1C13E735751CEE4B1AED1A5097355503F822452A3594D2157394E7DA189E52FA2061F689E2
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12242" V="0" DC="SM" EN="Office.Outlook.Desktop.Oab.OabXmlDownloadInfo" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="1105" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="Succeeded" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="Failed" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="1" F="Aborted" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="DownloadAttemptsCount">.. <A T="SUM">.. <S T="1" F="Downl
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):2759
                                                                    Entropy (8bit):4.343024330420551
                                                                    Encrypted:false
                                                                    SSDEEP:48:cKJrRgeQOvS82QCqJgquaqvrtqsreq8rnq/ro7piFxcm7:brRgeTb24J2jM8xMqzBFxN7
                                                                    MD5:85A9352B69AB30431E0168ABBB7C546F
                                                                    SHA1:602832FC3A8F62F73B5C07663DFADE41B92D529F
                                                                    SHA-256:E15950F616BAB096988C99A00A60E0032ABE7843F7526F11D4405C1C987C433D
                                                                    SHA-512:6BC8F1FD65DFCE9F60D3BEBDE776D3F65173C8B4B1D50DE1C8188CB898D019204CEE5AB89ED99B79B411221F897DAFEE1C219E0B0169FC00B83361C9F270DAE8
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12243" V="0" DC="SM" EN="Office.Outlook.Desktop.Oab.DownloadOabInfo" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="1106" G="{aa8fa310-0939-4ce3-b9bb-ae05b2695110}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="OR">.. <L>.. <S T="1" F="NeedOABListUpdate" />.. </L>.. <R>.. <S T="1" F="SyncOAB" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="4" F="NeedOABListUpdate" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="4" F="AutoDownload" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="4" F="SyncOAB" />..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):2118
                                                                    Entropy (8bit):4.266147705251687
                                                                    Encrypted:false
                                                                    SSDEEP:48:cRg8CBRgefYEvS8Od7cw/AOQeJPuQYvQ4TfX7/B7:d8CBRgenbiz4O/tNY4kfL/B7
                                                                    MD5:3285FB3D066A355A36EA02C540EC365A
                                                                    SHA1:0B9411A7701EF66F0C2ACE5C60E34E16EC187E41
                                                                    SHA-256:A8D9B92AC4FAFE9186CD74747B1B089ECD68415AA5F447C8D670D70EC1EE2B13
                                                                    SHA-512:9857697D0BFFBBA7889CC84F139E550D6F23F59A565D64051389B120BEB25B8234975E411DEF3F77B2C2FED81BCE5E827A667CE027C2D03EEFEEAEF57A89E32B
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12244" V="0" DC="SM" EN="Office.Outlook.Desktop.Search.ServiceSearchResultProviderReport" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="7190" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. <F T="4">.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <S T="1" F="IsAutoFanOutSearch" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </L>.. <R>.. <O T="EQ">.. <L>.. <S T="1" F="RequestType" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="4" F="ProtocolVersion" />.. </L>.. <R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):856
                                                                    Entropy (8bit):5.100596213990636
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdF4VzjpdRDDHwpatE0HXFJzDP0cOS0M9f20cuAGZcO9wcSZpDEERPSHaSMNOP:2daXdRgervX0cq0cCZcgx3
                                                                    MD5:845FDD7F355A159933021541D507475F
                                                                    SHA1:6ADDE9F2C90C05D31D593A1418E0EDAE0D03CDB8
                                                                    SHA-256:4C1B139631B019909EFD5B85313187037D476DCED3ACC74876065023A47661D9
                                                                    SHA-512:A2797EC7EACF6A634391C8626438D5EC5944DED3B1E37C2C81B1EBEF3DD0B5D0C9092A54FE37AEDE03EA5CD419C6606FB3EF9624099E1EAA4EE613895406D424
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12250" V="0" DC="SM" EN="Office.Outlook.Desktop.Tasks.ToDoAppHelpersError" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="7205" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="Activity" />.. <F N="HRESULT" />.. <F N="ErrorContext" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="Activity">.. <S T="1" F="Activity" />.. </C>.. <C T="I32" I="1" O="false" N="HResult">.. <S T="1" F="HRESULT" />.. </C>.. <C T="U32" I="2" O="false" N="ErrorContext">.. <S T="1" F="ErrorContext" />.. </C>.. <C T="U32" I="3" O="false" N="CountToDoError">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):5426
                                                                    Entropy (8bit):4.547054273670805
                                                                    Encrypted:false
                                                                    SSDEEP:48:chPRgeiqJfg8IgsrIATY4E3Eq0Yq+yyqSz78IrINYzWWqbMmr:yRgeiQfg8IgsrIQYFLu++478IMNmo
                                                                    MD5:C82504399A3337F36E964AC34BD5ECDD
                                                                    SHA1:6E4291439F57611483F4FEE022A270D52D336A68
                                                                    SHA-256:D1225A2AF44A04D09D88A21B52985500639B66070431C0FE867EC1B721F0BF7A
                                                                    SHA-512:A9906A17698ABCE9C1FE73EC8224E2922BA7972D113E64A5AFB6C83AC9107A4894961132E19462F5D6529F36EFD97750FE6C03807754CC39F2A24250DD046B96
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12252" V="1" DC="SM" EN="Office.Outlook.Desktop.CloudSettings.GeneralUsageStatistics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="910" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="2" E="911" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="3" E="914" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="4" E="920" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="5" E="925" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="6" E="926" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="7" E="928" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="8" E="929" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="9" E="931" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="10" E="932" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <A T="11" E="TelemetryShutdown" />.. <F T="12">..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):540
                                                                    Entropy (8bit):5.298329138092879
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdNVzjJ+SXdRDDHwpat59ED9qYbXQynBXIfpxNO2su:2dNldRge56rWp3
                                                                    MD5:8E2E716BC18A932A757046F3FB8169F5
                                                                    SHA1:1A0A99518E1620BB6B334EE566F2EFE0FBAA0A3A
                                                                    SHA-256:105CEF07142B35AFDC85B6C8024C8DC486FC5FD5B0C180D664A8E1B41CCE260B
                                                                    SHA-512:924AA9C770147E1F3C8FC3177DCA5C1DEADC942FF28DDF261760282F84FEA61B3546192D037E59B912B00630F331C1F8034DF39C3B668987B7318A33C05126BC
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12253" V="0" DC="SM" EN="Office.Outlook.Desktop.CloudSettings.Signatures.RegexParseFailures" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="64" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="932" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. </S>.. <C T="I32" I="0" O="false" N="RegexFailure">.. <S T="1" F="RegexError" />.. </C>.. <C T="B" I="1" O="false" N="IsInPack">.. <S T="1" F="IsInPack" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):642
                                                                    Entropy (8bit):5.196811042460487
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd8VVzjA6dRDDHwpatE3HXFJzDP0cOSf20cuAGZcO9j1HaSMNOjsu:2dsRdRgeCvX0cW0cCZcK
                                                                    MD5:18EA43403985D50549846D3ADBEE1C23
                                                                    SHA1:D583B275FC530CAB2F986504BE17CB5B6D4DF568
                                                                    SHA-256:DC8D753AA95518788A70231800DE0BCD9088FA3493FE60DCDE3045511DB1F22C
                                                                    SHA-512:41AE9803E6726BE53D2915235C4BB994FE8B06E1E10FCCE38E3BA34E7D1979620A91C2FDBD5185520321786745392A52D9705B2D8CB364E8F9F88E7823359FEF
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12256" V="0" DC="SM" EN="Office.Outlook.Desktop.Tasks.ToDoAppHelpersOpenTaskUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="7206" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="Activity" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="Activity">.. <S T="1" F="Activity" />.. </C>.. <C T="U32" I="1" O="false" N="CountToDoOpenTask">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):511
                                                                    Entropy (8bit):5.284104276982354
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdhVzjc/dRDDHwpatEiHXFJ5hEXMNO/HNUlu:2dhydRgeBvMXr7
                                                                    MD5:52D185986BD3D492045D874C857E5150
                                                                    SHA1:1F6B03B7D01FB0CBA62F2FB4DEF72C9BDD1DDE6B
                                                                    SHA-256:D76692351C170E0FE7B674732B4D28FF304747245F9AC9DB066E9C45FCA1D2EA
                                                                    SHA-512:F737E8FA8672D93F616CA732E4F9925DEE5B120927952F688A23EC157531B4E80AD1AF97116E76E4A06074081CC0E666E7013FD664EA64BCA56B49A5146EE386
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12257" V="0" DC="SM" EN="Office.Outlook.Desktop.Tasks.ToDoAppHelpersTransitionChanged" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="7207" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. </S>.. <C T="B" I="0" O="false" N="Enabled">.. <S T="1" F="Enabled" />.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):3114
                                                                    Entropy (8bit):4.437278758451228
                                                                    Encrypted:false
                                                                    SSDEEP:48:ciTRgeyxvRQIrJIYuIRvxsG87Y/7Rfy720IBi8OfH:NRgeIZDrqYBRJlaYTRfcNIBiDH
                                                                    MD5:796E831D2F8D15D3468B9F61B4B1F25E
                                                                    SHA1:53B8D72ADB4AEED91B563F8CC2D6A23C71F1E08C
                                                                    SHA-256:947F64110A87EC0CBA3A0C8C1B86CBA6B167CBA1D30045C1C9053FAA84FBA61A
                                                                    SHA-512:9B3409FF061E614002ADBF912D350A0684BE64E8AC8AA797F908218BA0672E81B5FFBD114288CB10E002C98626F225F7D98EF9ADF0CF36422F11D1F8AC6E5DC7
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12258" V="0" DC="SM" EN="Office.Outlook.Desktop.AIPParity.SmimeAsAnOutcomeOfLabeling" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <TI T="1" I="Daily" />.. <A T="2" E="TelemetryShutdown" />.. <Etw T="3" E="1314" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. <Etw T="4" E="1315" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. <F T="5">.. <O T="EQ">.. <L>.. <S T="3" F="SensitivityType" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="3" F="SensitivityType" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="3" F="SensitivityType" />.. </L>.. <R>.. <V V="2" T="U32" />.. </R>.. </O>.. </F>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):3194
                                                                    Entropy (8bit):4.228764224698014
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dX7xdRgelInSAt5LWz2tIs16P4PIPYPoP4PAG9sppKz1eAE3ftcfJ:cX7bRgelNAIzuVE3KfJ
                                                                    MD5:B672784B5A61143656D3C929ACCF023A
                                                                    SHA1:405F87C4E808525FCA3C52371C7356806409D4B1
                                                                    SHA-256:591FC2EB0F036B90FB2C28907085D0BCEA41C283236FD04CD66ADCD9FD107A18
                                                                    SHA-512:5BC818532ACAD181946A4C565E8A0BE027570A9BF550E2A51A20885996FB0C750D31282B19DD3239BFF48E1FD106E5664CF8980291C05F9318DDBB8E693F87C1
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12259" V="0" DC="SM" EN="Office.Outlook.Desktop.CloudSettings.OperationFailures" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <Etw T="2" E="910" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="3" E="911" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="4" E="914" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="5" E="920" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="6" E="923" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="7" E="925" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. <Etw T="8" E="926" G="{284b8d30-4aa6-4a0f-9143-ce2e8e1f10f0}" />.. </S>.. <G>.. <S T="2">.. <F N="HRESULT" />.. </S>.. <S T="3">.. <F N="HRESULT" />.. </S>.. <S T="4">.. <F N="HRESULT" />.. </S>.. <S T="5">.. <F N="HRESULT" />.. </S>.. <S T="6">..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1522
                                                                    Entropy (8bit):3.9886751959467244
                                                                    Encrypted:false
                                                                    SSDEEP:24:2djuysabt4sagFTsaBwOasalU5n6jnbnkhnrnykk:cjuy/t4KT1QZUkck
                                                                    MD5:2EFD0F4528452AF080187E8480AD5EEE
                                                                    SHA1:6586EECAA1FB77FC72D4CD331991B989F108DB96
                                                                    SHA-256:AB776AB43F212A7ECE08B0EA28075DFEC9C0F2248CBC0819C1177C4E18ECB671
                                                                    SHA-512:65E488BEBB5D1BAE7FE5A98295F49B875CCD3C072809461920DB1E96EABDAE07593DD20010E23C60FC02211C8DFDC2302EBBF2D20433F57749896652C47FF9DA
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12265" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="1317" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. <F T="2">.. <O T="EQ">.. <L>.. <S T="1" F="State" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="3">.. <O T="EQ">.. <L>.. <S T="1" F="State" />.. </L>.. <R>.. <V V="2" T="U32" />.. </R>.. </O>.. </F>.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="State" />.. </L>.. <R>.. <V V="3" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="State" />.. </L>.. <R>.. <V V="5" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="2">.. <F N="SessionID" />.. </S>.. <S T="3">.. <F N="SessionID" />.. </S>.. <S T="
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):3308
                                                                    Entropy (8bit):4.330727882057241
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dAxVsdRger06wOahaIJhabuhalvhagshagrhnVnonXn6jnbnSncaln6+BzgKW6E:cA78RgeI6QdJyugvlsNZgT1YJ
                                                                    MD5:A634B4D281CF3344528E03FC5CCCCD50
                                                                    SHA1:B47C22329C472A1A0D90343C3EC343AE1F205461
                                                                    SHA-256:23A08C3BBF2380CC746F1A0D58E14C590D5D408F02087ABD937E671664370FD9
                                                                    SHA-512:8BBA37E10256FB92B30E32A2F1E274ABC0DD9BE9B1EF0755D902CFEB264ECABC50903281036C47FE968A136116AC50179E7ED4980BCBCD15714E996329BF116F
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12266" V="1" DC="SM" EN="Office.Outlook.Desktop.Augloop.SessionInfo" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="100" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="12265" />.. <Etw T="2" E="1317" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. <Etw T="3" E="1326" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. <Etw T="4" E="1327" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. <F T="5">.. <O T="EQ">.. <L>.. <S T="2" F="State" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="2" F="State" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="2" F="State" />.. </L>.. <R>.. <V V="7" T="U32" />.. </R>.. </O>.. </F>.. <F T
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):2099
                                                                    Entropy (8bit):4.624147159111152
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dyjUdRgelLJrIu2aIvZIsojq8oiES+NZ71hBkG:cUERgelLJMu+vysKq8SjlUG
                                                                    MD5:D096DB6A7A53642F67664C955EE93C0F
                                                                    SHA1:6146A5BAF24CDBA6BAD4A2DF33C1CDB5E4A9BAC0
                                                                    SHA-256:71837884AC467C17BD770CC3D24171B92F40C4EE819D7621792771879B33C9E4
                                                                    SHA-512:C493F24A2CB0FFA7717C8FEED48D8CFF4309FFDB5A24399F12CAA369672889117C1D0598083FB589A4264DD5B7D677EEB7FCCB4E6A4B40DAF4733C09F9D8B4EF
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12267" V="0" DC="SM" EN="Office.Outlook.Desktop.Augloop.RuntimeInfo" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <Etw T="2" E="1316" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. <Etw T="3" E="1317" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. <Etw T="4" E="1319" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. <Etw T="5" E="1325" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. <F T="6">.. <O T="EQ">.. <L>.. <S T="2" F="Event" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="3" F="State" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="8">.. <O T="EQ">.. <L>.. <S T="4" F="Event" />.. </L>.. <R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1027
                                                                    Entropy (8bit):4.910305943403975
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdjiVzj6dRDDHwpatEi0CXFJicouDLfGByt9usbXpzRGOsCXd9A3/Nxd+D5xfs:2djiQdRge8avS6bRGo9+1+F/u
                                                                    MD5:AFBAF1E5348961113C976FB5AE4930F3
                                                                    SHA1:B5F0B9F2D15E78CCEBB2A0CA64A63C8C70BD93E0
                                                                    SHA-256:7F829A897C53E7939A3D8E01B18A028DF59C4CF59B0BF1D38F9AEC148FF28509
                                                                    SHA-512:2DC5F5D48694539FDA21A155179C1630D167EFAD01D6123F790E3C8F6D2D7FE8978EF6FC41D3F7198903A6655AA8E3D4B1F1260794AE3616F649B820F569F3D4
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12270" V="2" DC="SM" EN="Office.Outlook.Desktop.Exchange.ConnectionLatency" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="12272" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="1" />.. </S>.. </G>.. <C T="U32" I="0" O="falseNoError" N="Method">.. <S T="1" F="0" />.. </C>.. <C T="U32" I="1" O="falseNoError" N="AvgResponseTime">.. <A T="AVG">.. <S T="1" F="2" />.. </A>.. </C>.. <C T="U32" I="2" O="falseNoError" N="AvgProcessTime">.. <A T="AVG">.. <S T="1" F="3" />.. </A>.. </C>.. <C T="W" I="3" O="falseNoError" N="ServerCorrelation">.. <S T="1" F="1" />.. </C>.. <C T="W" I="4" O="falseNoError" N="OMSTenantId">.. <S T="1" F="4" />.. </C>.. <C T="U32" I="5" O="false" N="TotalCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):2797
                                                                    Entropy (8bit):4.430172181419194
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dR3ddRgelTJJnnunDdAv+XJjqsznjoza4/DkbmN7VVmVTXP8:cZfRgel1JnuhAvmqsvYfDmmx7sT/8
                                                                    MD5:F51C604BD1EECCEE37C78D9699F7B8AA
                                                                    SHA1:4A173227E51F59A4CF17EC00D0673456001FEBDD
                                                                    SHA-256:6B1294C188EE53A9963EE9AE7A50F7D07CAF3F00EC21DE0D3B7429F71A9D93CB
                                                                    SHA-512:A9A30EC397143DDECCF79464968456254EF28489A627D25F37C7F296C5666C68AA5D21AA7B52E2B9FD9F8FBB76E3DC8A52900FC55E8B244E1C91B331BDCE5E54
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12271" V="0" DC="SM" EN="Office.Outlook.Desktop.CertDialog.UsageMetrics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <Etw T="2" E="7072" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <Etw T="3" E="7118" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <Etw T="4" E="357" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. <Etw T="5" E="358" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. <F T="6">.. <O T="EQ">.. <L>.. <S T="2" F="Status" />.. </L>.. <R>.. <V V="25" T="U32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="2" F="Status" />.. </L>.. <R>.. <V V="26" T="U32" />.. </R>.. </O>.. </F>.. <F T="8">.. <O T="EQ">.. <L>.. <S T="3" F="fIsCertificateWarningsUpdateEnab
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):2103
                                                                    Entropy (8bit):4.006547095800159
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dHBrwOfVrTphfMIbR50P6iKPyBW+YP5/BwBkO:cpt5PFgCepSkkO
                                                                    MD5:1F15FFF9640838533936A07DD707631D
                                                                    SHA1:B74719882F6DEB4EC8258D5C7F9AC06510FE6E8F
                                                                    SHA-256:AEEB4CC1F73BBFBE71FC5FFD9DC7E54606DDAC3656A45A032C7F47920B1D066D
                                                                    SHA-512:33D438DF30A87EE755CCB404352DB43B2388E58AA9BC0D4AF7D676CD0372C1928C83E8F88DDFBA56DA445F10C15DEF27964E2B1B365286B2C47BBE451D805314
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12272" V="1" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="4104" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <Etw T="2" E="804" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. <R T="3" R="12272" />.. <TO T="4" I="5min">.. <S T="2" />.. </TO>.. <F T="5">.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <S T="1" F="rc" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="EQ">.. <L>.. <S T="1" F="Method" />.. </L>.. <R>.. <V V="13" T="U32" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="6">.. <O T="NE">.. <L>.. <S T="1" F="rc" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="NE"
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):646
                                                                    Entropy (8bit):5.159881866972559
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdQVzjwodRDDHwpatE+i9KA+Kbj8/UkiwfLCGli/jwHhSMNO2su:2dQGodRgelWmEr/i
                                                                    MD5:629B02A59E00F0FB0416D3EBB22E3800
                                                                    SHA1:055F10CE8F0E93C231F268A859C2F3A50EAEA8F8
                                                                    SHA-256:FC6CC8E06BE395DA5DC555F0140C0ACEBAD6681E706402436D20161AADE485E6
                                                                    SHA-512:EBD29D22A1C9E574E80AB0817D5DDF91878B3FCF3E9068E77CBB36355E5FA8605A790ED6C77E22A88C3CF22F153977E5A2F755BD21D2AEFFCF4B46E98268C259
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12274" V="0" DC="SM" EN="Office.Outlook.Desktop.CertDialog.CertErrorCodes" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <Etw T="2" E="7118" G="{11adbd74-7df2-4e8e-802b-b3bcbfd04a78}" />.. </S>.. <G>.. <S T="2">.. <F N="SSLErrorFlags" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="CertErrorValue">.. <S T="2" F="SSLErrorFlags" />.. </C>.. <C T="U32" I="1" O="false" N="CountOfErrors">.. <C>.. <S T="2" />.. </C>.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):736
                                                                    Entropy (8bit):5.114319234534773
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdFVzj40bdRDDHwpatEBcHXFJzDv0MrXHaSMjPw4lfZNOjsu:2dF60bdRgekGvVAl4
                                                                    MD5:E9265E0026690D2ED96C09303D22C745
                                                                    SHA1:43F368CFEC3E677C139CC69809AEFAEE9F1EEACB
                                                                    SHA-256:5BA635B7B842A9D7B3E9B320023D2C59A40C4A9CC72D2168A461277027C2901E
                                                                    SHA-512:F0EFD96E9F827989D3A9522A4CE1F4D6E64DCCF792CBA51E43C84D0E8FC077944BF0E3503980365E5988FF5904CF4F75FA2C0D88027ED21D69B2C949D186025C
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12275" V="0" DC="SM" EN="Office.Outlook.Desktop.Opx.FindTimeFailures" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="23430" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="Context" />.. <F N="HRESULT" />.. </S>.. </G>.. <C T="U16" I="0" O="false" N="FailureCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="I64" I="1" O="false" N="ErrorContext">.. <S T="1" F="Context" />.. </C>.. <C T="I64" I="2" O="false" N="FailureType">.. <S T="1" F="HRESULT" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1142
                                                                    Entropy (8bit):5.064939235251545
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdyVzj40Vm6dRDDHwpatEBZHXFJzDdiI59vFNTAHUx6Ii1Xii3nbK/Lnt7Lfnw:2dy60XdRgeklvVnFN5YKxPF+Pjl
                                                                    MD5:1A5E76F0B2AF3830AFB63676D40B29E2
                                                                    SHA1:D2C51C10A57D4159679BFDCA4D2266CE9C3F1D04
                                                                    SHA-256:03F14F6414FB862080FCFAB0A25E90A0CCC4D63D0CEF7611E0E464DB303E911C
                                                                    SHA-512:B68E3BFFAF3710AC5D5C2D2C862907217D8298B9AD00CAF272770EF048E8991CD3F9DD6D4C70963865A78A11919D9BAC4A02F34479EC0D16C560331061AA4F7D
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12276" V="0" DC="SM" EN="Office.Outlook.Desktop.Opx.FindTimeUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="23431" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="fInPreviewPane" />.. <F N="fComposeMode" />.. <F N="fusertem" />.. <F N="fHasRecipientsOnLoad" />.. <F N="fPollCreated" />.. </S>.. </G>.. <C T="B" I="0" O="false" N="IsLoadedInPreviewPane">.. <S T="1" F="fInPreviewPane" />.. </C>.. <C T="B" I="1" O="false" N="IsComposeMode">.. <S T="1" F="fComposeMode" />.. </C>.. <C T="B" I="2" O="false" N="IsCalendarItem">.. <S T="1" F="fusertem" />.. </C>.. <C T="B" I="3" O="false" N="HasRecipientsOnLoad">.. <S T="1" F="fHasRecipientsOnLoad" />.. </C>.. <C T="B" I="4" O="false" N="IsPollCreated">.. <S T="1" F="fPollCreated" />.. </
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1218
                                                                    Entropy (8bit):4.529787600854941
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd8VzjasdRDDHwpatEc6NXFJiRV1DP1D+wsvXlOaNeCfNH/M//k5eNX/c//aNf:2d8ksdRgeyxvJwOfffZqTaTXFUFZ
                                                                    MD5:CDBBDC977F6ABE4338DF99F4D03F1C3F
                                                                    SHA1:DD451F5C0174A4C022878C0E903484BAA6FE6D58
                                                                    SHA-256:B94A0FB1B405C4E641A7C11DAC3F4965116840DE7D6B94C3D6E2D5896FA9156D
                                                                    SHA-512:4DC3CAD5DA9CFFE6B4170411D747C3C506494249708B806ECF7D84A6D67895469F25EC5D106EED6B113B2E2EB8BDB6A2E965230DBB33B4E193F91A6148F6A1DC
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12278" V="0" DC="SM" EN="Office.Outlook.Desktop.DLP.SessionInfo" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <TI T="1" I="Daily" />.. <A T="2" E="TelemetryShutdown" />.. <Etw T="3" E="1321" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. <Etw T="4" E="1328" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. <F T="5">.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <S T="3" F="Annotation" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="EQ">.. <L>.. <S T="3" F="Event" />.. </L>.. <R>.. <V V="3" T="U32" />.. </R>.. </O>.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="Count_DLPRegisterAnnotation">.. <C>.. <S T="5"
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):847
                                                                    Entropy (8bit):5.128536452002948
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dBR/LodRgefUsEvS538t+A38tm38tF1xDS:cB1ARgefXEvS538t+A38tm38tF1xDS
                                                                    MD5:A1ED2EC655D815D6B06EF529A653DAC0
                                                                    SHA1:1ABF3C61E56CC70DD170932E22035344D67B3212
                                                                    SHA-256:C28DDD7BE8277CDC743EE7BBF0BC3721DA01F74A6F8157353E9D34F4E7EA744B
                                                                    SHA-512:F7881C319F7AB5D4DA31F0C90239C79E6DF36FC39039F694BE4FF2CB1044D80EEFAA3DE3436D97C584945B9E9F593498C29F2EF7E6805AB06C40C5EC1D311A06
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12280" V="0" DC="SM" EN="Office.Outlook.Desktop.Search.SearchUseCaseReport" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="7191" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="SearchResultsProvider" />.. <F N="SearchUseCase" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="SearchResultsProvider">.. <S T="1" F="SearchResultsProvider" />.. </C>.. <C T="U32" I="1" O="false" N="SearchUseCase">.. <S T="1" F="SearchUseCase" />.. </C>.. <C T="U32" I="2" O="false" N="Count_CompletedQueries">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):703
                                                                    Entropy (8bit):5.1248500836889805
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdMVzjTLQ13dRDDHwpatEBQkFHXFJicouD8yfBpN+YdjQpNHaSMNO5csu:2dM5o3dRgekZvSPMp8Y2pQ
                                                                    MD5:970DF553E091E18F278680E03180CF23
                                                                    SHA1:7D7922D580DAC953114B4BF2A3363C00C447CCDF
                                                                    SHA-256:2F5D4AD66AC22B155586DFBCA6814D91A2C4F8646B69B10FBBC85933698929A6
                                                                    SHA-512:5243E1AF814FFDFFDDBC38E68EA3C26E5879159D35987824D004A784F770F5E82D0E909C82DE008D3E437BD205A00AB35F63D135D77E44FAAF080510FFDF3186
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12281" V="0" DC="SM" EN="Office.Outlook.Desktop.StorylinePost.LicenseSource" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="23426" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="LicensesSource" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="LicensesSource">.. <S T="1" F="LicensesSource" />.. </C>.. <C T="U32" I="1" O="false" N="Count_LicensesSource">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1536
                                                                    Entropy (8bit):5.099030432630739
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dZ5oKd6dRgeMEopYJOE7XNQNsawHieqcwTDHlVK8gC:cZ5oKd2RgeTW0OidCwHieg39
                                                                    MD5:0D75E32965D7EF5845BEC25C410530B5
                                                                    SHA1:5778F204C17D606D3F8803ADC10804121ED98FA2
                                                                    SHA-256:2EC7B7604B7E4973A4AD29F1CD5FC880AA7811A4072B4A103E64B88DB0819853
                                                                    SHA-512:ADA66441CD059A499FF4FD64AD422EF5208A81D5AD4B8045561597501A2D3D7028C924D484481CF9A89592D8E1B40310B0AAEDC162908DFEDC726A000D4F1EEB
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12282" V="2" DC="SM" EN="Office.Outlook.Desktop.StorylinePost.LicenseServiceResults" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="50" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="23422" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <Etw T="2" E="23429" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. </S>.. <C T="I64" I="0" O="false" N="ServiceCallResult">.. <S T="1" F="Hresult" />.. </C>.. <C T="B" I="1" O="false" N="HasAuthToken">.. <S T="1" F="HasAuthToken" />.. </C>.. <C T="B" I="2" O="false" N="HttpRequestValid">.. <S T="1" F="HttpRequestValid" />.. </C>.. <C T="I32" I="3" O="false" N="HttpRequestResponse">.. <S T="1" F="httpRequestResponse" />.. </C>.. <C T="B" I="4" O="false" N="HasResponseBody">.. <S T="1" F="HasResponseBody" />.. </C>.. <C T="U32" I="5" O="false" N="LastStage">.. <S T="1" F="LastStage" />.. </C>.. <C T="U64" I="6" O="false" N="ElapsedTime"
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):734
                                                                    Entropy (8bit):5.246887870275643
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdBVzjVvdRDDHwpat5r8XtW1VxtOMnyBfCL4/AfMM0kE3ufYWb2NO2su:2dBTvdRgegmtxnofI4CUlZx
                                                                    MD5:AF1C8E67E2AC3FD5D89A39B5BB3F32C0
                                                                    SHA1:0D81DCD2D0643057DB7EF2739D0A4159D6A05493
                                                                    SHA-256:877E4815E69E30DE63E7137955D844CC7766ED0273F0FB2F76C961AC41038DB3
                                                                    SHA-512:521658312510CA6B16C09C64343548C2FF3AEBC6E61F0953EDF31C36A6C436F5BDD879FC4F15B715CAEFDCF6DE288B11F8083CA281995F46EBA73EC40DAFEC46
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12285" V="1" DC="SM" EN="Office.Outlook.Desktop.Augloop.AnnotationLatency" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="1000" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="1332" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. </S>.. <C T="G" I="0" O="true" N="GUID_SessionID">.. <S T="1" F="SessionID" />.. </C>.. <C T="U32" I="1" O="false" N="Type_Annotation">.. <S T="1" F="Annotation" />.. </C>.. <C T="U64" I="2" O="false" N="Time_LatencyInMs">.. <S T="1" F="EvaluationTime" />.. </C>.. <C T="U64" I="3" O="true" N="Value_CustomParam">.. <S T="1" F="CustomParam" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):4392
                                                                    Entropy (8bit):4.091469457405557
                                                                    Encrypted:false
                                                                    SSDEEP:96:hRge5Onb7OtxvOF0Dy175Bsw9YDKlWbuMu:hDBc
                                                                    MD5:A8A5ACB331AC493E9DFF1255310B385B
                                                                    SHA1:58CA4EB16707B33CD73D2BDDCD0E4263B51456CD
                                                                    SHA-256:559ABAB840BFCB31C479B6CD5A451C23143398D2133C6CCA7BFF7B84918933D5
                                                                    SHA-512:5AEBF481BB73A5D90BE47BB77DA51540892FACB34BBFC37ED59E3D7EA1DE2412517600055FD19AF5E002490B2F9A8AA91043CC76374EE5AB8CDB4255BC1CEA87
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12286" V="1" DC="SM" EN="Office.Outlook.Desktop.Attachments.SensitivityLabelExtraction" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSP" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <Etw T="2" E="1341" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. <F T="3">.. <O T="LT">.. <L>.. <S T="2" F="ExtractionTime" />.. </L>.. <R>.. <V V="200" T="U64" />.. </R>.. </O>.. </F>.. <F T="4">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="2" F="ExtractionTime" />.. </L>.. <R>.. <V V="200" T="U64" />.. </R>.. </O>.. </L>.. <R>.. <O T="LT">.. <L>.. <S T="2" F="ExtractionTime" />.. </L>.. <R>.. <V V="500" T="U64" />.. </R>.. </O>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):3544
                                                                    Entropy (8bit):4.433117672032861
                                                                    Encrypted:false
                                                                    SSDEEP:48:c6QLRgeyxvquPXvPisA85/EfytFCIU0LcJ3vxCW0G74F+:WLRgeISoCpAsfAQsCxKGMo
                                                                    MD5:21870F04A5DC1199736CBC151DC0F37B
                                                                    SHA1:083D79B9DE667D06CD22B8511D11E6EE7524A52D
                                                                    SHA-256:760B88CBE77F6411A6A2A6692F2DA571B6918B2390B44F5F3B45C92FF2B5EFCD
                                                                    SHA-512:4105C7B8AFAEB56409794284DD31A2C860098348ABAA5CE7F2E385AA1662CD71F56781BBD14C17AA131C794DC4CFE2B63CE3AC31A3984D515F82D85971125F02
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12287" V="0" DC="SM" EN="Office.Outlook.Desktop.AIPParity.LabelInheritance" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <TI T="1" I="Daily" />.. <A T="2" E="TelemetryShutdown" />.. <Etw T="3" E="1337" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. <Etw T="4" E="1338" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. <Etw T="5" E="1339" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. <Etw T="6" E="1340" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. <F T="7">.. <O T="EQ">.. <L>.. <S T="3" F="AttachmentAction" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="8">.. <O T="EQ">.. <L>.. <S T="3" F="AttachmentAction" />.. </L>.. <R>.. <V V="2" T="U32" />.. </R>.. </O>.. </F>.. <F T="9">.. <O T="EQ">.. <L>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):7732
                                                                    Entropy (8bit):4.216025346340067
                                                                    Encrypted:false
                                                                    SSDEEP:96:URgeITTscXgWscIofN2P9OrLRYni/+sI0MIkvIImIqbY0trLVc7XZ:UDIXVtIVjXZ
                                                                    MD5:E17F4A07588366DF490198E9CAE98981
                                                                    SHA1:9DB2E6DC38FF81009069A1463374601AF1BD3DC9
                                                                    SHA-256:4E50B45092F3D255E0DFAEE72655535A9D2721A7E9AC675FA98B4DEF34478E8A
                                                                    SHA-512:70EE19B2FE1121D8DE0D24C8BF30732DF694C46A7856EF6A796A76BF20DEF8848A87D9877D438BA45960A3EDDC4B95D6F380C1CAA79B8D5EFEC748757C29A236
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12288" V="0" DC="SM" EN="Office.Outlook.Desktop.DLP.DLPAnnotationParam" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <TI T="1" I="Daily" />.. <A T="2" E="TelemetryShutdown" />.. <Etw T="3" E="1334" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="3" F="IsPolicyTipShownAsDialog" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="3" F="IsPolicyTipShownAsDialog" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="3" F="fBlockActionEnabled" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):5194
                                                                    Entropy (8bit):4.2873300617786185
                                                                    Encrypted:false
                                                                    SSDEEP:96:sRgeI6XYyRhm8/7Mm12KLjfYw1GKxP40LrtqjYJM0fs3T3tZ:sDIMZYZ
                                                                    MD5:6D2AC45627C05E102FAF9A3B9C12B263
                                                                    SHA1:6D7A5440D836ED512D29E963E4A4E933C48C7CCB
                                                                    SHA-256:85D59703DC9D37AB81F4BF4D8EFFBE4A308DFBBFD8A008668A03FBE87F34FCC0
                                                                    SHA-512:EAAED79EB5087FF8AB455CD92A8F11EF7A1963AEA09EF70788814849D4B817A8BCD4E9A8D2E0F7B5BE77C476639A37859D2CC46886E42E7C6A792FF6BC1EE6D6
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12289" V="0" DC="SM" EN="Office.Outlook.Desktop.DLP.DLPDialogDisplayed" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <TI T="1" I="Daily" />.. <A T="2" E="TelemetryShutdown" />.. <Etw T="3" E="1335" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="3" F="DialogType" />.. </L>.. <R>.. <V V="1" T="U32" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="3" F="DialogType" />.. </L>.. <R>.. <V V="2" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="3" F="DialogType" />.. </L>.. <R>.. <V V="3" T="U32" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="EQ">.. <L>.. <S T="3" F="DialogType" />.. </L>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):698
                                                                    Entropy (8bit):4.948125356986863
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd+3VzjL6SPdRDDHwpatElV1DXFJicobs8Os1IX/c//BIpONXNO5AHNUlu:2dOZXdRges7vSt2w7
                                                                    MD5:365A9FB5BDA6840EDABE05B4A4208E8D
                                                                    SHA1:AE4677F71A04E7B14779380CDE6A521287FF26A9
                                                                    SHA-256:2D33899761B7DD698C73F8CBFEE2CEBFAC9154869214157D7201C2912D7D249C
                                                                    SHA-512:CFB7216D21CA778401D33B13BA8D0E81687D360995560118997D6B1AA33974E2A4085BAFE26BAD16796411934B2D1005AFAA50FF54830DE117CF13DD8A4DC286
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12290" V="0" DC="SM" EN="Office.Outlook.Desktop.Signals.ViewMsgAvgTime" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="1600" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <C T="U64" I="0" O="false" N="AvgTime">.. <A T="AVG">.. <O T="SUB">.. <L>.. <S T="1" F="EndTime" />.. </L>.. <R>.. <S T="1" F="StartTime" />.. </R>.. </O>.. </A>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):665
                                                                    Entropy (8bit):5.109592792578308
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdTVzjL8NdRDDHwpatllV1DXFJicouD0MfXzFZ9HaSMNO5csu:2dTZ8NdRgeT7vScz0
                                                                    MD5:F06D21675B6041847BCA5C155248416E
                                                                    SHA1:DA0A0A1B15292A511D5B0EA85110D8E6922D4854
                                                                    SHA-256:C8BE052E45215FC533618A78554B288F7AF1AD2ED8863EBC32248799D6A25E85
                                                                    SHA-512:E2BC9DFE8E952736C361EA6908BD9906969CEA80A7AF39F49796FA144B1BAA346D201DB4ADE122ECEE8735681F1573F6B3177916D6F29942BB74BCD1DC2848B2
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12291" V="0" DC="SM" EN="Office.Outlook.Desktop.Signals.ViewMsgSendRate" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSP" xmlns="">.. <S>.. <Etw T="1" E="1600" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="HRESULT" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="SignalCode">.. <S T="1" F="HRESULT" />.. </C>.. <C T="U32" I="1" O="false" N="Views">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):804
                                                                    Entropy (8bit):5.102147812737932
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdcVzjTLT3LKdRDDHwpatEBIVl2HXFJicouDv0MZT3Q0OXHaSMGPt/87SZNOAP:2dcR/3LKdRgeknvSQ3Q5a7y
                                                                    MD5:C2B5445E367753C098C63E220F9D1FF7
                                                                    SHA1:6C705E451200C5E19097AAE640CDAD796740567E
                                                                    SHA-256:BD3AC1C5143E776EA2D5E27A34D20B8A9AED683784C78AE61ADDAFB412B2B17D
                                                                    SHA-512:46F92D0AE62A0E554E4CB0BC49D0AA0D609ADDDDC0D9C653A7C33601939A5A986148B78903DF8285468C36DF90A751CA48AAE72AE5723E192878C7C440E476F8
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12292" V="0" DC="SM" EN="Office.Outlook.Desktop.Search.SearchRecipientChangeListener" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="23280" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="Context" />.. <F N="HRESULT" />.. </S>.. </G>.. <C T="U16" I="0" O="false" N="SearchRecipientListenerCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="Context">.. <S T="1" F="Context" />.. </C>.. <C T="I32" I="2" O="false" N="Hresult">.. <S T="1" F="HRESULT" />.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):700
                                                                    Entropy (8bit):5.218784140980424
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdtjVzj47r76dRDDHwpatEB3aHc1NQzD0MzCJ/ZpSXHaSMNO5csu:2dtj67rmdRgeklqVOSu
                                                                    MD5:09DE71F14AC05FEEBDB45D05931504F6
                                                                    SHA1:C80F9DE4A42D19160D196A39A7E7A594AD440616
                                                                    SHA-256:5196B2BEB9ADAE507022603533FFEC2B495DB588D3CF3820EEC059069AB83A06
                                                                    SHA-512:BDD8F65CB613DB8F6D2696409C63DF1C38D53196D436D06BA48F8086C0F921973473E1B042B60568324DE506D45BE29CDCE992D8CB45D138D96C981BAD7A89F5
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12293" V="0" DC="SM" EN="Office.Outlook.Desktop.Opx.HybridWorkHoursUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="23432" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <TI T="2" I="Daily" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="HRESULT" />.. </S>.. </G>.. <C T="I64" I="0" O="false" N="OpxHybridWorkClickHRESULT">.. <S T="1" F="HRESULT" />.. </C>.. <C T="U32" I="1" O="false" N="OpxHybridWorkClickCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):826
                                                                    Entropy (8bit):5.186377606677101
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d/RRgRdRgefpsEvS538trC38tm38tSfn27q:c/47RgefOEvS538trC38tm38twn27q
                                                                    MD5:1E909174FE1DE9433A7CC98F23F21268
                                                                    SHA1:3433A22CAFDABF3FD428C1579DCB96632EAA6B2A
                                                                    SHA-256:12182A9A60FD1E2C4AA069BB44752CC334CFDB56709C3907F1F02F47BF87E37C
                                                                    SHA-512:A6F496AE6C9D68AA72360C67982BE1783D44CF6FC397EEDD42D7804E9D35CB716BBEE02B87D7FC53AEBC20F6AED2BA810FC9DF3F3374EC9FC4CD12C8D19C4E45
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12295" V="0" DC="SM" EN="Office.Outlook.Desktop.Search.KQLQueryProvider" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="7192" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="SearchResultsProvider" />.. <F N="KQLType" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="SearchResultsProvider">.. <S T="1" F="SearchResultsProvider" />.. </C>.. <C T="W" I="1" O="true" N="KQLType">.. <S T="1" F="KQLType" />.. </C>.. <C T="U32" I="2" O="false" N="Count_CompletedKQLQueries">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):987
                                                                    Entropy (8bit):4.7451577719375875
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdo3Vzj6WdRDDHwpatE+ijV1D+tNqNOHUX/c//wVrMpONd+kXqNOHUX/c//bLf:2do3ZdRgelbt4U0jqTU0igG
                                                                    MD5:86021E69FF6702DF9D43099D0A51B03E
                                                                    SHA1:2A0BFF5D1584A0C0EBF34BA4993D3A416D2E9DA3
                                                                    SHA-256:A75CC5B38D0A294515A2ECE79E1B5E83D9AE392F03144DDE3C80D3004F9087C8
                                                                    SHA-512:6C0A4C1BB5E4D562F73F02DC1601B3F966C7F4A1093A75803D43369D0C5EBED6922FF779BB78702B098023FB89E9E5392CB36A8190E921B0416408FA245001D0
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12296" V="0" DC="SM" EN="Office.Outlook.Desktop.AIPParity.LouderUXControlStatus" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <Etw T="2" E="1333" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. <F T="3">.. <O T="EQ">.. <L>.. <S T="2" F="HasCLPControl" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="4">.. <O T="EQ">.. <L>.. <S T="2" F="HasCLPControl" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="Count_StatusOk">.. <C>.. <S T="3" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="Count_StatusError">.. <C>.. <S T="4" />.. </C>.. </C>.. <T>.. <S T="1" />.. </T>.. <ST>.. <S T="2" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):687
                                                                    Entropy (8bit):5.1154451908657625
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd7VzjTLTBPdRDDHwpatE+nqswXFJicouD+TLNfbTsPLMjMHaSMNOAjsu:2d7R/BPdRgefnqsEvS5LBcLm
                                                                    MD5:73F4AFD8727284869BEF1B05C23E3BD1
                                                                    SHA1:5635A0D82F5CAFF6B8D149796FCEA4E978E94EE1
                                                                    SHA-256:C0E127D5026CCF8243B43B5EFE0720551119C1D0FBEDC32EE68F0E32267EA742
                                                                    SHA-512:557DBBDFE6A9EF36B5AB6F4574B9A9D09F2C06DD885D9261081351303E917C5782092213DC7AC976391E38F2C6FC119657BCF6B0C1D48D38EC56937013B7FFBF
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12299" V="0" DC="SM" EN="Office.Outlook.Desktop.Search.SearchQueryScope" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="7193" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="SearchScope" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="SearchScope">.. <S T="1" F="SearchScope" />.. </C>.. <C T="U32" I="1" O="false" N="Count_SearchScopes">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1064
                                                                    Entropy (8bit):5.052697301987389
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dMRnuodRgefLsEvS5UA/nBH38tQ/41F5PrCepY10:cMcARgefYEvS5RnV38t641zPg0
                                                                    MD5:F09AB0E70A3F025D6185D8F065AA592B
                                                                    SHA1:0695600BCDA617D99AF71A063DF3E737F16DE7BF
                                                                    SHA-256:B81D3073C3E90D1CFF0925643B58B42E3FD6E156816808FE346B83D96AAF04A3
                                                                    SHA-512:EC4371CE511D87E7FBE061A43DCFE23B3106203D5343040E8FA436A1AF6A826862AC6F85117AC9BE5D0836BF131DCFF907308FE5998C6910A1CF0101CA485EDC
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12300" V="0" DC="SM" EN="Office.Outlook.Desktop.Search.ServiceSearchUseCaseReport" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="7190" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="SearchUseCase" />.. <F N="RequestType" />.. <F N="StoreType" />.. <F N="ProtocolVersion" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="SearchResultsProvider">.. <S T="1" F="RequestType" />.. </C>.. <C T="U32" I="1" O="false" N="SearchUseCase">.. <S T="1" F="SearchUseCase" />.. </C>.. <C T="W" I="2" O="true" N="StoreType">.. <S T="1" F="StoreType" />.. </C>.. <C T="W" I="3" O="true" N="Version">.. <S T="1" F="ProtocolVersion" />.. </C>.. <C T="U32" I="4" O="false" N="Count_ServiceSearchQueries">.. <C>.. <S T="1" />.. </C>.
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1213
                                                                    Entropy (8bit):5.179425422555095
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdBVzjy11dRDDHwpat5WiolC1Df1Dr1pahazQfj9n+SGMant9SGVSnsSG7znHU:2dBOdRgeqJYAbjPUilCCcPVe7
                                                                    MD5:189939027664C39A8620F38B48E4CA47
                                                                    SHA1:26871F918427183DFAAB2E6731978672A498FCF3
                                                                    SHA-256:59F111C35FCB63EA3006EE28D5BB5138F2299E395FBD287DE07DF8243EDE21EE
                                                                    SHA-512:FAB88FE46C8F67B7DCD2C274060B4A124D8E4754CE8BD20AC257ED046DB9C55D97919A28C29E98D5367B7423D5F0499064E183D99FDFB3BD1C19314B369AE9F7
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12301" V="0" DC="SM" EN="Office.Outlook.Desktop.Monarch.CachedNudgeRetrieval" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="5" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="1503" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. <Etw T="2" E="1502" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. <Etw T="3" E="1413" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. </S>.. <C T="I64" I="0" O="true" N="GetCachedNudgeOutcome">.. <S T="1" F="HResult" />.. </C>.. <C T="B" I="1" O="true" N="CachedNudgeExists">.. <S T="1" F="NudgeHasValue" />.. </C>.. <C T="B" I="2" O="true" N="CachedNudgeExpired">.. <S T="1" F="NudgeExpired" />.. </C>.. <C T="B" I="3" O="true" N="CachedNudgeLanguageMatches">.. <S T="1" F="LanguageMatches" />.. </C>.. <C T="B" I="4" O="true" N="GotCachedNudge">.. <S T="2" F="NudgeHasValue" />.. </C>.. <C T="W" I="5" O="true" N="CachedNudgeId">.. <S T="2" F="Nudg
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):2852
                                                                    Entropy (8bit):5.103405488141552
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dJYK1gdRgeNtP2YMU+BNveNfNcs8pQl3MCOd/AdoZAZVAzAkBv795Z:c+K1YRgeNVCJeZqPpaZOdFYOv795Z
                                                                    MD5:9F2BDDA33408A1AAA661D447B0AF5CC8
                                                                    SHA1:C4CBC9607D7915D1F3DDB91A20C385D1293D54FA
                                                                    SHA-256:A1FBD6BD600E7A17F896ABF0A372384EBBF1DC3C274936F3B984F9F8BB42E570
                                                                    SHA-512:C659380487CEA36F82FD029D35602E5EA739D5AEE8F96E12B09FF0454FF077DEC0376494B71391E81B0639418EE0EA47C558867C19E00F4314B03364EAEB61E0
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12302" V="0" DC="SM" EN="Office.Outlook.Desktop.Monarch.NudgeServiceClientUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="5" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="1500" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. <Etw T="2" E="1501" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. <Etw T="3" E="1504" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. <Etw T="4" E="1505" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. <Etw T="5" E="1506" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. <Etw T="6" E="1412" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. </S>.. <C T="B" I="0" O="false" N="SurpassedHighWatermark">.. <S T="3" F="NewHighWatermark" />.. </C>.. <C T="B" I="1" O="false" N="SurpassedNextQueryTime">.. <S T="3" F="SurpassedNextQueryTime" />.. </C>.. <C T="B" I="2" O="false" N="ServiceCallSuccess">.. <S T="2" F="ServiceCallSucceeded" />.. </C>.. <C T="B"
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):4307
                                                                    Entropy (8bit):3.9666200863587897
                                                                    Encrypted:false
                                                                    SSDEEP:48:ctsRgellt46TSPPvzsO8V/CfyEozOlYKG:nRgeHrTSPPLtm6fXUuXG
                                                                    MD5:99F742E63F1929CED0749C32ADAA13B5
                                                                    SHA1:1D4F93A3276D4A8F945854532028659A20ACE6DA
                                                                    SHA-256:E3FB19010783BD761B2B0CB5DE1D947E66DEB8F28E12BD84398A985052A6F45D
                                                                    SHA-512:C28271269DCAD5DC2F1A0185ECA283561441D09A8570C8A63F2826DD26A76AC7AD26A2B2A4F10765974A6861BE05ABAC9E5CAA3A78C10F6F825956DA51A4E887
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12305" V="0" DC="SM" EN="Office.Outlook.Desktop.DLP.OversharingWaitOnSendUX" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetryShutdown" />.. <Etw T="2" E="1348" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. <F T="3">.. <O T="EQ">.. <L>.. <S T="2" F="WaitOnSendTimeout" />.. </L>.. <R>.. <V V="0" T="U64" />.. </R>.. </O>.. </F>.. <F T="4">.. <O T="AND">.. <L>.. <O T="GT">.. <L>.. <S T="2" F="WaitOnSendTimeout" />.. </L>.. <R>.. <V V="0" T="U64" />.. </R>.. </O>.. </L>.. <R>.. <O T="LE">.. <L>.. <S T="2" F="WaitOnSendTimeout" />.. </L>.. <R>.. <V V="25" T="U64" />.. </R>.. </O>.. </R>.
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):3747
                                                                    Entropy (8bit):4.552109496398068
                                                                    Encrypted:false
                                                                    SSDEEP:48:c6aRgeUvVT5T8r5gCC90HcIp6gedY2j0jz8:MRgeU51irjv8
                                                                    MD5:3E0E31C1CD75CAA0FA109C8CC9159985
                                                                    SHA1:DF3AE483642083348DDB836D7985D67366C96B05
                                                                    SHA-256:8175D3DA9338CB87C0D073538335D1552004CFBA9789C0DAA1192A147B88BE9A
                                                                    SHA-512:817C5A61793BE40B08A4EB3067DD6756167AC1D44F16F7E1EF3E32FAFD458BA0F4E427B83E5A4C1A74E1369361E71F9B2C10D3D8B449417E1CE3D75F5B44630A
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12306" V="0" DC="SM" EN="Office.Outlook.Desktop.Monarch.InstallFailure" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="5" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="1408" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. <Etw T="2" E="1403" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. <Etw T="3" E="1404" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. <Etw T="4" E="1405" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. <Etw T="5" E="1406" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. <Etw T="6" E="1407" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. <Etw T="7" E="1310" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. <F T="8">.. <O T="EQ">.. <L>.. <S T="6" F="HRESULT" />.. </L>.. <R>.. <V V="0" T="I32" />.. </R>.. </O>.. </F>.. <F T="9">.. <O T="NE">.. <L>.. <S T="6" F="HRESULT" />.. </L>.
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):705
                                                                    Entropy (8bit):5.1713223585465835
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdvVzjTLTqOdRDDHwpatEuswXFJicouDAKPwOffKPMfQ9+KPwxjUKPHaSMNOAP:2dvR/bdRgebsEvSBjcj/jqR
                                                                    MD5:113EA8A384EEBE4F13F329DE9E9ED9AB
                                                                    SHA1:7E7A79BD05417D2D46590FBBEB4CD8760DB40828
                                                                    SHA-256:A24A8369D7B0B084FDD0736D5C573CF03DA6DD9DF51078C937E47CBBBD7DF1C5
                                                                    SHA-512:D8A5663DADF34487627D741A84CC3913973D17033E86B5FE5E53E4AAA343A7E1D660CB438FC3DE3180C543BD7737CA8DCADB490158123167F7B3CC3FF02434F8
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12307" V="0" DC="SM" EN="Office.Outlook.Desktop.Search.SearchQueryFailure" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="7143" G="{287bf315-5a11-4b2f-b069-b761ade25a49}" />.. <A T="2" E="TelemetryShutdown" />.. <TI T="3" I="Daily" />.. </S>.. <G>.. <S T="1">.. <F N="QueryProblemType" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="QueryProblemType">.. <S T="1" F="QueryProblemType" />.. </C>.. <C T="U32" I="1" O="false" N="Count_QueryProblems">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):983
                                                                    Entropy (8bit):4.745089407453764
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdSYYVzjEikdRDDHwpatEkY1DXFJi+tNqNO7X/c//wVrMpONd+kXqNO7X/c//U:2dSYYiHdRge2vJt4sjqTsii7
                                                                    MD5:071D282BBE2E1267D56DCE4EE832864E
                                                                    SHA1:3CA3CBAED0178C1DDD29B9BA1FF75D5BBDC1B67E
                                                                    SHA-256:988B41C21C0EBC7291B5A8DDBD8988DFADC941016EC0B34667320D9B8BB37CA6
                                                                    SHA-512:35CA43A4680FF77F6411B4F7BDD6EEB42DDAD9C981C7286F90F2039CA8B96D46416A3D7C8E6C4F837346D8CB17E2E05DEC35EEA148081FAEFA28AD91CBADD740
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12308" V="0" DC="SM" EN="Office.Outlook.Desktop.NotificationBar.BrowserSignInShowBarMetrics" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="348" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. <A T="2" E="TelemetryShutdown" />.. <F T="3">.. <O T="EQ">.. <L>.. <S T="1" F="FShowBar" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="FShowBar" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="Count_ShowBar">.. <C>.. <S T="3" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="Count_HideBar">.. <C>.. <S T="4" />.. </C>.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):694
                                                                    Entropy (8bit):5.233666361008724
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdCYVzjEieXsBdRDDHwpatEi1DXFJzDTXiOfCXefUrXixj2mXefHaSMNOjsu:2dpilXsBdRgeBvLXivXesrXiVXet
                                                                    MD5:60BF91E53D836510861BFC197135F481
                                                                    SHA1:3A2CC439F182831D9B5AB7C4417B23D1862BD309
                                                                    SHA-256:A3182B1301007C321FEC4C2EAFC8C66CD44947545473E4BE7CD63519F0F701B7
                                                                    SHA-512:405EEE298A39A82932ED8A0A076AED5B5F658FA7CA9ED848FA89223A8FDD956C9E4B4E30385D2516449CB52855D776164EFD05C071A2E4A0D2ECAB187161CA25
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12309" V="0" DC="SM" EN="Office.Outlook.Desktop.NotificationBar.BrowserSignInUserInteractions" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="349" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. <A T="2" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="UserInteractionType" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="UserInteractionType">.. <S T="1" F="UserInteractionType" />.. </C>.. <C T="U32" I="1" O="false" N="Count_UserInteractionType">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1796
                                                                    Entropy (8bit):4.292079816834656
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d91ixBdRgeDvJt4CjqOSyzxwOfSyzTTyPPZ7:cfqrRgeDvJt4UqOVtHeB7
                                                                    MD5:F79390B0B069A4998416F4660DC81FE4
                                                                    SHA1:62830D522390ECF8E6E4E02885AE57DE5EA926FC
                                                                    SHA-256:1846AE6F50EE62AB5E4AAA12FBC0D849CC96494E764EB9CBAA2E6326B8334F6A
                                                                    SHA-512:9BB8BBD5E4CD177F012A65F23B7E1AF32F164023864AD0341A461A7AE367700D047F226DD281F0098719201D716BC9593256B8DD75E78D37629DF10329114921
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12310" V="0" DC="SM" EN="Office.Outlook.Desktop.NotificationBar.BrowserSignInAuthResult" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="350" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. <A T="2" E="TelemetryShutdown" />.. <F T="3">.. <O T="EQ">.. <L>.. <S T="1" F="FAuthenticateSuccessfully" />.. </L>.. <R>.. <V V="true" T="B" />.. </R>.. </O>.. </F>.. <F T="4">.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <S T="1" F="FAuthenticateSuccessfully" />.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </L>.. <R>.. <S T="1" F="FCancelled" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <S
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):774
                                                                    Entropy (8bit):5.1907400721586505
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdoVzjt6dRDDHwpatEXHXFJzDfeaXsbSA+n0PRNxxFp7XHaSMNOjsu:2do2dRgeWv+eWPdxzl
                                                                    MD5:E316392FD842873D4A38C258B6B7B454
                                                                    SHA1:481877ECF21AD442345F065A1DA20FD10BAA85AB
                                                                    SHA-256:892886185B3372A4A00C0C34913CC7BEE44AB54ED45EF046EE116B9DD0C10146
                                                                    SHA-512:50DC5CD5BBD5355A89D62637F3904A5480CABB035AC10906B68E75E39E3AE6775ADCE4292DE4A97532DE5FE560E735A5E4F7F4DF0F037C4A5141AC06ABE3D485
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12313" V="0" DC="SM" EN="Office.Outlook.Desktop.Hub.MeetingAppsUsage" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="7220" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="AppId_PrivacyCleared" />.. <F N="fTeamsMeeting" />.. </S>.. </G>.. <C T="W" I="0" O="false" N="AppId">.. <S T="1" F="AppId_PrivacyCleared" />.. </C>.. <C T="B" I="1" O="false" N="IsTeamsMeeting">.. <S T="1" F="fTeamsMeeting" />.. </C>.. <C T="U32" I="2" O="false" N="MeetingAppsUsageCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):882
                                                                    Entropy (8bit):5.1043436330675
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd5gBVzjJAdRDDHwpatECHXFJzDfXsbSA+jC/clXw4lfC/uXoXHaSMNOjsu:2daBYdRge1v35LlWl
                                                                    MD5:EFFBED88C171363EF799E5090105AD27
                                                                    SHA1:4B624DBE9A5FB1FBA27BAAB9FD0617CA39B0ED13
                                                                    SHA-256:72333A1EE0AD5B2B5B1EFBA9A92B11F32981BE0620C5CB7E2081A09724DCD40F
                                                                    SHA-512:E2D5F3CD5DA1993CD1E30C0C6DD9BB769B922BE03DF05626D23A6A6AC3750341442030AE04C8E3F370B070885D641F828203BF0EB17B4E84A53698A223021A0C
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12314" V="1" DC="SM" EN="Office.Outlook.Desktop.Hub.MeetingAppsFailures" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="7221" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" />.. <A T="2" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="AppId_PrivacyCleared" />.. </S>.. </G>.. <C T="W" I="0" O="false" N="AppId">.. <S T="1" F="AppId_PrivacyCleared" />.. </C>.. <C T="I64" I="1" O="false" N="ErrorContext">.. <A T="FIRST">.. <S T="1" F="ErrorContext" />.. </A>.. </C>.. <C T="I64" I="2" O="false" N="FailureType">.. <A T="FIRST">.. <S T="1" F="HRESULT" />.. </A>.. </C>.. <C T="U16" I="3" O="false" N="FailureCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1063
                                                                    Entropy (8bit):4.887112081163108
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdxVzj930dRDDHwpat5r01DI10DhW8/hf1b8OKX/c//fpONkMnGYt/9tJk3MbQ:2dxb30dRgeGSyYv+7
                                                                    MD5:C2FDE2ACE66958A69A64FF11361ADE55
                                                                    SHA1:B5ED7D257ED3DFC4CD98B6E1B129A8F298896948
                                                                    SHA-256:6ECCA9A553D47A5B08D4D19FA2396D18DF2378ECBA13F4F782E4A1E08E354C5A
                                                                    SHA-512:1E995A8BBE27581D167310219427F21C8CC7AE95D5B9BF76E66F1E4CE409753AD812989559F0CCC1B6A481933E849F500B03B41EAC676C9A1CA4493F3B4F326D
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12316" V="0" DC="SM" EN="Office.Outlook.Desktop.Copilot.CallSummarize" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" S="10" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="1702" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. <Etw T="2" E="1703" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. </S>.. <G>.. <S T="1">.. <F N="ThreadId" />.. </S>.. <S T="2">.. <F N="ThreadId" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="TotalTime">.. <U T="100nsToMs">.. <O T="SUB">.. <L>.. <S T="2" F="TimeStamp100ns" />.. </L>.. <R>.. <S T="1" F="TimeStamp100ns" />.. </R>.. </O>.. </U>.. </C>.. <C T="B" I="1" O="false" N="Cached">.. <S T="2" F="FromCache" />.. </C>.. <C T="I32" I="2" O="false" N="Status">.. <S T="2" F="Status" />.. </C>.. <C T="I32" I="3" O="false" N="Error">.. <S T="2" F="HRESULT" />.. </C>.. <T>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):666
                                                                    Entropy (8bit):5.218706967788315
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdEUZVzj4nuBdRDDHwpat4AQiG1DXFJzD+ffA3IJnu+/HaSMlU2yNOjsu:2dEUZOn0dRge0vWcmnf/2d
                                                                    MD5:BAB5BEF3F8E39A2334D82E553772652A
                                                                    SHA1:A9BEF1FAB36773E3C7344CD23E3569A235FEA518
                                                                    SHA-256:4D80734D0D6E29A9D0BE96FF2BB2DBBF05EFF51A8AE4B3B36813BA2D7C3DA3C4
                                                                    SHA-512:5406EFA014BC0DF07B7036CEB1B19AC875E6E76ECFDE8D431C9942518238AC0EFB8DDAFDA46D049D91475E9E1D00C38E0BE709F6524D637DFE92CEFC5E989216
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12319" V="2" DC="SM EUPI" EN="Office.Outlook.Desktop.Copilot.SummarizeButtonSeen" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="1708" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. <A T="2" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="UID" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="CountSummarizeButtonSeen">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="G" I="1" O="false" N="AccountUID">.. <S T="1" F="UID" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):960
                                                                    Entropy (8bit):4.594069818668252
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdCOlV1DH410DhW8/hfDb8OKX/c//fpONkMIYmntxt/9u3p1DRQNO/HNUlu:2drDLQrh1F7
                                                                    MD5:90DA0E70C7BC80F596C6308C2613C764
                                                                    SHA1:1CB588E578C3061BD09C5B2EDC7B3C3C7505EC0A
                                                                    SHA-256:8DF995711C6FD28FB180B66F3370DDA2B46316D73F8AB05126DD8E8D4BE95E38
                                                                    SHA-512:C8ABE23E8C2E77636273CB911B46B303F02EC8373BDA6B62514F26561C07264162CD04D67FC50E692B861C341956119532D2754DBC563940D4FEBDF00019A53F
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12320" V="0" DC="SM" T="Subrule" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="1709" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. <Etw T="2" E="1710" G="{081f51e8-2528-44af-ad0b-6e2e5c7242ad}" />.. </S>.. <G>.. <S T="1">.. <F N="ThreadId" />.. </S>.. <S T="2">.. <F N="ThreadId" />.. </S>.. </G>.. <C T="U32" I="0" O="false">.. <U T="100nsToMs">.. <O T="SUB">.. <L>.. <S T="2" F="TimeStamp100ns" />.. </L>.. <R>.. <S T="1" F="TimeStamp100ns" />.. </R>.. </O>.. </U>.. </C>.. <C T="U32" I="1" O="false">.. <S T="2" F="Scenario" />.. </C>.. <C T="B" I="2" O="false">.. <S T="2" F="FromCache" />.. </C>.. <C T="I32" I="3" O="false">.. <S T="2" F="Status" />.. </C>.. <C T="I32" I="4" O="false">.. <S T="2" F="HRESULT" />.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1177
                                                                    Entropy (8bit):4.74856567353489
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdXVzjfg6dRDDHwpatEi0e9XFJzDLg5/efJiNxnGYOtJk1MbSNyN1DLgRApfXT:2dXe6dRge86vcophXYY1AcqJG
                                                                    MD5:CE90AC3A97C76D423E03C42A2D540B00
                                                                    SHA1:2ACC67B653E4A68C86B01BE8CC5804CAE02662DB
                                                                    SHA-256:15D2AD69542C8653B89F57CBD52172383FC761064031D52F233A390FF5B84047
                                                                    SHA-512:52AF9E01AFE116397B3D5E863CB0A43237B048E68F360F477B855ECD1963826D8465407EC7B35BDD50FAC8620BA10C08FB7BD4D5102127AD145BADE63CE1017E
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12321" V="0" DC="SM" EN="Office.Outlook.Desktop.Copilot.BaseCallAggregatedResults" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="12320" />.. <A T="2" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="1" />.. <F N="2" />.. <F N="3" />.. <F N="4" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="Scenario">.. <S T="1" F="1" />.. </C>.. <C T="B" I="1" O="false" N="Cached">.. <S T="1" F="2" />.. </C>.. <C T="I32" I="2" O="false" N="Status">.. <S T="1" F="3" />.. </C>.. <C T="I32" I="3" O="false" N="Error">.. <S T="1" F="4" />.. </C>.. <C T="U32" I="4" O="false" N="Min_TotalTime">.. <A T="MIN">.. <S T="1" F="0" />.. </A>.. </C>.. <C T="U32" I="5" O="false" N="Max_TotalTime">.. <A T="MAX">.. <S T="1" F="0" />.. </A>.. </C>.. <C T="U32" I="6" O="false" N="Avg_TotalTime">.. <A T="AVG
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):870
                                                                    Entropy (8bit):4.9012975637774945
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdJVzjsRyHPdRDDHwpat4AQiBxczPO+u/Y//OBX/c//lpONdcoNBnPRyoXHaSM:2dJpdRgevIuFHv34XD7
                                                                    MD5:ED2EEA9F69EC31D6D2D4421AE496AF34
                                                                    SHA1:C106EA33A1F2707064814A72B79316C77F5E0072
                                                                    SHA-256:000B3A298EFDDB91E16626978813ACC4107A5473AA4EA297BEF78F31AF8C5F30
                                                                    SHA-512:4EDB26551C10C6795DF3AE8451DF6B79C95A868941A398B0B5A0B4E4C8DA04B32E0748A15EECFD1497AC12942BDA4B0A7F222916B764605859F8D234BF293D6E
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12322" V="1" DC="SM" EN="Office.Outlook.Desktop.Sync.OldStyleConflictCount" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <Etw T="1" E="287" G="{f762ce39-ac6c-4e1c-b55f-0e11586e6d07}" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="cbPclNew" />.. </L>.. <R>.. <S T="1" F="cbPclCur" />.. </R>.. </O>.. </F>.. <TI T="3" I="Daily" />.. <A T="4" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="ConflictCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="PclLosingDataCount">.. <C>.. <S T="2" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="4" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):326
                                                                    Entropy (8bit):5.328630182548662
                                                                    Encrypted:false
                                                                    SSDEEP:6:TMVBd7YDkhOVzj1Q3jqBdRijeDHwp1MTZztOHpEXj6eOn2sby:TMHdkjVzj1Q3j6dRDDHwpata+jpO2su
                                                                    MD5:3D538D98D462800080F27BF5B71AABFA
                                                                    SHA1:05BE032ADB2DA6F884F7FAD5A5297AFD83A5E060
                                                                    SHA-256:53C2988A917C41D3F3C58D47CF04764309353EFB5D65CC804D9B0D918AB25804
                                                                    SHA-512:FF7E3CFCD7F29343F67B7745BAC6C50FAFE6718DE65E9CE8623216418BC00A4EED4C71A81AB028DF235FFAB97B56884FF2C23AF674084F0001E0784FE93449AF
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="12324" V="0" DC="SM" EN="Office.Outlook.Desktop.NoOpRuleToAllClients" ATT="d807609276744245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" E="false" S="1" DCa="PSU" xmlns="">.. <S>.. <A T="1" E="TelemetrySuspend" />.. </S>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):296
                                                                    Entropy (8bit):5.2674047932916945
                                                                    Encrypted:false
                                                                    SSDEEP:6:TMVBd7S/ck/XrhGQXulJDZSa94BDhbYlAS8lLerhB4On2sby:TMHdm/BI2qSawSCLerT4O2su
                                                                    MD5:F05BB49727B8D444F7A2326340350A4A
                                                                    SHA1:26C16C9982009A49002B79F76C787B5DA9A56511
                                                                    SHA-256:AAA257D28A9D4D1C901AED1AC23EB9D5E33F37A5A38579B641EEE705A8E70BA0
                                                                    SHA-512:DEC3DC8AC12C3995C0C86F3820BEDE48E22D40C0C6DE2B43A62C4DCE6BCD75147164727CF69B9890BBCE498B1651968A45D5939740775A129B28D0E1EF6E1D33
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="130009" V="0" DC="SM" EN="Office.Telemetry.DynamicConfigNotSet" ATT="f998cc5ba4d448d6a1e8e913ff18be94-dd122e0a-fcf8-4dc5-9dbb-6afac5325183-7405" DCa="PSP" xmlns="">.. <S>.. <UTS T="1" Id="depeq" />.. </S>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):674
                                                                    Entropy (8bit):4.954621155916417
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdm80nXFCjSawSCLerKXFJiQj9DFNXJjXFbEtMqcXHaSMNO5AHNUlu:2dmDXGlwArCv5RV+9c07
                                                                    MD5:BCDD117E151424029040784A770A980D
                                                                    SHA1:C7C28DED2644AC182DEDBC283A2DE38A0DCB3D43
                                                                    SHA-256:A8F9B357507E7B5F708A8DDAB6585127A5BF82349A268B883D898A6D81F24364
                                                                    SHA-512:3C1ACC9FE52E5F99E37F2025E8A0F7A595FDA9929E546751FF3BB3F1A3A7A0C76E392B73EC44E1C61E520D3703C5CD89B191229CD19D17B8B94077D6A0073BE4
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="130010" V="0" DC="SM" EN="Office.Telemetry.NonOfficeEventCount" ATT="f998cc5ba4d448d6a1e8e913ff18be94-dd122e0a-fcf8-4dc5-9dbb-6afac5325183-7405" DCa="PSP" xmlns="">.. <S>.. <UTS T="1" Id="4pjk9" />.. <A T="2" E="TelemetryShutdown" />.. <A T="3" E="TelemetrySuspend" />.. </S>.. <G>.. <S T="1">.. <F N="EventName" />.. </S>.. </G>.. <C T="W" I="0" O="false" N="NonOfficeEventName">.. <S T="1" F="EventName" />.. </C>.. <C T="U64" I="1" O="false" N="EventCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):517
                                                                    Entropy (8bit):5.066654795394057
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdSdjTMFCkoCAvQierBnfXFJiQjFTTXHaSMNO5AHNUlu:2duTMFlHAvcr9v5V07
                                                                    MD5:B193C459E813A668C2FD4248FE9581BD
                                                                    SHA1:0660F4A37A94468CE68DA9041D27753178922664
                                                                    SHA-256:CE55143C4CC81C90D661E0247576AC6E41F454F090F943CB5732D159DB67DD0C
                                                                    SHA-512:AC0C98393EC09049F06E35BC4C9EE5F7CF869846F6362BE9B7C288E65F59D03179FF88FFDB969B6FCBE6A8A236F945E4F1C0B24E5FB7EA3A12AAC2B92A890608
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170000" V="6" DC="SM" EN="Office.Graphics.GVizSmartArtOnLoad" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="axhrr" />.. <A T="2" E="TelemetryShutdown" />.. <A T="3" E="TelemetrySuspend" />.. </S>.. <C T="U32" I="0" O="false" N="SmartArtCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):5980
                                                                    Entropy (8bit):4.560543374557417
                                                                    Encrypted:false
                                                                    SSDEEP:48:ciPgvcMuyltVxCRc3pp4gYfIrAySEFA/o3GPQiZUN1GUT25I8hJ:PPgzu64WIf7ySEA/o3gQGQwU25Ii
                                                                    MD5:63E0611A735D2F2668A655AAC4FD5E49
                                                                    SHA1:4513CED4EC17FB469BE6436767F0929920739781
                                                                    SHA-256:194120AAD5C24D6B41071CE0017DE2606507D2E75809F4026C61E7F0BC4FEB69
                                                                    SHA-512:160ED09B7162F5C3008CD798987465797EEF02507F279FA7B89D99A677979CCE91EBBACBADBB94AB1A447C52E8E6BA3640E026EF3EE8B344907AD280BD4930EA
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170002" V="6" DC="SM" EN="Office.Graphics.GVisCommandSelectionPassthrough" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="axwza" />.. <F T="2">.. <O T="EQ">.. <L>.. <S T="1" F="AlgorithmState" />.. </L>.. <R>.. <V V="Begin" T="W" />.. </R>.. </O>.. </F>.. <F T="3">.. <O T="AND">.. <L>.. <O T="EQ">.. <L>.. <S T="1" F="AlgorithmState" />.. </L>.. <R>.. <V V="Begin" T="W" />.. </R>.. </O>.. </L>.. <R>.. <O T="NE">.. <L>.. <S T="1" F="Cmd_Name" />.. </L>.. <R>.. <V V="NULL" T="W" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <F T="4">.. <O T="OR">.. <L>.. <O T="OR">..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):695
                                                                    Entropy (8bit):4.988669315276604
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdSEGkoCAvQiiHXFJiQjEciRDaXOUdyXHaSMNO35csu:2d75HAvMv5p/IS
                                                                    MD5:418C5EE3DA4F31BAEA523DAA597A654C
                                                                    SHA1:5EF013F918665170A2820FD7C6FB59765855EA74
                                                                    SHA-256:EBC4C60C9856A4294A0BBEA3C648FA24A5586CF90B754204287BC7A933BD4F5F
                                                                    SHA-512:9F514C6BE0E807EB60644E8C912E9390235057A2A37575F9408F5507A56EED2E646DFB78BDFCA520407B442EA7474D01991AEE8AE662F2AC222B30DC91A6531A
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170003" V="1" DC="SM" EN="Office.Graphics.GVisExceptions" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UCSS T="1" C="OART Exception" S="Medium Unexpected" />.. <A T="2" E="TelemetryShutdown" />.. <A T="3" E="TelemetrySuspend" />.. <TI T="4" I="10min" />.. </S>.. <G>.. <S T="1">.. <F N="ULS_TagId" />.. </S>.. </G>.. <C T="W" I="0" O="false" N="TagID">.. <S T="1" F="ULS_TagId" />.. </C>.. <C T="U32" I="1" O="false" N="TagCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="4" />.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):706
                                                                    Entropy (8bit):5.025811692997561
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdSMxk3we7koCAvQqAQierLNerHQiBjFJQXHaSM4cQXHhSMNOAdHNS7lu:2d7kAPHAvfrLYrwo4vDr
                                                                    MD5:3FB804DEA45421658FF21BB2E901DCC6
                                                                    SHA1:20AA0F9CDE554999840DD64F80833A41E5F3CF37
                                                                    SHA-256:E209724DB848748C389C0E053643E372A49273676648F58866D3F3EA390CA840
                                                                    SHA-512:9366B3F9FFDA7A21AA0A78402FBF39BEE7D0318E4CB87C8F7C2F45791722579B63D7DC48D0FF7F647FE59A2C9A47B706C547FC64BD99CF25FA22F3B0AA35A55B
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170005" V="2" DC="SM" EN="Office.Graphics.GVizARC" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="avx7w" />.. <UTS T="2" Id="avx7x" />.. <A T="3" E="TelemetryShutdown" />.. <A T="4" E="TelemetrySuspend" />.. </S>.. <C T="U32" I="0" O="false" N="HardwareCriticalFailureCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="SoftwareCriticalFailureCount">.. <C>.. <S T="2" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="4" />.. </T>.. <ST>.. <S T="1" />.. <S T="2" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1081
                                                                    Entropy (8bit):4.99472127077792
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdSiZyui4pkoCAvQierDsysSN1UdLKftkw9CFIl1fnzle+Dl9osxxroqoocfrq:2d7Zyui4iHAvcrDRjz4ORh9JIdnWk9s
                                                                    MD5:8D5BD0B7837E15CDF137C2EEC0592D9F
                                                                    SHA1:005FCD83EDBDE70A8BBB4C00216A56BBDBA0C67D
                                                                    SHA-256:D211965E524DC42BE23817E6340653CE761CEF77059EB3133048C582ED227880
                                                                    SHA-512:10256A7558B13D014CAEB63070302BE0C87ADC11D86A59E78B1CE3B36E19D8E689E0649E7C0E4FCB5241999B51ED583705625E9333D984E6585D7B34F9C4074E
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170007" V="5" DC="SM" EN="Office.Graphics.GvizInsertPictureTelemetry" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="az707" A="ar0tn bqo11" />.. </S>.. <C T="W" I="0" O="true" N="PictureSource">.. <S T="1" F="StorageProvider" M="Ignore" />.. </C>.. <C T="W" I="1" O="true" N="PictureFormatType">.. <S T="1" F="FileMimeType" M="Ignore" />.. </C>.. <C T="I64" I="2" O="true" N="PictureSize">.. <S T="1" F="ImageFileSize" M="Ignore" />.. </C>.. <C T="I64" I="3" O="true" N="PictureHeight">.. <S T="1" F="Height" M="Ignore" />.. </C>.. <C T="I64" I="4" O="true" N="PictureWidth">.. <S T="1" F="Width" M="Ignore" />.. </C>.. <C T="D" I="5" O="true" N="PictureDpiX">.. <S T="1" F="DpiX" M="Ignore" />.. </C>.. <C T="D" I="6" O="true" N="PictureDpiY">.. <S T="1" F="DpiY" M="Ignore" />.. </C>.. <C T="B" I="7" O="true" N="IsAnimated">.. <S
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):739
                                                                    Entropy (8bit):5.101483793033583
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdSzsZgJi4pkoCAvQier2riKMAe+DlMyrMfXfxxrdyd+DVfIltNO2su:2d0sZIi4iHAvcrSiK/hSZni+BK
                                                                    MD5:B0A4100DB7E9FCA8847722728F08B965
                                                                    SHA1:D4575D82DAC337F58DD05634E7AB6CD446954F90
                                                                    SHA-256:E4627AA23BBC9E529FE26EB4F3C89334E291503C875D7D35BD698C5F503ABAEB
                                                                    SHA-512:EF69652BE4156062D3AE1A12BA5C5ADFF8A397F77F43A3B1713EE581C15CDF2BAC39081CFA9E18AE94BC5B81D34FBCD2564A1C0BD1F09DE5F6D5CCCCFB890156
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170009" V="1" DC="SM" EN="Office.Graphics.GVizInsertPictureDPITelemetry" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="ar39m" A="asjr4 bah6r" />.. </S>.. <C T="I64" I="0" O="false" N="PictureHeight">.. <S T="1" F="Height" />.. </C>.. <C T="I64" I="1" O="false" N="PictureWidth">.. <S T="1" F="Width" />.. </C>.. <C T="D" I="2" O="false" N="PictureDpiX">.. <S T="1" F="DpiX" />.. </C>.. <C T="D" I="3" O="false" N="PictureDpiY">.. <S T="1" F="DpiY" />.. </C>.. <C T="W" I="4" O="false" N="PictureFormatType">.. <S T="1" F="ImageFormat" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):820
                                                                    Entropy (8bit):4.826457377074059
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdSJggikoCAvQierhferFMYD2EfW8/2EfMOHWIab/b8O2X/c//FpONkMNOjsu:2dODFHAvcr8rFf3rWbau
                                                                    MD5:B7A35F02F75A093E0C7CB13EEBA957B0
                                                                    SHA1:1C7DDF99971F1114486BEB22803E160D3E0B6422
                                                                    SHA-256:A684E4135445F2FFD9424DAE62D11231BE8E1CA595A152923F076F00488086C0
                                                                    SHA-512:A6D4C701F86C80921B259994B9D81742C78939F0096FC095D60EEB4C26F4348322E6334FC64E02EEE50775F66858FB10ED55BEC675D66F7A289E8E51B4820E12
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170011" V="2" DC="SM" EN="Office.Graphics.SmartArtIdleLayout" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="awjgf" />.. <UTS T="2" Id="asnax" />.. </S>.. <G>.. <S T="1">.. <F N="SmartArtGuid" />.. </S>.. <S T="2">.. <F N="SmartArtGuid" />.. </S>.. </G>.. <C T="G" I="0" O="true" N="SmartArtID">.. <S T="1" F="SmartArtGuid" M="Ignore" />.. </C>.. <C T="U32" I="1" O="true" N="Duration">.. <U T="100nsToMs">.. <O T="SUB">.. <L>.. <S T="2" F="TimeStamp100ns" M="Ignore" />.. </L>.. <R>.. <S T="1" F="TimeStamp100ns" M="Ignore" />.. </R>.. </O>.. </U>.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1352
                                                                    Entropy (8bit):4.880790943619387
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dQsCHAvfr1uyqCZnr7sQCz6lINzKHOEW:ckgvfZuyHnXsQCz6lxW
                                                                    MD5:BA1B2695827A778CBBA4EAB61845277A
                                                                    SHA1:BDACAD9A2D3D0985130A776B6D18D662CD350C57
                                                                    SHA-256:AAC1F207659EE57F264ABD3E2D5B3E123902041743CD02F23A8038C23FA7983C
                                                                    SHA-512:0EE65B0F05C6F30FA9C07ADF39C0717FD584FE7970D421F3B1EA98CD62860A666754818074089EFCA7693AE5DFD20ECD527EF6FB1F31F06EC923EF57A748AAB6
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170012" V="12" DC="SM" EN="Office.Graphics.GVizInkStroke" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bgwr8" A="aqxmg" />.. <F T="2">.. <O T="EQ">.. <L>.. <S T="1" F="InkAction" />.. </L>.. <R>.. <V V="StylusUp" T="W" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="InputType">.. <S T="2" F="InputType" />.. </C>.. <C T="W" I="1" O="true" N="PenTip">.. <S T="2" F="PenTip" M="Ignore" />.. </C>.. <C T="B" I="2" O="true" N="IsDirectInk">.. <S T="2" F="IsDirectInk" M="Ignore" />.. </C>.. <C T="B" I="3" O="true" N="UsingTrackpadMode">.. <S T="2" F="UsingTrackpadMode" M="Ignore" />.. </C>.. <C T="B" I="4" O="true" N="IsAnimated">.. <S T="2" F="IsAnimated" M="Ignore" />.. </C>.. <C T="W" I="5" O="true" N="AnimationName">.. <S T="2" F="
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):378
                                                                    Entropy (8bit):5.227853114045981
                                                                    Encrypted:false
                                                                    SSDEEP:6:TMVBd7mvEkI2JMBBKMyxqb0c7oCDLChvRCUHperhLnPoURfI6vxxNOn2sby:TMHdSvyuwMkoCAvQierRhfI6ZxNO2su
                                                                    MD5:A87BA7BCA6E326C4606C3E6B82B2AABE
                                                                    SHA1:CE3BA5B4DBE1878B893F6107374F9D7CDA04A1DE
                                                                    SHA-256:D119BB0514010439019F0F793A35455A1D86457971A529EC049F8CD2684F36F3
                                                                    SHA-512:7D6672B37569407481BAD03983CBEE2FA90CDAB71BF0ABCC41505BFE2C9C2F839F40312A56C84B09965F28C89DF8EB4953B6089C953324C0FE903F2C9A88C492
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170013" V="1" DC="SM" EN="Office.Graphics.GVizSlideShowInkSavev1" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="axhji" />.. </S>.. <C T="B" I="0" O="false" N="InkSaved">.. <S T="1" F="InkSaved" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1373
                                                                    Entropy (8bit):4.794620389997292
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dmt20OOO5HAv8huXGHsSt4BGHsm+/9RQ0q+kaqwYGqe:cUNKgv8huXIXt4BIk1RtYGb
                                                                    MD5:EF514A20C4A80A191723BEB5508D250E
                                                                    SHA1:A3272F3C187A22DF4EA142FC111E07FC4CA1B600
                                                                    SHA-256:8C39093AAD28335C2FC61D4A6F1529BB048BBCE699772B617796C676DAAEB556
                                                                    SHA-512:A9240AEB8B0D7E8B0BE5A45306936013EEEE6D6813584A1CDF363DE8316D65B00B929788DAA33CAF049D5F68388E4D1285F1D3B54D6F7AC893BBF649590C0C2F
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170014" V="4" DC="SM" EN="Office.Graphics.GVizClipboardDataDeliveryStart" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" S="500" DCa="PSU" xmlns="">.. <S>.. <UCSS T="1" C="OART Clipboard" S="Monitorable Unexpected" />.. <F T="2">.. <O T="NE">.. <L>.. <S T="1" F="ULS_TagId" />.. </L>.. <R>.. <V V="aw1jo" T="W" />.. </R>.. </O>.. </F>.. <F T="3">.. <O T="EQ">.. <L>.. <S T="1" F="ULS_TagId" />.. </L>.. <R>.. <V V="aw1jo" T="W" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="ULS_TagId">.. <S T="1" F="ULS_TagId" />.. </C>.. <C T="W" I="1" O="true" N="AdvertisedFormats">.. <S T="1" F="AdvertisedFormats" M="Ignore" />.. </C>.. <C T="W" I="2" O="true" N="SelectedFormat">.. <S T="1" F="SelectedFormat" M="Ignore" />.. </C>.. <C T="W" I="3" O="true" N="Codepath"
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1777
                                                                    Entropy (8bit):4.294503887640287
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dMi4iHAvcrgvLJT6DqwONo6JIJAPuaTDquVDDSywoT1x7:cMYgvcMvLJT8qXodJgquVnfx7
                                                                    MD5:F9E0C06685D3A6F2D481D56F482AF5D0
                                                                    SHA1:DDCB3880925E49F06087900D9477F51C1DFD2E82
                                                                    SHA-256:38A5A98F690F3C77AE1C6D5CFF2A6CFB40B4819BD07D59532CCF760CB1F1AB73
                                                                    SHA-512:757B548522B91A3D7272740D53DCAD0C2CD732F4F44943A982AFA8AEB4C5B5A184B141BE16F0438081AEE9E23F6C3862961B1811B166146A2BCCBABC7176469A
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170016" V="7" DC="SM" EN="Office.Graphics.GvizPictureLoadTelemetry" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="aqww0" />.. <A T="2" E="TelemetrySuspend" />.. <A T="3" E="TelemetryShutdown" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="Crop" />.. </L>.. <R>.. <V V="True" T="B" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="GT">.. <L>.. <S T="1" F="EffectsApplied" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <O T="COALESCE">.. <L>.. <S T="1" F="IsSVG" M="Ignore" />.. </L>.. <R>.. <V V="False" T="B" />.. </R>.. </O>.. </L>.. <R>.. <V V="True" T="B" />.. </
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1398
                                                                    Entropy (8bit):4.951307118216317
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d3koHAv3r/PazmmQ13IdJLzcM7HhzORMOwizjNMbYzzmMTS:cUogv3V3I3
                                                                    MD5:B29F2A89922CED2F133DDDE4C880C6F5
                                                                    SHA1:BB4CE992E46AABCC87FB743A1B99F31D3983AA69
                                                                    SHA-256:4EF1455906E4F29285B1B3FA6E7635820F2172B9133F633E5A24EE4BF9592B24
                                                                    SHA-512:BF48CF7D87BEC0EA87A7DA1DCCA1E75ABD7D749079E06F90850C923DC9ADB897564B5898B8C353FEBCA405650BCCC02E1664A9F961FF0283B6A83213B2833011
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170019" V="1" DC="SM" EN="Office.Graphics.GVizARCDevice" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="DC" xmlns="">.. <S>.. <UTS T="1" Id="avx8c" />.. </S>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="1" F="TimeStamp100ns" />.. </C>.. <C T="U32" I="1" O="true" N="VendorId">.. <S T="1" F="VendorId" M="Ignore" />.. </C>.. <C T="U32" I="2" O="true" N="DeviceId">.. <S T="1" F="DeviceId" M="Ignore" />.. </C>.. <C T="U32" I="3" O="true" N="SubSysId">.. <S T="1" F="SubSysId" M="Ignore" />.. </C>.. <C T="U32" I="4" O="true" N="RevisionId">.. <S T="1" F="RevisionId" M="Ignore" />.. </C>.. <C T="W" I="5" O="true" N="Description">.. <S T="1" F="Description" M="Ignore" />.. </C>.. <C T="U32" I="6" O="true" N="DriverVersionMajor">.. <S T="1" F="DriverVersionMajor" M="Ignore" />.. </C>.. <C T="U32" I="7" O="true" N="DriverVersionMinor">.. <S T="1" F="DriverVe
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):601
                                                                    Entropy (8bit):4.056172629241999
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdSWZber3nf+u/qNOTfX/c//PpONd+tNqNOGX/c//uDpONQlVD4NOcsu:2d/UrXmuyQvKt4rTPG
                                                                    MD5:DFA255B135958B7657384B76B081C465
                                                                    SHA1:A1EE72E8BF0F50B24AE87C68693748B7FEDEF316
                                                                    SHA-256:8D4EB4EAE918355407D938C8A083C5A7B320487CBC866C7AAF9FBF1E60B1EB1D
                                                                    SHA-512:2FF77EB57D32FF3F54BEC9F14D71FCCF3620963D4135F987DB64141FF3719B59EFA618C05EE3F7367DE823D3FD65BF2383AB3FEA64AA02B0F39CF5AA63AB1282
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170021" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <UTS T="1" Id="aq4c0" />.. <F T="2">.. <O T="EQ">.. <L>.. <S T="1" F="Feature" />.. </L>.. <R>.. <V V="Slide" T="W" />.. </R>.. </O>.. </F>.. <F T="3">.. <O T="EQ">.. <L>.. <S T="2" F="Event" />.. </L>.. <R>.. <V V="Start" T="W" />.. </R>.. </O>.. </F>.. </S>.. <C T="FT" I="0" O="false">.. <S T="3" F="TimeStamp100ns" />.. </C>.. <T>.. <S T="3" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):755
                                                                    Entropy (8bit):4.6580088883765125
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdS12ukoCAvQrer59XFJ5C/7PNWyNmu/vENP/k//zLMx2Nf/0//jLMhmMNOSjz:2d7RHAv7r5hvYTPP+KL6G
                                                                    MD5:4A407E9411155665D936DB52E585D546
                                                                    SHA1:B7ACFBA28DFACE650A7A7FE3F6522C7FA721A293
                                                                    SHA-256:973F79916EBE464ABF6F7BD02D6273D19CA046D34878131E8016A0988BC94F82
                                                                    SHA-512:D8DBCFEC631D08BC289F69A88E8C535D6609B3B99C5D0CC6BA0920227F5D4078046AE535CEE4D04F8FCA566715A43B2F240F9B3CF42CCC62EE1A959319BF4268
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170022" V="2" DC="SM" EN="Office.Graphics.GVisInkLoad" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" S="1" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="b8ipj" A="anui5" />.. <A T="2" E="TelemetryShutdown" />.. </S>.. <C T="B" I="0" O="false" N="ContainsInkStrokes">.. <O T="COALESCE">.. <L>.. <O T="EQ">.. <L>.. <U T="EqualsNull">.. <S T="1" F="TimeStamp100ns" />.. </U>.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </L>.. <R>.. <V V="false" T="B" />.. </R>.. </O>.. </C>.. <T>.. <S T="1" />.. <S T="2" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1978
                                                                    Entropy (8bit):4.865007630199703
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dUPHAvcrEPA2r1u4lRW8x6AVd7ZNeMCnTAjAG81Eqjpw:cUPgvcKZlblcTAjAGmpw
                                                                    MD5:918A9F7E16AE40CD90F2C6DA9B641772
                                                                    SHA1:892FF60441721AE8CC7CF37B55A15FBFE82B6484
                                                                    SHA-256:89F31306ECE3CEE3AACC0F35821BD3CDE05124E849B79D51B165B8E85C46D1CC
                                                                    SHA-512:228C816074E3750275BD4EC97923AFC60BD39F642326CAF2C4C5BB8A7EB2E7B213858EE348BCBBAE0336F9659C4DDCD8D9641DCB3B3EA29433F4057AD252DE67
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170024" V="2" DC="SM" EN="Office.Graphics.GVisShapeLoadPassthrough" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="a4xg1" />.. </S>.. <C T="FT" I="0" O="false" N="Time">.. <S T="1" F="TimeStamp100ns" />.. </C>.. <C T="W" I="1" O="true" N="Name">.. <S T="1" F="DrEl_TName" />.. </C>.. <C T="U32" I="2" O="true" N="Id">.. <S T="1" F="DrEl_Id" />.. </C>.. <C T="U32" I="3" O="false" N="Interval">.. <S T="1" F="Intv" />.. </C>.. <C T="U32" I="4" O="true" N="WidthEMU">.. <S T="1" F="DrEl_W" />.. </C>.. <C T="U32" I="5" O="true" N="HeightEMU">.. <S T="1" F="DrEl_H" />.. </C>.. <C T="W" I="6" O="true" N="Type">.. <S T="1" F="DrEl_Type" M="Ignore" />.. </C>.. <C T="B" I="7" O="true" N="Textbox">.. <S T="1" F="DrEl_Txtbox" M="Ignore" />.. </C>.. <C T="B" I="8" O="true" N="Line">.. <S T="1" F="Prop_Line" M="Ignore" />.. </C>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1397
                                                                    Entropy (8bit):4.624076210416062
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dWgGi4iHAvcrl2rBMTTP5amwOaBzASJvfS60J:cPGYgvc8uTPPQBXJXCJ
                                                                    MD5:96D3EA047045AA5FEA38C4C0E030CE7A
                                                                    SHA1:BD5AE82B1814EFDAD48898E0CDBD3D7EAE972FC2
                                                                    SHA-256:F4DB352A86A7BC1C671C47429711AA6F49185D08C1056BA2539BEB4CBE2876E7
                                                                    SHA-512:F1801B591E9F9B965D99B46CC382954FB552B2EEA4140A3418DE0E50D79F69A75AFB3170A66C6108C8F537B15D3963368839FD030C53E630BB82BFFBA1B8BF80
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170026" V="0" DC="SM" EN="Office.Graphics.GvisIgxTextTelemetry" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="a6mzy" />.. <UTS T="2" Id="axwza" />.. <SR T="3" R="Igx::">.. <S T="2" F="Cmd_Name" />.. </SR>.. <F T="4">.. <O T="EQ">.. <L>.. <S T="3" F="AlgorithmState" />.. </L>.. <R>.. <V V="End" T="W" />.. </R>.. </O>.. </F>.. <F T="5">.. <O T="EQ">.. <L>.. <S T="1" F="ULS_Category" />.. </L>.. <R>.. <V V="Scope Summary" T="W" />.. </R>.. </O>.. </F>.. <F T="6">.. <O T="EQ">.. <L>.. <S T="5" F="ScopeName" M="Ignore" />.. </L>.. <R>.. <V V="FileIO::CMsoOLDocBase::Close" T="W" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="4">.. <F N="Cmd_Name" />.. <F N
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):582
                                                                    Entropy (8bit):5.144590977150849
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdSCZ7koCAvQierBFVKI2dn+KufydytUdNO2su:2d+HAvcrgaa1T
                                                                    MD5:6FED60969E2A0FF0B4031FA943C0B49F
                                                                    SHA1:1A2F3EC4281336EB650F72A987B1464BB185A521
                                                                    SHA-256:C175CB2A33151E4BDF6E74FE0E77B2FB539BA3377EE969B918A7F803AA1AE1B3
                                                                    SHA-512:771A29361752C4DC773C9B275BFE0F5286BDF37A5EE2DA973DA731B2EABC75CC51CF94A4C8C654E5C608DDA74D79075017BCAE051C7A452AD6C439D3096DC7EB
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170027" V="0" DC="SM" EN="Office.Graphics.GvisIgxCPOpenCloseFrameWidgetXButton" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bbxeh" A="bb9a0 bb9a1" />.. </S>.. <C T="B" I="0" O="true" N="IsTouch">.. <S T="1" F="IsTouch" M="Ignore" />.. </C>.. <C T="B" I="1" O="true" N="CPState">.. <S T="1" F="CPState" M="Ignore" />.. </C>.. <C T="W" I="2" O="false" N="TagID">.. <S T="1" F="ULS_TagId" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):553
                                                                    Entropy (8bit):4.969728038448219
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdSKa8rkoCAvQieroereVv8X7PNWYuEf/0//OEhmMNOSjsu:2dmHAvcrPr48PoEPq
                                                                    MD5:29493EFE9911810F5277E0143479C8A3
                                                                    SHA1:45DCB80F9B49804218C03D3824AE9E44F4AB03BA
                                                                    SHA-256:7C178B2E5EBC2C6E923F88770BBD4EC417414F7EED8D54998134DAD5B6CDA2F8
                                                                    SHA-512:D3D7D2D45E77B5B1BAB284BC6DF258E8F437A2D0FC3D528AAA405B34F755CB1C55F69868195B0747ED092597D37208D9AD2CDA56CF46C3C9FC288739FE0A2820
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170030" V="1" DC="SM" EN="Office.Graphics.GFXLegacyInk" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bcze6" />.. <UTS T="2" Id="bdgkj" />.. </S>.. <C T="B" I="0" O="true" N="LegacyInk">.. <O T="COALESCE">.. <L>.. <S T="1" F="IsLegacy" M="Ignore" />.. </L>.. <R>.. <S T="2" F="IsLegacy" M="Ignore" />.. </R>.. </O>.. </C>.. <T>.. <S T="1" />.. <S T="2" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):641
                                                                    Entropy (8bit):4.903636660795986
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdS0rkoCAvQiernerXNQiBjF4LEXHaSM7qOXHhSMNOAdHNS7lu:2doHAvcrerXqoBaDr
                                                                    MD5:AFBE46BFE61FCBC9C64CDF4896533183
                                                                    SHA1:E365B923E0C2BD5487B7268511A6617F6359E9F3
                                                                    SHA-256:6519A355273F56A057535CD379079D8A71E512A36C01ECA18E8F5AD5D37DD765
                                                                    SHA-512:3CEF0C082B40902EFB3CCC116F60CA8EDB6A889E51C2D82C6520B0E1B420345252C98C7EC1C4C8B028144BBF9B939361FF22502CD024D133612571885B7343F3
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170032" V="2" DC="SM" EN="Office.Graphics.XErrors" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="aopfi" />.. <UTS T="2" Id="aopfj" />.. <A T="3" E="TelemetryShutdown" />.. <A T="4" E="TelemetrySuspend" />.. </S>.. <C T="U32" I="0" O="false" N="BlueXCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="RedXCount">.. <C>.. <S T="2" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="4" />.. </T>.. <ST>.. <S T="1" />.. <S T="2" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):385
                                                                    Entropy (8bit):5.136853677559959
                                                                    Encrypted:false
                                                                    SSDEEP:6:TMVBd7mxkq4Yb0c7oCDLChvRCUHperhDpJrzVlrzwyXPfPSSMNOn2sby:TMHdSrCkoCAvQierpXzHtXHaSMNO2su
                                                                    MD5:843452212CEDA1ADAC17AC275C9AA57E
                                                                    SHA1:E0307E27FBC591B69EAB1AACFD74654D7B102998
                                                                    SHA-256:F9526108AC0659CAF5261122FBAF9842865B04DFE1244B321C1AF55872F83223
                                                                    SHA-512:627A47F370552A4640A19BCFE8F06097F6E17C439909B521AE42098861654442BF13CF93638157A69D2B309F9250D1FA832C6CD264C79A26001C9F96148ED523
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170033" V="0" DC="SM" EN="Office.Graphics.DirectInkCount" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bb5lm" />.. </S>.. <C T="U32" I="0" O="true" N="DirectInkCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):697
                                                                    Entropy (8bit):5.019036184216836
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdSB0tRnIkoCAvQierrgydvFRKcXFJzDaXOUdyXHaSMNO/HNUlu:2d3HAvcrrfLlvm/Ip7
                                                                    MD5:842E7D9AEE17184674A20F467EE8BDE4
                                                                    SHA1:ACF980F161E7FD65B6ADB5E5C1D41797FCD6C5C5
                                                                    SHA-256:4787A42DE16791E087BAEC1841A92DF14F0C74CBDB2F425C6C0BBFE3F20DC322
                                                                    SHA-512:63646FA0E4E2D38023D4A837DDC1EC92ACD60F55488767C4C5654DE129C929F581AD447442BF5BE839235FCBDBF90EA8F665BE4EE3FA8820B90C9BAEFE9DD3D5
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170034" V="1" DC="SM" EN="Office.Graphics.SmartArtCoauthoringConflictInfo" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bfo77" A="bfo78 bfo79 bfo8a bfo8b bfo8c bfo8d bfo8e bfo8f bfo8g bfo8h bfo8i bfo8j bfo8k" />.. <A T="2" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="ULS_TagId" />.. </S>.. </G>.. <C T="W" I="0" O="false" N="TagID">.. <S T="1" F="ULS_TagId" />.. </C>.. <C T="U32" I="1" O="false" N="TagCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):809
                                                                    Entropy (8bit):4.856392286032534
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdS/xl6rkoCAvQierIiH+SXFJzDP4ydXtt/AGqdrNedynm/3ROXHaSMNO/HNUw:2dKrHAvcrfvXrttF6r0cmsp7
                                                                    MD5:9DCED172BAF73EBF6C7CAAEFEC2F6D9C
                                                                    SHA1:852CEA1CF8B916187472156D6BD0ABDE05A9F5B7
                                                                    SHA-256:86AB0DBB90D8BD3108472E32219277A425301FA37EBC2C2F6D5BD842359168D4
                                                                    SHA-512:6BE4408C8AF768250AD8D8DA61A65F800527362CAEBB5399CE0ACE744B93026DA9C96FEA165EBED0E6E66962167428970434D6CA99BF6ACC98F56D60C61A7B87
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170035" V="1" DC="SM" EN="Office.Graphics.FormatPainterUsage" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="axum5" A="axum6 axum7 beg4t" />.. <A T="2" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="Action" />.. <F N="from" />.. <F N="to" />.. </S>.. </G>.. <C T="W" I="0" O="false" N="Action">.. <S T="1" F="Action" />.. </C>.. <C T="W" I="1" O="false" N="Source">.. <S T="1" F="from" />.. </C>.. <C T="W" I="2" O="false" N="Destination">.. <S T="1" F="to" />.. </C>.. <C T="U32" I="3" O="false" N="Count">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1169
                                                                    Entropy (8bit):4.822742548829354
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dt9lHAvcrtr5rxrq2rWNKAnOQ8jH15TDkD:ct9lgvcBdle2iNKAkFkD
                                                                    MD5:92B3092F11F34A6511540F647FAA8087
                                                                    SHA1:860944E730B98C8905221A4C6EAB897DC162AF0B
                                                                    SHA-256:4C5E1CC1DEB2E26981A4F29F293878B602C252AA94AB355F161DA75F8227998B
                                                                    SHA-512:83FB269453BB8F69163B45462650FDABF7095FF036E81A946E3B1FEF85AA75B5A4BE198FAE14A4EDEB24880532C6B9E16A6E533A96107D497B176B160DAC799E
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170037" V="1" DC="SM" EN="Office.Graphics.GvisIgxBulletCustomization" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bdld4" />.. <UTS T="2" Id="bdld5" />.. <UTS T="3" Id="bdld6" />.. <UTS T="4" Id="bdld7" />.. <UTS T="5" Id="bdld8" />.. <A T="6" E="TelemetryShutdown" />.. <A T="7" E="TelemetrySuspend" />.. </S>.. <C T="U32" I="0" O="true" N="BulletSizeCustomizationCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="true" N="BulletColorCustomizationCount">.. <C>.. <S T="2" />.. </C>.. </C>.. <C T="U32" I="2" O="true" N="NumberBulletCustomizationCount">.. <C>.. <S T="3" />.. </C>.. </C>.. <C T="U32" I="3" O="true" N="PictureBulletCustomizationCount">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U32" I="4" O="true" N="CharBulletCustomizationCount">.. <C>.. <S T="5" />.. </
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):702
                                                                    Entropy (8bit):5.0149827785161785
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdSFiCkoCAvQier1eruerJVCGONan+i0GnNant9PGoNaNOS5csu:2dCilHAvcrgrBrIc/Wn
                                                                    MD5:698394FDF95BC924F1E1D2F5150FA82C
                                                                    SHA1:7974D0E69C1C5E7B0EE89FE1268C6224BD7D048A
                                                                    SHA-256:797E45A338DA5158135564FA1A8328E6700BF1F25BEAE9589B9AE78E166243A0
                                                                    SHA-512:E9D5C61CC943081E5B82FAD68CC4103741E80946E470783C9E9EC22E9A04365EC99E9622DB53D43FC2188A51D13CB3CBCD5181DCC1C6DD5BF74D16D171777E4D
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170038" V="0" DC="SM" EN="Office.Graphics.InkPointerMode" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bfslj" />.. <UTS T="2" Id="bfmm5" />.. <UTS T="3" Id="bfmm6" />.. </S>.. <C T="B" I="0" O="true" N="ExcelPenPointerMode">.. <S T="1" F="PenPointerMode" M="Ignore" />.. </C>.. <C T="B" I="1" O="true" N="PPTPenPointerMode">.. <S T="2" F="PenPointerMode" M="Ignore" />.. </C>.. <C T="B" I="2" O="true" N="WordPenPointerMode">.. <S T="3" F="PenPointerMode" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. <S T="2" />.. <S T="3" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):600
                                                                    Entropy (8bit):4.9230249967709785
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdSICkoCAvQij+u/qNO8yX/c//kpONUVrGnNaNOjsu:2dPlHAvAuyBG01
                                                                    MD5:8E08A4A4434C6709EBDA69D7BD93223F
                                                                    SHA1:0DAEA87E70E8EF0AC4C83E6087AD6F551ECFAC5A
                                                                    SHA-256:1287C8686BB0382C84E9F9A11430B0995C48659037EC0430B668E7EC190F5493
                                                                    SHA-512:9F309FA4599119D2CBFB56C58BD73D58213E806AF3EC27A8909101C2D9455760CAAF7F49CB0DEB233039E7D85B5A67C432EA917A3E8E2D60330D308AFF1770DE
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170039" V="0" DC="SM" EN="Office.Graphics.InkPointerModeForFork" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UCSS T="1" C="Office Ink Object" S="Medium" />.. <F T="2">.. <O T="EQ">.. <L>.. <S T="1" F="ULS_TagId" />.. </L>.. <R>.. <V V="0000" T="W" />.. </R>.. </O>.. </F>.. </S>.. <C T="B" I="0" O="true" N="PenPointerMode">.. <S T="2" F="PenPointerMode" M="Ignore" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):389
                                                                    Entropy (8bit):5.168654440867369
                                                                    Encrypted:false
                                                                    SSDEEP:6:TMVBd7mR2mkULl8qb0c7oCDLChvRCUHperhztEnPNVlr8L7C/BLlW9NOn2sby:TMHdSRNlCkoCAvQier2V+uVlaNO2su
                                                                    MD5:3F1320444F09DC47C7D53EE61A3BC164
                                                                    SHA1:DF4B5D280DCC4D4918B0B70C3CD86AF7EB1D0ABE
                                                                    SHA-256:3CB08AFA5BD579158FF88CEE805780D30A9B5E2271F1A79B723A3127313D2F96
                                                                    SHA-512:F47EE9533F935B9656F2E2F7DC98C034E96364EC481D358BA37D69041BC92B942180763044739A61EBD2B87ABDCB1B789F1E4CAF99720CBB136D7FE1FEB2F0D0
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170040" V="0" DC="SM" EN="Office.Graphics.PenSelectMode" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="pen99" />.. </S>.. <C T="B" I="0" O="true" N="PenSelectMode">.. <S T="1" F="PenSelectMode" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):755
                                                                    Entropy (8bit):4.845207902572627
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdSpkoCAvQJerQ1sN+u/xH/OlKbX/c//8pONwsAlaOXyKQp9lSCNOjsu:2d/HAv3rQK8uRZua
                                                                    MD5:FF35978853CFE18A3DB88D45ACA46F01
                                                                    SHA1:B5C22FCF47755CD7953FFE0AE23B986C0FDA576C
                                                                    SHA-256:96A9537135511939C2EADEE3F1D04346BE6621C6B8759ADCDBE94B045F292C4D
                                                                    SHA-512:EAB0E56AC661ECA641345BD6F7F0C3553AD8B3D275470FF42ABF05763C611E9C0CE8A38C0F52B20BD4D07078367B9AACF1B97776553AE7F48BD9E717779B020A
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170041" V="2" DC="SM" EN="Office.Graphics.ARCWaitTime" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="DC" xmlns="">.. <S>.. <UTS T="1" Id="bfi37" A="bfi38" />.. <F T="2">.. <O T="GT">.. <L>.. <S T="1" F="TimeElapsedMS" />.. </L>.. <R>.. <V V="100" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="true" N="TagID">.. <S T="2" F="ULS_TagId" M="Ignore" />.. </C>.. <C T="U32" I="1" O="true" N="ElapsedTime">.. <S T="2" F="TimeElapsedMS" M="Ignore" />.. </C>.. <C T="U32" I="2" O="true" N="Result">.. <S T="2" F="Result" M="Ignore" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):715
                                                                    Entropy (8bit):5.037196898720328
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdS0ttokoCAvQier8NXFJiQj5szgxCfhxSn+zghOhhrIpygxocXHaSMNO5AHN9:2dhtdHAvcrCv5lcNdSurzw07
                                                                    MD5:36BEFE950748CEEB84509AAAD0E1417C
                                                                    SHA1:83234D07FD0FF74AD2522E8F40EDA5CB287F4501
                                                                    SHA-256:9383D029320A97925642D00955D451109346A50EA6595CEACA8FCAFCDE6E6284
                                                                    SHA-512:44CA372484414A2A51831DFF426C4BA49A19FF0EDB44A3E414FEC1778FBC56F3EC7003C1C4DAA6DB4C3102FD9616D02ED3572BCEC5FFF17E881AD36156E1DC99
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170042" V="4" DC="SM" EN="Office.Graphics.GFXFilterTypeRequested" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bhlwe" />.. <A T="2" E="TelemetryShutdown" />.. <A T="3" E="TelemetrySuspend" />.. </S>.. <C T="W" I="0" O="true" N="FilterType">.. <S T="1" F="FilterTypeRequested" />.. </C>.. <C T="B" I="1" O="true" N="FilterAllowed">.. <S T="1" F="FilterAllowed" M="Ignore" />.. </C>.. <C T="U32" I="2" O="false" N="FilterTypeCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):473
                                                                    Entropy (8bit):5.07230516973807
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdSIUpkoCAvQJer3glVZ6C7cXHaSMNO2su:2dXRHAv3rwPj7cK
                                                                    MD5:AF187181F83172CD89F38E1DF195ABD8
                                                                    SHA1:270C498B965D550DA3071CF8E0C0EE50ED5402E4
                                                                    SHA-256:21E1AEE38B930E82263F44F6AADC9975630EF933941562DCFC7465C4F5FB1B53
                                                                    SHA-512:DEE72DAB36A4EC86FA84A1CA7A25725A05E8373AB89EEE44BC1B4AAC5443D68D0F76C46905B71F0C8FFCE3E1C77033A3AA441C8D9748A89819EABA3E2B2BA47C
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170043" V="1" DC="SM" EN="Office.Graphics.CacheFull" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="DC" xmlns="">.. <S>.. <UTS T="1" Id="bgyr9" />.. </S>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="1" F="TimeStamp100ns" />.. </C>.. <C T="U32" I="1" O="false" N="CacheFullCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):519
                                                                    Entropy (8bit):5.066486734278268
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdSVqaIkoCAvQier2XFJiQjF0uXHaSMNO5AHNUlu:2dFMHAvcrmv5W7
                                                                    MD5:F98CD51CFC2E4B9A685E12A0F62109B9
                                                                    SHA1:0C5F7DAD7195931B74DB9127495EA8B9766FA185
                                                                    SHA-256:A978C9E902A0A7FCCDCA51AFA14252367697DFFAE32623F8FDAF4762E3FB20B6
                                                                    SHA-512:BDC1EAEFD43AC3C2348DA61EFA45EA3BD967475959984B7BB63CEC65574B84ADD5CB46E27EDF7037BAC1C497C5DAF2D3F5063974B6B03380F44CED5AD5927A8B
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170044" V="4" DC="SM" EN="Office.Graphics.GfxEPSFilterInsert" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bhg21" />.. <A T="2" E="TelemetryShutdown" />.. <A T="3" E="TelemetrySuspend" />.. </S>.. <C T="U32" I="0" O="false" N="EPSFilterInsert">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):578
                                                                    Entropy (8bit):5.162787367717548
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdSZfkoCAvQierHBuV9NkW+n+uL73nt9t8SfCdNO2su:2dqMHAvcrH46W8qq4
                                                                    MD5:FC85AF5E55A9EF3838DA4C1D0C94E625
                                                                    SHA1:0A58327848F5BD33550B82FD6FAD9DF67B4D287B
                                                                    SHA-256:2E9D90219EBCD88768E0E70B7AC5C45C3088C8EE21AB2FDB104C4F50DC40787D
                                                                    SHA-512:10CDC7CFDAEC6603B83C00C4CFD97E555B1E1563D0F4226A47D29615ED87165FA38B14E2BFDC1353523BD2A616E3DB3F8147F72D2434C102FDDC9FE2FEC88835
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170048" V="0" DC="SM" EN="Office.Graphics.BGRWithBrush" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bi7up" />.. </S>.. <C T="B" I="0" O="true" N="BrushExperience">.. <S T="1" F="Brush Experience" />.. </C>.. <C T="B" I="1" O="true" N="BgRemovalUsingDrag">.. <S T="1" F="Bg Removal Using Drag" />.. </C>.. <C T="B" I="2" O="true" N="ChangesAccepted">.. <S T="1" F="Changes Accepted" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):2976
                                                                    Entropy (8bit):4.9871689157577395
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dtvxIHAvcrANSWvHuEj2Kd10gwRedOQpgMSgenvtNc1gdE/Y7uT3w8fE4WUEHWb:cpxIgvc6gAIqUj1lgcbl2GMwLfw
                                                                    MD5:D9820344DFB41D5E653DE1BB499D3466
                                                                    SHA1:F550017D674AA71A362FEE7285C408D2B84E36C1
                                                                    SHA-256:F9493245AA4B8678E2B1A630947621C0F0B14DCB3140056060CBF2DC59A04D19
                                                                    SHA-512:A5420888F9F6CA00EFF302165847FA757655EC14D52DF9473268299B050DB872A4844A997090B3B85F165A4D27D39443308B70BADDD7C402589047C0B7AA90C0
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170050" V="2" DC="SM" EN="Office.Graphics.SVGStats" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bjjme" />.. </S>.. <C T="U32" I="0" O="true" N="SVGFileCount">.. <S T="1" F="SVG_File_Count" M="Ignore" />.. </C>.. <C T="U32" I="1" O="true" N="TotalTagCount">.. <S T="1" F="SVG_Elements_Total_Count" M="Ignore" />.. </C>.. <C T="U32" I="2" O="true" N="FilterBlendCount">.. <S T="1" F="SVG_Filter_Blend_Total_Count" M="Ignore" />.. </C>.. <C T="U32" I="3" O="true" N="FilterMatrixCount">.. <S T="1" F="SVG_Filter_ColorMatrix_Total_Count" M="Ignore" />.. </C>.. <C T="U32" I="4" O="true" N="ComponentTransferCount">.. <S T="1" F="SVG_Filter_ComponentTransfer_Total_Count" M="Ignore" />.. </C>.. <C T="U32" I="5" O="true" N="CompositeCount">.. <S T="1" F="SVG_Filter_Composite_Total_Count" M="Ignore" />.. </C>.. <C T="U32" I="6" O="true" N="C
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):607
                                                                    Entropy (8bit):5.000787995445468
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdSnGqkoCAvQJerHhXFJiQjXlVZ6iDXHaSMNO5AHNUlu:2dTHAv3rHtv5rPX07
                                                                    MD5:78A79CE38068ED010B127894D812D8FF
                                                                    SHA1:B3E41FE1E0B3DBDBC08D8065E130CDDC442D9DA9
                                                                    SHA-256:BF23CD0D99C0E63E852431AEBE61EDE572AED2B96D0457BD8E7C3D566E9E0CA5
                                                                    SHA-512:9ED98C17435700B7CC4271AB787930046412F85FF39B667BB6E954A9FA0B0138BF061473A88E1D6CF2BCE10A44AB7E1D2361307E89706B100B333F3FCEE5C911
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170052" V="2" DC="SM" EN="Office.Graphics.EvictedCache" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="DC" xmlns="">.. <S>.. <UTS T="1" Id="bi90m" />.. <A T="2" E="TelemetryShutdown" />.. <A T="3" E="TelemetrySuspend" />.. </S>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="1" F="TimeStamp100ns" />.. </C>.. <C T="U32" I="1" O="false" N="EvictedCacheCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):453
                                                                    Entropy (8bit):5.144547003197568
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdSfrZ7koCAvQJerE5G+EpbOSZtM4lNO2su:2dgrqHAv3rlL
                                                                    MD5:02D53336240281CF7F5E999BEACCD121
                                                                    SHA1:5177C37E53E14BA25A97C4F558E7887EAAB9E467
                                                                    SHA-256:D243CF46E5EAF56A43BCA31E8D254AD690BE084210F3D2566AE8E9D071205996
                                                                    SHA-512:98CE24D47AB99A16C3AD56B5AA02119BE2E10DB76C3377636BD3A99B0CE2A65618DFF41CC573BE8DF1F2C0038E9B2C4A81A96B260ED59D535E000E5E61412E27
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170053" V="1" DC="SM" EN="Office.Graphics.SpriteMem" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="DC" xmlns="">.. <S>.. <UTS T="1" Id="bkj8w" />.. </S>.. <C T="U64" I="0" O="true" N="CurrentSpriteMem">.. <S T="1" F="Current" />.. </C>.. <C T="U64" I="1" O="true" N="MaxSpriteMem">.. <S T="1" F="Peak" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):627
                                                                    Entropy (8bit):5.155859118419826
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdSsTKpkoCAvQqAQ+erhjG+EpbOt6ZCiuXAedy9z/s+NO2su:2dZKiHAvHrhOyjk0+
                                                                    MD5:68EEB4EB84FDC7C0799FD029B4F85E21
                                                                    SHA1:C83A27C600C538B690862C0AC877030948C96651
                                                                    SHA-256:0F2FCDF329E471C82724E5C3EB0831CCF64091EBD39C5CEB91EB717E3C64F79B
                                                                    SHA-512:2E8D435983631AF29CEB2C03BA744472CF60F1E932A6BEF2F0680FD1B78039F0C217D6BF20AA5F2D7AE0F7315A7E1301BD4231BF83E4078C9DC1000C7C6F61FF
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170054" V="1" DC="SM" EN="Office.Graphics.SpriteMemCorrupt" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" SP="CriticalBusinessImpact" DL="B" DCa="DC" xmlns="">.. <S>.. <UTS T="1" Id="bkj8v" />.. </S>.. <C T="U64" I="0" O="true" N="CurrentSpriteMem">.. <S T="1" F="Current sprite memory in use" />.. </C>.. <C T="U64" I="1" O="true" N="SpriteMemToRemove">.. <S T="1" F="Amount to remove" />.. </C>.. <C T="W" I="2" O="true" N="Function">.. <S T="1" F="Called from function : " />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):653
                                                                    Entropy (8bit):5.165545586320683
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdSBIVKpkoCAvQierDKvOUddLz/St9dBXeQXMNsAn/3ZMNO2su:2d6IgiHAvcrev///gjc1u
                                                                    MD5:0EAF5B7124C94B6EB648039C4C1231CA
                                                                    SHA1:996B2AB77570DDF9574F6B0D3F93CCB4BD5CD05B
                                                                    SHA-256:AB5DF448EC06EDE239CE86F5FC8A6D155349B1451EE99065E39361E39C3DD1D7
                                                                    SHA-512:03919EB4275DE2D7F21C983160B2BC5A8042079E688D449E5EC2A682BC840C1A3B43E08EEC7C937AEA2B460AB12DA3A96420CBA42D9EA7350AB06724F457C745
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170056" V="0" DC="SM" EN="Office.Graphics.InvalidCharacterPos" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bmw6j" A="bmw6k" />.. </S>.. <C T="W" I="0" O="false" N="TagID">.. <S T="1" F="ULS_TagId" />.. </C>.. <C T="W" I="1" O="true" N="Function">.. <S T="1" F="Function" />.. </C>.. <C T="I32" I="2" O="true" N="TextBodyLength">.. <S T="1" F="TextBody Length" />.. </C>.. <C T="I32" I="3" O="true" N="RightCharPosition">.. <S T="1" F="right.m_charPos" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):523
                                                                    Entropy (8bit):5.057892482651669
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdSgVekoCAvQiergOXFJiQjFDlcXHaSMNO5AHNUlu:2dFVhHAvcrfv5Xc07
                                                                    MD5:4D23F684387F1A6DE0221BA674B0ED49
                                                                    SHA1:2AEDB7C64BE5A35CEAFCC343C3C125B444013910
                                                                    SHA-256:4547ACF1AEC0B426534454F589B4B36CCA67E2CD147DD7CFFBB4FE18E2F45A03
                                                                    SHA-512:BA7B0B98C5A65DEC20826E6A6D74870A4A6B0B3131DBFF70BE3D0E18077DA00D0DF80EC9C4A9C45DD8EFDCCD23CCB3D8264BF030304A763F6394FB14BA4DD625
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170058" V="1" DC="SM" EN="Office.Graphics.ShapeInteraction" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bopvj" />.. <A T="2" E="TelemetryShutdown" />.. <A T="3" E="TelemetrySuspend" />.. </S>.. <C T="U32" I="0" O="false" N="ShapeInteractionCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):525
                                                                    Entropy (8bit):5.0963759077169914
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdS1za+7koCAvQierWXFJiQjFk6RXHaSMNO5AHNUlu:2do4HAvcrGv5j07
                                                                    MD5:CC333796EF5E702872FCA9550F856C9D
                                                                    SHA1:85AF74847FA2C8EDCAA2CF92E80C06C2F8059F14
                                                                    SHA-256:A37682E3B7DA4C1E530D73B7CBB207469EDB96475CFEFDE09427DB48BCADD711
                                                                    SHA-512:2795F5BD6E073A60DD8B49E02F0E24742E1CE301C3D971F88DEEB135B1D57CEFBB11EFF7623DD1F246CDFEFD8E9CF0BAE623311E972FC91FE83735F29690AAD7
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170059" V="1" DC="SM" EN="Office.Graphics.BarrelButtonLasso" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bopvk" />.. <A T="2" E="TelemetryShutdown" />.. <A T="3" E="TelemetrySuspend" />.. </S>.. <C T="U32" I="0" O="false" N="BarrelButtonLassoCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):391
                                                                    Entropy (8bit):5.241455521463736
                                                                    Encrypted:false
                                                                    SSDEEP:6:TMVBd7mLHykZTqb0c7oCDLChvRCtRMFpAQUHperhF7dxkUSwNOn2sby:TMHdSprkoCAvQqAQierfJOUdNO2su
                                                                    MD5:A488C50B92123B508760CC3EB36D10EE
                                                                    SHA1:B0B8E48BA0825D2BB9A085A7FA2DBB097D5226C6
                                                                    SHA-256:67D008FD54527348F2344E7B9FDCE6966E3023A9194F90493260ADA9A8893276
                                                                    SHA-512:3621745FA260ACEA65FCA1B2A2643F6EBA3E9E2811970DF3E48776D25508768F78566AA13C4DA4AD10521A5461885854472F29340334DA69443D6344DEB415C0
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170060" V="1" DC="SM" EN="Office.Graphics.D2D1Usage" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bqo3s" />.. </S>.. <C T="W" I="0" O="false" N="TagID">.. <S T="1" F="ULS_TagId" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):841
                                                                    Entropy (8bit):4.495890781581802
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdS0NkoCAvQier0XFJiQjE+kXqNOjPNewHYH/M//jrM5eNX/c//QQnpONG/RX3:2d3GHAvcrgv5vTAPuaTDQD7
                                                                    MD5:68EE80CC790475D0324B760479ADE7C2
                                                                    SHA1:1F29347A4C3CF4EB37C9815B7B8F37077DC9FA1C
                                                                    SHA-256:3AFBF730CDE57543EB757FB2BBF16C7E5DEF85AE6C677978FAB68EC35AE22B71
                                                                    SHA-512:08FA58FE2CF920DE42AE3FFF3C5A2233271F0A6DDADF379D5EC6274D8C29ABFEA25845339E0592671DEFB35BF7AFCCC232A590287B801C8B7AF74515CAB7F5D6
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170061" V="5" DC="SM" EN="Office.Graphics.SVGLoad" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="aqww0" />.. <A T="2" E="TelemetryShutdown" />.. <A T="3" E="TelemetrySuspend" />.. <F T="4">.. <O T="EQ">.. <L>.. <O T="COALESCE">.. <L>.. <S T="1" F="IsSVG" M="Ignore" />.. </L>.. <R>.. <V V="False" T="B" />.. </R>.. </O>.. </L>.. <R>.. <V V="True" T="B" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="false" N="SVGCount">.. <C>.. <S T="4" />.. </C>.. </C>.. <T>.. <S T="3" />.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):390
                                                                    Entropy (8bit):5.131476606472836
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdSeYyYs7koCAvQier5zQyXjXHaSMNO2su:2dIyYs4HAvcr7jK
                                                                    MD5:453F813F8061FDF2468715C5B436D33E
                                                                    SHA1:CDC81168A525E48B9E26B8D6A0F22AB55B032BFF
                                                                    SHA-256:61D2BF8CBAAC280BD902DA9AF9321DC86838980D5A6CEBA4EF51F404DDF3C139
                                                                    SHA-512:6B547FD81C7D26049EE8B43B82A3026C47EDD3BA0CD453B5BCA631A8F3F2BBB1772FAC9A1E1130F8F7E9B5C9D92939287EB6CF4792D244A83F64E1598D30898C
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170065" V="0" DC="SM" EN="Office.Graphics.StencilOutside" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="brl93" />.. </S>.. <C T="U32" I="0" O="true" N="StencilOutsideCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):412
                                                                    Entropy (8bit):5.224378013807265
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdSro9koCAvQierQzQyN3OXHaSMNO2su:2dwoWHAvcri+K
                                                                    MD5:59BB827938E1CD1AF3A044EF54EE7DFE
                                                                    SHA1:BEF188770E9F2AA713411AC71F3FC0638FF190D4
                                                                    SHA-256:03AF34634250F6AE4DB15EB9B406AEC8943EA3B3C442C44C0052FEF9D3B62BA2
                                                                    SHA-512:E6A419D743F7FB15D8A43FAE0635BD812EC12CDE701D1D0EC565026049EBAE88734916377EF1BA31B6854697FF14D7A0A177864CB014EB1AA3CC63C0272AF57F
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170068" V="0" DC="SM" EN="Office.Graphics.StencilNotOnInkBackground" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="boipy" />.. </S>.. <C T="U32" I="0" O="true" N="StencilNotOnInkBackgroundCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):523
                                                                    Entropy (8bit):5.056234104340099
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdSHokoCAvQierCXFJiQjFbywXHaSMNO5AHNUlu:2dUvHAvcrav5307
                                                                    MD5:F441F1D65A76ED4A331E1B767E846595
                                                                    SHA1:458219D0DD102330135C5191BEB055F0955B78C2
                                                                    SHA-256:E4BAE3A55AB1BCD4CA9B7474F4397C5AED099D99D89489A32D7AAD694440C546
                                                                    SHA-512:50C006C23031DA0F4C87F3E753F8AA520259770871C97632D1D728725C4740DF6357DBD4A7390CA95634E89BF69E9C3B50C1D087E6864C372D6FCCC59D94F1E9
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170069" V="1" DC="SM" EN="Office.Graphics.StencilInkStroke" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="boip0" />.. <A T="2" E="TelemetryShutdown" />.. <A T="3" E="TelemetrySuspend" />.. </S>.. <C T="U32" I="0" O="false" N="StencilInkStrokeCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):552
                                                                    Entropy (8bit):5.088954158136153
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdS5gUlGkpkoCAvQierZzGi0dLzNfI6UVxnt9tIDNO2su:2dogaGkiHAvcrY/N2Va
                                                                    MD5:029E6A810B2F854148580D95CA2D9C47
                                                                    SHA1:D18E0932AB2AA8DEE6C46D384FE6EF60D0BE3B25
                                                                    SHA-256:7564DFF5CE0D2FFEB8C59E9ABF44FFCE50BFA871ED2FB283D91295FCA45FF931
                                                                    SHA-512:43CB65DC5DD773D2111D74DE2FD9E6D2D3BBD061D68468E63141EE262A8EEEAC0A8495C4394A135440233D9107445BD039E50F1D234BE1B8C720FDF7CBC910F2
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170070" V="2" DC="SM" EN="Office.Graphics.StencilCommitedData" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="blnis" />.. </S>.. <C T="U32" I="0" O="true" N="SeqId">.. <S T="1" F="seqId" M="Ignore" />.. </C>.. <C T="W" I="1" O="true" N="InkDeviceType">.. <S T="1" F="InkDeviceType" />.. </C>.. <C T="B" I="2" O="true" N="Init">.. <S T="1" F="Init" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):669
                                                                    Entropy (8bit):5.062611791411667
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdSrvG2koCAvQier8HszVYaGSTwdy9zNfI6U3nstIDNO2su:2dgvGJHAvcr8HnYN2b
                                                                    MD5:9AF04E8D2912B44561AFB4053EF8442F
                                                                    SHA1:250F6ED1BC87E54562854B859037C1180F82F77E
                                                                    SHA-256:1A116F74E5589A0733C80855AC7EC12385DF649D647A4BAC2C0CD4D0769E8BEA
                                                                    SHA-512:9BB78D60B065F7A72E624B6B977A4BE956155C502BF88462BC883678DBD985396783A22EFFCFAA61E8706DC34F564F1F6E92D826988375333F6EB7821CB999FF
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170071" V="2" DC="SM" EN="Office.Graphics.StencilFailCommit" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="boipf" />.. </S>.. <C T="U32" I="0" O="true" N="ToCommitSeqId">.. <S T="1" F="toCommitSeqId" M="Ignore" />.. </C>.. <C T="U32" I="1" O="true" N="CurSeqId">.. <S T="1" F="curSeqId" M="Ignore" />.. </C>.. <C T="W" I="2" O="true" N="InkDeviceType">.. <S T="1" F="InkDeviceType" M="Ignore" />.. </C>.. <C T="B" I="3" O="true" N="Init">.. <S T="1" F="Init" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):392
                                                                    Entropy (8bit):5.210519152134
                                                                    Encrypted:false
                                                                    SSDEEP:6:TMVBd7mEpkyeuqb0c7oCDLChvRCUHperhbGHkdsVlrcyRO/SXRI9NOn2sby:TMHdSEXpkoCAvQiergHSsQyA2iNO2su
                                                                    MD5:D3A6D8A89D8BE3869FE9B0CA699D6D0C
                                                                    SHA1:E4424D8FD76B28A50DABDFE6F2E056CFA3680A5D
                                                                    SHA-256:7C9092161E7C3CD21D98D69C5263CBBA6EAA5C009DC6044AA9D9A3655773ACD6
                                                                    SHA-512:43C35028B75E615D1A7EAABC33E081E24EBD6638C4C81CCDACE825806D07A6278469F6BC8C9C425BE5814F6038193D27659FEDDFB80F034B2F84A14456224B3D
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170072" V="2" DC="SM" EN="Office.Graphics.StencilInkMode" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="boipz" />.. </S>.. <C T="W" I="0" O="true" N="StencilInkMode">.. <S T="1" F="StencilInkMode" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):597
                                                                    Entropy (8bit):5.138112127312645
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdShXLg8rkoCAvQierwHFAoszFMdL75fuDnt9tIDNO2su:2d6XmHAvcrWNPBh
                                                                    MD5:9C84BA54DAFBF134E47668AD72141159
                                                                    SHA1:533D83E75AEDAC2D9BDF20C424DB0A75AAA6FF0A
                                                                    SHA-256:5532D3A3E16A6853C8A242611771EACB2FA8616AC190FB2E849FF9C2307B3251
                                                                    SHA-512:A0571B50AEA77FD8713A755132AADFFB171AA19868B6F7A7BA5EAE31194352BF1056C217B753D500380EE9CCA2B2B4F5B85560359B4CC3B01161C4A5AF1A4B24
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170073" V="2" DC="SM" EN="Office.Graphics.StencilDeviceChangeNC" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="boipj" />.. </S>.. <C T="U32" I="0" O="true" N="CommitedSeqId">.. <S T="1" F="commitedSeqId" M="Ignore" />.. </C>.. <C T="W" I="1" O="true" N="CommitedInkDeviceType">.. <S T="1" F="CommitedInkDeviceType" M="Ignore" />.. </C>.. <C T="B" I="2" O="true" N="Init">.. <S T="1" F="Init" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):589
                                                                    Entropy (8bit):5.121041291659901
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdSqXLSrkoCAvQiersXzf8dLzNfI6U3nt9tIDNO2su:2dxXvHAvcrsE/N2s
                                                                    MD5:ACACCBA8B2FF3E481E6274C8DDF86265
                                                                    SHA1:E4C85C358FB78932A42A2D58B335EAEF76C9C037
                                                                    SHA-256:3BD8A6506CCCF1C83487B04FEC9206A90096F5819F8169CD745ADEE35E1C8352
                                                                    SHA-512:34D52213FF8AAC90D9F77B2921FE29A2D6631638C29BB45D10B0BF93DED2606553D7DC9D00012EFAE9EE42600C99D4219C0BA77EA3D6AF35C6E32E1F5BC87428
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170074" V="2" DC="SM" EN="Office.Graphics.StencilDeviceChange" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="boipk" />.. </S>.. <C T="U32" I="0" O="true" N="ToCommitSequenceId">.. <S T="1" F="toCommitSequenceId" M="Ignore" />.. </C>.. <C T="W" I="1" O="true" N="InkDeviceType">.. <S T="1" F="InkDeviceType" M="Ignore" />.. </C>.. <C T="B" I="2" O="true" N="Init">.. <S T="1" F="Init" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):933
                                                                    Entropy (8bit):5.028116295023816
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdS7VdkoCAvQierIYA+jPntbKNx1X5S9gN1DyDuMMIfxxT/OdyNO2su:2dKV2HAvcrIG4zT1yhbZJ/2i
                                                                    MD5:9DAEF7923371590B4F64CB407531EABE
                                                                    SHA1:4A370B97B71598D3FE517A2C6E34F4F56BD2B6F0
                                                                    SHA-256:C5DFF11E28772228F0AE0C7F8F82577B72EAB8CA5814CDF65ECC89D0A14914DF
                                                                    SHA-512:282DC8EEFBFDB6AAA4160D0349BD5476848FD9DAD1EB85626D1CE87F8EDB3BDC8850C239411E09483D8DAA03F5B806F4D5FFBECBF0E23CE0FB3E7D8E34056734
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170075" V="2" DC="SM" EN="Office.Graphics.FailedIBitmap" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="br19m" />.. </S>.. <C T="G" I="0" O="false" N="OriginalPixelFormat">.. <S T="1" F="Original pixel format" />.. </C>.. <C T="G" I="1" O="false" N="ConvertedPixelFormat">.. <S T="1" F="Converted pixel format" />.. </C>.. <C T="B" I="2" O="false" N="FailedToGetInfo">.. <S T="1" F="Failed to get IWicBitmapSource info" />.. </C>.. <C T="U32" I="3" O="false" N="PixelWidth">.. <S T="1" F="Pixel width" />.. </C>.. <C T="U32" I="4" O="false" N="PixelHeight">.. <S T="1" F="Pixel height" />.. </C>.. <C T="D" I="5" O="false" N="DpiX">.. <S T="1" F="DpiX" />.. </C>.. <C T="D" I="6" O="false" N="DpiY">.. <S T="1" F="DpiY" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):385
                                                                    Entropy (8bit):5.186798035649007
                                                                    Encrypted:false
                                                                    SSDEEP:6:TMVBd7mXlkVVJb0c7oCDLChvRCUHperhdpJrCZXM7yXPfPSSMNOn2sby:TMHdSM4koCAvQiervXQMOXHaSMNO2su
                                                                    MD5:EB1BB018005D0815CB8B4F1FC2B80106
                                                                    SHA1:0048EC35F47126354A48C8776200370639418AEA
                                                                    SHA-256:1A964F5C2E73E643490A7F2E328A2EA595CAB319B58E694BA60212BE25048548
                                                                    SHA-512:913E7D2CA97F3F27B8673BF3CF21B785AA699D9A077744AA6699F5CAF4974A664060694671BF85F312CF6C21CD3BA93C914F65DF9AC63083B1BF5B75E61BB1EE
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170076" V="1" DC="SM" EN="Office.Graphics.NoHWAdapter" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bjghy" />.. </S>.. <C T="U32" I="0" O="false" N="NoHWAdapterCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):389
                                                                    Entropy (8bit):5.237558642548256
                                                                    Encrypted:false
                                                                    SSDEEP:6:TMVBd7md4kD1mab0c7oCDLChvRCUHperhpkdsVlrfnst/+sgs9NOn2sby:TMHdSXs7koCAvQierqsznG/+8NO2su
                                                                    MD5:7854904FC54F3C9DE80FF7B286464A29
                                                                    SHA1:3E46A0326B60ACC372040D71FAF070970123768D
                                                                    SHA-256:47B200E4CC615DD90F7007B058233ACB19B3AF1FF4CBC8E9F4DA0BE23655D6AD
                                                                    SHA-512:46C4C6C8C6CC2388FEB70716331501B480E8D0D263791007B1A8C164C024A4465FF4BED423835994584487B60AA0E69BB3D83E1316E0615B84BB5B5FFCA9FBE0
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170077" V="1" DC="SM" EN="Office.Graphics.InsertModel3D" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bvqvh" />.. </S>.. <C T="W" I="0" O="true" N="FileExtension">.. <S T="1" F="FileExtension" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):483
                                                                    Entropy (8bit):5.20477265199328
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdS2JVm7koCAvQqAQierSN/UzaTbIONO2su:2dFJ9HAvfrSNMUF
                                                                    MD5:77842042E86E179DE7F53F59C53DDB80
                                                                    SHA1:5C8214887638A179ACF9336CC029E3CECAE7C72B
                                                                    SHA-256:EEFD868E1F334CC8508C01406642B747ECA2C0C47E1A0085C55BAE840993549D
                                                                    SHA-512:63F8E464865E10042B4A11B6914F1DC4388ABF4F60A42EC6D7B7A80E24BDEF84F4307233D906BA81BBDEB1F2D16E28F4D5EAF4706110C63AD055B1B5A2CF71CE
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170078" V="2" DC="SM" EN="Office.Graphics.LoadModel3D" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bvqwc" />.. </S>.. <C T="W" I="0" O="false" N="Function">.. <S T="1" F="ULS_Message" />.. </C>.. <C T="U32" I="1" O="true" N="ModelID">.. <S T="1" F="ID" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):385
                                                                    Entropy (8bit):5.158593051010716
                                                                    Encrypted:false
                                                                    SSDEEP:6:TMVBd7mlSkDoab0c7oCDLChvRCUHperhXbpJrCI2R2NyXPfPSSMNOn2sby:TMHdSl/o7koCAvQierZM2EXHaSMNO2su
                                                                    MD5:3718893E33DADAF2FBEFAE3AA0987060
                                                                    SHA1:A358B0A5F30D9158C2C9B071023A88497F82421D
                                                                    SHA-256:A719458C889BC9CE96EC6C757D795E2C6B1F7DE677A96DB8908F1F3E617E3F50
                                                                    SHA-512:92C5B54733F6A9393D8C2C7A6688C27D87D0C6AFD20B3DF7EC7E7EF0753E59E5A6FF8901A0A5C4853BCC6DE137AD51D723C3B2848A866A394D6CBFB8C7572C24
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170080" V="1" DC="SM" EN="Office.Graphics.CopyModel3D" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bvqvg" />.. </S>.. <C T="U32" I="0" O="false" N="CopyModel3DCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):547
                                                                    Entropy (8bit):5.004801070488056
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdSI6Kk3rkoCAvQierAr7PNWY6Nxf/0//Y6PdYhmMNO2su:2dB6/3IHAvcrAPeN2U
                                                                    MD5:9B13021DF6AB7D65B95F9DA9BB6E9BA9
                                                                    SHA1:E75B3A47425B822BC8A1BD33FC4C7F902E54801B
                                                                    SHA-256:E4DC795238F92060F56E1BF556E389CE011EB3C6597E0698BB3550F005E400C3
                                                                    SHA-512:08125CA3A3F953812152772497F83B68DFB063C1078F955BBACFFAAD52D9C8B644F11A0E7988ABEB57E2C3D15487D8A7BB4661190A44F542D28DCC40CD11C89C
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170081" V="2" DC="SM" EN="Office.Graphics.InkEffects" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="b0tof" A="bvuie coukr" />.. </S>.. <C T="G" I="0" O="false" N="InkEffect">.. <O T="COALESCE">.. <L>.. <S T="1" F="Ink Effect GUID" M="Ignore" />.. </L>.. <R>.. <S T="1" F="Ink Effect GUID for new ink" M="Ignore" />.. </R>.. </O>.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):403
                                                                    Entropy (8bit):5.157378070735827
                                                                    Encrypted:false
                                                                    SSDEEP:6:TMVBd7mn2FkSHxYb0c7oCDLChvRCUHperhyHfWNkJrC6HFyXPfPSSMNOn2sby:TMHdSuH7koCAvQierEhGXHaSMNO2su
                                                                    MD5:111C82FE49A9189C7F817C42FD7872AC
                                                                    SHA1:A3428A440FCB1C94308488CA5EDAABF0B125FECD
                                                                    SHA-256:CDFDE66806DF095450C741B27F391227F0D307CB1C7AE36AEEDD7A4BAC828223
                                                                    SHA-512:9E7F5C520A9178899CD01E0243C7BC3E82246BCCBD77A082A946740B6F14CEC1643B38C34D06A6904D5481E4C221E9DB0578B1AA30E5C46509526ADA5F386498
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170082" V="1" DC="SM" EN="Office.Graphics.LoadDefaultPens" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bvtft" A="bz4a6" />.. </S>.. <C T="U32" I="0" O="false" N="LoadDefaultPensCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1087
                                                                    Entropy (8bit):4.941903364756859
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdSrRkoCAvQierbGF0tt/UzZ66OIPkM96AXIla4Rlf4jHxp5onvxDoy5uiEGsz:2dQaHAvcr80ttMcJACl0HmNrRRDHO
                                                                    MD5:980BF1495AA145A06E8E27D11899F7E3
                                                                    SHA1:1B565E8373E31992DADD6AE2C73E915A07F448E4
                                                                    SHA-256:40628F65FEDB6C3646ABD802CB8DB6F6CA6E9D11289DB66C7EAB862FED8A196D
                                                                    SHA-512:C681CEF19FED5295128B13D68226712E03D77EA169EF5AA95078A3820506E4EA6BEA71688A1788546027C701BBD12AA52E02C27AF7F53C4804AAB4571495B60A
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170083" V="6" DC="SM" EN="Office.Graphics.RoamingPen" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bvtfz" A="bz4bc b50fz b3wfp clf2y" />.. </S>.. <C T="W" I="0" O="false" N="Action">.. <S T="1" F="ULS_Message" />.. </C>.. <C T="U64" I="1" O="true" N="Item">.. <S T="1" F="Item" M="Ignore" />.. </C>.. <C T="U64" I="2" O="true" N="ItemCount">.. <S T="1" F="Count" M="Ignore" />.. </C>.. <C T="U32" I="3" O="true" N="Type">.. <S T="1" F="Type" M="Ignore" />.. </C>.. <C T="F" I="4" O="true" N="Thickness">.. <S T="1" F="Thickness" M="Ignore" />.. </C>.. <C T="I8" I="5" O="true" N="RGB_R">.. <S T="1" F="RGB_R" M="Ignore" />.. </C>.. <C T="I8" I="6" O="true" N="RGB_G">.. <S T="1" F="RGB_G" M="Ignore" />.. </C>.. <C T="I8" I="7" O="true" N="RGB_B">.. <S T="1" F="RGB_B" M="Ignore" />.. </C>.. <C T="U32" I="8" O="true" N="Effect"
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):837
                                                                    Entropy (8bit):4.935067632892513
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdSEwokoCAvQierSXFJjEQzDABHf2k+HyLXHaSMntiStNQLNO5AHNUlu:2dXwvHAvcrqvLYBHv+HiFf7
                                                                    MD5:F79998F45A8CEE037D43757260AC87A8
                                                                    SHA1:42BB3D4BE5F1955668A80E40C3A787C599C649F1
                                                                    SHA-256:75A0472FE44DABD1C54A88A6A3690CDA768FEAAA10DBF1135B8833C18D565C7A
                                                                    SHA-512:6E5C181F0F0E4DF64D1F3D3F31606E86C1D72F063A764A45D41475D4D74CEADEAC83B114AAC71AA020EC09A1AEAC649617A5815BDCF96AD4336BDE83B5C8702A
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170086" V="2" DC="SM" EN="Office.Graphics.InkEffectsLoad" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="b0toe" />.. <A T="2" E="TelemetrySuspend" />.. <A T="3" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="effectGUID" />.. </S>.. </G>.. <C T="G" I="0" O="false" N="InkEffect">.. <S T="1" F="effectGUID" />.. </C>.. <C T="U32" I="1" O="false" N="EffectCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="B" I="2" O="false" N="Highlighter">.. <S T="1" F="fHighlighter" />.. </C>.. <C T="U32" I="3" O="false" N="StrokeColor">.. <S T="1" F="strokeColor" />.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):842
                                                                    Entropy (8bit):5.008606900129766
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdSudkoCAvQierHkAsatNE8aPcqop9LDuM9oOWfrxxOOdkd3zN6NO2su:2dN2HAvcrHvlMofh9mFg2oDg
                                                                    MD5:8B7A97E3953B343235574BF2E9C83B4B
                                                                    SHA1:57D4386E489FF63CED3F69530DC1D5B5632413B3
                                                                    SHA-256:9735939BD59A62B46B12F411FA3959386FEB041DA479B88D3C9A06A3744E66BA
                                                                    SHA-512:E8FE7CC649B3BEC9570DC34BB9BCC3D206168009F9FC18B432504199635C29AC1518B05421BA33386532A13A3DA02171CDCF61AF657E6DC4740C8334BBD0ADEE
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170087" V="2" DC="SM" EN="Office.Graphics.SecondFailedIBitmap" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bi2pe" />.. </S>.. <C T="W" I="0" O="true" N="ErrorString">.. <S T="1" F="Error String" M="Ignore" />.. </C>.. <C T="U32" I="1" O="true" N="PixelWidth">.. <S T="1" F="Pixel width" M="Ignore" />.. </C>.. <C T="U32" I="2" O="true" N="PixelHeight">.. <S T="1" F="Pixel height" M="Ignore" />.. </C>.. <C T="D" I="3" O="true" N="DpiX">.. <S T="1" F="DpiX" M="Ignore" />.. </C>.. <C T="D" I="4" O="true" N="DpiY">.. <S T="1" F="DpiY" M="Ignore" />.. </C>.. <C T="W" I="5" O="true" N="Filetype">.. <S T="1" F="Filetype" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):821
                                                                    Entropy (8bit):5.025216526423468
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdStT7LGANkoCAvQqAQ+Qf7iuXFJiQj9DaXOUd+McSxp5XHaSMNO5AHNUlu:2doyAGHAvVi+v5A/G207
                                                                    MD5:5805CE220ED63F0A0EF2192FB897226F
                                                                    SHA1:56403587C231FD0F0660730786B32A6CE846F11F
                                                                    SHA-256:D4F580A7CC4ED69F47E969314E2A7B3ACC1EC4147A4F140D82334D53765E8E62
                                                                    SHA-512:12720982CE37C4151E03D749416CD550A75B557AE392187B3AA13FD8BA0C23905CFC19BD72C9777A4EB032727ECE8F67D3103B3364E774D3612B5B3EF4CE6EF1
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170088" V="3" DC="SM" EN="Office.Graphics.ARCExceptions" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" SP="CriticalBusinessImpact" DL="B" DCa="DC" xmlns="">.. <S>.. <UCSS T="1" C="ARC Exception Telemetry" S="Assert Unexpected" />.. <A T="2" E="TelemetryShutdown" />.. <A T="3" E="TelemetrySuspend" />.. </S>.. <G>.. <S T="1">.. <F N="ULS_TagId" />.. </S>.. </G>.. <C T="W" I="0" O="false" N="TagID">.. <S T="1" F="ULS_TagId" />.. </C>.. <C T="I32" I="1" O="true" N="HResult">.. <S T="1" F="SH_ErrorCode" M="Ignore" />.. </C>.. <C T="U32" I="2" O="false" N="TagCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):381
                                                                    Entropy (8bit):5.250708539150798
                                                                    Encrypted:false
                                                                    SSDEEP:6:TMVBd7mdFkxQdO4MIHb0c7oCDLChvRCUHperhTdClrCsHVlv//USwNOn2sby:TMHdS5OWIkoCAvQier9dqD1lfUdNO2su
                                                                    MD5:9A7A9307E2EE4C834D86EF36D2F5E4CD
                                                                    SHA1:6D5AC3013C17FCAB9E7E8CC24191A601115B2F5B
                                                                    SHA-256:2DDEEE58D4D6549C9E28B893E7AEEE51380226C9CB5411931E15BC855E595435
                                                                    SHA-512:F7DCCC3DF457960E521B9EE4B6BC2C0E4C3DF63D1698256A9FDC35BAA101A312CBF73AEF9EB968A06547290F471ADFF1A75C7EBC5336E135939F100DCCA815F3
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170089" V="1" DC="SM" EN="Office.Graphics.SetAdjustHandleFailed" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="b6uuo" />.. </S>.. <C T="I32" I="0" O="false" N="ShapeType">.. <S T="1" F="ULS_TagId" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1064
                                                                    Entropy (8bit):4.9447351696321915
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdSV4i1UkoCAvQiertq/EAdsDE6M9tN4AnwI/wnHDOUnn+E4ZnV7TdNhDxH901:2dgHAvcrtqc8J6bbqqi7TJDhCwSl
                                                                    MD5:A36A06F8AF00FD36171950A9087842C0
                                                                    SHA1:19A241BD6EF1BDB09ECF9EB311A5B6DC953179F0
                                                                    SHA-256:6F0B7C52BD2935089956185DABDE3A31D66949846031B1BFC4065C8E59FDF26D
                                                                    SHA-512:6D5F1B0E2CC5EAD06926C589D36699141588B1C5850D5524DD707AF852E375D6A37D11734DB942B8DA13D1FE3FE0413C92F010F51C48FDD5DE968E603A69F740
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170091" V="2" DC="SM" EN="Office.Graphics.EditorTrackerManager" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bd6oe" />.. </S>.. <C T="W" I="0" O="false" N="Exception">.. <S T="1" F="Exception" />.. </C>.. <C T="W" I="1" O="false" N="EditorTypeName">.. <S T="1" F="EditorTypeName" />.. </C>.. <C T="I32" I="2" O="false" N="Step">.. <S T="1" F="Step" />.. </C>.. <C T="B" I="3" O="false" N="Cancel">.. <S T="1" F="fCancel" />.. </C>.. <C T="B" I="4" O="false" N="Aborted">.. <S T="1" F="fAborted" />.. </C>.. <C T="B" I="5" O="false" N="KeepTrackingOnMouseUp">.. <S T="1" F="fKeepTrackingOnMouseUp" />.. </C>.. <C T="B" I="6" O="false" N="Dragging">.. <S T="1" F="fDragging" />.. </C>.. <C T="U32" I="7" O="false" N="Tag">.. <S T="1" F="Tag" />.. </C>.. <C T="W" I="8" O="true" N="TrackerTypeName">.. <S T="1" F="TrackerTypeNam
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):674
                                                                    Entropy (8bit):5.042936927823301
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdS1UxIkoCAvQiery+iVthjcdLfNady9tSRdVYNEINO2su:2dKqHAvcry+cjg8p+z
                                                                    MD5:D2032B73B1359AA42472D306637B64F0
                                                                    SHA1:315F9128018823521346CF6FBEB3E968CBE3A306
                                                                    SHA-256:4962325ABE814FD0518D5D1027403A0927FE3F8B3FA8610FE22D14B86D9736DC
                                                                    SHA-512:279D5075B9CF571BA89A2F5E5C979BB3E0B6CF6BA0BF1247B8CAAB58B73BF831085C436BBBA285A02C4E4C9605B14705E366DC0A20E702C888C6CA210B5253AB
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170095" V="1" DC="SM" EN="Office.Graphics.DecorativeAltText" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="clezs" A="clp1n" />.. </S>.. <C T="B" I="0" O="true" N="Decorative">.. <S T="1" F="fDecorative" M="Ignore" />.. </C>.. <C T="W" I="1" O="true" N="ObjectName">.. <S T="1" F="ObjectName" M="Ignore" />.. </C>.. <C T="W" I="2" O="true" N="ObjectClass">.. <S T="1" F="ObjectClass" M="Ignore" />.. </C>.. <C T="W" I="3" O="true" N="Source">.. <S T="1" F="Source" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):385
                                                                    Entropy (8bit):5.232298743887801
                                                                    Encrypted:false
                                                                    SSDEEP:6:TMVBd7m64kYcAFb0c7oCDLChvRCUHperh8NJrzVlrcS5W9NOn2sby:TMHdSNIkoCAvQierCDz4SgNO2su
                                                                    MD5:AFD98BCB9169D53F3CAB8E89D031DCA4
                                                                    SHA1:6347FB3146CEDCD173E69383C0A0E4AA9A0E1232
                                                                    SHA-256:20DE5E360A12988CD95AD1469397572D9965D1C8EEC0BDFDB4541E805A16F4E6
                                                                    SHA-512:10FA4443E333815FE06980F701172BAAB42E69874D68B9A1904D6F6D64302D39E2719117505AAF60FD3D4C3EF4A6232309021815F44CBAE2182A893BF4B5F86D
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170096" V="1" DC="SM" EN="Office.Graphics.CallBackAborted" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="ayaco" />.. </S>.. <C T="U32" I="0" O="true" N="LastError">.. <S T="1" F="LastError" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):459
                                                                    Entropy (8bit):5.163018688316438
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdSPyUkoCAvQierRz4AEhndLukdoNO2su:2d9HAvcrWjd+
                                                                    MD5:5797FB18CD112107BCEF88D9E034DF44
                                                                    SHA1:AE8381010C4C3A140839FBF72EE3EE0F160F85D2
                                                                    SHA-256:04D66BE119689BC57BD686AB3BEF57AF784145A0082E400CEB839414B673E456
                                                                    SHA-512:2C8D6A9D6C0176E961A373EA793E4DA2E9A45D4BB3F7D43642ED2301188231562494FD4D56447019D0E97C36017DB716A559024F543B0ED467504F990BA8DC76
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170097" V="1" DC="SM" EN="Office.Graphics.FilterError" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="awzl6" />.. </S>.. <C T="I32" I="0" O="true" N="LRet">.. <S T="1" F="lRet" M="Ignore" />.. </C>.. <C T="W" I="1" O="true" N="KeyPath">.. <S T="1" F="KeyPath" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):427
                                                                    Entropy (8bit):5.220784057366084
                                                                    Encrypted:false
                                                                    SSDEEP:6:TMVBd7mr0kA4Yb0c7oCDLChvRCUHperhch+2nqUmvApx7IkUSwNOn2sby:TMHdSr7koCAvQierc/nqvA5UdNO2su
                                                                    MD5:EBBFBFC8B647C2EE6C115AA89A24CF55
                                                                    SHA1:F2B8BCB7947592326B05B3D082444F1BC146C001
                                                                    SHA-256:8996246362ECA863035333079B41001FE4CE63F8739F82AC0E3EA22E9B4336FD
                                                                    SHA-512:177131C44AFE8C90FBD5C8B7BF46EB276F09DA2A8E60DE2F8E845FD17CD42A8E381E5791EA361C8A69D29645AD5818B8FB7372370573FA5D23A6D254D270F04E
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170098" V="2" DC="SM" EN="Office.Graphics.SVGExceptions" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="cn0zy" A="cn0z0 bo1g9 cn0z3 cn0z5 cn0z7 cn0z9 cn00b bo1ha bo1hb" />.. </S>.. <C T="TAG" I="0" O="false" N="TagID">.. <S T="1" F="ULS_TagId" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):972
                                                                    Entropy (8bit):4.9717830381726476
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d30HAvfrBrFreFryVdr5AedezA97oMz3IJ:ckgvf9paFuVdkMLIJ
                                                                    MD5:7B0DF3E4653B865412BA93009B0F012F
                                                                    SHA1:30AAF88BAC2FAECE3CE7BA7EEDE49DAA2CA048B8
                                                                    SHA-256:99C38F00F63CA6A660B1A66989450FB1C14AAFEACDB671157C6DB931A6B5D2A7
                                                                    SHA-512:9AD6114DE198168FE605BEC34C6B63E491F53ABDE2FE019A9493084899D840A7A743DF84E11D650E822387CD1405E966A80E42E86871A12325620BEF0DF79128
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170099" V="2" DC="SM" EN="Office.Graphics.InsertMedia.Android" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="clog3" />.. <UTS T="2" Id="co8vc" />.. <UTS T="3" Id="cq8vw" />.. <UTS T="4" Id="bqp2g" />.. <UTS T="5" Id="cra8v" />.. <US T="6">.. <S T="5" />.. <S T="4" />.. <S T="3" />.. </US>.. </S>.. <C T="I8" I="0" O="false" N="RequestCode">.. <S T="1" F="RequestCode" />.. </C>.. <C T="I8" I="1" O="false" N="ResultCode">.. <S T="1" F="ResultCode" />.. </C>.. <C T="W" I="2" O="true" N="FailureReason">.. <S T="2" F="FailureReason" />.. </C>.. <C T="W" I="3" O="true" N="MediaFormat">.. <S T="2" F="ImageFormat" />.. </C>.. <C T="TAG" I="4" O="true" N="InsertMediaViaGalleryResult">.. <S T="6" F="ULS_Tag" />.. </C>.. <T>.. <S T="6" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):3951
                                                                    Entropy (8bit):4.96713371845371
                                                                    Encrypted:false
                                                                    SSDEEP:96:ag5NkwRDjRq9vRh3R2j++sZ+KGGsQ+0JoHJVsDJn+nJ6Ju:aggwRDjRq9vRh3R2C+swlGs/0JEJVsDG
                                                                    MD5:CBF0E03FAD048D3B4DF205F1452427E0
                                                                    SHA1:8A30B6D4D632AA4664FAEBFAE5D9602C17844EE3
                                                                    SHA-256:4CB22D0E02FC97403A6A0DE28065CF60D5C3940D85ED1DC550C5CC89D8DD0C0C
                                                                    SHA-512:5C9D4486B4556AE7EDC47D26F3FD8EFDF2AF629C4214BBAA8FD19B847377DF4A05417FD2D918F56120033CBD83A4F3E547FB82490A60067E66ED1BAAB91BAD1B
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170103" V="1" DC="SM" EN="Office.Graphics.SVGErrorDetails" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="csp59" />.. </S>.. <C T="B" I="0" O="true" N="SVGEnabled">.. <S T="1" F="SVG enabled" M="Ignore" />.. </C>.. <C T="I32" I="1" O="true" N="Constructor">.. <S T="1" F="Constructor" M="Ignore" />.. </C>.. <C T="B" I="2" O="true" N="WasEverResetToOriginalImage">.. <S T="1" F="Was ever reset to original image" M="Ignore" />.. </C>.. <C T="B" I="3" O="true" N="Embedded">.. <S T="1" F="Embedded" M="Ignore" />.. </C>.. <C T="W" I="4" O="true" N="BlipEmbedRelID">.. <S T="1" F="Blip embed rel ID" M="Ignore" />.. </C>.. <C T="I32" I="5" O="true" N="BlipValidationCount">.. <S T="1" F="Blip validation count" M="Ignore" />.. </C>.. <C T="I32" I="6" O="true" N="BlipValidationHistory1">.. <S T="1" F="Blip validation history 1" M="Ignore"
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):520
                                                                    Entropy (8bit):5.08129738073591
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdSYti4koCAvQierDRpSXFJiQjFwcXHaSMNO5AHNUlu:2dztifHAvcrNpqv56c07
                                                                    MD5:C06A45BE0BC2594B28A9CD32FE848085
                                                                    SHA1:8698954D12D4B1D8D0EBD802DF9C9DD41D84576A
                                                                    SHA-256:14446F18D4201A6B4406EE5E51AF48CA23F8F9CF9DD77F57A1ED28C7A3B590C7
                                                                    SHA-512:E076145A0C550999E1F27304F63D70FAED7F11193101598A2799F9D6B07FAE402CB3EABFCB26875C97C7340A8B276E9E4307E432DF1C386ED8FBC21F7AA21EDE
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170104" V="1" DC="SM" EN="Office.Graphics.InkReplayInvokedByDevice" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bm46y" />.. <A T="2" E="TelemetryShutdown" />.. <A T="3" E="TelemetrySuspend" />.. </S>.. <C T="U32" I="0" O="false" N="EventCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):595
                                                                    Entropy (8bit):5.12679608720651
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdSNY3qkoCAvQierrH9HPG1dmKu0ady9AUBNO2su:2dEAHAvcrpeCmH
                                                                    MD5:A693E5D751C9F5EB97ECA56E9BA84FBB
                                                                    SHA1:D4E29A58AAEC82BCA1D4CA214329AD4360189803
                                                                    SHA-256:CFB4A733D84ECEE4A1DD2CD400B02946164CF85649FD05E61912A7BFF0AA13C4
                                                                    SHA-512:CCEFECE0C3D685608C4190A3DB216730D9324220312DF5781407B61C9759F2C0E9D1A15B9493D4735DE0D756D2F6FAEB23B8F1A7AEB884EFA14FBAB21E31D765
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170105" V="3" DC="SM" EN="Office.Graphics.HrCreateProtectedTempFile" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="ctgbb" A="ctgbc" />.. </S>.. <C T="I64" I="0" O="true" N="ResultCode">.. <S T="1" F="ResultCode" M="Ignore" />.. </C>.. <C T="I64" I="1" O="true" N="TimeElapsed">.. <S T="1" F="Time Elapsed:" M="Ignore" />.. </C>.. <C T="W" I="2" O="true" N="TagID">.. <S T="1" F="ULS_TagId" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):388
                                                                    Entropy (8bit):5.237791233136849
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdSiqkNQzkoCAvQiertysSdOUDNO2su:2dxCgHAvcrtyTd/p
                                                                    MD5:7BD3D8712610AA77111F20ED567C1DFD
                                                                    SHA1:EEF4437E8A466600D2D358E0244B6DA340AE7941
                                                                    SHA-256:24D1C79C5363954847D3495418EA4F30CB0EE8DC9612A7884A3A5EA58C8FDA5D
                                                                    SHA-512:40EC5B2F8B4DDEDD16A83C9052225EA7B16C0D4895C4DEE9BA7F066DA671A5EA63799C6940CF874EB9D2700511D8023234D7E5DD628A99105C087D9D8B6696D2
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170106" V="2" DC="SM" EN="Office.Graphics.IcachedResourceKey" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="cu3ee" />.. </S>.. <C T="W" I="0" O="true" N="Callstack">.. <S T="1" F="ULS_Message" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):601
                                                                    Entropy (8bit):5.008918737836408
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdSYBrkoCAvQierXPXFJiQjF0OXHaSM+0XGNO5AHNUlu:2dhSHAvcrvv5GOag7
                                                                    MD5:971BFC494DDE8C53988F167BEC264200
                                                                    SHA1:F513F5178BBEF3F8FE65118BBBCCDA85D16B3F69
                                                                    SHA-256:14AA0CD62D029C965E762507F0F2FED0EB6E32DA5D5D01BCB50C69E4C95F1B78
                                                                    SHA-512:29F8327F20222D27F3748614B29E95D34BEEF68DE90A45E6123C184A41D3460E0D6F2C603AC3D888CA58D979B5E37B57615ECFD084799DF3F68A858CFBB577AD
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170107" V="1" DC="SM" EN="Office.Graphics.OartTextImeErrors" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="auhqr" />.. <A T="2" E="TelemetryShutdown" />.. <A T="3" E="TelemetrySuspend" />.. </S>.. <C T="U32" I="0" O="false" N="ErrorCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="I32" I="1" O="true" N="IMEFailure">.. <S T="1" F="hr" M="Ignore" />.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1023
                                                                    Entropy (8bit):5.047932031129572
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdSNciu7koCAvQier5fXFJiQjFHmXHaSMn+uNyant9BoavlInsN6nHxGV7d3S7:2dUci/HAvcrNv5tm5loiKm7
                                                                    MD5:A2AF4593F7BC851C09001251684DEFE4
                                                                    SHA1:78A0B33D12B8353C520E7769F7CF540A9E213080
                                                                    SHA-256:3D237C04DDDDEBD5F118B95714722A18A6905C85072BD03EAD3B9B524AB1B687
                                                                    SHA-512:071200D7F7BF8DF8954667B0BCD64B90D75F0B7D3C1DA68D3B9B5A9F174CD6E4B52AAC14F501EC8A6E1FC2F8ADCD719975F815919C6D95C50D1915F171256E2D
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170110" V="0" DC="SM" EN="Office.Graphics.StylusUpView" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bjzqh" />.. <A T="2" E="TelemetryShutdown" />.. <A T="3" E="TelemetrySuspend" />.. </S>.. <C T="U32" I="0" O="false" N="StylusUpCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="B" I="1" O="true" N="AnimationsPlaying">.. <S T="1" F="fAnimationsPlaying" M="Ignore" />.. </C>.. <C T="B" I="2" O="true" N="InitiatedFromSlideshow">.. <S T="1" F="fInitiatedFromSlideshow" M="Ignore" />.. </C>.. <C T="B" I="3" O="true" N="MixedDpi">.. <S T="1" F="fMixedDpi" M="Ignore" />.. </C>.. <C T="B" I="4" O="true" N="PacketCallBack">.. <S T="1" F="FPacketCallBack" M="Ignore" />.. </C>.. <C T="W" I="5" O="true" N="ViewName">.. <S T="1" F="ViewName" M="Ignore" />.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T=
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):690
                                                                    Entropy (8bit):5.005017077268136
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdSNa1koCAvQierhNXFJiQjFwcXHaSMYZSdy96LNO5AHNUlu:2dUlHAvcrrv56ccf7
                                                                    MD5:41A998C28598972706C303BE8CAA91D4
                                                                    SHA1:F2ABF7E6D5B2526CE206F26483B423E048967ADA
                                                                    SHA-256:9465BADD7B0061D68D564E0AEB066C96428A5540DECEFED1915755698B50D4C2
                                                                    SHA-512:0C6048B97796D245D3F3CCEF443542162D35FEC58DF51BE7DD94EE548C198CFCE1B4C713EC8FB716EFD9F691EF39F6BFBE8FF9A647B1998442A1F528C3AD360C
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170111" V="2" DC="SM" EN="Office.Graphics.FixedDelayLoadFailure" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="dbw1y" />.. <A T="2" E="TelemetryShutdown" />.. <A T="3" E="TelemetrySuspend" />.. </S>.. <C T="U32" I="0" O="false" N="EventCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U16" I="1" O="true" N="NumRetries">.. <S T="1" F="NumRetries" M="Ignore" />.. </C>.. <C T="W" I="2" O="true" N="DllName">.. <S T="1" F="DllName" />.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):609
                                                                    Entropy (8bit):5.050041213245167
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdSNxxkoCAvQierIXFJiQjFwcXHaSMdL6bNO5AHNUlu:2dUkHAvcr8v56caS7
                                                                    MD5:470599DD8AF00E0C7A988D9A641F61D2
                                                                    SHA1:5B2FE28CF641B09313D54C7A3D79C168FC0FBF3A
                                                                    SHA-256:F58E1773016EE52E485C7839916DF9E3F631BEFE730DF6844EE1313BF0ACFA06
                                                                    SHA-512:DDC3A8D2A0D650D9A22EC3B24F254814C6D51228B5B00CE1A0687783D9FD482507EF2E3B44771000A95541C7CBF234D07E798925A84D39D59BCB58217663A8F0
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170112" V="1" DC="SM" EN="Office.Graphics.DidNotFixDelayLoadFailure" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="dbw1z" />.. <A T="2" E="TelemetryShutdown" />.. <A T="3" E="TelemetrySuspend" />.. </S>.. <C T="U32" I="0" O="false" N="EventCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="W" I="1" O="true" N="DllName">.. <S T="1" F="DllName" M="Ignore" />.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):472
                                                                    Entropy (8bit):5.1494512612021985
                                                                    Encrypted:false
                                                                    SSDEEP:6:TMVBd7mNekh2FJb0c7oCDLChvRCUHperheNlrzVlrE+F/G+Vs9ndtqsVlrT6/Ulz:TMHdSN5bkoCAvQierwzoKEdL6UDNO2su
                                                                    MD5:02F0E8EE06B7B0B21F8BBF4A5E81853B
                                                                    SHA1:E58C6016A7760BBCBA0C65A8C26F12857E9E6B09
                                                                    SHA-256:E5001F4CF1217FB8AD78AFCBCD269496C1E132C93D802E1F8D67C0A76110D290
                                                                    SHA-512:493115249179B77F044AD6805DA8A18CA6E7084DE212343906A7C0F6212774C218BCA5B3476B49A379C0D61B8402577C8458DAC4BF1A48BC3B58CA3E3D81D7B9
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170113" V="0" DC="SM" EN="Office.Graphics.GDIError" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="cusas" />.. </S>.. <C T="I32" I="0" O="true" N="GdipStatus">.. <S T="1" F="GdipStatus" M="Ignore" />.. </C>.. <C T="W" I="1" O="true" N="Message">.. <S T="1" F="ULS_Message" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):822
                                                                    Entropy (8bit):5.015492524119104
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdSNS6koCAvQierdXFJiQjFqRXHaSMaMHfndy9dIb43Mi8nNO5AHNUlu:2dUStHAvcrBv50gdj37
                                                                    MD5:EEC563CA6AB0EF713A010226FAF5417A
                                                                    SHA1:3F12B759EB303F52722462461C8C4D9C44C8479E
                                                                    SHA-256:174FA2BA67C5A46B6838BA9E4D1C3B63386BD57F5773DA67D042CC5CBEBF5658
                                                                    SHA-512:3CB519732D394A6D399F4068130145FE5F7962DF9CF7383E9C6F99F05605FEF78FBE3574B558284FA6B3E0F0AED88CBB82F8C30F08BA7507052965A7364F81E9
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170114" V="1" DC="SM" EN="Office.Graphics.RemoveObserver" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="cs84o" />.. <A T="2" E="TelemetryShutdown" />.. <A T="3" E="TelemetrySuspend" />.. </S>.. <C T="U32" I="0" O="false" N="HitCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="true" N="ThreadID">.. <S T="1" F="threadID" M="Ignore" />.. </C>.. <C T="W" I="2" O="true" N="IBlobObserver">.. <S T="1" F="IBlobObserver" M="Ignore" />.. </C>.. <C T="U32" I="3" O="true" N="TotalBlobsBeingObserved">.. <S T="1" F="totalBlobsBeingObserved" M="Ignore" />.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):593
                                                                    Entropy (8bit):5.117813499836631
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdSNzMg4pkoCAvQiDA520OXHaSMdXUddy9McScoNO2su:2dUwniHAvRA5XOaE/4pA
                                                                    MD5:A694236DB55D9549EC3ACF545040A006
                                                                    SHA1:E6E744F28D00DF2A43E5EB38499A418FC57B9133
                                                                    SHA-256:36FDE83F3E78D51CFEE4AC76E4F48ED06AAE296B1254F1F6F2632D6A2DE32109
                                                                    SHA-512:18A3BD557F14BE93A0DDACDADC96FD1B6EF93E4F3AD36EC681C5C7206D1D2CC8AA5DF9C273E513570A49B0ED644F5BCC30C9C473DE10EE359D908DCE2BF118EC
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170115" V="1" DC="SM" EN="Office.Graphics.ARCFailureDetails" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UCSS T="1" C="ARCExceptions" S="Assert Unexpected Monitorable" />.. </S>.. <C T="U32" I="0" O="false" N="ErrorCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="W" I="1" O="false" N="TagID">.. <S T="1" F="ULS_TagId" />.. </C>.. <C T="W" I="2" O="true" N="HResult">.. <S T="1" F="HRESULT" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):383
                                                                    Entropy (8bit):5.232831662269484
                                                                    Encrypted:false
                                                                    SSDEEP:6:TMVBd7mN1Dkd+4MwwYb0c7oCDLChvRCUHperhdCdxVe/EpnyNOn2sby:TMHdSN1p4MkoCAvQierHAq/EANO2su
                                                                    MD5:58275387F4B467C834F9443956392F7E
                                                                    SHA1:0F3B75617955371E8269FE63108898C57B298570
                                                                    SHA-256:11FA615DB937714766E1485EA6A921DBC11AE4260461DFBC5B184021501234B9
                                                                    SHA-512:4A27C832FB57342876BCE4EE0AA993D2BC7D012E1355EE3521505A4E0FF032B34A335906B188DDBEE2708BF1F7763157035D57F3443AA1254EF32040D515B486
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170116" V="0" DC="SM" EN="Office.Graphics.GeometryValidationFailure" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="ddr1p" />.. </S>.. <C T="W" I="0" O="false" N="Exception">.. <S T="1" F="Exception" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):608
                                                                    Entropy (8bit):5.023617146178391
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdSN83HpkoCAvQierHlNXFJiQjFwcXHaSMarfI1NO5AHNUlu:2dU8SHAvcrHlxv56cF87
                                                                    MD5:4352EFE0DB7721C6C191C76C0920CDE7
                                                                    SHA1:D32038F97B403475D1D9B898930FC7E36D7C6A3B
                                                                    SHA-256:F4F0E0AD129792934859777C7680745432B20EFFE69171D94E44477C168E75E1
                                                                    SHA-512:D9DA9BE428E263BE0BE0371789EDA4F835AD2A2F0A8138885817C9DA779DE9ADE1DB2823498E60394AEBBECEA3159C4BC593109ACE8448C0CC431D4D00446CE5
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170117" V="0" DC="SM" EN="Office.Graphics.NonInkingInputType" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="92g1p" />.. <A T="2" E="TelemetryShutdown" />.. <A T="3" E="TelemetrySuspend" />.. </S>.. <C T="U32" I="0" O="false" N="EventCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="true" N="InputType">.. <S T="1" F="InputType" M="Ignore" />.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):615
                                                                    Entropy (8bit):5.0378639054893295
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdSNp/HpkoCAvQierBXFJiQjFwcXHaSMarfI1NO5AHNUlu:2dUp6HAvcrNv56cF87
                                                                    MD5:1D65CC384A2EA63DCD6EB3C779A31BF7
                                                                    SHA1:A3B3D1526C417BAF4A0C96A82C683BB4D26FCD9A
                                                                    SHA-256:561E23F9BB868AA17C4BD158F770A6CDD3C8D5D63EF11EA745AFEA1162042829
                                                                    SHA-512:834DFEC3D8C33F230B08D030609CE00E556EDD804F0228F5E98F7943194D33E2EDD557BAAD8250A7DF681867A853C8A1066022FF3DA1C9DCA048927115415C92
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170118" V="1" DC="SM" EN="Office.Graphics.InkingInputType" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="92gxn" A="9j45m" />.. <A T="2" E="TelemetryShutdown" />.. <A T="3" E="TelemetrySuspend" />.. </S>.. <C T="U32" I="0" O="false" N="EventCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="true" N="InputType">.. <S T="1" F="InputType" M="Ignore" />.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):533
                                                                    Entropy (8bit):5.041553102711772
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdSYeXIkoCAvQierOOXFJnqRXHaSMCf5xNO/HNUlu:2d3wHAvcrOevmfRS7
                                                                    MD5:F18EA73E631A8720075589FCF209A986
                                                                    SHA1:FAE1367ED41D45D8E00EB3AEFA9DFD2EA0A5F786
                                                                    SHA-256:F7F6E275D7BC14E3D2E089B37904313F99B2A06E0DE60B4C2038ED43BEF74FC5
                                                                    SHA-512:3A91D28E9F0F6F168D251A149F2FF55BDA759E6178AEC9E1EAA1F112FCC904A2BDE9D68DDE18A2AA3A8CFA4D7E60CCD54EFFDD9AB98792221FCE9D5D1F69EF0D
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170127" V="0" DC="SM" EN="Office.Graphics.InkGestureFailed" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9ux3n" />.. <A T="2" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="HitCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="SRType">.. <S T="1" F="SRType" />.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):584
                                                                    Entropy (8bit):5.089351679566497
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdSaOCkoCAvQqAQier9fXFJnqRXHaSMawEuiENO/HNUlu:2dFOlHAvfr9vvmCEdz7
                                                                    MD5:15A7DDB39B68666EAADAA4E9DC0EDD89
                                                                    SHA1:FD2BF6D828300D3AFCBB20779D3AB0FE10597CBD
                                                                    SHA-256:7391916039C847A755B5B58E9AEE350EE159C42656DCF4E4DDAD9DFDA1AE69E8
                                                                    SHA-512:41ECE7F2CB2E3F3A874DB894C8FA344945803A3ECEBB3AD0F15BD4C2A58AC65AEED7632DDB72B26DD98330EB3C96B25648BF4591B18EABE96EE31863B7773F53
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170129" V="0" DC="SM" EN="Office.Graphics.IntelServiceTimeout" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="co05t" />.. <A T="2" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="HitCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="true" N="TriggerCode">.. <S T="1" F="TriggerCode" M="Ignore" />.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):564
                                                                    Entropy (8bit):5.0528345816430535
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdSPqepkoCAvQierGXFJnqRXHaSMaG+/fbOg8NO/HNUlu:2d8UHAvcr2vmDTHb7
                                                                    MD5:019D609CC143EFF5F3DDF5331D6B84D9
                                                                    SHA1:EDE827DD60E75B1D4E626F3BF24E177EFE61F716
                                                                    SHA-256:63AE59D45FEAFF09E64FF0631516D7E7F901FDE745F61F493CC4847ACC455052
                                                                    SHA-512:A18B2A6004BAB7CAEC4A8E0F2EA964FE4AB15E1333B5F49714B98C00D3E8FB79835B95374D800F2FFB53193EF8F130C921FC4FBAC4C990E8330855EABC587E52
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170130" V="0" DC="SM" EN="Office.Graphics.PenToolType" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="84n7u" />.. <A T="2" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="HitCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="true" N="CurrentPenToolType">.. <S T="1" F="Current Pen ToolType" M="Ignore" />.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):464
                                                                    Entropy (8bit):5.121640629689538
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdSpB7koCAvQiermZXFJnV9nXHaSMNO/HNUlu:2dy4HAvcrYvbp7
                                                                    MD5:94FFE94F09ABDFE69FCEF92B3329120E
                                                                    SHA1:328BB8D7CB96F30D531801018984B83C235980BC
                                                                    SHA-256:8AD1D8198F897BCAD27ED8295CA2314C1B52F1ADA9E70AA593C7DBDF0B727E6A
                                                                    SHA-512:D802460807E9F3FEF4E323319D1962DB1A8AD3095AD33CB8505E042B92CE28CB18E6F52491B3674F2FA25AF741DC994E02F0C7C286F1BCF6D36030BF57BCCA63
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170133" V="0" DC="SM" EN="Office.Graphics.Win32OnlineVideoPlayback" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="c5z9m" />.. <A T="2" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="PlayCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):454
                                                                    Entropy (8bit):5.068829243379877
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdSqj0koCAvQier8XFJnV9nXHaSMNO/HNUlu:2d77HAvcrIvbp7
                                                                    MD5:5F3A7913BC72F19D173A71E8CC271459
                                                                    SHA1:203FF5B2E938FC67F719E70E5D1E3344AEC49501
                                                                    SHA-256:263255C83D2AB3795331DC610909CD6B80BD1AD96DEC480386CF18E91EA941D6
                                                                    SHA-512:8BC605CCD50D6BDEEB2654A4BF724987C7FF3BCAE14168AFF200947DC5277C382C32D7A5C7AE3CBD199ADCD24F10E1BF911C4F4BD614E6A28CE9497F5DEF5FA2
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170134" V="0" DC="SM" EN="Office.Graphics.InsertSmartArt" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bhlc7" />.. <A T="2" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="PlayCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):653
                                                                    Entropy (8bit):5.040958428955208
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdSaKWI1okoCAvQierMJXFJn/XHaSMIIupPNQ9PINO/HNUlu:2daWIVHAvcrM1v/tQ7
                                                                    MD5:C0A4764642FDB4A2D49787DBC1D3F2BF
                                                                    SHA1:61B1D81AF3C212EF84B69EA4FC37B71E42875387
                                                                    SHA-256:C63917C35F1B221AF24D73F3A3BC7ACEB2B7094BF9F692BB23427E01FD9DA551
                                                                    SHA-512:3458CA87B1BA994467977A201D89CF48E9609FE1FFD345801A132A15E11AB25322ED5EA1672D0C3100C0828D7D8C8417211E41745F689203E0B283D587569AA1
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170135" V="4" DC="SM" EN="Office.Graphics.AltTextFeedbackUIClick" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="5czg2" A="545u8" />.. <A T="2" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="ClickCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="Id">.. <S T="1" F="Id" M="Ignore" />.. </C>.. <C T="U32" I="2" O="false" N="QuerySource">.. <S T="1" F="QuerySource" M="Ignore" />.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):662
                                                                    Entropy (8bit):5.072618292926917
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdSJ5KZDkoCAvQieraXFJn/XHaSM+cDmpPNQ9PINO/HNUlu:2dqtHAvcrSv/NAiQ7
                                                                    MD5:370C8282B3F134BA2AD89C7C79582041
                                                                    SHA1:F231A0E23C73CAE0E6ABA2EC7C525768E0949112
                                                                    SHA-256:64448833054C66D7FCBB009F8887E3CD318816043BAB85186E77E53DB702AF5D
                                                                    SHA-512:3C07D2DA06B58CE813177505E0E42C90F52B19684AD7A7B18A5FFEFCF8B5D846CE0EA2A2C95A561AA1D1AF4090F049DD40063059BC70E92E86AE836785CE95FF
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170136" V="3" DC="SM" EN="Office.Graphics.AltTextBarClick" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="5czg4" A="545va" />.. <A T="2" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="ClickCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="FirstClick">.. <S T="1" F="FirstClick" M="Ignore" />.. </C>.. <C T="U32" I="2" O="false" N="QuerySource">.. <S T="1" F="QuerySource" M="Ignore" />.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):559
                                                                    Entropy (8bit):5.085893402940255
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdS4ZkoCAvQierrXFJnqRXHaSMnd/9aNO/HNUlu:2daHAvcrjvmsl57
                                                                    MD5:C4135EFB841BF65B71DA076B7FE6F994
                                                                    SHA1:F892F312C3DED0D2D7B58EB218188D523A0DD7D3
                                                                    SHA-256:E015483A9A37E55C83F6CCCE1F1E90BA2B6EC5D35083C55C49A9E4DFB0DEA282
                                                                    SHA-512:30E5DF6618AAB8D4BC23C69285CB8FBD3F65D522EEEEC88D61DAE4D735CF0C032A26EC1BEC038876EAD99015894B384E32069674F2BA5A163EF3E473BDC5BC41
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170137" V="0" DC="SM" EN="Office.Graphics.DelayCanvasInkInput" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="b6vhm" />.. <A T="2" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="HitCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="B" I="1" O="false" N="DelayCreation">.. <S T="1" F="DelayCreation" M="Ignore" />.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):465
                                                                    Entropy (8bit):5.114277201077218
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdSsTcIkoCAvQierzXFJnqRXHaSMNO/HNUlu:2dnTeHAvcrLvmp7
                                                                    MD5:DE22369294116CAFC3BAA1FBB940BF46
                                                                    SHA1:33D7B8581040A9D0E60C33E79F9FFD3C2647E276
                                                                    SHA-256:70FC29FC335C8CB472B4F1AEE5D354529DDA9E866657043DF29DA5204D98E999
                                                                    SHA-512:D55E890D684BDC93A47692CC595746C201CCC5D9BB114F8146AF8840671D7C3F45674F43F2A6CD5D7D66D0FB62A066F2B4827E06D0E9B10EF7B41A2429353547
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170138" V="0" DC="SM" EN="Office.Graphics.OnlineVideoAuthInfoMissing" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="6ra28" />.. <A T="2" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="HitCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):467
                                                                    Entropy (8bit):5.1236575579002785
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdSOfIkoCAvQierVXFJnqRXHaSMNO/HNUlu:2djXHAvcr5vmp7
                                                                    MD5:ED83698C5C5F1E655EB67F06388223AA
                                                                    SHA1:84EE40D6C01C3C72C737D6F02E6E4E89532D6174
                                                                    SHA-256:F7EFEAA740D5902ECAF3592C4E3F9FEC60537042BECF4616543AC46F90CB724C
                                                                    SHA-512:1F618B37A26D3407B25CC43E00456AD58445461B9D96687357B6DD5F831CABD9A16FC935943AFDBDDF3CD6C14B2D7A7307B2AD8A18854873A59C862EE5766E8D
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170139" V="0" DC="SM" EN="Office.Graphics.OnlineVideoAuthTicketMissing" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="6ra26" />.. <A T="2" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="HitCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):467
                                                                    Entropy (8bit):5.114441792324692
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdS6koCAvQiernXFJnqRXHaSMNO/HNUlu:2diHAvcrXvmp7
                                                                    MD5:5A5E8FCD2C426315EC88CEE0085C41C8
                                                                    SHA1:A080B9F517994EC4DB3F8010F9E02193DFE6543D
                                                                    SHA-256:909BF7B326295CE3A631658AC9CCC7F6748A5D17B7E9265D16943B2B899F6DAC
                                                                    SHA-512:E146B486EF52383382660CC01A162BAC0E28A8CFB67ECC255B297978B940B201B50353AC0E4F15E2FB16941DAC95BA2409149C784D2821F2E967799F16288915
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170140" V="0" DC="SM" EN="Office.Graphics.OnlineVideoAuthTicketInvalid" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="6ra24" />.. <A T="2" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="HitCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):695
                                                                    Entropy (8bit):5.116568979660504
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdSSBrkoCAvQierg19purzUpElFrF5NXFJzDaXOUdyXHaSMNO/HNUlu:2dXSHAvcrg19p64kr1vm/Ip7
                                                                    MD5:4F62F5F1120405231E3F31E204B8D488
                                                                    SHA1:6F1403515F7FA1FE2DAB0F191286617F285D23F8
                                                                    SHA-256:78BD7583DE21A57A442E75DFD506C97DBB8F7FA629ED1BCC98C130AD0FF5D86E
                                                                    SHA-512:845B07B6F0DF6DEBB0D9018C0619E7E52D14924A2738EB7C22D4655167D3500333BF5CDD27BE88792B9F5677FE9AA0B976F369C87F4A6A554D3797549D6B13D2
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170141" V="0" DC="SM" EN="Office.Graphics.CameoErrors" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="6vec7" A="6vec5 6vec4 6zbuc 6zbub 7wj9k 6ri1f 6sucd 6zbvs 6zbvq 6fu1f 6d0mz 6pkg4 6pkg2 6pkg0 6pkgy 6pkgw" />.. <A T="2" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="ULS_TagId" />.. </S>.. </G>.. <C T="W" I="0" O="false" N="TagID">.. <S T="1" F="ULS_TagId" />.. </C>.. <C T="U32" I="1" O="false" N="TagCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):537
                                                                    Entropy (8bit):5.070273196820279
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdS7TbkoCAvQierVXFJTRcSp9yXHaSMNO/HNUlu:2dy8HAvcr5vSKop7
                                                                    MD5:FB7A81BE7DD8FFD95BD9D125C0B20204
                                                                    SHA1:6D75274B9309D845C923F09805E2E601EEB5CF92
                                                                    SHA-256:CEDA3466305BC848994E4DFEB3F3D77EFD48C5478C7370C04AF4CF40CB9CD18C
                                                                    SHA-512:4818E5E0CB3B8F83D38C3B5C444DE3C0AD3F6F304E5611A8E919081DBC46D05CA5C02D9A83B8D06FFE2841CF238CEF7DB248CEA42F5BA6A13113C07659D01EC3
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="170142" V="2" DC="SM" EN="Office.Graphics.DXGIFactoryError" ATT="cfcfdb91c68c4329bb8b7cb7babb3cf7-e082c2f2-ef1d-427a-ac4d-b0b700afe7a7-7655" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bjghv" />.. <A T="2" E="TelemetryShutdown" />.. </S>.. <C T="I32" I="0" O="false" N="HResult">.. <S T="1" F="HR result" />.. </C>.. <C T="U32" I="1" O="false" N="TagCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):917
                                                                    Entropy (8bit):4.92696250027353
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd+FuEFgKbfcHxp8eBSNahozCP+6bdy9kOw7dVVtN6R1p1x76NOcsu:2dw0HAItKB1O
                                                                    MD5:516DAF9F915018EAB08CB0B3BFED421D
                                                                    SHA1:C034D1D52AC9CC24A77B3A948788667649FD56B2
                                                                    SHA-256:240E32AB698FDBA99DFE1307B4D804F465B717F89A3E4F10E163C9344FAEE3D7
                                                                    SHA-512:C8D43E7323D1253CFC76B1A8CEE7C68B733B487B105FC2BB074E02EE7D402DC0C3D6C78C5B44E811FE4DBE95FFC3D23665409875EA8E93DC3C8B0838E5578BF3
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="180178" V="0" DC="SM" EN="Office.Excel.Charting.ChartingErrors" ATT="19eb5e37de684ce38ce5cf3d5842d3f7-e8722941-bde5-4b98-9cd5-2775ec51482c-6873" DCa="PSU" xmlns="">.. <S>.. <UCSS T="1" C="Chart Load" S="Assert Unexpected" />.. <UCSS T="2" C="Chart Error" S="Assert Unexpected" />.. <US T="3">.. <S T="1" />.. <S T="2" />.. </US>.. </S>.. <C T="I32" I="0" O="true" N="ErrorCode">.. <S T="3" F="SH_ErrorCode" M="Ignore" />.. </C>.. <C T="I32" I="1" O="true" N="ErrorId">.. <S T="3" F="SH_ErrorId" M="Ignore" />.. </C>.. <C T="W" I="2" O="true" N="ErrorMessage">.. <S T="3" F="Error Message" M="Ignore" />.. </C>.. <C T="W" I="3" O="true" N="FormatString">.. <S T="3" F="FormatString" M="Ignore" />.. </C>.. <C T="I32" I="4" O="true" N="LCID">.. <S T="3" F="LCID" M="Ignore" />.. </C>.. <T>.. <S T="3" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1358
                                                                    Entropy (8bit):5.052627368675133
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dd0VeMY8rx3owzQ4oNFo4rOxmoi71c7muogcUDoMdHWzogXcOK:cweF8NYwz8koA3i7a7mvgcU8MdvgXcN
                                                                    MD5:7E7787603B5331A8CB798B3395A022D3
                                                                    SHA1:7EE564B391B18DFD925D96687F38CE82A25F73FD
                                                                    SHA-256:101A06CBBDE8E7F2B67EF01ADD3F0EC7BD8C4DB68666EC7E7E02B154C37DF279
                                                                    SHA-512:45E77EA95C54A091ED13197A17A218246042A2F536EDA59A1DC504042FBFDD6139DE535E2542C06F54FEEE423EFC66487F71D2BA83C6D2164A37C974095294E0
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="222015" V="6" DC="SM" EN="Office.NaturalLanguage.Proofing.ProofingEventsRuleSpellerEvent" ATT="71cc1046851042108843d90e5d3ef6c1-61e5de5c-238c-4de5-95de-3b40d20ea6e5-6899" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="a2dok" A="bkoh0 bn8xh" />.. </S>.. <C T="I32" I="0" O="true" N="SpellerEventUndoID">.. <S T="1" F="UndoID" M="Ignore" />.. </C>.. <C T="W" I="1" O="true" N="SpellerEventCultureTag">.. <S T="1" F="CultureTag" M="Ignore" />.. </C>.. <C T="W" I="2" O="true" N="SpellerEventEventName">.. <S T="1" F="EventName" M="Ignore" />.. </C>.. <C T="I32" I="3" O="true" N="IndexSelectedSuggestion">.. <S T="1" F="IndexSelectedSuggestion" M="Ignore" />.. </C>.. <C T="B" I="4" O="true" N="SpellerEventIsFromApplicationUndo">.. <S T="1" F="IsFromApplicationUndo" M="Ignore" />.. </C>.. <C T="U32" I="5" O="true" N="SpellerEventEndPoint">.. <S T="1" F="EndPoint" M="Ignore" />.. </C>.. <C T="B" I="6" O="true" N="Speller
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):548
                                                                    Entropy (8bit):5.225258869256733
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdrcx/tySjtG9JU7PqLKEerCsntSjtg/AGqdLNSjtg/6NO2su:2dr0A+tmMY8rCCt+tgF6p+tgC
                                                                    MD5:E3865BDCDD9165B9B49A4AA2D42C3788
                                                                    SHA1:E232168E7637CB796BE3EDDE51BD8ACD5AACA6A8
                                                                    SHA-256:58EEEB9CBD4D5C5F6F1943CCD4F86CB15FC40F082E8700280359AD7DD1E97647
                                                                    SHA-512:EC0C816A328C130F54D0D7EA762328F50F8D03B4899FAF0A285412E6016BFD0035CD586B62EC7C1868BE00FE9CF7F64960C04F91F3CCEA5C7E4A15AD8516489D
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="222042" V="0" DC="SM" EN="Office.NaturalLanguage.Proofing.ProofingToolsAdvertisementAction" ATT="71cc1046851042108843d90e5d3ef6c1-61e5de5c-238c-4de5-95de-3b40d20ea6e5-6899" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bdgkg" />.. </S>.. <C T="W" I="0" O="true" N="ActionProofingToolsAdvertisementAction">.. <S T="1" F="Action" />.. </C>.. <C T="W" I="1" O="true" N="LanguageTagProofingToolsAdvertisementAction">.. <S T="1" F="LanguageTag" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):619
                                                                    Entropy (8bit):5.212456246069162
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd7bx/tRV9JU7PqLKEer1s+FnY6dVdKp4wyNO2su:2d1RMY8r13
                                                                    MD5:A40F524DEC025CA5E9FD71C452212C37
                                                                    SHA1:239B37C082E6F26F43ED6A0FFE07CF95CEF47A4B
                                                                    SHA-256:ED99A27126594F2709EABC2466394C5EF68F75699E0AD6250A79E250F90D72FF
                                                                    SHA-512:E771B227132250253E82A89946C123A3D4C1E133417DDCD4B69405D320381E4C9A15749B5A13830CCEA070B841E708B36611A561C6E80F82FDD066C315DD0873
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="222043" V="0" DC="SM" EN="Office.NaturalLanguage.Proofing.ProofingOptionChange" ATT="71cc1046851042108843d90e5d3ef6c1-61e5de5c-238c-4de5-95de-3b40d20ea6e5-6899" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bdgkh" />.. </S>.. <C T="W" I="0" O="true" N="OptionNameProofingOptionChange">.. <S T="1" F="OptionName" />.. </C>.. <C T="U32" I="1" O="false" N="OldValueProofingOptionChange">.. <S T="1" F="OldValue" />.. </C>.. <C T="U32" I="2" O="false" N="NewValueProofingOptionChange">.. <S T="1" F="NewValue" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):805
                                                                    Entropy (8bit):5.197205363382414
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdBJex/tJ49JU7PqLKEerHlykvMfgdhRZPMfyt3RrfMfkn0hMfIm78xNO2su:2dunMMY8rHlyEM07hMIrfMVMdw3
                                                                    MD5:0DD20DC5150BB5C4DAD74BE1480E6F2F
                                                                    SHA1:6B1F4637CC765D0EF3687E4474AD71056DF9004C
                                                                    SHA-256:68F1BDB711AB052426A9A8B5D6D5656CC9F7C249C9A3A34DC15E4DE8DC652D9E
                                                                    SHA-512:6602E288FA7E9E334EF2F11BB65B5B5CCFFFAA92867A8569410FF54A1CF85CCC89CDF92D4220375A4FCA14F66E4A09C0D023C154CFA6E4270572B696185ACCE2
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="222049" V="1" DC="SM" EN="Office.NaturalLanguage.Proofing.ProofingOptionState" ATT="71cc1046851042108843d90e5d3ef6c1-61e5de5c-238c-4de5-95de-3b40d20ea6e5-6899" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bij74" A="bn8xq" />.. </S>.. <C T="W" I="0" O="false" N="CultureTagProofingOptionState">.. <S T="1" F="CultureTag" />.. </C>.. <C T="W" I="1" O="false" N="ProofingOptionNameProofingOptionState">.. <S T="1" F="ProofingOptionName" />.. </C>.. <C T="I32" I="2" O="false" N="ProofingOptionValueProofingOptionState">.. <S T="1" F="ProofingOptionValue" />.. </C>.. <C T="B" I="3" O="false" N="IsDataShareableOutsideOfficeProofingOptionState">.. <S T="1" F="IsDataShareableOutsideOffice" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1344
                                                                    Entropy (8bit):5.082434400405127
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dk8MY8rjzQzKxr81JV71c7mPcUC+syHF6D:cxF8fzDgr7a7mPcUM
                                                                    MD5:527C4AF7A1F18F0FCEC5C024E28F0FFF
                                                                    SHA1:4361E0F13AC318A6CD8E1AA46B5F3B0DE1C31091
                                                                    SHA-256:532E79F1FDF4CCB927EA683235872D27A8EBE9BE43654D703188A2A4EE9E75D1
                                                                    SHA-512:6379DD29E0DB04A43C80411D5AF40EC85E507FCB76BBC906989C2807FB030B3686866F0327B2E8CE9037EEC48E390FE38F8C0FD3B9DBCA6A6A6B90DF238EF781
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="222100" V="7" DC="SM" EN="Office.NaturalLanguage.Proofing.ProofingEventsRuleGrammarEvent" ATT="71cc1046851042108843d90e5d3ef6c1-61e5de5c-238c-4de5-95de-3b40d20ea6e5-6899" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="a22tu" A="bkoh1 bn8xj" />.. </S>.. <C T="I32" I="0" O="true" N="GrammarEventUndoID">.. <S T="1" F="UndoID" M="Ignore" />.. </C>.. <C T="W" I="1" O="true" N="GrammarEventCritiqueName">.. <S T="1" F="CritiqueName" M="Ignore" />.. </C>.. <C T="W" I="2" O="true" N="GrammarEventCultureTag">.. <S T="1" F="CultureTag" M="Ignore" />.. </C>.. <C T="W" I="3" O="false" N="GrammarEventEventName">.. <S T="1" F="EventName" />.. </C>.. <C T="I32" I="4" O="true" N="GrammarEventIndexSelectedSuggestion">.. <S T="1" F="IndexSelectedSuggestion" M="Ignore" />.. </C>.. <C T="B" I="5" O="true" N="GrammarEventIsFromApplicationUndo">.. <S T="1" F="IsFromApplicationUndo" M="Ignore" />.. </C>.. <C T="U32" I="6" O="true"
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1741
                                                                    Entropy (8bit):5.0902287582059165
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dSqaDMY8rY3p+dF1GtvD/0jscm7dHwGNMXcR:cwDF8s0pKdwG2XcR
                                                                    MD5:EF905904B45B3429A0C58432BC88005C
                                                                    SHA1:C1B538BCFBFFEB25EC1DF4E372950184D6ABF04D
                                                                    SHA-256:10AEA8083F4B2136C5E5B902D2816CD81ABCE2D125E5D6A43604E725AE5261F2
                                                                    SHA-512:D5FD9881C2B41204177C9F2A96469E8296A4E4AC78AEF0BEAD16BA1382E7B8C8CAB5657CE5E04B1D7811209D9DDAB3B2B54E927690882671932E9F9F9EE6288E
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="222101" V="3" DC="SM" EN="Office.NaturalLanguage.Proofing.ProofingEventsRuleGrammarRuleStatusEvent" ATT="71cc1046851042108843d90e5d3ef6c1-61e5de5c-238c-4de5-95de-3b40d20ea6e5-6899" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="a22tv" A="bij73 bn8xk" />.. </S>.. <C T="W" I="0" O="false" N="GrammarEventCritiqueName">.. <S T="1" F="CritiqueName" />.. </C>.. <C T="W" I="1" O="true" N="GrammarEventCultureTag">.. <S T="1" F="CultureTag" />.. </C>.. <C T="B" I="2" O="true" N="GrammarEventIsEnabled">.. <S T="1" F="IsEnabled" />.. </C>.. <C T="I32" I="3" O="true" N="GrammarEventDllVersionMajor">.. <S T="1" F="DllVersionMajor" />.. </C>.. <C T="I32" I="4" O="true" N="GrammarEventDllVersionMinor">.. <S T="1" F="DllVersionMinor" />.. </C>.. <C T="I32" I="5" O="true" N="GrammarEventDllVersionBuild">.. <S T="1" F="DllVersionBuild" />.. </C>.. <C T="I32" I="6" O="true" N="GrammarEventDllVersionRevision">.. <S T="1" F="
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1754
                                                                    Entropy (8bit):5.099058382662732
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dfoZMY8rHmxEdO1ftAbW/dSsj3adHwGNFXcR:cqF8yxEAmvdwGvXcR
                                                                    MD5:20CACE5E68B4729AB60AB8FAE14E5A3A
                                                                    SHA1:886EB258AE778237CAF547F7ED30EF46270FF4A1
                                                                    SHA-256:67EB0A0915F2C4434D8E8A57308B0AC75304A3CE1BE5D70B330A0978104A193D
                                                                    SHA-512:72160D844EE7F614D6BBFF615806630E9F25FB5BDEA61C1717C93549617B5CC72F050ABA4F57EF1D2507206798272B63D5B18C8D52F85C5D54D5CBD6E2D20682
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="222102" V="1" DC="SM" EN="Office.NaturalLanguage.Proofing.ProofingEventsRuleGrammarEnable" ATT="71cc1046851042108843d90e5d3ef6c1-61e5de5c-238c-4de5-95de-3b40d20ea6e5-6899" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bgjm6" A="bn8xl" />.. </S>.. <C T="W" I="0" O="false" N="GrammarEventCultureTag">.. <S T="1" F="CultureTag" />.. </C>.. <C T="B" I="1" O="false" N="GrammarEventIsForegroundChecking">.. <S T="1" F="IsForegroundChecking" />.. </C>.. <C T="B" I="2" O="false" N="GrammarEventIsEnabled">.. <S T="1" F="IsEnabled" />.. </C>.. <C T="I32" I="3" O="false" N="GrammarEventDllVersionMajor">.. <S T="1" F="DllVersionMajor" />.. </C>.. <C T="I32" I="4" O="false" N="GrammarEventDllVersionMinor">.. <S T="1" F="DllVersionMinor" />.. </C>.. <C T="I32" I="5" O="false" N="GrammarEventDllVersionBuild">.. <S T="1" F="DllVersionBuild" />.. </C>.. <C T="I32" I="6" O="false" N="GrammarEventDllVersionRevision">.. <S T=
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1229
                                                                    Entropy (8bit):5.103797470026722
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dh4eMY8rPSFNoebdrNtxei71c7m2gcU1MdHM:cueF8LOCebdBnei7a7m2gcU1MdM
                                                                    MD5:2A3655FB6191CFFA02D59D4231405454
                                                                    SHA1:C2B844F56E9571DE114BEE73DF030AA19356FFAB
                                                                    SHA-256:A5DCC0ACC40E8DDC458832E1ED3BE01D3BF0051940CADBBE38371938B46D3D6D
                                                                    SHA-512:58DAE748C17463AB828A4BA5A390BAE848AE207B9CB7FEDCCF9BB472D330CACC288AFD2D52D4E98DCC830FC75F2108440BCA1A0A344B20E244793429500D1104
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="222200" V="5" DC="SM" EN="Office.NaturalLanguage.Proofing.ProofingEventsRuleContextualSpellerEvent" ATT="71cc1046851042108843d90e5d3ef6c1-61e5de5c-238c-4de5-95de-3b40d20ea6e5-6899" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="a22tx" A="bkoh2 bn8xn" />.. </S>.. <C T="W" I="0" O="true" N="ContextualSpellerEventCultureTag">.. <S T="1" F="CultureTag" M="Ignore" />.. </C>.. <C T="W" I="1" O="true" N="ContextualSpellerEventName">.. <S T="1" F="EventName" M="Ignore" />.. </C>.. <C T="I32" I="2" O="true" N="ContextualSpellerEventScore">.. <S T="1" F="Score" M="Ignore" />.. </C>.. <C T="I32" I="3" O="true" N="ContextualSpellerEventIndexSelectedSuggestion">.. <S T="1" F="IndexSelectedSuggestion" M="Ignore" />.. </C>.. <C T="B" I="4" O="true" N="ContextualSpellerEventIsFromApplicationUndo">.. <S T="1" F="IsFromApplicationUndo" M="Ignore" />.. </C>.. <C T="U32" I="5" O="true" N="ContextualSpellerEventEndPoint">.. <S T="
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):414
                                                                    Entropy (8bit):5.267547289812924
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd1C2uj4D5Mtlj87ereMfA+LwxNO2su:2dlucVMvj8irBI3
                                                                    MD5:4C2721823FE7A9E3AB863CA7E9D333DE
                                                                    SHA1:7239F108C63FB255C8B140144F7FF32D51DD182F
                                                                    SHA-256:D586E050D5B4C3BD3E52A9E8A1153744C29CE83660F0FF59957F14E9D295308D
                                                                    SHA-512:4ADA20C3FB192ABAA0042296E3ED8A4FD13A47FE4F868B15921DE18DD116EB618D4E8274EA9BBD064BF2285F7B7AAB900526D84497055528BF0D54CFB0057357
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="224008" V="0" DC="SM" EN="Office.Licensing.OfficeClientLicensing.Client.ReportLicensingEnteringRFM" ATT="c1a0db0127964674a0d62fde5ab0fe62-6ec4ac45-cebc-4f80-aa83-b6b9d3a86ed7-7719" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="a2y9o" />.. </S>.. <C T="I64" I="0" O="false" N="AppState">.. <S T="1" F="AppState" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):451
                                                                    Entropy (8bit):5.254582578930078
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdjMC2/nXW5Mtlj87erklVBR2FMNO2su:2dOP0Mvj8irkPia
                                                                    MD5:2F739B8B1DF01F02308ED6C1AB504D26
                                                                    SHA1:88F3336C9C514EC78E68999744FD2905ADCC1EBA
                                                                    SHA-256:BCCBCF53A7D5D3BB383A7A1A46685D29427B10FC499C7D90B616794AD4540423
                                                                    SHA-512:BFB7F8A78549D5F78618C4B0A744EF6E4D4797AE4D0DB40BFBB30AFE0AC695C26E93B99ECCE3EDE69EF1441454683CCDE46242F5516C351755783151F196AF17
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="224010" V="0" DC="SM" EN="Office.Licensing.OfficeClientLicensing.Client.HeartbeatActivationAttempted" ATT="c1a0db0127964674a0d62fde5ab0fe62-6ec4ac45-cebc-4f80-aa83-b6b9d3a86ed7-7719" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="a46xr" />.. </S>.. <C T="FT" I="0" O="false" N="HeartbeatAttemptingActivate">.. <S T="1" F="TimeStamp100ns" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):999
                                                                    Entropy (8bit):5.004221928187262
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdDC2jN4D5Mtlj87erderAfer9w6dke/Nydy0mRakX+e/iX+yp1DXgS+/nSSx6:2drjWVMvj8irorAWr9Bke1ik+eM+k12K
                                                                    MD5:FB2B6BC598F12538C97FBFFC295296AA
                                                                    SHA1:7FCEACE24F94DF89BE63CF51F927E534033E8EB4
                                                                    SHA-256:456A0A96574834E11FC18DBC79B22569CB2818A181DC3D1A3A1FDA5367E02D2F
                                                                    SHA-512:FB2628E0F9C9B68EF9D1CA7F56A1C938DC174039A6047267397EA6AF683023C6C5DE16F0430A00A3EDA2117F9A3FB354E27267692CECEE6603616E72EB88277D
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="224011" V="0" DC="SM" EN="Office.Licensing.OfficeClientLicensing.Client.ReportActivationDetails" ATT="c1a0db0127964674a0d62fde5ab0fe62-6ec4ac45-cebc-4f80-aa83-b6b9d3a86ed7-7719" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="a46wg" />.. <UTS T="2" Id="a46vn" />.. <UTS T="3" Id="a46wh" />.. </S>.. <C T="W" I="0" O="false" N="Client">.. <S T="2" F="Client" />.. </C>.. <C T="W" I="1" O="false" N="ClientVersion">.. <S T="2" F="ClientVersion" />.. </C>.. <C T="W" I="2" O="false" N="ClientLanguage">.. <S T="2" F="ClientLanguage" />.. </C>.. <C T="I32" I="3" O="false" N="OfficeMajorVersion">.. <S T="2" F="OfficeMajorVersion" />.. </C>.. <C T="I32" I="4" O="false" N="Protocol">.. <S T="2" F="Protocol" />.. </C>.. <C T="G" I="5" O="false" N="CorrelationId">.. <S T="2" F="CorrelationId" />.. </C>.. <C T="I64" I="6" O="true" N="Result">.. <S T="3" F="HRESULT" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):427
                                                                    Entropy (8bit):5.239081682219337
                                                                    Encrypted:false
                                                                    SSDEEP:6:TMVBdNktC2tk45MqaIajECChHperh0cwNjxPVCx3AA+/LylNOn2sby:TMHd2C2N5Mtlj87erQxlV0o6NO2su
                                                                    MD5:C517CD929CEF395534B5ED8B8EB96AF5
                                                                    SHA1:6B7625FACE0A22E83B48B77056A779B16CD177D1
                                                                    SHA-256:2FEE7819A033E06E2331CB08137F79D81E419EFA03B272A14C2EDA00BBEB671D
                                                                    SHA-512:72CE5B1EC9D4126DF51799F1F23E20268699E2AB02ED6732AB98F4171470478210685F31028A0AB9928E3C2C22887542104ACE8977A60AC626EB1AA48ACC45C1
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="224012" V="0" DC="SM" EN="Office.Licensing.OfficeClientLicensing.Client.UserNotifiedToReboot" ATT="c1a0db0127964674a0d62fde5ab0fe62-6ec4ac45-cebc-4f80-aa83-b6b9d3a86ed7-7719" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="a2y8m" />.. </S>.. <C T="FT" I="0" O="false" N="RebootNotificationTime">.. <S T="1" F="TimeStamp100ns" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):818
                                                                    Entropy (8bit):5.066086618929864
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd5C2Ok5Mtlj87er7er3Nere/er5lVr6jlWKfdjlV9BfLjlEnsfe/4NOScsu:2dhOOMvj8irir3YrRr5POnrYia
                                                                    MD5:6CD44453FDB074D9D5A8DC211AA3EFC9
                                                                    SHA1:E598330D6555030469D70F0D6BDB40812BDD4A11
                                                                    SHA-256:217B52E2E153B1AB11BD72565C181E13D012FD5D621F77F1AFF51C2AA2F2DA94
                                                                    SHA-512:29AB30696E6FED9FAFF3CA38F1AF92139796BB84B3CCCF351A9667FD2400813D49E4188D7AAD2D08CA2EBC35CFD2EA7708DC903F9097A519DFA2CBC32FCCB72B
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="224013" V="0" DC="SM" EN="Office.Licensing.OfficeClientLicensing.Client.ShowSignInUI" ATT="c1a0db0127964674a0d62fde5ab0fe62-6ec4ac45-cebc-4f80-aa83-b6b9d3a86ed7-7719" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="a2zam" />.. <UTS T="2" Id="a2zan" />.. <UTS T="3" Id="a2zcd" />.. <UTS T="4" Id="a2zao" />.. </S>.. <C T="FT" I="0" O="false" N="EnteringShowSignInUI">.. <S T="1" F="TimeStamp100ns" />.. </C>.. <C T="FT" I="1" O="true" N="AttemptingPassedIdentity">.. <S T="2" F="TimeStamp100ns" />.. </C>.. <C T="FT" I="2" O="true" N="ObtainedIdentity">.. <S T="4" F="TimeStamp100ns" />.. </C>.. <C T="FT" I="3" O="true" N="ActiveIdentityToNull">.. <S T="3" F="TimeStamp100ns" />.. </C>.. <T>.. <S T="1" />.. <S T="3" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1266
                                                                    Entropy (8bit):4.886380355747692
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dfOyMvj8ir9rDrurPrtrwi5/S79Q1lM7:cmjtRvyzBX5/UclM7
                                                                    MD5:12909807CF667874B36662ACE6058162
                                                                    SHA1:4A9F8A7D758908A3EDBD7936D3F1747F8357D2BE
                                                                    SHA-256:6CE0FBAD63170CF3E6B540BD9540F792C849D061EE95F0FDE1CF9C696151D990
                                                                    SHA-512:54C5F4A67BE708A25385CCB66ABB2206C14984DA2CC84E3FC0478B198B6134BA02EF96725A552940A67515ABDD09F5475545AC2FCD9EBF7D1A567AD85BAE0EA4
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="224059" V="0" DC="SM" EN="Office.Licensing.GetLicenseInfoForMachineKey.LicenseAccountResult" ATT="c1a0db0127964674a0d62fde5ab0fe62-6ec4ac45-cebc-4f80-aa83-b6b9d3a86ed7-7719" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bgqus" />.. <UTS T="2" Id="bgqut" />.. <UTS T="3" Id="bgqup" />.. <UTS T="4" Id="bgquv" />.. <UTS T="5" Id="bgquw" />.. <UTS T="6" Id="bgquy" />.. <TO T="7" I="30s">.. <S T="1" />.. </TO>.. <A T="8" E="TelemetrySuspend" />.. <A T="9" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="IsAccountReceived">.. <C>.. <S T="5" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="IsAccountFull">.. <C>.. <S T="6" />.. </C>.. </C>.. <C T="I64" I="2" O="true" N="FailureResult">.. <S T="3" F="HRESULT" M="Ignore" />.. </C>.. <C T="U32" I="3" O="true" N="FailureReasonCode">.. <S T="3" F="ErrorCode" M="Ignore" />.. </C>.. <C T="U32" I="4" O="false" N="IsInputM
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):2244
                                                                    Entropy (8bit):4.766413313999244
                                                                    Encrypted:false
                                                                    SSDEEP:48:cMOjqF0qoZTCOFH6Elr/lpXdKRyJHt8/w7:KAiBC/w7
                                                                    MD5:9F1FD3252AF1F48DE401E1B7185CFD3E
                                                                    SHA1:C5CB302BE8545CE6C439FE2C5E5611FF7AB72F2C
                                                                    SHA-256:828EBCD7C4353FAAF1919506743622F1DC948F7FBFDC554FEB4592F951A17280
                                                                    SHA-512:9500ED349994B41E988E6C1A4A679F0C9214A7C5E6ACDA9305A050C4CD91F9E614AFC8B07A8144DA4F1C26C3624060396927A385B1F0283935E4CB71E42EDDEF
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="224060" V="0" DC="SM" EN="Office.Licensing.OfficeClientLicensing.RedemptionAPI.Completion" ATT="c1a0db0127964674a0d62fde5ab0fe62-6ec4ac45-cebc-4f80-aa83-b6b9d3a86ed7-7719" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bc9ms" />.. <UTS T="2" Id="bf35l" />.. <UTS T="3" Id="bf346" />.. <UTS T="4" Id="bf35b" />.. <UTS T="5" Id="bf34q" />.. <UTS T="6" Id="bf34r" />.. <UTS T="7" Id="bf34s" />.. <UTS T="8" Id="bc9mt" />.. </S>.. <C T="W" I="0" O="false" N="LanguageCode">.. <S T="1" F="LanguageCode" />.. </C>.. <C T="W" I="1" O="false" N="CountryCode">.. <S T="1" F="CountryCode" />.. </C>.. <C T="B" I="2" O="true" N="ACSRequestSucceeded">.. <S T="2" F="Result.Succeeded" M="Ignore" />.. </C>.. <C T="W" I="3" O="true" N="ClientTransactionId">.. <S T="3" F="ClientTransactionId" M="Ignore" />.. </C>.. <C T="U32" I="4" O="true" N="PurchaseType">.. <S T="3" F="PurchaseType" M="Ig
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1512
                                                                    Entropy (8bit):4.3803114020730005
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dtNMvj8trB8rFhrLrkdr9mFrkr3Bl9Zrj9ZvSEg9Soy3c:c8jqV87vgd5uYDBl9p999g9Z0c
                                                                    MD5:02DDAB629963A6C66560DE003254240E
                                                                    SHA1:5C0A1D2EA1005416DBAB352F81D09EA0E6C28CC6
                                                                    SHA-256:7581C0615820F91AC29D7E141DA3F9EEBD6DD76E14C9EFD5653111C4F67C286F
                                                                    SHA-512:605C49382FC39D96141B44E107518C007933FA79B47DC758BEC28C7AD110A0E8A9391F74A6EAF8E082492BB2D31BFF5C505B87777FA506D3051B3EC74B3E0A43
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="224061" V="0" DC="SM" EN="Office.Licensing.OfficeClientLicensing.OOBE.Closed" ATT="c1a0db0127964674a0d62fde5ab0fe62-6ec4ac45-cebc-4f80-aa83-b6b9d3a86ed7-7719" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="a7op4" />.. <UTS T="2" Id="a7oqa" />.. <UTS T="3" Id="a7oqj" />.. <UTS T="4" Id="a7opw" />.. <UTS T="5" Id="a7opz" />.. <UTS T="6" Id="bhcnc" />.. <UTS T="7" Id="a7op7" />.. <F T="8">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="1" F="Destination" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </L>.. <R>.. <O T="LE">.. <L>.. <S T="1" F="Destination" />.. </L>.. <R>.. <V V="3" T="U32" />.. </R>.. </O>.. </R>.. </O>.. </F>.. <US T="9">.. <S T="8" />.. <S T=
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):859
                                                                    Entropy (8bit):4.8742487780544455
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdPNCeuE5Mtlj8HAQierBRerSfOS+tNqNOsX/c//tpON+HNPTff44KGmydkoXt:2deuMvj8trB8rSm5t4jeFT4vGmWkorZ
                                                                    MD5:F33DC1030A3C4A0AD2985212D28D51B1
                                                                    SHA1:DC05F5534076109EE1E9F5A43AE5D7F2741CCF7D
                                                                    SHA-256:23B603E0531BF6E422B505E301AEC4DDB4B13682F4887EBED30936BEAFC29BDD
                                                                    SHA-512:5F19849A38278F300DEECF8FBA83FEAB002A54F1E8185899FEE65545C981BCA4D8B6681FEF01AA9031AA5D286E4EDC49C46379CA4A1B14938E9F5F0C51AAA99E
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="224062" V="0" DC="SM" EN="Office.Licensing.OfficeClientLicensing.OOBEWelcome.ButtonClicked" ATT="c1a0db0127964674a0d62fde5ab0fe62-6ec4ac45-cebc-4f80-aa83-b6b9d3a86ed7-7719" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="a7op4" />.. <UTS T="2" Id="a7opz" />.. <F T="3">.. <O T="EQ">.. <L>.. <S T="1" F="Source" />.. </L>.. <R>.. <V V="0" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <G>.. <S T="3">.. <F N="ActionTarget" />.. </S>.. </G>.. <C T="U32" I="0" O="false" N="OOBEButtonPressed">.. <S T="3" F="ActionTarget" />.. </C>.. <C T="U32" I="1" O="false" N="OOBEButtonPressedCount">.. <C>.. <S T="3" />.. </C>.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="3" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):2037
                                                                    Entropy (8bit):4.964290580121227
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d22Mvj8irErZrnr/gTjkTogqwy4VuYF3wBzFwIhMKN+UFfYMF7:c29jtYNLbgTeogNutwyjfF7
                                                                    MD5:5307C21B0D24976D878F79376AC263FF
                                                                    SHA1:8F16434126C729FB98A1156A94B9AE9FE53A0A9A
                                                                    SHA-256:85F4A22DE45C2374FB60A48D5F5C01B31CC57FE9216F08F096D80CB025B28A76
                                                                    SHA-512:18DEF79BEAC9757C95D7CD53AB87394A756A342D7AD925C001F8C4320B00CA07F4AAD9E6CD548F5267875357419B30C11BDC4720D38ECD47E51E6785CE4885C5
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="224068" V="0" DC="SM" EN="Office.Licensing.OfficeClientLicensing.Session.TryGetSessionToken" ATT="c1a0db0127964674a0d62fde5ab0fe62-6ec4ac45-cebc-4f80-aa83-b6b9d3a86ed7-7719" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bjzq0" />.. <UTS T="2" Id="bjzq2" />.. <UTS T="3" Id="bjzq3" />.. <UTS T="4" Id="bjzq4" />.. <A T="5" E="TelemetrySuspend" />.. <A T="6" E="TelemetryShutdown" />.. </S>.. <C T="B" I="0" O="false" N="AuthSessionNull">.. <S T="1" F="AuthSessionNull" M="Ignore" />.. </C>.. <C T="U64" I="1" O="false" N="SigningCertLength">.. <S T="1" F="SigningCertLength" M="Ignore" />.. </C>.. <C T="B" I="2" O="false" N="ChosenEntitlementNull">.. <S T="1" F="ChosenEntitlementNull" M="Ignore" />.. </C>.. <C T="B" I="3" O="false" N="OlsIdentityNull">.. <S T="1" F="OlsIdentityNull" M="Ignore" />.. </C>.. <C T="B" I="4" O="false" N="ActiveIdentityNull">.. <S T="1" F="ActiveIdentityNull" M="Ignore" />.. </C
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):419
                                                                    Entropy (8bit):4.271508382564369
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdNberPO+u/qNOPX/c//spONwspSZNOjsu:2dQrPNuygNo
                                                                    MD5:CA6D18BE1B6CB81896D5C642C0FEB2A8
                                                                    SHA1:EAB023C0FB0FDC78EDD135713DD748D1BD3D54CD
                                                                    SHA-256:85F0D5B3888C115DDFDFF5509748B4EC508A54236B295BD5103B5C1F9EB1B50F
                                                                    SHA-512:D44DE97A2201758CEE068D0D272692D273ECBC3F656587549DCD2A86AE16162868B2D158013AF633A63F0744B236DFC93FA048E584CF9D0EF4D321B752E05142
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="224072" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <UTS T="1" Id="ba9f8" />.. <F T="2">.. <O T="EQ">.. <L>.. <S T="1" F="OOBEMode" />.. </L>.. <R>.. <V V="OEMTA" T="W" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="true">.. <S T="2" F="OOBEMode" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):482
                                                                    Entropy (8bit):4.279287793372496
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd2yberJHferT+tNqNOGmfX/c//+pONU5oVrzNOAHNUlu:2d2TrJ2rit4DmvI97
                                                                    MD5:08141D4106FCB910715B54F07E45377E
                                                                    SHA1:D049C9C519286573331EB62A5FC7C28DAAF3FFD6
                                                                    SHA-256:637E5BE8EC0EA41FCBC695C4C10E9412AA031F7EADD397F8EB1499A7FA3744DA
                                                                    SHA-512:2B50437C78B59764C6A856D66848224766A07D6722B4EC172D7E7C96C93F1638B5ECD218D70FF0DEF861FC0C971A27EC0C2219DA48A575749C4559DE9818922D
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="224073" V="1" DC="SM" T="Subrule" xmlns="">.. <S>.. <UTS T="1" Id="bnpxq" />.. <UTS T="2" Id="a7oqj" />.. <F T="3">.. <O T="EQ">.. <L>.. <S T="2" F="ActionTarget" />.. </L>.. <R>.. <V V="7" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <C T="B" I="0" O="false">.. <V V="true" T="B" />.. </C>.. <T>.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):482
                                                                    Entropy (8bit):4.280853950015988
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdgberJHferT+tNqNOGmfX/c//apONU5oVrzNOAHNUlu:2dJrJ2rit4Dmvk97
                                                                    MD5:3892DDB7F37107D5C79CCDB071F909B5
                                                                    SHA1:020BDF2B0C626D7264F956B7558D1EBC61BD4335
                                                                    SHA-256:233F71AEF6E49C6899F77A9951913356801180905B31609497D8A6A538B25D1E
                                                                    SHA-512:0CA0E39DE8B73D144C58ECA90A70CD8230766C27249D8B196900E9984A64C1D58E6F68DBEDFBE32CE7F7718C46A63C4B7AC20508C83AA908AEEDB0A177DD6B23
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="224074" V="1" DC="SM" T="Subrule" xmlns="">.. <S>.. <UTS T="1" Id="bnpxq" />.. <UTS T="2" Id="a7oqj" />.. <F T="3">.. <O T="EQ">.. <L>.. <S T="2" F="ActionTarget" />.. </L>.. <R>.. <V V="3" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <C T="B" I="0" O="false">.. <V V="true" T="B" />.. </C>.. <T>.. <S T="3" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1160
                                                                    Entropy (8bit):4.866322685671609
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dsWMvj8xqrW2r9mFrcrvvg9Jcmr79mu/37:csdj7y25uwTvg9Gdu/37
                                                                    MD5:381C66EF71FC04C0FDEF8D09B75367F7
                                                                    SHA1:9B9862F09006A391E92BFE528C628E7EF00145F5
                                                                    SHA-256:48727DD73FB647296FFAE2E95D74BFE9415B861533D28383BB5DA7C17E60E47D
                                                                    SHA-512:3760DDDE52EE395CC9BB690FCE7BFA9C9770E93AAF63A94295CFE2BF390A11E82CA25A4FDC4290609FDA1F31CEDD70028163F6C60018C72DB4E0AF25F1C4A3B3
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="224075" V="1" DC="SM" EN="Office.Licensing.OfficeClientLicensing.GetGenuineTicketFailure" ATT="c1a0db0127964674a0d62fde5ab0fe62-6ec4ac45-cebc-4f80-aa83-b6b9d3a86ed7-7719" DCa="PSU" xmlns="">.. <S>.. <R T="1" R="224072" />.. <R T="2" R="224073" />.. <R T="3" R="224074" />.. <UTS T="4" Id="bnpxq" />.. <UTS T="5" Id="a7opz" />.. <UTS T="6" Id="a7oql" />.. <UTS T="7" Id="a7oqj" />.. <F T="8">.. <O T="EQ">.. <L>.. <S T="7" F="Destination" />.. </L>.. <R>.. <V V="16" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <C T="I64" I="0" O="true" N="GetGenuineTicketResult">.. <S T="4" F="HRESULT" />.. </C>.. <C T="B" I="1" O="true" N="RetryButtonClicked">.. <S T="2" F="0" />.. </C>.. <C T="B" I="2" O="true" N="ContinueButtonClicked">.. <S T="3" F="0" />.. </C>.. <C T="TAG" I="3" O="true" N="BindingMissing">.. <S T="6" F="ULS_Tag" M="Ignore" />.. </C>.. <C
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):504
                                                                    Entropy (8bit):5.200872545078664
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd/CFKp5Mtlj87ersAXXMSM3O9YPEmyNO2su:2dG2Mvj8irsAXXOLMmi
                                                                    MD5:14EA0A76EF1108E1F357549AAA2F6FA3
                                                                    SHA1:38D83E36D518CDA20FB7DDD7B3D3080A83E6CFD9
                                                                    SHA-256:D223E391B461993581D221EC150739D31CB061A0C762697C04677972FE967904
                                                                    SHA-512:3B4079DF4EB918C5627F07A938519E0F151591ADEF40184CC356AA3907F97DCB40383E42B5B3E15FCAC2275AF15CC185DC488BA6114AFB9F5415C04B6086BB2B
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="224082" V="0" DC="SM" EN="Office.Licensing.OfficeClientLicensing.Session.ReportLicenseMessage" ATT="c1a0db0127964674a0d62fde5ab0fe62-6ec4ac45-cebc-4f80-aa83-b6b9d3a86ed7-7719" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="a2zcw" />.. </S>.. <C T="I64" I="0" O="false" N="PopulateLicenseError">.. <S T="1" F="MessageIDS" />.. </C>.. <C T="I64" I="1" O="false" N="ResultCode">.. <S T="1" F="Error" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):829
                                                                    Entropy (8bit):5.066160040947317
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdcCvr95Mtlj87erDer8erWBjEaSrYS69czvXa/9+UNe+NO5A3XGHNUlu:2drr7Mvj8irqrjrUFSrYlvi7
                                                                    MD5:3C6ED9D0FA22F0ED88E4AA7910B76CB9
                                                                    SHA1:EBD150A480824DF6EC8124F23C93933D00C42354
                                                                    SHA-256:4B969BFF4C80F008ADED9DC6FCFD11112E27568BA16E0588C98C6F682FD4B100
                                                                    SHA-512:8E7B79101EF49F826CDF8850F69BA1FDEB57BBBB4959A4F80B4C4FCDAF5EEFA0DBF89E6C543FA3DE19D4E9864EF266C94A4FBD9F869CE76FFA68EC536E252897
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="224083" V="0" DC="SM" EN="Office.Licensing.OfficeClientLicensing.InAppAFOPinValidationResult" ATT="c1a0db0127964674a0d62fde5ab0fe62-6ec4ac45-cebc-4f80-aa83-b6b9d3a86ed7-7719" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bnpw6" />.. <UTS T="2" Id="bnpw8" />.. <UTS T="3" Id="bnpw9" />.. <A T="4" E="TelemetrySuspend" />.. <A T="5" E="TelemetryShutdown" />.. </S>.. <C T="I64" I="0" O="false" N="PinValidationResult">.. <S T="1" F="PinResult" />.. </C>.. <C T="TAG" I="1" O="true" N="DisableAFO">.. <S T="2" F="ULS_Tag" M="Ignore" />.. </C>.. <C T="TAG" I="2" O="true" N="SkipAFOOnce">.. <S T="3" F="ULS_Tag" M="Ignore" />.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. <S T="4" />.. <S T="5" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):812
                                                                    Entropy (8bit):5.017010499705265
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdpCD5Mtlj87erDerXndYS69ezZdyJHCdh30N1Dglfn9xNO/HNUlu:2dwMvj8irqrNYlkzYyha1clv9S7
                                                                    MD5:4E18E98FADFAC4D1A440D7F81070C24D
                                                                    SHA1:FC1B2DC94A167E5A4E2CD3D40525F9FC65B316F2
                                                                    SHA-256:8B9E08CFE21DB699A5A12A8F281C7F51F613486D35B0C15B0367BE0774EAE6F4
                                                                    SHA-512:53DA7B04B97B7245ADB55E1EC5A200258C6A66EEF733A7930755CA648FB32271429C47682C89DC6F1800822D98639003FDE3693B0186BD32751DD9B2E54CABB2
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="224084" V="0" DC="SM" EN="Office.Licensing.OfficeClientLicensing.InAppAFOSuccess" ATT="c1a0db0127964674a0d62fde5ab0fe62-6ec4ac45-cebc-4f80-aa83-b6b9d3a86ed7-7719" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bnpw6" />.. <UTS T="2" Id="bc9mt" />.. </S>.. <C T="I64" I="0" O="false" N="RedemptionResult">.. <S T="1" F="PinResult" />.. </C>.. <C T="I32" I="1" O="false" N="IsSuccess">.. <S T="2" F="ResultCode" />.. </C>.. <C T="W" I="2" O="false" N="StatusCode">.. <S T="2" F="StatusCode" />.. </C>.. <C T="W" I="3" O="false" N="StatusMessage">.. <S T="2" F="StatusMessage" />.. </C>.. <C T="U32" I="4" O="false" N="ErrorType">.. <S T="2" F="ErrorType" />.. </C>.. <T>.. <S T="2" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):2463
                                                                    Entropy (8bit):4.341998590848822
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dMMvj8trsrerKbigJujQauvjfsjw8lQaGDfUGve6rF16ntF7:cPjaoC+GgJujQvvTsk8lQTD76ntF7
                                                                    MD5:E02DB2CBE22EE006046CCE6CDFA4CC88
                                                                    SHA1:BEF3C35984CB4BEA111A45207BA0CF1770151ED0
                                                                    SHA-256:BBB9F96E1EA13E9EE79119C4DFB3892DA617239635F750235A3B1F2F2FD6FD57
                                                                    SHA-512:2A8DE215D94547D3140C553B5D7DEE3F44FE1CAC014D48D72C8BC97670A1BEF3B1F74AA2221758600C9DB2F326ECD5214C39E81C6FC5ACCC3B4BB458A6513E40
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="224085" V="0" DC="SM" EN="Office.Licensing.PreExpirationBusBarInteraction" ATT="c1a0db0127964674a0d62fde5ab0fe62-6ec4ac45-cebc-4f80-aa83-b6b9d3a86ed7-7719" S="1" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="a4673" />.. <UTS T="2" Id="a468a" />.. <UTS T="3" Id="a5ri8" />.. <TI T="4" I="30min" />.. <A T="5" E="TelemetrySuspend" />.. <A T="6" E="TelemetryShutdown" />.. <F T="7">.. <O T="EQ">.. <L>.. <S T="1" F="PartType" />.. </L>.. <R>.. <V V="40" T="I32" />.. </R>.. </O>.. </F>.. <F T="8">.. <O T="EQ">.. <L>.. <S T="2" F="ButtonAction" />.. </L>.. <R>.. <V V="Buy" T="W" />.. </R>.. </O>.. </F>.. <F T="9">.. <O T="EQ">.. <L>.. <S T="2" F="ButtonAction" />.. </L>.. <R>.. <V V="Remind Me Later" T="W" />.. </R>.. </O>.. </F>.. <F T="10">..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1921
                                                                    Entropy (8bit):4.414808067265105
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dAMvj8trsrerKbigJujQaevjOslQa2FUGI1q1tF7:cDjaoC+GgJujQjvislQK1+tF7
                                                                    MD5:3C40953A1DBA50ED8FAF04EE350006B5
                                                                    SHA1:D55AF128665BB6C09CEFB37B30C532C6AC44A105
                                                                    SHA-256:BAEEFB1C6300C9FA281DB65CCAE479D8168338C9CC11F6DDC3CEFEA4DF4A6B06
                                                                    SHA-512:0759E489A5D12BBB0EAD4FB5051F82C55C02CCE75DDE973FBC004A392B5DA4C7F1570F763A544A13C61AF5F2E0801664F2222E7A30F2E2489257653CF9485694
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="224086" V="0" DC="SM" EN="Office.Licensing.PostExpirationBusBarInteraction" ATT="c1a0db0127964674a0d62fde5ab0fe62-6ec4ac45-cebc-4f80-aa83-b6b9d3a86ed7-7719" S="1" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="a4673" />.. <UTS T="2" Id="a468a" />.. <UTS T="3" Id="a5ri8" />.. <TI T="4" I="30min" />.. <A T="5" E="TelemetrySuspend" />.. <A T="6" E="TelemetryShutdown" />.. <F T="7">.. <O T="EQ">.. <L>.. <S T="1" F="PartType" />.. </L>.. <R>.. <V V="35" T="I32" />.. </R>.. </O>.. </F>.. <F T="8">.. <O T="EQ">.. <L>.. <S T="2" F="ButtonAction" />.. </L>.. <R>.. <V V="&amp;Reactivate" T="W" />.. </R>.. </O>.. </F>.. <F T="9">.. <O T="EQ">.. <L>.. <S T="3" F="PartType" />.. </L>.. <R>.. <V V="35" T="I32" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32"
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1404
                                                                    Entropy (8bit):4.403513241689896
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd35Mtlj8HAQ4Wner5erXN+tNlOJeMfH/M//aO5eNX/c//JeaOH/M//x5eNpOk:2dJMvj8OrkrMt4fzrjPTKEMjwtVj7
                                                                    MD5:87360B49636F0DCCC60717EDB08D8813
                                                                    SHA1:B89E5F079A09FD9870E7EAC3FFB5EF97D95470C5
                                                                    SHA-256:E62BD682384470EE4F0C457BC2504A14ABCA4C12C5558541C1E04C8D468713D1
                                                                    SHA-512:770E75FF16F542BFE8C815EC9673E2DE608F916DCFF9E361B8803AD8B8016508BC40EE7FF7EF538947A582FE4E9237475639F92064892153C0F16C9BDE367AE8
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="224087" V="1" DC="SM" EN="Office.Licensing.ExpirationDialogTiming" ATT="c1a0db0127964674a0d62fde5ab0fe62-6ec4ac45-cebc-4f80-aa83-b6b9d3a86ed7-7719" SP="CriticalBusinessImpact" DCa="PSP PSU" xmlns="">.. <S>.. <UTS T="1" Id="bbxmb" />.. <UTS T="2" Id="bbxmc" />.. <F T="3">.. <O T="AND">.. <L>.. <O T="LE">.. <L>.. <V V="5" T="I32" />.. </L>.. <R>.. <S T="2" F="EventId" />.. </R>.. </O>.. </L>.. <R>.. <O T="LE">.. <L>.. <S T="2" F="EventId" />.. </L>.. <R>.. <V V="22" T="I32" />.. </R>.. </O>.. </R>.. </O>.. </F>.. </S>.. <C T="FT" I="0" O="true" N="ActionTime">.. <S T="3" F="TimeStamp100ns" />.. </C>.. <C T="U32" I="1" O="true" N="DialogAction">.. <S T="3" F="EventId" />.. </C>.. <C T="I32" I="2" O="true" N=
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):442
                                                                    Entropy (8bit):4.387335043604801
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdu4berA+u/qNOCER+X/c//RpONaDjERBNOjsu:2dGr/uyiK5I
                                                                    MD5:531B8F0D4153E8339D1FFE5E35834F6B
                                                                    SHA1:65D8DB20D000A1BE78D850E8E59BE4264CCECFCA
                                                                    SHA-256:AAA0D8F7338DF419C6475B17E34BB403CF43D10CE07DD3FF5FE0AF245D6953FA
                                                                    SHA-512:C713E05F6CD19FFA552F8B15A20F98BF10AE558C5D862279610938E00C23004415F2A8996FD00E1696F7DF09CF102E7D04B9393678F2028DB01B4B07B79BC155
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="224900" V="0" DC="SM" T="Subrule" xmlns="">.. <S>.. <UTS T="1" Id="bbr5m" />.. <F T="2">.. <O T="EQ">.. <L>.. <S T="1" F="DoLicValidationMode" />.. </L>.. <R>.. <V V="0" T="I32" />.. </R>.. </O>.. </F>.. </S>.. <C T="I32" I="0" O="false">.. <S T="2" F="DoLicValidationMode" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):2283
                                                                    Entropy (8bit):4.823043803033768
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dn28R9MMvj8FvlX4nWrZWra87rRKVopwH2ca1Q1qCwJrJdfZSruGNh3rHK0S:cn2A9PjCMWtWv79KVerc2cqCrfPrLS
                                                                    MD5:90469D1824E410C6BEF384B218D9F15E
                                                                    SHA1:904B3DA4AAA4808330B5BBFB67D9AE981225BBB8
                                                                    SHA-256:1C7AE9C9FF9A520669A8EA458978FE14E71A09425038486E168F4707C5858CFD
                                                                    SHA-512:207FF7537FFC93A7824F4D8545B34457E1275AE086BA95FEAEDA1BA6A557A8A2631D1D42B71FBE6360764CBA12BFC18A60F950C551056168189C79CF834D83E3
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="224901" V="11" DC="SM" EN="Office.Licensing.OfficeClientLicensing.DoLicenseValidation" ATT="c1a0db0127964674a0d62fde5ab0fe62-6ec4ac45-cebc-4f80-aa83-b6b9d3a86ed7-7719" SP="CriticalCensus" T="Upload-Medium" DL="A" DCa="PSU" xmlns="">.. <RIS>.. <RI N="Metadata" />.. </RIS>.. <S>.. <R T="1" R="224900" />.. <R T="2" R="224902" />.. <UTS T="3" Id="be7wx" />.. <UTS T="4" Id="be7wy" />.. <SS T="5" G="{a36a970d-45a9-4e0d-9cab-2a235cc9d7c6}" />.. <F T="6">.. <O T="NE">.. <L>.. <S T="2" F="0" M="Ignore" />.. </L>.. <R>.. <V V="{99999999-9999-9999-9999-999999999999}" T="G" />.. </R>.. </O>.. </F>.. <F T="7">.. <O T="NE">.. <L>.. <S T="2" F="1" M="Ignore" />.. </L>.. <R>.. <V V="99999-999-999999" T="W" />.. </R>.. </O>.. </F>.. </S>.. <C T="I32" I="0" O="true" N="FullValidationMode">.. <S T="1" F="0" M="
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):449
                                                                    Entropy (8bit):4.885360338479295
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd11bi0eferrNu87rRKfwSK6dXSGyINOSjsu:2d1XeWrro87rRKsqb
                                                                    MD5:5C9BEFCB331203989683B51BF460F006
                                                                    SHA1:359845C58E57BE3BAE70AC8C4E33AD547A643EA8
                                                                    SHA-256:F6303095F28BF6FAED52F9761F65E4EA60719B599C2453EB39B5C4F431084B38
                                                                    SHA-512:1F164F6D61D1C14D313B355B49C0FED9C344F5E4FAEFF12D9B18E4CC5415B8044665BDB787101442075489CDEF151A15683A2F27CBF30A5729AEF114BCCC1B6C
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="224902" V="2" DC="SM" T="Subrule" xmlns="">.. <S>.. <R T="1" R="120100" />.. <UTS T="2" Id="bbr5q" />.. <SS T="3" G="{a36a970d-45a9-4e0d-9cab-2a235cc9d7c6}" />.. </S>.. <C T="G" I="0" O="falseNoError">.. <S T="3" F="Acid" M="Ignore" />.. </C>.. <C T="W" I="1" O="falseNoError">.. <S T="3" F="MachineKey" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. <S T="2" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):442
                                                                    Entropy (8bit):5.277290268081167
                                                                    Encrypted:false
                                                                    SSDEEP:6:TMVBdwMkB45MqaIajECCORMFpAQ/yWnerhUNlrzVlrqyiMH/XyiwxNOn2sby:TMHdX5Mtlj8HAQqWnerOzUMfbwxNO2su
                                                                    MD5:FF222B05A3237FD966B26CE02A8EFC01
                                                                    SHA1:809CDCC8DA0749BC0375B08AE9D012DF326EDBDF
                                                                    SHA-256:B1ECDB6DCD6441BD85B0C2DB4435304AC68612FCC5DF4FF63646673631A5F6D9
                                                                    SHA-512:AC0E7C1FD7D28E56CD87451B0C602E0C7955C020352FD51DAE8277C535B56AD039B27F6FD66182D10010DD5FBD6F86A515BAC387BFEE089343487D7F23B41C2F
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="224910" V="1" DC="SM" EN="Office.Licensing.ExpirationDialogShown" ATT="c1a0db0127964674a0d62fde5ab0fe62-6ec4ac45-cebc-4f80-aa83-b6b9d3a86ed7-7719" SP="CriticalBusinessImpact" DL="A" DCa="PSP PSU" xmlns="">.. <S>.. <UTS T="1" Id="bbxmb" />.. </S>.. <C T="I32" I="0" O="true" N="LicNotificationState">.. <S T="1" F="LicNotificationState" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1123
                                                                    Entropy (8bit):4.870041544620127
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd94NgZQQUWCgerTcDQiBjEPQ3D0VSmiXl1lVZmwcSj9tpb/rtdVGw/d+xGC7T:2d2fQ1irloKqPiEJbB+co
                                                                    MD5:D5F96FBCBFADFA8C5760146B15A1183A
                                                                    SHA1:41854F958A608A2456BFE7DA791DC530B8F23528
                                                                    SHA-256:33E851543EA41820F4E8808831C968E35724A6859E84C4A81B737D64E3C90177
                                                                    SHA-512:60B5239F86FB414063B1C619B5FBA2B6726A6483C4185EE735424B76B64E04250EDAE7E7C18C32DEAB1CCD98DE8F3CCB02DE29EE446F037215808102C69FA517
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="226000" V="0" DC="SM" EN="Office.Globalization.OLEOGetHculture" ATT="fa2d8726ec914a019f61aa83d1a0f156-ff2e4b12-d084-4558-9515-fbf9e1224e49-7217" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="a52i0" />.. <TI T="2" I="Hourly" />.. <A T="3" E="TelemetryShutdown" />.. <A T="4" E="TelemetrySuspend" />.. <TR T="5" />.. </S>.. <G>.. <S T="1">.. <F N="HResult" />.. <F N="ResultOrigin" />.. <F N="wzTag" />.. <F N="wzAliasTag" />.. </S>.. </G>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="5" F="TimeStamp100ns" />.. </C>.. <C T="I32" I="1" O="false" N="HResult">.. <S T="1" F="HResult" />.. </C>.. <C T="I32" I="2" O="false" N="ResultOrigin">.. <S T="1" F="ResultOrigin" />.. </C>.. <C T="W" I="3" O="true" N="CultureTag">.. <S T="1" F="wzTag" />.. </C>.. <C T="W" I="4" O="true" N="CultureAliasTag">.. <S T="1" F="wzAliasTag" />.. </C>.. <C T="U32" I="5" O="false" N="CultureCoun
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):484
                                                                    Entropy (8bit):5.147263789391309
                                                                    Encrypted:false
                                                                    SSDEEP:6:TMVBdNvEk2c4n0zJDxS9QUQHLuzOHperhVJrzVlrre/OVyndtqsVlrZ/MPNOn2su:TMHdlp40z7QQUWCger5zmTdLV6NO2su
                                                                    MD5:97CC37FCD83D4BF5459AF276EEE99837
                                                                    SHA1:DF01E5EA9EC968D460B67EE0E08F14376669B0C3
                                                                    SHA-256:827E2485D2BFF65C8BDDEAE40915F500D4903C81B810C09CE140FB92D5230C7B
                                                                    SHA-512:E5244EEBB104F0E2F7E98BF8D744D42A3E33BEE81ED7C0A1D538CE1446219ADB77D48853E86E658A1A9779403D6B0DA10D6FF3526A5C6417CD6F3C05B2565E16
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="226003" V="1" DC="SM" EN="Office.Globalization.PluggableUILanguageList" ATT="fa2d8726ec914a019f61aa83d1a0f156-ff2e4b12-d084-4558-9515-fbf9e1224e49-7217" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="a2003" />.. </S>.. <C T="U32" I="0" O="true" N="OrderOfLanguage">.. <S T="1" F="OrderOfLanguage" />.. </C>.. <C T="W" I="1" O="true" N="LanguageTag">.. <S T="1" F="LanguageTag" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):525
                                                                    Entropy (8bit):5.033843064015127
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdfy4hQQUWCger9MgZTNoCydy9yDNO2su:2dEQ1irri9
                                                                    MD5:8870B0E60F540C2A508980F503D6EB80
                                                                    SHA1:96A21ECB789F465EB4598FC1324C2E16A7A52880
                                                                    SHA-256:DE15008469EAE48E13E4FA64E97D6C3F67961DD686A0C9FA799F9BD127929FDC
                                                                    SHA-512:AB4B101D6DAB782DFAB57E7739F12A805A36C5D303D37D0C3B9B52FAA9A222DE7EE54F5E4E5704993F263086EF95931568142AD5EF28E1E74395E6472DBB492B
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="226009" V="0" DC="SM" EN="Office.Globalization.StringResources" ATT="fa2d8726ec914a019f61aa83d1a0f156-ff2e4b12-d084-4558-9515-fbf9e1224e49-7217" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="b56v5" />.. </S>.. <C T="U32" I="0" O="false" N="Alias">.. <S T="1" F="alias" />.. </C>.. <C T="U32" I="1" O="false" N="Ids">.. <S T="1" F="ids" />.. </C>.. <C T="W" I="2" O="true" N="Container">.. <S T="1" F="container" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):577
                                                                    Entropy (8bit):4.841183079259023
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdRaK1VNneryYerTAOerw2erx1/ivXahIfs6fBNOXasu:2dRakNery/rTmrwJrxGf
                                                                    MD5:240DF33199F5A724037519C5908B65A7
                                                                    SHA1:5D062DDFC922C14335850E165D9406E63CBFEFDA
                                                                    SHA-256:356AAA22D2155107BC47EE1245A25ADF3D5680032EC1AA94083A51E807743D0A
                                                                    SHA-512:5FB9C690737F3B205B725D131FA7AD1470CA452FA765C01818B6E129730F6A3882743A6121AB15B2171CB7E27956ADAD8F02CABDF29489953F7D775ADCB43C50
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="230161" V="0" DC="SM" EN="Office.ClickToRun.MsoMigrate" ATT="0da1917aa56040d3a011c3813ca36107-76f080d8-b37f-4635-8054-5c133fcd04c4-6587" S="3" DCa="PSP" xmlns="">.. <S>.. <UTS T="1" Id="c5n43" />.. <UTS T="2" Id="c5n44" />.. <UTS T="3" Id="c5n45" />.. <UTS T="4" Id="c5n46" />.. <US T="5">.. <S T="1" />.. <S T="2" />.. <S T="3" />.. <S T="4" />.. </US>.. </S>.. <C T="TAG" I="0" O="true" N="EventID">.. <S T="5" F="ULS_Tag" M="Ignore" />.. </C>.. <T>.. <S T="5" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):424
                                                                    Entropy (8bit):5.269047223186581
                                                                    Encrypted:false
                                                                    SSDEEP:6:TMVBdbV/lkzv4tXIGgkahzmhdFoIzoIPc1RMFpAQUHperhIRnyNjxPVCEULylNOQ:TMHdlm46GhMo/VzPAQier8olVg6NO2su
                                                                    MD5:AA2FAAA25958AAD66EF9A72760A3D8C3
                                                                    SHA1:24F7C7539AE86878100102DF93864823C25DF057
                                                                    SHA-256:4A27506CA8B0A89BC0F98A6A3DE43602BF59A0D1D795404D853B689A71A720E4
                                                                    SHA-512:D4A6D53C903C05E02E4C72E232E1C7DB79E85D5A9A2499A9087496089282A0D61B218220FE2416D3196EDBA2585E99975B99A975CFF78798855E98F714378B88
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="23070" V="1" DC="SM" EN="Office.Docs.TempFileDownloadDAVFallback" ATT="c274b3e05ac5448dae8fbb7466da6acb-fd6dc8de-18b7-409c-a696-4bd66f7a5322-7902" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bppa1" A="bwt18" />.. </S>.. <C T="FT" I="0" O="false" N="TimeStamp">.. <S T="1" F="TimeStamp100ns" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1213
                                                                    Entropy (8bit):4.96243667727836
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dqFl94dVrzqP3F83dIC0b0+9r+RRv+k+KawS:coWVL3d+AQgvFO
                                                                    MD5:AE1487CA7894AAADF2DF6DAFF7850AF9
                                                                    SHA1:53340784FBD1E68FDEAB00CB17799983DAED76F3
                                                                    SHA-256:47289C409A8226AFCA8335D154B664317C6B3F2C676EF331F925C634D02F4B02
                                                                    SHA-512:B69B10650505174732DA1CB8620321DA1419978165534C8E3AF9439C71B7DA1E3C427476208E001C96AE1A1EBA54BE320782EC949E44344AB9C2738673BF37D4
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="240005" V="8" DC="SM" EN="Office.Security.SrDesktopOpen" ATT="05e0c2fd5fff432bac7a175220223da5-2eec7cb2-952b-4862-9fd4-16ed083da5ec-7364" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="a4sch" />.. </S>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="1" F="TimeStamp100ns" />.. </C>.. <C T="U8" I="1" O="true" N="Reasons">.. <S T="1" F="Reasons" />.. </C>.. <C T="U64" I="2" O="true" N="DocumentPointer">.. <S T="1" F="pioldoc" M="Ignore" />.. </C>.. <C T="W" I="3" O="true" N="InternetFileSafetyDetail">.. <S T="1" F="InternetFileSafetyDetail" M="Ignore" />.. </C>.. <C T="U8" I="4" O="true" N="Policy">.. <S T="1" F="Policy" M="Ignore" />.. </C>.. <C T="I32" I="5" O="true" N="DirtyFileChangesDecision">.. <S T="1" F="DirtyFileChangesDecision" M="Ignore" />.. </C>.. <C T="W" I="6" O="true" N="OriginalInternetFileSafetyDetail">.. <S T="1" F="OriginalInternetFileSafetyDetail" M="Ignore" />.. </C>.. <C T="W
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):474
                                                                    Entropy (8bit):5.159607339821488
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdLHik2Yl2U4dier1lVh16Z/BZdLINO2su:2dL1l94dVr1Ph43ds
                                                                    MD5:FFBDC6EFC40B3477B5A482908C270646
                                                                    SHA1:EA751B67DFC2437736405CF2F85DC1134B2745B0
                                                                    SHA-256:AE043B642A9CBD9AEFFFD45B123ACB6DC2012AC5A2718FC5FE700794C0B5718F
                                                                    SHA-512:C022837F5C460C44AF31C9C5853597298735DB02EA69601B66A30BDF4C26898A3DE59DD13788C939DFFE39067870762206DE4DE86156391792C1797B95FAA990
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="240006" V="2" DC="SM" EN="Office.Security.SrDesktopExit" ATT="05e0c2fd5fff432bac7a175220223da5-2eec7cb2-952b-4862-9fd4-16ed083da5ec-7364" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="a4sci" />.. </S>.. <C T="FT" I="0" O="false" N="UserExit">.. <S T="1" F="TimeStamp100ns" />.. </C>.. <C T="U64" I="1" O="true" N="DocumentPointer">.. <S T="1" F="pioldoc" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1489
                                                                    Entropy (8bit):4.819354673822056
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d2yl94dVr1r0rer5rnalv9mKYX1VtFRn4HcgNthXa+vi:c24WVBAK9LY1mKYlTFvCn9i
                                                                    MD5:F52F3D39A79A610FCE9B4410C928A768
                                                                    SHA1:505F2FD7AEE61566A6381D8B56D4B408364996E5
                                                                    SHA-256:68FE5FCA36080DBEF79D8D00AB5344B90E291DBE7591A9C2019641DBE0605767
                                                                    SHA-512:9E298D8F35A19068ED61FECC97ED993699E1BA0D9FF963B7B1DB28329B2EBF8BE54DFB0ED1DE47095CE51F6F6833B7DAABB152D95698E64CA7D6F63AC401941B
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="240007" V="2" DC="SM" EN="Office.Security.GkDesktop" ATT="05e0c2fd5fff432bac7a175220223da5-2eec7cb2-952b-4862-9fd4-16ed083da5ec-7364" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="a4sca" />.. <UTS T="2" Id="a4sb8" />.. <UTS T="3" Id="a4sb9" />.. <UTS T="4" Id="a4scb" />.. <UTS T="5" Id="a4scc" />.. <US T="6">.. <S T="1" />.. <S T="2" />.. <S T="3" />.. <S T="4" />.. </US>.. </S>.. <C T="TAG" I="0" O="false" N="GkOutcomeTag">.. <S T="6" F="ULS_Tag" />.. </C>.. <C T="U32" I="1" O="true" N="ErrorType">.. <S T="2" F="ErrorType" />.. </C>.. <C T="U32" I="2" O="true" N="Status">.. <S T="2" F="Status" />.. </C>.. <C T="U32" I="3" O="true" N="ContentType">.. <S T="2" F="Content Type" />.. </C>.. <C T="U32" I="4" O="true" N="FileType">.. <S T="2" F="File Type" />.. </C>.. <C T="U32" I="5" O="true" N="ClientData">.. <S T="2" F="Client Data" />.. </C>.. <C T="U32" I="6" O="true" N
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):802
                                                                    Entropy (8bit):4.831014635904131
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdAFEk2Yl2U4dierAfereOerFer9er8erdfCahIffONfSlVZkIu3NOgsu:2dUXl94dVr9rUrwrIrjrdjqPU
                                                                    MD5:F076F619270AE5742F7881FFA396F03B
                                                                    SHA1:7D5BD9147EDF134FDBA28C0D6EB03F928EF857C9
                                                                    SHA-256:21A1E3360449A9A3E3AE39CFF1F2E039DFD8B516C2162C4613AA0D828F16F2F8
                                                                    SHA-512:67E762EA760C570C3C462F68603A25F358E95F35F92A86644449D7C658E1B0A4A49C5AD0E95BB206E88FD44894C3BF589FB8ECA2223E7AE7AA084465CAA01C82
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="240008" V="1" DC="SM" EN="Office.Security.IrmDesktopActions" ATT="05e0c2fd5fff432bac7a175220223da5-2eec7cb2-952b-4862-9fd4-16ed083da5ec-7364" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bb4u1" A="a4sb2" />.. <UTS T="2" Id="bb4u2" A="a4sb3" />.. <UTS T="3" Id="bpcvn" A="a4sb4" />.. <UTS T="4" Id="bpcvm" />.. <UTS T="5" Id="bpcvo" />.. <UTS T="6" Id="bb414" A="a4sb5" />.. <US T="7">.. <S T="1" />.. <S T="2" />.. <S T="3" />.. <S T="4" />.. <S T="5" />.. <S T="6" />.. </US>.. </S>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="7" F="TimeStamp100ns" />.. </C>.. <C T="TAG" I="1" O="false" N="IrmActionTag">.. <S T="7" F="ULS_Tag" />.. </C>.. <T>.. <S T="7" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):500
                                                                    Entropy (8bit):5.150720505795691
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdppaak2Yl2U4dierRNMONlVZ6hfIxNO2su:2dpul94dVrRNMONP6Q3
                                                                    MD5:BCFA2EF01CCA654DDCDAEDFE477E2DAC
                                                                    SHA1:DF1EA66A6E59FCFB7AEC7C664107CF0C782FDD16
                                                                    SHA-256:192F75C7B68DA6AF8F8B39B568A0FAE130D140EF84C7CA0A1C7EAF677A090C60
                                                                    SHA-512:EFEBE24DAC077BF3E219D55665477D6D66F680BE8170002AA8D556FCA20AAB10C8E2F4D716FBF5DAAD8D5B86911B45622CCFE284030FF121C6E363483EF2D4B6
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="240009" V="3" DC="SM" EN="Office.Security.IrmDesktopTemplate" ATT="05e0c2fd5fff432bac7a175220223da5-2eec7cb2-952b-4862-9fd4-16ed083da5ec-7364" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bb4vc" A="a4scg a5t8l bb4vc" />.. </S>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="1" F="TimeStamp100ns" />.. </C>.. <C T="U32" I="1" O="false" N="TemplateType">.. <S T="1" F="Template Type" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):672
                                                                    Entropy (8bit):5.13262305364165
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdNMlUZk2Yl2U4dieriIylVZ6dQTPNOATPNyntOR9cs7AlNO2su:2d2lnl94dVrCP0QTTTf9k
                                                                    MD5:43E546ADA277181893A13A7C2803B222
                                                                    SHA1:A0CDEE00B36B9302D8D6560701C3E263CCA947E8
                                                                    SHA-256:AECA2B62689B926986DA02BECBAEB3C85DF5378D1B9411EBF15AFE4362FB527F
                                                                    SHA-512:3225720EB77AFFB0E4D4B87ACEE708AB82905A154CDA493D9E58C30C5B0BB9E6CF07AA9727DBD1AD61C3933B63C99214DC4FD4A20327152439BB9BE6C134726A
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="240010" V="2" DC="SM" EN="Office.Security.SrDesktopCheck" ATT="05e0c2fd5fff432bac7a175220223da5-2eec7cb2-952b-4862-9fd4-16ed083da5ec-7364" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="a5yzu" A="a529j" />.. </S>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="1" F="TimeStamp100ns" />.. </C>.. <C T="W" I="1" O="false" N="PackageFamilyName">.. <S T="1" F="PackageFamilyName" />.. </C>.. <C T="B" I="2" O="false" N="IsTrustedApp">.. <S T="1" F="FTrustedApp" />.. </C>.. <C T="I32" I="3" O="true" N="AppZoneId">.. <S T="1" F="AppZoneId" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):688
                                                                    Entropy (8bit):5.0595822943463995
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdMyk2Yl2U4dqAQierqqlVZ6neqqOzyntDI2lm5fNTHNO2su:2dMll94dSrqqP0ogt
                                                                    MD5:93122001BF572AF435DEDCD88758E29F
                                                                    SHA1:F4034C61AEB9517AB8885B33BF60058D17A51386
                                                                    SHA-256:41E168DA3238E4982079F9195411A34A8AA69BE1819F1EDCDF86BDA6CD4863A5
                                                                    SHA-512:5048DAD02B775F890AE0251CF7A74E910CDC3D34C9F5EDDF0A93C95E9A23C80CFB63E22CF8C966B904762FE4CE0864329FD1A6F052FFD16E48AE2A2A538C4A70
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="240012" V="1" DC="SM" EN="Office.Security.OTCMacroEncountered" ATT="05e0c2fd5fff432bac7a175220223da5-2eec7cb2-952b-4862-9fd4-16ed083da5ec-7364" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="a7ys8" />.. </S>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="1" F="TimeStamp100ns" />.. </C>.. <C T="B" I="1" O="false" N="FromInternet">.. <S T="1" F="FromInternet" />.. </C>.. <C T="B" I="2" O="false" N="IsTrusted">.. <S T="1" F="IsTrusted" />.. </C>.. <C T="I32" I="3" O="false" N="TrustCenterSetting">.. <S T="1" F="TrustCenterSetting" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):497
                                                                    Entropy (8bit):5.181641897379635
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdOMk2Yl2U4dqAQierXNlVZ6n4ZSfbuxNO2su:2dO/l94dSrdPPSzu3
                                                                    MD5:DD77E7E84416491F7E2FF60F9F36520C
                                                                    SHA1:DF48489D06269D0DB29A3EC4D0BE13E1E0ED37CE
                                                                    SHA-256:1D960451B96DE1A5E5644541D830018AFE75FC81F2DF98D3E162FB6BD757D2A9
                                                                    SHA-512:B7D22E5B1B7CF70A95BD89B999B9B58780E84C05B722965D23CBA485E6DF5EA1E611575FD195EA1C2F0E6BE101BB55378BBED4DDB9DEF48091B214A67FA2FB70
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="240013" V="1" DC="SM" EN="Office.Security.OTCMacroPrompted" ATT="05e0c2fd5fff432bac7a175220223da5-2eec7cb2-952b-4862-9fd4-16ed083da5ec-7364" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="a7ytc" />.. </S>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="1" F="TimeStamp100ns" />.. </C>.. <C T="B" I="1" O="false" N="PromptType">.. <S T="1" F="PromptType" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):500
                                                                    Entropy (8bit):5.174408507922367
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdM9Drk2Yl2U4dqAQierelVZ6neqqOzyNO2su:2dM9Dkl94dSreP0i
                                                                    MD5:1CF6CB2A93CCF4BF2A0283040B58610A
                                                                    SHA1:CDA72CE1CA8C16CB577C38BBC03E66B8FB674D3F
                                                                    SHA-256:438FDE88478203519A2D58AD0C88F18D06858935A823C111E9E58F14E56D319B
                                                                    SHA-512:3A009B1F31875958032B867AAFD2296B6C530F3CAB6A288FF53BE6FEBA3959012703285808C15AE86595C59880548707906E1880656B5E6A11AA32B3FE8A3C8D
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="240014" V="1" DC="SM" EN="Office.Security.OTCMacroEnabled" ATT="05e0c2fd5fff432bac7a175220223da5-2eec7cb2-952b-4862-9fd4-16ed083da5ec-7364" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="a7ys7" />.. </S>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="1" F="TimeStamp100ns" />.. </C>.. <C T="B" I="1" O="false" N="FromInternet">.. <S T="1" F="FromInternet" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):425
                                                                    Entropy (8bit):5.2807690978522235
                                                                    Encrypted:false
                                                                    SSDEEP:6:TMVBdcU2zMkQpmOMgwH4JBPW5d2XI7hn2U4dtRMFpAQUHperh7NjxPVCIJA+/Lyr:TMHdK6Xrk2Yl2U4dqAQierrlVZ6NO2su
                                                                    MD5:12ABBECF4A75D08DE65E2B7952B67BA3
                                                                    SHA1:89E007CA78918C9A368E2FEDCBBFDB0CB8B36AEF
                                                                    SHA-256:5001414DC2F4F7540B3F968A810B0DC222D74CDB4D3BA9E650D2B3B87D4C2A0F
                                                                    SHA-512:AB6205310FC5206D3EA083DBD6E6DDF284A142E38E7181D6F54D6E3CF0682EBD9C496A1A16C30FFEA9ADAD3745014035511ECE6DB3F6B636A21FA14D8BEDEE12
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="240015" V="1" DC="SM" EN="Office.Security.OTCMacroRegistryBlockEnabled" ATT="05e0c2fd5fff432bac7a175220223da5-2eec7cb2-952b-4862-9fd4-16ed083da5ec-7364" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="a7yta" />.. </S>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="1" F="TimeStamp100ns" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):518
                                                                    Entropy (8bit):5.263687858779708
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdLErk2Yl2U4dqAQierP5lVZ6d1x2XtHMNO2su:2dLfl94dSrP5P0X2m
                                                                    MD5:DD68A6A813B8F7C5DDF512ECC1B855EE
                                                                    SHA1:7A303105BBA802198B483408BFE02E3922C52024
                                                                    SHA-256:EF7A8A3526A647498166B47F8AB6808454BA9CAD516EE65A5F241B20D71CA5BB
                                                                    SHA-512:896E9B9F5085DEBF8453FBFDE7F44345BEC05EEE1252332FD8C63B974F2948A5B1A760DE697CEC00E15686361A6FE6417B2886360D39295468650BD841E4E51B
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="240016" V="0" DC="SM" EN="Office.Security.CryptoMissingAlgorithm" ATT="05e0c2fd5fff432bac7a175220223da5-2eec7cb2-952b-4862-9fd4-16ed083da5ec-7364" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="baqjt" />.. </S>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="1" F="TimeStamp100ns" />.. </C>.. <C T="W" I="1" O="false" N="EncryptionAlgorithm">.. <S T="1" F="Crypto Algorithm" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):637
                                                                    Entropy (8bit):5.158077005948144
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdG9V+k2Yl2U4dqAQierJ3NlVZ6Z/BZdLIdy9I0b/Ic0+INO2su:2d6Tl94dSrJ9P83dIZ0b0+g
                                                                    MD5:6E1E89B5C8C5AFE4EEB5ECBB763639AD
                                                                    SHA1:3F63ADB301594F4F6C75A2040AC6086B87BADCF4
                                                                    SHA-256:413D4E21DF9AEAB7FE67400444980DB74544C1DD1EC342C81834AF3C8CD58624
                                                                    SHA-512:2068250EA71D633C5E5E93CA86C8AEAC085E0A61F362C6B08C012833F9E4F3387EFB8AD75CB8C8463473F6992C4424F15F74B84A6D72B646D9B9DCB0B87351B7
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="240018" V="0" DC="SM" EN="Office.Security.InternetFileBypassPV" ATT="05e0c2fd5fff432bac7a175220223da5-2eec7cb2-952b-4862-9fd4-16ed083da5ec-7364" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bcjno" />.. </S>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="1" F="TimeStamp100ns" />.. </C>.. <C T="U64" I="1" O="true" N="DocumentPointer">.. <S T="1" F="pioldoc" M="Ignore" />.. </C>.. <C T="W" I="2" O="true" N="InternetFileSafetyDetail">.. <S T="1" F="InternetFileSafetyDetail" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):607
                                                                    Entropy (8bit):5.117041119471356
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdE4Qk2Yl2U4dqAQierE76JOvkdofwtBsfIiJENO2su:2dEkl94dSrE7gQo
                                                                    MD5:90FAC10ED9B225CEC6F4D4D9F2EF6CDC
                                                                    SHA1:42CEB0CE15A6763421298EF42CA5CFCE09BD8892
                                                                    SHA-256:3A151A1D003D266F11D392ECB7E565A1801F0AB7B7E82D38DA772CB8E7F72B9B
                                                                    SHA-512:D46FA8C386D22C24B51E2DB2C5EBBB4DCEADC002844B7756498CDD1ED85D4EDB7A0C49B0337A704B8E879F251CB3E189F0EBE3012A3C4AA32DC00BC597F496C5
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="240020" V="0" DC="SM" EN="Office.Security.MsoLoadMsipc" ATT="05e0c2fd5fff432bac7a175220223da5-2eec7cb2-952b-4862-9fd4-16ed083da5ec-7364" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bdn4k" />.. </S>.. <C T="W" I="0" O="false" N="ProductId">.. <S T="1" F="ProductId" M="Ignore" />.. </C>.. <C T="W" I="1" O="false" N="ComponentId">.. <S T="1" F="ComponentId" M="Ignore" />.. </C>.. <C T="I32" I="2" O="false" N="InstallState">.. <S T="1" F="InstallState" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):611
                                                                    Entropy (8bit):5.168393642237472
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdFvoo9rk2Yl2U4dqAQierNPsQuUIRLIiUwt2XM9tNO2su:2dFwo9kl94dSrNP/IRSKx
                                                                    MD5:F83740C89920E12621C47DC6A9D1EE2F
                                                                    SHA1:794DAE8A8B8F64A3A3183893A883DD882B8D1249
                                                                    SHA-256:0CB6480C04FD5C911FD78806CEDA7783B4A9F335B695BE7CF2B6CA381D2D9E7C
                                                                    SHA-512:5E4248EAD8D5288AB185124FDE5F8493395951104C2C85ABE51D3B75781FED20699CF6160D4E062FD8809B135BEF4709ECCE34E315496E16E4A1BEE1343B10F6
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="240021" V="1" DC="SM" EN="Office.Security.HyperlinkActivation" ATT="05e0c2fd5fff432bac7a175220223da5-2eec7cb2-952b-4862-9fd4-16ed083da5ec-7364" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bdo4a" />.. </S>.. <C T="W" I="0" O="true" N="UrlScheme">.. <S T="1" F="UrlScheme" M="Ignore" />.. </C>.. <C T="U32" I="1" O="false" N="UrlZone">.. <S T="1" F="UrlZone" M="Ignore" />.. </C>.. <C T="I32" I="2" O="false" N="MapUrlToZoneHr">.. <S T="1" F="MapUrlToZoneHr" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1305
                                                                    Entropy (8bit):4.9621845209574555
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdRalrk2Yl2U4dierlsPB/L8N/IiXnpdl3m9IibfN1Df8NNE35n3YgQ9xJ5NNX:2dTl94dVrwB8Rg7F1IahdSvmb0b
                                                                    MD5:BE3958ED220964F2F66920BA912EA761
                                                                    SHA1:8BA4918FA4EB6CBA4F54B49C2CD1EB94AE280618
                                                                    SHA-256:9929CF91C1F5573263CAC2F79C38F07C0A9F842134328B49E70CABB7B6A3750C
                                                                    SHA-512:04D59B13E26C8C01ADC08C9DB7D24BE8725CEB3D7FD9CFC8EAB78DE0CFD245D65E5042A7E9562A09F74C898F946CCFCA64C02DA3056EBD53381F0002691FE675
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="240025" V="1" DC="SM" EN="Office.Security.DlpDesktopClassificationCount" ATT="05e0c2fd5fff432bac7a175220223da5-2eec7cb2-952b-4862-9fd4-16ed083da5ec-7364" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bgqq0" />.. </S>.. <C T="U32" I="0" O="false" N="CategoriesOnOpen">.. <S T="1" F="CategoriesOnOpen" />.. </C>.. <C T="U32" I="1" O="false" N="InstancesOnOpen">.. <S T="1" F="InstancesOnOpen" />.. </C>.. <C T="U32" I="2" O="false" N="CategoriesOnClose">.. <S T="1" F="CategoriesOnClose" />.. </C>.. <C T="U32" I="3" O="false" N="InstancesOnClose">.. <S T="1" F="InstancesOnClose" />.. </C>.. <C T="U32" I="4" O="false" N="EvaluationRuns">.. <S T="1" F="EvaluationRuns" />.. </C>.. <C T="B" I="5" O="false" N="DidOverride">.. <S T="1" F="DidOverride" />.. </C>.. <C T="U32" I="6" O="false" N="ServerRuleIds">.. <S T="1" F="ServerRuleIds" M="Ignore" />.. </C>.. <C T="U32" I="7" O="false" N="ClientRuleIds">.. <S T=
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):6692
                                                                    Entropy (8bit):4.267690316369607
                                                                    Encrypted:false
                                                                    SSDEEP:96:4WaiJqpeUKwhMHPytYPz9qjixvqFXHanb4nd:43iJ3mzRHanb4nd
                                                                    MD5:7733594F341EE4AAD941DE905705F392
                                                                    SHA1:35DAB53EFD9243B7D641AA676071A21A81C0A185
                                                                    SHA-256:B7919AB25D08A36D7A19AFB711FBDD8D55D09F24C3C5314FBC11099CCAC0B258
                                                                    SHA-512:670679AFD93DA840A5D6B5445BE9CDFF4EA7AE7C87017966355C34E11C6BD9B70D47028EB7E4F6EB374DFACC797ADE01A1545706980EC868359A66E76F8070A7
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="240026" V="0" DC="SM" EN="Office.Security.CryptoFileOpenDetails" ATT="05e0c2fd5fff432bac7a175220223da5-2eec7cb2-952b-4862-9fd4-16ed083da5ec-7364" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="a3v6n" />.. <UTS T="2" Id="bmn4l" />.. <UTS T="3" Id="bggkq" />.. <UTS T="4" Id="bmn4k" />.. <UTS T="5" Id="a23iu" />.. <UTS T="6" Id="blu8c" />.. <UTS T="7" Id="bgi47" />.. <UTS T="8" Id="blu8d" />.. <UTS T="9" Id="a3v6q" />.. <UTS T="10" Id="blr4c" />.. <UTS T="11" Id="bgi3u" />.. <UTS T="12" Id="blr4b" />.. <US T="13">.. <S T="1" />.. <S T="2" />.. <S T="3" />.. <S T="4" />.. <S T="5" />.. <S T="6" />.. <S T="7" />.. <S T="8" />.. <S T="9" />.. <S T="10" />.. <S T="11" />.. <S T="12" />.. </US>.. <UTS T="14" Id="a3v6o" />.. <UTS T="15" Id="bggkr" />.. <UTS T="16" Id="bauqz" />.. <UTS T="17" Id="bgi48" />.. <
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):511
                                                                    Entropy (8bit):5.129653497869513
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd6J0pk2Yl2U4dqAQiersfer1OSNah6O/K0NOcsu:2dEl94dSrsWrfHOi+
                                                                    MD5:9E760D60C003411D626E25DCFE71EF8E
                                                                    SHA1:B4E9D635FEB9F6CFB1A2859C60E70A4478F6F1D5
                                                                    SHA-256:3676FE3A10C8DBD2F49047C964D8BE782F2CAAB9A33F1836672B801FD7E77143
                                                                    SHA-512:93B399C931588D8859F534C27D9785F5711203AE7BB4CE8E83E3F37977BCAEAB7BC1A2273A1A56E9FE4CD5B25AC65237885AC37DA91A5F98B45E45436F8F15EA
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="240029" V="0" DC="SM" EN="Office.Security.TrustCenterMotWBlock" ATT="05e0c2fd5fff432bac7a175220223da5-2eec7cb2-952b-4862-9fd4-16ed083da5ec-7364" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bhfmy" />.. <UTS T="2" Id="bhfmz" />.. <US T="3">.. <S T="1" />.. <S T="2" />.. </US>.. </S>.. <C T="W" I="0" O="false" N="AddinExtension">.. <S T="3" F="AddinExtension" />.. </C>.. <T>.. <S T="3" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):612
                                                                    Entropy (8bit):5.147125217335964
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdn/5k2Yl2U4dqAQierEkRqqOzynSCXPuGXPlMp13Duz3DSNO2su:2dn/Sl94dSrEteBNu+u
                                                                    MD5:24A635509F8CC1599F64692601E074C8
                                                                    SHA1:D4F6EBC1A83555A467E6869BFA99E7A7D0449E8A
                                                                    SHA-256:F4A16FE427D3E8EE1D6FD95653BE5C30E0F1D2DF27A96CE0D785A643443AE0E3
                                                                    SHA-512:4CF752D828C1F38D1E8AD67144B420A0D5B0937549DE1728613EC83436E8935DDDAFE652F921B4F4B00B7C6B0446EC3C0671E25E65EB981E7741417DF96E62D7
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="240030" V="0" DC="SM" EN="Office.Security.TCOcxUFIPrompt" ATT="05e0c2fd5fff432bac7a175220223da5-2eec7cb2-952b-4862-9fd4-16ed083da5ec-7364" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bhi92" />.. </S>.. <C T="B" I="0" O="false" N="FromInternet">.. <S T="1" F="FromInternet" />.. </C>.. <C T="B" I="1" O="false" N="SecureReaderMode">.. <S T="1" F="SecureReaderMode" />.. </C>.. <C T="U32" I="2" O="false" N="OcxTrustCenterSettings">.. <S T="1" F="OcxTrustCenterSettings" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):508
                                                                    Entropy (8bit):5.209510880922825
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdneJEMPCZk2Yl2U4dqAQieru1RqqOzynSCXPuGXPlMNO2su:2dn9Byl94dSrukeBNk
                                                                    MD5:97335EE08DE92CE0DF7F34641B8EE20F
                                                                    SHA1:3859CBB7F3196940F367D861DD86F845A11E0F8C
                                                                    SHA-256:6F8599C5E10EE7526AF60E1B4E6CEF9312C3673B1872E9C4E8C437DF0DC9DAFC
                                                                    SHA-512:F4EF19A472E3635E76F4EDC168505D4BE65A8F54E83150D6398807FCE9A37BDA83E671C749B357D8F0C31674A3A820B5B9CE8C233F2E180B701D09079432DB3C
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="240031" V="0" DC="SM" EN="Office.Security.TCOcxUFIClickThrough" ATT="05e0c2fd5fff432bac7a175220223da5-2eec7cb2-952b-4862-9fd4-16ed083da5ec-7364" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bhi91" />.. </S>.. <C T="B" I="0" O="false" N="FromInternet">.. <S T="1" F="FromInternet" />.. </C>.. <C T="B" I="1" O="false" N="SecureReaderMode">.. <S T="1" F="SecureReaderMode" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):857
                                                                    Entropy (8bit):5.034294155560994
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdnvjJk2Yl2U4dqAQieri/KyneqqOzyntkypFIVyp3vcynHDJCXPuGXPlM23Dz:2dnvjCl94dSriCGWp5p0AOBNH+u
                                                                    MD5:E6F5F1451DE2D2ED09416075C09F173F
                                                                    SHA1:59D2D1172AF4069B0B8173211060C61CB8DD4974
                                                                    SHA-256:DC778837CE7ADDDBC08C42266374347B6D9031919A49FFA4D67FB19AEB7C0115
                                                                    SHA-512:304DCF527BD7C345BCC7B1B675619F6C1ECA470F0C66C30C819D83522096F1CAA6B454B0BF2F1B3E68BC4874C8FA9B6CE0C2CDC871147C947E43D91B6601B8D9
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="240032" V="0" DC="SM" EN="Office.Security.TCOcxTrustedEncounter" ATT="05e0c2fd5fff432bac7a175220223da5-2eec7cb2-952b-4862-9fd4-16ed083da5ec-7364" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bhi94" />.. </S>.. <C T="U64" I="0" O="false" N="DocID">.. <S T="1" F="DocID" />.. </C>.. <C T="B" I="1" O="false" N="FromInternet">.. <S T="1" F="FromInternet" />.. </C>.. <C T="B" I="2" O="false" N="IsEmbeddable">.. <S T="1" F="IsEmbeddable" />.. </C>.. <C T="G" I="3" O="false" N="Clsid">.. <S T="1" F="CLSID" />.. </C>.. <C T="B" I="4" O="false" N="SecureReaderMode">.. <S T="1" F="SecureReaderMode" />.. </C>.. <C T="U32" I="5" O="false" N="OcxTrustCenterSettings">.. <S T="1" F="OcxTrustCenterSettings" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1032
                                                                    Entropy (8bit):4.986787084387682
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dnglPWtCl94dSr2GWp5pwtKaaBNCF1k+u:cUWSWSLWzxMU+u
                                                                    MD5:64131342FC87A55C07D0E109080DC852
                                                                    SHA1:4388DA3815B7F01294DEA017B607C7C76AC3B93E
                                                                    SHA-256:AA2474C085BE7AEE4F0C57DCCF07F91A06AD20E994F0248D405998AC976FF915
                                                                    SHA-512:0DCBCE1A79A50499FA611BB4055AE7CBC161E14F10E0002FC73B20165008B20DDCDD289F26F4DC518E14CA83A8F81C1F40BABF155463BAB6411E21C504024F80
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="240033" V="0" DC="SM" EN="Office.Security.TCOcxNonTrustedEncounter" ATT="05e0c2fd5fff432bac7a175220223da5-2eec7cb2-952b-4862-9fd4-16ed083da5ec-7364" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bhi93" />.. </S>.. <C T="U64" I="0" O="false" N="DocID">.. <S T="1" F="DocID" />.. </C>.. <C T="B" I="1" O="false" N="FromInternet">.. <S T="1" F="FromInternet" />.. </C>.. <C T="B" I="2" O="false" N="IsEmbeddable">.. <S T="1" F="IsEmbeddable" />.. </C>.. <C T="B" I="3" O="false" N="SafeForInit">.. <S T="1" F="SafeForInit" />.. </C>.. <C T="G" I="4" O="false" N="Clsid">.. <S T="1" F="CLSID" />.. </C>.. <C T="B" I="5" O="false" N="SecureReaderMode">.. <S T="1" F="SecureReaderMode" />.. </C>.. <C T="U32" I="6" O="false" N="Permission">.. <S T="1" F="Permission" />.. </C>.. <C T="U32" I="7" O="false" N="OcxTrustCenterSettings">.. <S T="1" F="OcxTrustCenterSettings" />.. </C>.. <T>.
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):394
                                                                    Entropy (8bit):5.240886248173541
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdnSWF0xmak2Yl2U4dierHIHJ9NO2su:2dnm6l94dVrgz
                                                                    MD5:A48C0EB35FCEE2BECA55CA6C5D04A7A8
                                                                    SHA1:EF40F1AECD3E7510264488DFC85E0F6FC5F04B1C
                                                                    SHA-256:43F4646D0A156E86F2F1FBC442039E399CA786F93B92CA369033A06F16BC2927
                                                                    SHA-512:5C6A2C238E49585ADF0D2A906B636D7B4781E2A03AEF19A08F74358240DF720A4A2E1071191505909B8C44183F39125DEBFC90D369C75027211678056314AF48
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="240034" V="0" DC="SM" EN="Office.Security.RestrictedOwnerRightsTemplateUsage" ATT="05e0c2fd5fff432bac7a175220223da5-2eec7cb2-952b-4862-9fd4-16ed083da5ec-7364" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bho7n" />.. </S>.. <C T="I32" I="0" O="false" N="UserResponse">.. <S T="1" F="Result" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):754
                                                                    Entropy (8bit):5.075970820784445
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdnyOQk2Yl2U4dqAQierDGJUICYneqqOzyntFI2fjykNAygd+xU/E4NO2su:2dnbrl94dSrcErIT+OcQ
                                                                    MD5:CEAD67DA0731D54621842D714E758529
                                                                    SHA1:C7DC7F1E4F161F4D438963678779810491D72554
                                                                    SHA-256:29A33FB5694BBAF7E5DF472904198C14101D8CD3AFAE6189D5A709715C820214
                                                                    SHA-512:1D099D7B7C71BDC43166179D24D3A74F8EF295F736BBEE02B20C9A84A9F8B35E0596E59E38904193A73A0CCFC75E39C0DAF0985FF807BEC710519616370DAE3C
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="240038" V="0" DC="SM" EN="Office.Security.TWCPackagerData" ATT="05e0c2fd5fff432bac7a175220223da5-2eec7cb2-952b-4862-9fd4-16ed083da5ec-7364" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bmzuw" />.. </S>.. <C T="B" I="0" O="false" N="IsBlocked">.. <S T="1" F="IsBlocked" />.. </C>.. <C T="B" I="1" O="false" N="FromInternet">.. <S T="1" F="FromInternet" />.. </C>.. <C T="B" I="2" O="false" N="IsTrustedDoc">.. <S T="1" F="IsTrustedDoc" />.. </C>.. <C T="U32" I="3" O="false" N="PackagerSetting">.. <S T="1" F="PackagerSetting" />.. </C>.. <C T="W" I="4" O="true" N="Extension">.. <S T="1" F="Extension" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):665
                                                                    Entropy (8bit):5.100744436625914
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdn2FKkak2Yl2U4dqAQierDFRqqOzynaI2fp+ykNAygdVmbSEmyNO2su:2dnEl94dSrwDMITYvmi
                                                                    MD5:37EC689C64BAB22111C9BB055DEB2B9E
                                                                    SHA1:450B7CBDDE8A3866F8550CE5489AE498C987B325
                                                                    SHA-256:FECB0A4F68A76EE843A852456E1D926E06724125B09DE2589E67F19CE2EBCCB4
                                                                    SHA-512:357A960543F40A03E4E7A67860CC7C6647B8E4C1D08FC746EBB36FA330DE586D53E34A1AB6D093926449F8E4D0353BBF292E2779F72AAA6A71815178782B7D52
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="240039" V="0" DC="SM" EN="Office.Security.TWCPackagerError" ATT="05e0c2fd5fff432bac7a175220223da5-2eec7cb2-952b-4862-9fd4-16ed083da5ec-7364" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bmzuv" />.. </S>.. <C T="B" I="0" O="false" N="FromInternet">.. <S T="1" F="FromInternet" />.. </C>.. <C T="B" I="1" O="false" N="IsTrustedDoc">.. <S T="1" F="IsTrustedDoc" />.. </C>.. <C T="U32" I="2" O="false" N="PackagerSetting">.. <S T="1" F="PackagerSetting" />.. </C>.. <C T="W" I="3" O="true" N="Error">.. <S T="1" F="Error" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1024
                                                                    Entropy (8bit):4.983834335315003
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd51vSnpYoAQ8nerMer+erhSNXahISlVZLacSp9XS/xpMs3f7SVfO9N1xFzbrO:2dHvSrrzrRrpPXnRvD1bzPznCuE
                                                                    MD5:834A80614C3867F58FDB4DFA3D0DD2EA
                                                                    SHA1:742C669272B6391726FF9AA42EFF5C49D1FA2CB7
                                                                    SHA-256:B453B9A3F3A521E2CCF8A60E8E1D553477EE046E9B41DD9F03E8F772BB4C26DB
                                                                    SHA-512:7B09E2CFB4E230F6E34C85C1EB9B62AF6959A799C03CFBDA3E35AFE59FE33518DE6DC685D4203927F5D81B2B119ED7A28AC1F14E9B7CAE7F3DE118EF5730AFDB
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="320001" V="2" DC="SM" EN="Office.Extensibility.ODPActivationForTaga55rq" ATT="db334b301e7b474db5e0f02f07c51a47-a1b5bc36-1bbe-482f-a64a-c2d9cb606706-7439" SP="CriticalBusinessImpact" DCa="DC PSP PSU" xmlns="">.. <S>.. <UTS T="1" Id="a55rq" />.. <UTS T="2" Id="c6io6" />.. <UTS T="3" Id="dfid5" />.. <US T="4">.. <S T="1" />.. <S T="2" />.. <S T="3" />.. </US>.. </S>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="4" F="TimeStamp100ns" />.. </C>.. <C T="U32" I="1" O="true" N="AssetId">.. <S T="4" F="AssetId" />.. </C>.. <C T="U32" I="2" O="true" N="AppInformation">.. <S T="4" F="AppInformation" />.. </C>.. <C T="I32" I="3" O="true" N="ErrorResult">.. <S T="4" F="ErrorResult" />.. </C>.. <C T="U32" I="4" O="true" N="NotificationFlags">.. <S T="4" F="NotificationFlags" />.. </C>.. <C T="W" I="5" O="true" N="AppInstanceId">.. <S T="4" F="AppInstanceId" />.. </C>.. <T>.. <S
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1558
                                                                    Entropy (8bit):4.915226921571471
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd5FvWe6npYunerYferferK/NXahI0zcS+CTpk7t9zldsxOgCkp1x++66IHrnv:2d/vs6rYWrWrKQgqgm1GsChH4vZZWulm
                                                                    MD5:20CE206C4C39A0FAC66DF790B89F6D38
                                                                    SHA1:6BB5433364F561B6B11A4D0CF78DD00F60BC6E30
                                                                    SHA-256:5EB15C22B0EAFF202899E125F6D53128ECC864F2A544F716862C5D4001B6A77B
                                                                    SHA-512:72F8ABF5B6266F001F3DC7C0D09EAF9BB5453026FA635CBC1641E770835F2B24CDA29CB836E7A8C41561BACCB4437942CDE436E01173C9F9626F1E3D1E9FDE4F
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="320002" V="5" DC="SM" EN="Office.Extensibility.ODPActivationForTaga55rs" ATT="db334b301e7b474db5e0f02f07c51a47-a1b5bc36-1bbe-482f-a64a-c2d9cb606706-7439" DCa="DC PSP PSU" xmlns="">.. <S>.. <UTS T="1" Id="a55rs" />.. <UTS T="2" Id="c6ipb" />.. <UTS T="3" Id="dfid7" />.. <US T="4">.. <S T="1" />.. <S T="2" />.. <S T="3" />.. </US>.. </S>.. <C T="U32" I="0" O="true" N="AssetId">.. <S T="4" F="AssetId" />.. </C>.. <C T="I32" I="1" O="true" N="SandboxCreationTime">.. <S T="4" F="SandboxCreationTime" M="Ignore" />.. </C>.. <C T="I32" I="2" O="true" N="PageLoadTime">.. <S T="4" F="PageLoadTime" M="Ignore" />.. </C>.. <C T="I32" I="3" O="true" N="AppStateTime">.. <S T="4" F="AppStateTime" M="Ignore" />.. </C>.. <C T="I32" I="4" O="true" N="AppInstallTime">.. <S T="4" F="AppInstallTime" M="Ignore" />.. </C>.. <C T="I32" I="5" O="true" N="ManifestDownloadTime">.. <S T="4" F="ManifestDownlo
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):810
                                                                    Entropy (8bit):4.956671743952537
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd52+jnpYunerffer3er7NXahISlVZLacSp9yyfpxs3f7SVfO9NOBsu:2dgU6rururQPJvi
                                                                    MD5:C4B59F2333CA9ADC12209F83BE2C8364
                                                                    SHA1:563298D3DBDDF2759DBB9FEF3ACED35882CBBCC8
                                                                    SHA-256:50BF0480B236CEA2B41890A2691DF1164283A75DCE699EB4BBA0E587EB64805B
                                                                    SHA-512:0D4B4F667AE096B16AB66B9ED58417E6D9EAD7CF40B94893A01E455B408620E748154E5370ABD34668EA6764C3642AED1ACC7C8AE9A3BFAE13EDE5B97A0CFBBB
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="320003" V="1" DC="SM" EN="Office.Extensibility.ODPAppManagementMenu" ATT="db334b301e7b474db5e0f02f07c51a47-a1b5bc36-1bbe-482f-a64a-c2d9cb606706-7439" DCa="DC PSP PSU" xmlns="">.. <S>.. <UTS T="1" Id="a55rr" />.. <UTS T="2" Id="c6io7" />.. <UTS T="3" Id="dfid6" />.. <US T="4">.. <S T="1" />.. <S T="2" />.. <S T="3" />.. </US>.. </S>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="4" F="TimeStamp100ns" />.. </C>.. <C T="U32" I="1" O="true" N="AssetId">.. <S T="4" F="AssetId" />.. </C>.. <C T="U32" I="2" O="true" N="OperationMetadata">.. <S T="4" F="OperationMetadata" />.. </C>.. <C T="I32" I="3" O="true" N="ErrorResult">.. <S T="4" F="ErrorResult" />.. </C>.. <T>.. <S T="4" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1633
                                                                    Entropy (8bit):4.801127268927651
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dyErB5uM9vtYRE1uX+NDkQiTAoWfloMUw6NIP3:c5DugthuX+5wifRUw6uP3
                                                                    MD5:7C58177810A5048EE7A9E46AEB00BA32
                                                                    SHA1:B4DAD248437975C516B66C4B516DB5FE9915A7F3
                                                                    SHA-256:D834A4BB538994AA7941256A96782E9C7A84ABACAF23C7C24AA01B40F314B960
                                                                    SHA-512:74B437AA86FA0A0A48F7D18729076D7D52D36DC08A828D83FD39A06AE2BFB7C27F40855D9B50F10D17F680B3565A13E92B492C33C44C484F5FA9A89C2096C57E
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="320004" V="6" DC="SM" EN="Office.Extensibility.ODPLatency" ATT="db334b301e7b474db5e0f02f07c51a47-a1b5bc36-1bbe-482f-a64a-c2d9cb606706-7439" SP="CriticalUsage" DCa="DC PSP PSU" xmlns="">.. <S>.. <UTS T="1" Id="ayc4y" />.. <F T="2">.. <O T="NE">.. <L>.. <S T="1" F="AppId" />.. </L>.. <R>.. <V V="b6d654a6-1a0a-4c6c-b5e8-edab9ddc7875" T="W" />.. </R>.. </O>.. </F>.. </S>.. <C T="U32" I="0" O="true" N="AssetId">.. <S T="1" F="AssetId" />.. </C>.. <C T="U32" I="1" O="true" N="AppInfo">.. <S T="1" F="AppInfo" />.. </C>.. <C T="I32" I="2" O="true" N="Stage1Time">.. <S T="1" F="Stage1Time" />.. </C>.. <C T="I32" I="3" O="true" N="Stage2Time">.. <S T="1" F="Stage2Time" />.. </C>.. <C T="I32" I="4" O="true" N="Stage3Time">.. <S T="1" F="Stage3Time" />.. </C>.. <C T="I32" I="5" O="true" N="Stage4Time">.. <S T="1" F="Stage4Time" />.. </C>.. <C T="I32" I="6
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):871
                                                                    Entropy (8bit):4.941001095293419
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd5uS8InpY0erJxNGAkd0QlXXwK+odNvAPxKfOb9sDp1N9LKMhUzPNO2su:2dw+urJxNGnnXs9+Tzrup
                                                                    MD5:FDB20212A8F04A95AFCE29EBFED57507
                                                                    SHA1:3F16E99EBADA661C5F9A9771255D3A05C69C192B
                                                                    SHA-256:5D6FBB6D67645D92B5856A2B20959AAB6B2BD0B2804497B41633949FB64C0AA7
                                                                    SHA-512:6A9FC5ABF5DEC4B2A8778F232E1121B599635AB443DDF8C7F8475BDDB8F4745AA5F140246142099E47F251242C647F9D963D7BD4384F86367EC2FFCB5F581A64
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="320007" V="3" DC="SM" EN="Office.Extensibility.ODPAppCommands" ATT="db334b301e7b474db5e0f02f07c51a47-a1b5bc36-1bbe-482f-a64a-c2d9cb606706-7439" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bc4pv" A="a7x9h" />.. </S>.. <C T="W" I="0" O="false" N="SolutionId">.. <S T="1" F="SolutionId" />.. </C>.. <C T="W" I="1" O="false" N="RibbonId">.. <S T="1" F="RibbonId" />.. </C>.. <C T="I64" I="2" O="false" N="Groups">.. <S T="1" F="Groups" />.. </C>.. <C T="I64" I="3" O="false" N="Controls">.. <S T="1" F="Controls" />.. </C>.. <C T="I64" I="4" O="false" N="CustomTabs">.. <S T="1" F="CustomTabs" />.. </C>.. <C T="I64" I="5" O="false" N="Menus">.. <S T="1" F="Menus" />.. </C>.. <C T="I64" I="6" O="false" N="Context">.. <S T="1" F="Context" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):532
                                                                    Entropy (8bit):5.248473934644969
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd5V8s5hnpYoAQ/nerJ/GAkOpfP5xNO2su:2djqrJ/G0p353
                                                                    MD5:31011ADD1025FE6A82E707219144A7C9
                                                                    SHA1:71BB48B43243EA38FF66E1B726FC3DAF454E042E
                                                                    SHA-256:8C1C399CED544E47F0F61BA66C2AA4A9A70533ACAAAB4F56AE1AEA8C7B50A66E
                                                                    SHA-512:17B6C40BC002B346B08F99DFF5EF325AE45743AD0115138BD37179EED5248BC819CC0E6BB55C3CF1F713FDB012E7D69264B8BAC292191ABD9C75BE2E6052BCED
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="320009" V="1" DC="SM" EN="Office.Extensibility.ODPAppCommandsRibbonClick" ATT="db334b301e7b474db5e0f02f07c51a47-a1b5bc36-1bbe-482f-a64a-c2d9cb606706-7439" SP="CriticalBusinessImpact" DL="B" DCa="DC PSP PSU" xmlns="">.. <S>.. <UTS T="1" Id="bc4po" />.. </S>.. <C T="W" I="0" O="false" N="SolutionId">.. <S T="1" F="SolutionId" />.. </C>.. <C T="I32" I="1" O="false" N="CommandActionType">.. <S T="1" F="CommandActionType" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):567
                                                                    Entropy (8bit):5.149485476742115
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd5s8anpYoAQ8nerVK7GAkfuwdyTPNO2su:2d8rrg7GvG
                                                                    MD5:DC3DE5CF38ABE78497FD2033E8654DFC
                                                                    SHA1:7A550CD312C595E6C8D344265D6AF41343893A49
                                                                    SHA-256:93985861CC82DB4DEBD9F53688984520D5CBC1E711699D0AD27468494C271CDB
                                                                    SHA-512:A0A3B573A424A6748EFCAD893CD108A353C53BE90621EDB98AE94D375666FB677EA057B60190017EB40396F9FE3E0277B88DEBF2187F8415A725606494A06FA7
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="320016" V="0" DC="SM" EN="Office.Extensibility.ODPAppCommandsCache" ATT="db334b301e7b474db5e0f02f07c51a47-a1b5bc36-1bbe-482f-a64a-c2d9cb606706-7439" SP="CriticalBusinessImpact" DCa="DC PSP PSU" xmlns="">.. <S>.. <UTS T="1" Id="bk9r7" />.. </S>.. <C T="W" I="0" O="false" N="SolutionId">.. <S T="1" F="SolutionId" />.. </C>.. <C T="I64" I="1" O="false" N="Hr">.. <S T="1" F="Hr" />.. </C>.. <C T="W" I="2" O="false" N="Context">.. <S T="1" F="Context" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):526
                                                                    Entropy (8bit):5.258568738062466
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd5gHn5hnpYoAQ8nerVGAkOpfP5xNO2su:2dCDrrVG0p353
                                                                    MD5:F5A50841182A66E9F9E58F0DE749DC7A
                                                                    SHA1:A27A65C6409225DB789DA541571DC33F61D5EA5F
                                                                    SHA-256:1FF65FF05B8A6F336F695114314C36600ED57601E0A04D7204DDCA7EE9AD0EED
                                                                    SHA-512:F312D23C3F28E663C29C660D9D12672849D3871836A8625887792BBFD79AC1C8C09397B0C39369DD421101D3AE4AC4F270E14C2CA9498AAFCC5561A32310BCB5
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="320021" V="0" DC="SM" EN="Office.Extensibility.ODPRibbonBridgeRibbonClick" ATT="db334b301e7b474db5e0f02f07c51a47-a1b5bc36-1bbe-482f-a64a-c2d9cb606706-7439" SP="CriticalBusinessImpact" DCa="DC PSP PSU" xmlns="">.. <S>.. <UTS T="1" Id="bk9r8" />.. </S>.. <C T="W" I="0" O="false" N="SolutionId">.. <S T="1" F="SolutionId" />.. </C>.. <C T="I32" I="1" O="false" N="CommandActionType">.. <S T="1" F="CommandActionType" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):426
                                                                    Entropy (8bit):5.304259006004121
                                                                    Encrypted:false
                                                                    SSDEEP:6:TMVBd5umkJL3B/ED3BH3g0gZiRSjwRwRMFpAQ8nerhbMNkdxYJ1OSj4yNOn2sby:TMHd5uPEdnpYoAQ8neryAGAkNO2su
                                                                    MD5:7560DB9FF06D4817E449C3864F0E78D9
                                                                    SHA1:CDD27E0F285E66E884D84EC4A7359007963F4E85
                                                                    SHA-256:BCE7D611AF817B982F14C330666DFAD379AD1CD6BFABF74F8D646A98F55D588B
                                                                    SHA-512:37992956948CC0A79102C82561FB2EBF4E64D8639CD691B6414FDCEBAAF2D1B73B0787172391B49C285AA6BEB59D6B8F012AC9C607A08A6408E5944E35B0A64E
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="320022" V="0" DC="SM" EN="Office.Extensibility.ODPRecommendedGalleryClick" ATT="db334b301e7b474db5e0f02f07c51a47-a1b5bc36-1bbe-482f-a64a-c2d9cb606706-7439" SP="CriticalBusinessImpact" DCa="DC PSP PSU" xmlns="">.. <S>.. <UTS T="1" Id="boktx" />.. </S>.. <C T="W" I="0" O="false" N="SolutionId">.. <S T="1" F="SolutionId" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):783
                                                                    Entropy (8bit):5.090994225069874
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd5lIVnpYoAQ8nerwi9dPAstOHO8Hyfa/S+p1Dr7SRO9NO2su:2dUVrrwc412a641f7gOz
                                                                    MD5:262ABB73CD87C2FDBA63244912C052F9
                                                                    SHA1:F763B9D1F77A2282784D6D0AE894ECF239528D81
                                                                    SHA-256:BBC6F47A32D8F295045828C08FEECA98A398DCD3148E9DE253838671E532ED81
                                                                    SHA-512:E74BCA06D5F03A7058121AA4B0DB7EF4121D2AA131DF000789227DF4F5B5736E00D817E3A621F7014B28DA7EA029EAF0171C546B63D8DC3391BF0578F4557C66
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="320029" V="0" DC="SM" EN="Office.Extensibility.ODPSsoConsentDialog" ATT="db334b301e7b474db5e0f02f07c51a47-a1b5bc36-1bbe-482f-a64a-c2d9cb606706-7439" SP="CriticalBusinessImpact" DCa="DC PSP PSU" xmlns="">.. <S>.. <UTS T="1" Id="bz504" />.. </S>.. <C T="W" I="0" O="false" N="CorrelationId">.. <S T="1" F="CorrelationId" />.. </C>.. <C T="W" I="1" O="false" N="AssetId">.. <S T="1" F="AssetId" />.. </C>.. <C T="I32" I="2" O="false" N="DialogCode">.. <S T="1" F="DialogCode" />.. </C>.. <C T="I32" I="3" O="false" N="LaunchingReason">.. <S T="1" F="LaunchingReason" />.. </C>.. <C T="I32" I="4" O="false" N="SSOConsentResult">.. <S T="1" F="SSOConsentResult" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):691
                                                                    Entropy (8bit):5.1809592445794275
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd5d8FnpY9s18nerlUf7SE3fO9dLIAkdy9y1AuHnF1uM1SNO2su:2dQFWs13rqL2fcnjfo
                                                                    MD5:EB99445E6A161551CCB659331552F5D9
                                                                    SHA1:F5550984A01167FBAC0F7FBCB428595CAA3222E4
                                                                    SHA-256:6911DD6727985AEF88A0431851BF669CCF362DEF18635AB056481B5879E96C84
                                                                    SHA-512:D987332F767CEAFD747C95A7FECF21DBBE9822A6947D473ED6887DCE5EB6E954994F92A30DB94768BC986D7A27C7677ED4A3447CAFFF6F5EAC17789BD5AED473
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="320032" V="0" DC="SM" EN="Office.Extensibility.DeepLinkingDocumentShowTrustUI" ATT="db334b301e7b474db5e0f02f07c51a47-a1b5bc36-1bbe-482f-a64a-c2d9cb606706-7439" SP="CriticalExperimentation" DCa="DC PSP PSU" xmlns="">.. <S>.. <UTS T="1" Id="b2d31" />.. </S>.. <C T="I32" I="0" O="false" N="ErrorResult">.. <S T="1" F="ErrorResult" />.. </C>.. <C T="W" I="1" O="true" N="SolutionId">.. <S T="1" F="SolutionId" />.. </C>.. <C T="W" I="2" O="true" N="AppInstanceId">.. <S T="1" F="AppInstanceId" />.. </C>.. <C T="B" I="3" O="false" N="ShowDialog">.. <S T="1" F="ShowDialog" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):778
                                                                    Entropy (8bit):5.085567761626465
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd5OBnpY9s18nerrSso9dLIAkdy9y1AuH/HO8HynHDtI+NO2su:2dQBWs13rrSncnjfv1AZ
                                                                    MD5:9FCF47F309E430EAB02C368F2121A2D4
                                                                    SHA1:5F4A52512B2E69A57ED458340015D4FF560EF837
                                                                    SHA-256:D2F6F133E5BA591502ACDC75EA73EDE754819D9C9DAA73C2719E77C588B4980B
                                                                    SHA-512:AFB4F40A30AAACD8C181E71F4A3435AA60A3F871AEA913E7E4816F00E79803F914F8961BF1AB44D85DDEAB31B8CFFAB541FE6BD9E202158A757FE0D6A3BBC801
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="320033" V="0" DC="SM" EN="Office.Extensibility.DeepLinkingTrustResult" ATT="db334b301e7b474db5e0f02f07c51a47-a1b5bc36-1bbe-482f-a64a-c2d9cb606706-7439" SP="CriticalExperimentation" DCa="DC PSP PSU" xmlns="">.. <S>.. <UTS T="1" Id="b072l" />.. </S>.. <C T="W" I="0" O="true" N="CorrelationId">.. <S T="1" F="CorrelationId" />.. </C>.. <C T="W" I="1" O="true" N="SolutionId">.. <S T="1" F="SolutionId" />.. </C>.. <C T="W" I="2" O="true" N="AppInstanceId">.. <S T="1" F="AppInstanceId" />.. </C>.. <C T="I32" I="3" O="false" N="DialogCode">.. <S T="1" F="DialogCode" />.. </C>.. <C T="B" I="4" O="false" N="IsAddinTrusted">.. <S T="1" F="IsAddinTrusted" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):589
                                                                    Entropy (8bit):4.876370023266758
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd53bSnpY1nerRer9fSNah03f/HaSMGHhSMNOcsu:2dczr8r9qvf1
                                                                    MD5:DB5CB921C16EF56CD7AB5493BE47CF81
                                                                    SHA1:3C3268C8435FC6B217AADDF39BFB0CF949A42565
                                                                    SHA-256:EE46C02058A8EDB1273FA394B7D18BF95430C510F9477206DB1C44C18B5F6AB4
                                                                    SHA-512:50BE09B346D24F529AE2F1CA1787AA20478CC4934EA750E9E2079C3B964ADF94FFAC3D080E5C5402AADF16BD1C3C82AEA3C89D00125334FD0207606D157EEFD6
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="320034" V="0" DC="SM" EN="Office.Extensibility.StoreUserStatus" ATT="db334b301e7b474db5e0f02f07c51a47-a1b5bc36-1bbe-482f-a64a-c2d9cb606706-7439" S="1" DCa="DC PSP PSU" xmlns="">.. <S>.. <UTS T="1" Id="bvti6" />.. <UTS T="2" Id="bvti7" />.. <US T="3">.. <S T="1" />.. <S T="2" />.. </US>.. </S>.. <C T="U32" I="0" O="false" N="StoreOpen">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="StoreBlocked">.. <C>.. <S T="2" />.. </C>.. </C>.. <T>.. <S T="3" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1079
                                                                    Entropy (8bit):4.782006038078938
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd5PFs0npY1ner8NerzOerMer4erSfzahIffO0iHaSMfACWjHhSMpJN7SHISMg:2dnNzr8Yrzhrzrfr8AbN7657M1Z1P0NJ
                                                                    MD5:C3EF5EA8B7BD495AFADFB0EE100FE76E
                                                                    SHA1:C1BFB1D4D43CB934BF9B32AF6B32E49BAE4E233E
                                                                    SHA-256:E793D30C810061A61FA99E45C6B186CE9765881B7763D8D5C56ADC889775A098
                                                                    SHA-512:1FB1D99D27473A1C1944D5C2B88E27838B5254E27038D855249C04A7055677DC08C69BEDC3EA96BC3CFF8985457BC800ADADB18191C62430862BE54886AB1846
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="320035" V="0" DC="SM" EN="Office.Extensibility.StoreUserStatusError" ATT="db334b301e7b474db5e0f02f07c51a47-a1b5bc36-1bbe-482f-a64a-c2d9cb606706-7439" S="1" DCa="DC PSP PSU" xmlns="">.. <S>.. <UTS T="1" Id="bvti5" />.. <UTS T="2" Id="bvti8" />.. <UTS T="3" Id="bvti9" />.. <UTS T="4" Id="bvtja" />.. <UTS T="5" Id="bvtjb" />.. <US T="6">.. <S T="1" />.. <S T="2" />.. <S T="3" />.. <S T="4" />.. <S T="5" />.. </US>.. </S>.. <C T="U32" I="0" O="false" N="ErrorMakingRequest">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="1" O="false" N="RequestAlreadyInProgress">.. <C>.. <S T="2" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="StatusExistsInMemoryCache">.. <C>.. <S T="3" />.. </C>.. </C>.. <C T="U32" I="3" O="false" N="StatusExistsInRegistryCache">.. <C>.. <S T="4" />.. </C>.. </C>.. <C T="U32" I="4" O="false" N="GetCurrentUserError">.. <
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):666
                                                                    Entropy (8bit):4.984519219711497
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd5AlPnpYxnerbOSermSNah6ued+MTtigDNNOgD5NOcsu:2dKBNrbOFrxHmyQI
                                                                    MD5:2E5E7D02F4D8C8BAF56ED2D53A1F66EC
                                                                    SHA1:A4074058CBFE5CB11F5DB62FA277CB4AE7EED0AC
                                                                    SHA-256:F4478FC721DED66AB01BB26F418643D2DABD1DE0E6ED307897565037126DF60F
                                                                    SHA-512:474448A6935EA6FFBCEF71F1779F4EB2C5B604F2D40D877A4303AE966FE2FF986A11D60E8B89839F470DE7787A2712EDC209962ECC5C4CEAE2F21DC641900AE0
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="322001" V="0" DC="SM" EN="Office.Extensibility.COMAddinCount" ATT="db334b301e7b474db5e0f02f07c51a47-a1b5bc36-1bbe-482f-a64a-c2d9cb606706-7439" S="10" DCa="DC PSP PSU" xmlns="">.. <S>.. <UTS T="1" Id="aw54n" />.. <UTS T="2" Id="aymsa" />.. <US T="3">.. <S T="1" />.. <S T="2" />.. </US>.. </S>.. <C T="W" I="0" O="false" N="TagId">.. <S T="3" F="ULS_TagId" />.. </C>.. <C T="I32" I="1" O="true" N="ScopeId">.. <S T="3" F="ScopeId" />.. </C>.. <C T="I32" I="2" O="false" N="TotalInstalledAddins">.. <S T="3" F="TotalInstalledAddins" />.. </C>.. <T>.. <S T="3" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1358
                                                                    Entropy (8bit):4.90876199662902
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dBv7nDr4kV4Z79m+Un1heA+U+e5w1DYWn:cxnEjUEYWn
                                                                    MD5:BA2EF567B40F841F19823EAC65DF0154
                                                                    SHA1:8EEC3B07C10A11CBC0C323B0DD734371A17DD87D
                                                                    SHA-256:F2A494C577362D0DC5E9AD1EAEA54D932D2DCD8E8C32DA72D4C17D9147D77E26
                                                                    SHA-512:21A9CCE205C2A8EC9D79AEA5F148220E46D8A81E4C7C8D086E8E3A4BD5C9D0B3183892525A08F4F59F40EB57F2F9C96BC511CD5FD602715077B40A78F6B54F90
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="322006" V="5" DC="SM" EN="Office.Extensibility.COMAddinUnhandledException" ATT="db334b301e7b474db5e0f02f07c51a47-a1b5bc36-1bbe-482f-a64a-c2d9cb606706-7439" SP="CriticalUsage" DL="B" DCa="DC PSP PSU" xmlns="">.. <S>.. <UTS T="1" Id="bumpa" />.. </S>.. <C T="I32" I="0" O="true" N="ScopeId">.. <S T="1" F="ScopeId" M="Ignore" />.. </C>.. <C T="W" I="1" O="true" N="Method">.. <S T="1" F="Method" />.. </C>.. <C T="W" I="2" O="true" N="Interface">.. <S T="1" F="Interface" />.. </C>.. <C T="G" I="3" O="true" N="AddinId">.. <S T="1" F="AddinId" />.. </C>.. <C T="W" I="4" O="true" N="AddinProgId">.. <V V="" T="W" />.. </C>.. <C T="W" I="5" O="true" N="AddinFriendlyName">.. <V V="" T="W" />.. </C>.. <C T="W" I="6" O="true" N="AddinTimeDateStamp">.. <S T="1" F="AddinTimeDateStamp" M="Ignore" />.. </C>.. <C T="W" I="7" O="true" N="AddinVersion">.. <V V="" T="W" />.. </C>.. <C T="W" I="8" O="true" N="AddinFi
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1023
                                                                    Entropy (8bit):5.08414497026305
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd5di4snpYoAQjer1uUddlndytzs8nUUhMnHDd32UAA2YnmZcAwwnVd4AdNO2z:2dzi4ser1f/zWgSh+ADpL
                                                                    MD5:1B6C7ADD75A0826DE7EDD2038C037403
                                                                    SHA1:EE7A845AD41CF49A51E78E89D024C481F5F08E59
                                                                    SHA-256:A38D6B6B07E95851F680F56F8358B14ABB8E28DB44331A5771721205EF5A633F
                                                                    SHA-512:7EEF739343040EA40C9EAD5809ABACED2DD515CD536B84F02D374F2E5FC746ECE5ACA7317C3F0F234EBA01A528CE20AFEF4AA34F28C58A92B4B3DBC1A746977E
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="324013" V="0" DC="SM" EN="Office.Extensibility.VbaRefSecurityTelemetry" ATT="db334b301e7b474db5e0f02f07c51a47-a1b5bc36-1bbe-482f-a64a-c2d9cb606706-7439" SP="CriticalBusinessImpact" DL="B" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9uayh" />.. </S>.. <C T="W" I="0" O="false" N="TagId">.. <S T="1" F="ULS_TagId" />.. </C>.. <C T="W" I="1" O="false" N="ReferenceZone">.. <S T="1" F="ReferenceZone" />.. </C>.. <C T="W" I="2" O="false" N="SafeStatus">.. <S T="1" F="SafeStatus" />.. </C>.. <C T="B" I="3" O="false" N="UseLeafRefName">.. <S T="1" F="UseLeafRefName" />.. </C>.. <C T="B" I="4" O="false" N="AllowReferenceLoaded">.. <S T="1" F="AllowReferenceLoaded" />.. </C>.. <C T="B" I="5" O="false" N="AllowIntranetReferencesPolicy">.. <S T="1" F="AllowIntranetReferencesPolicy" />.. </C>.. <C T="B" I="6" O="false" N="AllowMotwReferencesPolicy">.. <S T="1" F="AllowMotwReferencesPolicy" />.. </C>.. <T>.. <S T
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):715
                                                                    Entropy (8bit):5.186374014667383
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd5l1OfhnpYoAQjersuUddAzy+e/wzy+ynteUImGYndKUveNO2su:2dv0fhersf/A2+eY2+DcGuG
                                                                    MD5:68DA5AF9012BFA2A79EF5F7A3005D162
                                                                    SHA1:197D87F64F6F33E233A2A39E321EF8CD0B132AF7
                                                                    SHA-256:FEB6C1014EC5BF37FBED1C2F62470B15E97FE5428FA52BEB1BFFB9FADBD98542
                                                                    SHA-512:BDCB02C12E4F236EC507E497B178020F09C3DBAD59FDBE4DB6FDB26264AE941B081BC4AFD3DFE359D505611736EC369D4C16C662406F6E2A8F831B871A6EE83A
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="324014" V="0" DC="SM" EN="Office.Extensibility.MacroDigSigSaveHighestVersion" ATT="db334b301e7b474db5e0f02f07c51a47-a1b5bc36-1bbe-482f-a64a-c2d9cb606706-7439" SP="CriticalBusinessImpact" DL="B" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9j4qm" />.. </S>.. <C T="W" I="0" O="false" N="TagId">.. <S T="1" F="ULS_TagId" />.. </C>.. <C T="W" I="1" O="false" N="DigSigVersion">.. <S T="1" F="DigSigVersion" />.. </C>.. <C T="B" I="2" O="false" N="IsDigSigCreated">.. <S T="1" F="IsDigSigCreated" />.. </C>.. <C T="B" I="3" O="false" N="UnderFGEnabledVbaV3Sig">.. <S T="1" F="UnderFGEnabledVbaV3Sig" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):850
                                                                    Entropy (8bit):5.191796263875905
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd5V4xyfsuhnpYoAQjer6uUddAzy+e/wzy+yntdrrqX7rrenurnO5jrnynHDhP:2d3tfsuher6f/A2+eY2+mqTFEnAFpQ8
                                                                    MD5:B56B9D5A48835CDF2DE43E018B06B683
                                                                    SHA1:8EB45E99D1794A664D1C0F8DEBFD6EABFAB4EE99
                                                                    SHA-256:667388E62AFD932E44282543EC5314427894C8042B1A378DB42B58022268A91E
                                                                    SHA-512:88C8EB9F2A816680F60B9B7479C24380E60CA7236AFCB929F31785DF23813EA86E0120D3E83526CD74F15B7D859AA682A1F40D1CBEB31159BC8E5870D835B347
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="324015" V="0" DC="SM" EN="Office.Extensibility.MacroDigSigVerifyVersion" ATT="db334b301e7b474db5e0f02f07c51a47-a1b5bc36-1bbe-482f-a64a-c2d9cb606706-7439" SP="CriticalBusinessImpact" DL="B" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="9j4qk" />.. </S>.. <C T="W" I="0" O="false" N="TagId">.. <S T="1" F="ULS_TagId" />.. </C>.. <C T="W" I="1" O="false" N="DigSigVersion">.. <S T="1" F="DigSigVersion" />.. </C>.. <C T="B" I="2" O="false" N="VerifiedAsValidSignature">.. <S T="1" F="VerifiedAsValidSignature" />.. </C>.. <C T="B" I="3" O="false" N="OnlyTrustVBASignatureV3">.. <S T="1" F="OnlyTrustVBASignatureV3" />.. </C>.. <C T="B" I="4" O="false" N="UnderFGEnabledVerifyVbaV3Sig">.. <S T="1" F="UnderFGEnabledVerifyVbaV3Sig" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):529
                                                                    Entropy (8bit):5.2598361101997035
                                                                    Encrypted:false
                                                                    SSDEEP:6:TMVBd5UAlkYL0OCHsC4Bf7tSPshsSs0FUHpnGpCdx2cUSwnnqxy0UW5yNOn2sby:TMHd51NCk7gkVigA5UdyUkyNO2su
                                                                    MD5:1600A71BD70E14301AB7A9EE2CEC1F20
                                                                    SHA1:D7FAB688A1C504AEF53AB6AE8FD88A5B1C45BEE2
                                                                    SHA-256:F90920017C41A02E28F38ACA67FC0E0A6F88812411E62EFB90945959D26834C6
                                                                    SHA-512:E2E6D4B1A1DE326CB785C2D1D636A3CEF7693A53025509317E43C04ECC1B3ED7EF1361BD31AE99FF9E5E5DBFF4C848BB42FAAFAED920E4801B54C641826C8B42
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="370000" V="1" DC="SM" EN="Office.TargetedMessaging.TmsWarningCategoryPassthrough" ATT="2f0a1931898144668b4994b491868b75-cc9fb197-8766-4b63-8e07-1887d3d330ac-7107" DCa="PSU" xmlns="">.. <S>.. <UCSS T="1" C="TargetedMessagingService" S="Monitorable" />.. </S>.. <C T="W" I="0" O="false" N="ULS_TagId">.. <S T="1" F="ULS_TagId" />.. </C>.. <C T="G" I="1" O="false" N="ULS_CorrelationID">.. <S T="1" F="ULS_CorrelationID" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):2270
                                                                    Entropy (8bit):4.715233540446112
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dXcMkbrMrnrBrVhrZrLrx+pJt396fHk1xY/S7D8J1Ux54AN/RidGXH7E8/Nytt7:cXKbwj1DlXcpJJwL2LUdGrtu7
                                                                    MD5:6A71752B53BED541A5AD6CA10FF13B16
                                                                    SHA1:A8FF44ED3F41A96C7391985C45D8B06E96FE1784
                                                                    SHA-256:071A5F17C0031096ECC814CF5D355FCB8FEB32EA797DFC4B50FECD5BCCCE3F69
                                                                    SHA-512:F026E8C9F9EFB878014773A2C98E6FF4319F0EDAACE3EF0FC2DC30C5A8F943F96688DAF15531AF243FA3FD0CDFA92EFFBE841E7526268F5C9559C16FDC2DC674
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="370001" V="2" DC="SM" EN="Office.TargetedMessaging.TmsGetMessageWebCall" ATT="2f0a1931898144668b4994b491868b75-cc9fb197-8766-4b63-8e07-1887d3d330ac-7107" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="a70w0" />.. <UTS T="2" Id="a70xq" />.. <UTS T="3" Id="a70w1" />.. <UTS T="4" Id="a70w2" />.. <UTS T="5" Id="a70w3" />.. <UTS T="6" Id="a70yv" />.. <UTS T="7" Id="a70x9" />.. <TI T="8" I="30s" />.. <A T="9" E="TelemetrySuspend" />.. <A T="10" E="TelemetryShutdown" />.. </S>.. <G>.. <S T="1">.. <F N="Thread ID" />.. </S>.. <S T="2">.. <F N="Thread ID" />.. </S>.. <S T="3">.. <F N="Thread ID" />.. </S>.. <S T="4">.. <F N="Thread ID" />.. </S>.. <S T="5">.. <F N="Thread ID" />.. </S>.. <S T="6">.. <F N="Thread ID" />.. </S>.. <S T="7">.. <F N="Thread ID" />.. </S>.. </G>.. <C T="W" I="0" O="false" N="Source">.. <S T="1" F="Source" />..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):5775
                                                                    Entropy (8bit):4.069718902007382
                                                                    Encrypted:false
                                                                    SSDEEP:96:SSY1Q4Qr3QbQrrVQ2QrnQJQrY1QHQKVsbkddl47:udM6OHsUn1Yrsbki7
                                                                    MD5:3067F25E37A6C69AA28B2D32344E20E9
                                                                    SHA1:C8124BD5E0106D66C789F68FB988A69C6501A7F3
                                                                    SHA-256:A187BF75D127D56697E2D25ACDAB300F3DA30B686B4B45AABF0139520E14C8C0
                                                                    SHA-512:A0BE7E3E83C744BD953D55ECDA6010F16CD9F60006C0B26D6D3AD177F695A610DAC6D5A2CB8DE82C61BB683857B1E147D281F416C8D2FA7D2D02347E941FC007
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="370002" V="2" DC="SM" EN="Office.TargetedMessaging.TmsBusBarInteraction" ATT="2f0a1931898144668b4994b491868b75-cc9fb197-8766-4b63-8e07-1887d3d330ac-7107" S="1" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="a70xu" />.. <UTS T="2" Id="a70y2" />.. <UTS T="3" Id="a8smq" />.. <UTS T="4" Id="a8smr" />.. <UTS T="5" Id="a8sms" />.. <UTS T="6" Id="a4673" />.. <UTS T="7" Id="a468a" />.. <UTS T="8" Id="a5ri9" />.. <UTS T="9" Id="a5ri8" />.. <UTS T="10" Id="a4679" />.. <UTS T="11" Id="a70w5" />.. <A T="12" E="TelemetrySuspend" />.. <A T="13" E="TelemetryShutdown" />.. <F T="14">.. <O T="EQ">.. <L>.. <S T="1" F="MessageKey: Source" />.. </L>.. <R>.. <V V="BizBar" T="W" />.. </R>.. </O>.. </F>.. <F T="15">.. <O T="AND">.. <L>.. <O T="GE">.. <L>.. <S T="6" F="PartType" />.. </L>.. <R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1120
                                                                    Entropy (8bit):4.86938725236406
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dyaMkbrkrMxYrtnTZZlHgN0oEKPkl7cF7:cysbYwxYBnTRgZTMqF7
                                                                    MD5:B3378EB31B57659DAFD13EBFC878DAAF
                                                                    SHA1:2E6F1C6CE274C233853672D061E40A9A572A1689
                                                                    SHA-256:32A09C10658D25D232C5AD2964DAE98718A7D9D7A9B1D855DCB855108A3084D1
                                                                    SHA-512:DEE6C8B4CBF9B8D7B2E5FBB20327E3D4E2268FE7F8A40544B2E0F5C4AEE4B0834769D8BAE94169D9CD9953B917B93B05EDC320BDF866B0C5B5EF77956327738B
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="370005" V="1" DC="SM" EN="Office.TargetedMessaging.TmsOutSpaceIteration" ATT="2f0a1931898144668b4994b491868b75-cc9fb197-8766-4b63-8e07-1887d3d330ac-7107" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="a70xu" />.. <UTS T="2" Id="babnb" />.. <UTS T="3" Id="babna" />.. <F T="4">.. <O T="EQ">.. <L>.. <S T="1" F="MessageKey: Source" />.. </L>.. <R>.. <V V="OutSpace" T="W" />.. </R>.. </O>.. </F>.. <A T="5" E="TelemetrySuspend" />.. <A T="6" E="TelemetryShutdown" />.. </S>.. <C T="I32" I="0" O="true" N="MessageId">.. <S T="4" F="MessageHeader: MessageId" M="Ignore" />.. </C>.. <C T="W" I="1" O="true" N="TransactionId">.. <S T="4" F="MessageHeader: TransactionId" M="Ignore" />.. </C>.. <C T="U32" I="2" O="false" N="OutSpaceMessageShowCount">.. <C>.. <S T="2" />.. </C>.. </C>.. <C T="U32" I="3" O="false" N="OutSpaceButtonClickCount">.. <C>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):786
                                                                    Entropy (8bit):4.983569627399716
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd5+A4Cwa7gkVierPb/erM4ert5BjEa/s8CnXXHaSMpqyXHISMNO3XGHNUlu:2dcNaMkbrPSrMfrtDF/2dya7
                                                                    MD5:D59BE6A15F4F52FFB398D8234259A54B
                                                                    SHA1:E1079B645E25C7F50D0A63EB041F0D37C1B7766C
                                                                    SHA-256:302C85D5F8568637AC2466274D58526155DE96F124A8B9255124FE210C02FB09
                                                                    SHA-512:ECCF2F41182C00A815B4D374A32E0021684913D64F76ED6D846B398E717802AE17CFC5345E029A4053AE1DBA36D3BB89D15185F8D91EBFC3394E73C8E6A8E70C
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="370006" V="0" DC="SM" EN="Office.TargetedMessaging.AutoRenewIteration" ATT="2f0a1931898144668b4994b491868b75-cc9fb197-8766-4b63-8e07-1887d3d330ac-7107" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="ban9c" />.. <UTS T="2" Id="ban9h" />.. <UTS T="3" Id="ban9a" />.. <A T="4" E="TelemetrySuspend" />.. <A T="5" E="TelemetryShutdown" />.. </S>.. <C T="W" I="0" O="true" N="HardwareId">.. <S T="2" F="HardwareId" M="Ignore" />.. </C>.. <C T="U32" I="1" O="false" N="AutoRenewShowCount">.. <C>.. <S T="1" />.. </C>.. </C>.. <C T="U32" I="2" O="false" N="AutoRenewClickCount">.. <C>.. <S T="3" />.. </C>.. </C>.. <T>.. <S T="4" />.. <S T="5" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):3344
                                                                    Entropy (8bit):4.7725483241132505
                                                                    Encrypted:false
                                                                    SSDEEP:48:cFcEKUGge6phZjFjeYr3LnzXmLJf5Mo6ws3gDnsUFXYyV50g7XkW3487:OctMoFdHxp7
                                                                    MD5:3CB447145158C2A33617B04F567D4B47
                                                                    SHA1:98DD266850A1AA5A372830B727BA95269D078092
                                                                    SHA-256:411FE601F852DED1A67AF9A9363DD03C1CEC74F5C07585D4049A47A3499EA4C5
                                                                    SHA-512:202EFCFED6B0559BB1E135EA18D503D051B7154FF42D06ED43E41ECE7A923D582401ABE651EF7E0EC215F8B784B690B48CFECE505422695C3EFB69DE784C233F
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="370007" V="3" DC="SM" EN="Office.TargetedMessaging.EnsureCached" ATT="2f0a1931898144668b4994b491868b75-cc9fb197-8766-4b63-8e07-1887d3d330ac-7107" SP="CriticalExperimentation" DL="B" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bjxcp" />.. <UTS T="2" Id="bjp68" />.. <UTS T="3" Id="bjp69" />.. <UTS T="4" Id="bjp7a" />.. <UTS T="5" Id="bjp7b" />.. <UTS T="6" Id="bjp7l" />.. <UTS T="7" Id="bjp7m" />.. <UTS T="8" Id="bjp7n" />.. <UTS T="9" Id="bjp7o" />.. <UTS T="10" Id="bjp7q" />.. <UTS T="11" Id="bjp7r" />.. <UTS T="12" Id="bjp7s" />.. <UTS T="13" Id="bjp7t" />.. <UTS T="14" Id="bjp7u" />.. <UTS T="15" Id="bjp7v" />.. <UTS T="16" Id="bjp7w" />.. <UTS T="17" Id="bjp7x" />.. <UTS T="18" Id="bjp7y" />.. <TO T="19" I="1min">.. <S T="1" />.. </TO>.. <A T="20" E="TelemetrySuspend" />.. <A T="21" E="TelemetryShutdown" />.. </S>.. <C T="U32" I="0" O="false" N="EnsureCached">..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):627
                                                                    Entropy (8bit):5.136223556840137
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd5Bvy07gkVierSjBiMfEIiwxP0diMfAGjdiwxdyc/yNOqHNUlu:2dS0Mkbry8iO7ljrr9o7
                                                                    MD5:C8534E28E00809D5967ED1A5A4702C71
                                                                    SHA1:69496E8B4AB66EDB7FB2A73BE3CBB80123DA0378
                                                                    SHA-256:8AE5995B64CE2154CCBC0FDD0D01DEF855195767D118D753E3945D68A1BEE4EA
                                                                    SHA-512:D7CEB2E2B32E1306AD0201B79DC55C25D41EC077813E629DD5B44DAF0E21C17F5A8EC4E5E4879DD02244E00DB09233E74098D26E5D878802340497C2ACBF4FBF
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="370009" V="0" DC="SM" EN="Office.TargetedMessaging.BusbarThemeSelectionStatus" ATT="2f0a1931898144668b4994b491868b75-cc9fb197-8766-4b63-8e07-1887d3d330ac-7107" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bp5hd" />.. </S>.. <C T="I32" I="0" O="false" N="ExpectedThemeType">.. <S T="1" F="ExpectedThemeType" />.. </C>.. <C T="I32" I="1" O="false" N="ActualThemeType">.. <S T="1" F="ActualThemeType" />.. </C>.. <C T="W" I="2" O="false" N="Description">.. <S T="1" F="Description" />.. </C>.. <T>.. <S T="1" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):857
                                                                    Entropy (8bit):5.036697503394607
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd5qrC07gkV2ws1SEernKMS0E7WNoSdR/SpidydtlImX/MDd+DrVJd3w7uX9kN:2dIBMkds1KrAsbRMyGKh+3Jg7utM
                                                                    MD5:6168B63FE8A00FAF98CD2DEA54F6ADB1
                                                                    SHA1:40D21CDA5156E68EEFA7BCD2A2E4E1863AD0B08A
                                                                    SHA-256:A9C296543A66C08E90E201647DC1F5780EEDD78E43DF3FEBBE3EF11E259F34A8
                                                                    SHA-512:0F3A2BB8D60AAB8B4682D72BC28E2BDF46DF2BA14BA65064E0AE5AF11EFB3E483D27414BBF7C2CA2D5DD6A2B4D6AEC49B6E232B8E80A4F5CCD04256098E4CBDB
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="370011" V="1" DC="SM" EN="Office.TargetedMessaging.ABExperimentMessageTrigger" ATT="2f0a1931898144668b4994b491868b75-cc9fb197-8766-4b63-8e07-1887d3d330ac-7107" SP="CriticalExperimentation" DL="B" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bpt5h" />.. </S>.. <C T="W" I="0" O="false" N="Surface">.. <S T="1" F="Surface" />.. </C>.. <C T="W" I="1" O="false" N="Flight">.. <S T="1" F="Flight" />.. </C>.. <C T="W" I="2" O="false" N="CampaignId">.. <S T="1" F="CampaignId" />.. </C>.. <C T="I32" I="3" O="false" N="MessageId">.. <S T="1" F="MessageId" />.. </C>.. <C T="W" I="4" O="false" N="TransactionId">.. <S T="1" F="TransactionId" />.. </C>.. <C T="W" I="5" O="true" N="TriggerPoint">.. <S T="1" F="TriggerPoint" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):398
                                                                    Entropy (8bit):5.264707739167976
                                                                    Encrypted:false
                                                                    SSDEEP:6:TMVBd5lvkY+1xxqsC4Bf7tSPshsSs0FUHperhHzFFCx7IwLKBsfUSFNOn2sby:TMHd5t277gkVierFFFGfUINO2su
                                                                    MD5:179827349E5E56D5A69154DB28A2F49C
                                                                    SHA1:940C086DB82F6BD002F03D8DE08529502497B7D3
                                                                    SHA-256:EFA1B4E75F35A2815616E0EBF5C10B486E9AF498726998D9310D459D21A464D6
                                                                    SHA-512:B7850FF106963994A0E8B75E4D19D9611E3764ECB9DDAADB55628C85583B161DBB5151229A3A720E2262E4C78BAA15ACD7F5863E119C182F2530B8D4B060ECF1
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="370012" V="0" DC="SM" EN="Office.TargetedMessaging.UnsupportedIdentityType" ATT="2f0a1931898144668b4994b491868b75-cc9fb197-8766-4b63-8e07-1887d3d330ac-7107" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bsg4m" A="bsg4l" />.. </S>.. <C T="TAG" I="0" O="false" N="EventId">.. <S T="1" F="ULS_Tag" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):3282
                                                                    Entropy (8bit):4.509322215022879
                                                                    Encrypted:false
                                                                    SSDEEP:48:c8NZ16WZ3FwW9ua3t72AYvLdqG1rdmq0kvmvaclGRwAV:1LtyQErT9heGRwAV
                                                                    MD5:DC556473D3032FBF184301545F929DD8
                                                                    SHA1:4F208F54E00984A01E2040D7B1EC19DB2A159F4C
                                                                    SHA-256:0C5CD23D2ECA1FFB28FF2921DDB63030685B481BCCFE0FD61C2792691F11B755
                                                                    SHA-512:8908EB81FAD1B37414F1252F6EB71A8455C368FE5B68372A8129F67C5567652F43BE933E76F9596CD2C8833D6C37B1330FED447E9375B00BB8E3502461B06C82
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="390004" V="3" DC="SM" EN="Office.Wildfire.CanvasDeprovisionedDialog" ATT="350d24c16a934c2d9734791ed7301d8e-73bafc90-ca43-424c-815a-63b076120b49-6725" SP="CriticalExperimentation" DCa="PSP PSU" xmlns="">.. <S>.. <UTS T="1" Id="ckyjo" />.. <UTS T="2" Id="ckyjp" />.. <UTS T="3" Id="ckyjq" />.. <UTS T="4" Id="ckyjg" />.. <UTS T="5" Id="cu6t1" />.. <UTS T="6" Id="ckyjf" />.. <UTS T="7" Id="ckyjh" />.. <UTS T="8" Id="ckyje" />.. <UTS T="9" Id="ckyji" />.. <UTS T="10" Id="ckyjk" />.. <UTS T="11" Id="ckyjj" />.. <UTS T="12" Id="ckyjl" />.. <UTS T="13" Id="ckyjn" />.. <UTS T="14" Id="ckyjm" />.. <F T="15">.. <O T="EQ">.. <L>.. <S T="4" F="IsGateEnabled" />.. </L>.. <R>.. <V V="True" T="B" />.. </R>.. </O>.. </F>.. <F T="16">.. <O T="EQ">.. <L>.. <S T="4" F="IsGateEnabled" />.. </L>.. <R>.. <V V="Fal
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):449
                                                                    Entropy (8bit):5.297798715342976
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd5XJXA+NZ1S4Hs14WnervAlNEu2uNO2su:2dTXtNZ17Hs1WrvAlavu
                                                                    MD5:21F035AAAA21E9B919920690017E1043
                                                                    SHA1:65BC7C9EC7481F390F84BB89D187E58C8C63119C
                                                                    SHA-256:06D994B675B0DB4AEE7D8FD325993ACEB1546217A59D8FF86B962A90AA096109
                                                                    SHA-512:C869874DFEA611D2C55FF752581F70B4A677DD731188585B9123FFB579772FDC955FB83E475BCB2D43DB39F6E8BF1F926C1AB86685B1CB3A7684D750D28FA322
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="390005" V="1" DC="SM" EN="Office.Wildfire.CanvasDialogResiliency" ATT="350d24c16a934c2d9734791ed7301d8e-73bafc90-ca43-424c-815a-63b076120b49-6725" SP="CriticalExperimentation" DCa="PSP PSU" xmlns="">.. <S>.. <UTS T="1" Id="b36lp" />.. </S>.. <C T="W" I="0" O="falseNoError" N="ResiliencyExperience">.. <S T="1" F="ExperienceLoaded" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1997
                                                                    Entropy (8bit):4.962466047797236
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dAFcFwTS30cq3P5s5GkWhbhScX8h3fUc+FfT+Nc0KN0oOBzBB:cCOwTs0JRQGRFyMpiFB
                                                                    MD5:D7DF0C81AF59C7EFFE06CEB8CD133843
                                                                    SHA1:4BFDD306EB8FE0638E6437F44DC841B32CB55E7F
                                                                    SHA-256:F0AD740F5DCB2AEA86AAD20083E7434AC09369DD6BBBCBC58DBC6547A4B70E7B
                                                                    SHA-512:5B6DB178A4DFB132E55794FFBD47B9E40BDC192419DF916CA1A5910DD248C6644E598F2AE60A62E31EBCB9955EEA00ED62C29B3CA5416661B531C9B6F2828544
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="440000" V="3" DC="SM" EN="Office.Charting.ActivityUnaggregatedCharting" ATT="8984684171524f0c86ea1d654968b2c4-7399462d-cac4-4abd-abdd-d14d00d89e06-7783" DCa="PSU" xmlns="">.. <RIS>.. <RI N="ActivityInstance" />.. </RIS>.. <S>.. <UCSS T="1" C="Charting" S="Medium" />.. </S>.. <C T="FT" I="0" O="false" N="CollectionTime">.. <S T="1" F="TimeStamp100ns" />.. </C>.. <C T="B" I="1" O="false" N="WasSuccessful">.. <S T="1" F="Success" />.. </C>.. <C T="I32" I="2" O="true" N="ErrorCode">.. <S T="1" F="ErrorCode" M="Ignore" />.. </C>.. <C T="W" I="3" O="false" N="LogScopeName">.. <S T="1" F="ScopeName" />.. </C>.. <C T="TAG" I="4" O="false" N="ULS_Tag">.. <S T="1" F="ULS_Tag" />.. </C>.. <C T="W" I="5" O="true" N="ParentScenarioName">.. <S T="1" F="ParentScenarioName" M="Ignore" />.. </C>.. <C T="TAG" I="6" O="true" N="ParentScenarioTag">.. <S T="1" F="ParentScenarioTag" M="Ignore" />.. </C>.. <C T="U32"
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1377
                                                                    Entropy (8bit):4.871091054185326
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9I1wjDcpuMt1k3BNjXMi+EsdnKE+2h6wl/FfrfXU:c+wPcpuMteNjXMzbdKshBdjfE
                                                                    MD5:B46B165F9E745F4F5B503276342D3296
                                                                    SHA1:A737470E29E337549DFBFC10C7A17FE25A42AB7E
                                                                    SHA-256:F0180146BF0C66C553B4A1D74187ACFD43A2362A5609211C1CA68499FD17E9D4
                                                                    SHA-512:9CD5B98D519507FAC488F79E60E645EC2AF60CF2470391B2AD7031795691F26DF29B5B86D598B3374135E6E3190409E7810D33B145B19550B534E63B52F93D56
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="700850" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Experimentation" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenExperimentation" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="W" I="6" O="f
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1414
                                                                    Entropy (8bit):4.904142181625683
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9reDcpuct1k3BNjXMi+EsdnKE+2h6wl/FfrfXU:c5ucpucteNjXMzbdKshBdjfE
                                                                    MD5:9E87387E0AC4BD3036DF06828ED7CF1F
                                                                    SHA1:A171101AC5BD83395C2376388F1823CE45ACA595
                                                                    SHA-256:6F0E926E57A575E4DE7C5CB8D77ABA73C0B783D418FB70608A1F2EA727B8560F
                                                                    SHA-512:E6C0933D3EDBE13005737F3BCB9687345336F728318F9B26771FCA14281C1FA880E47D0D5866E005B7FEB2A764DDC827B7032EABB0C68BC45C0F7756C4DAFB14
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="700851" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Experimentation.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenExperimentation" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractIn
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1370
                                                                    Entropy (8bit):4.864243128033522
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d96hD4uMt1k3BNjXMi+EsdnKE+2h6wl/FfBMYw9:cIR4uMteNjXMzbdKshBdZFS
                                                                    MD5:93F3BA34414AC3EDE75938D7BBD99E1B
                                                                    SHA1:C47EEA0BF9F154685AF5675825E824899A55B2CD
                                                                    SHA-256:BA3DACE531F26E80D49925FF7301134F3CB5121F7FBC91258A3CA6309D040EA4
                                                                    SHA-512:828C0D0C06B5E8513EBAB206A098FD9B26630F110525EEC039A5BEC04276589868838550662B3A11F534A1258C884D8A2141E4EE891AF47F9010C5F9EBEE9A19
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="700900" V="1" DC="SM" EN="Office.Telemetry.Event.Office.NaturalLanguage" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenProofing" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="W" I="6" O="false" N
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1407
                                                                    Entropy (8bit):4.898680122194441
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9EQrD4uct1k3BNjXMi+EsdnKE+2h6wl/FfBMYw9:cmQX4ucteNjXMzbdKshBdZFS
                                                                    MD5:AB22551D18F3734C6F3DE50B4DA0E627
                                                                    SHA1:AEC5ED838516B17C17CD5A483BFC7009C0C4403C
                                                                    SHA-256:E0CF8E6EF4246809D92BB6A141BEDD458089D7D01A1E49F6DD33FE9E85D0FB69
                                                                    SHA-512:7AFBD54B964483422BD38E83589A2918BB44ACDEC2885414872661D7C3DD1531857027C7C126F014A1A782BF1839334C0072FDED87C7A288D466D5170A84999A
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="700901" V="1" DC="SM" EN="Office.Telemetry.Event.Office.NaturalLanguage.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenProofing" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1368
                                                                    Entropy (8bit):4.870003164588434
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9PQUD2uMt1k3BNjXMi+EsdnKE+2h6wl/FfpNZ17B:clv2uMteNjXMzbdKshBdRNZ1l
                                                                    MD5:A6C7DB427C635E44EFF78659CBA27BE2
                                                                    SHA1:E0E84CFCB9F45C03117B5993F3A2A25E5428E49A
                                                                    SHA-256:115428712E29C5E4A842323CBDB457DBC4A5DA2883A2E2DAF25F3B8386F5FC93
                                                                    SHA-512:F1411CDB492EE6CA1C0297D57E809D9173506B4277857A5BAB054ECDC060C5BBBC7C0577D3EF18C428AFEDBAEF1656F7F9260B8BB062960D9DC1D3A68A23A218
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="700950" V="1" DC="SM" EN="Office.Telemetry.Event.Office.DynamicCanvas" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenWildfire" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="W" I="6" O="false" N="
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1405
                                                                    Entropy (8bit):4.903878162573853
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9EQYD2uct1k3BNjXMi+EsdnKE+2h6wl/FfpNZ17B:cah2ucteNjXMzbdKshBdRNZ1l
                                                                    MD5:9281BF3FDC7334D3DD411E21DB8011C2
                                                                    SHA1:0FF9A83687767BE068559F78D1BBC986C25EC616
                                                                    SHA-256:D99F85AAD2310137D583B055C0DA9A03F6EB1281D97F0BA151C891E4F67D3DD1
                                                                    SHA-512:3505E4C2FE8BDD0147BDA976EC0C01E7F9A0622C8EABFEE7EC1780C36A155A1CF6E21E965A91DE7D045DDFCC03F5549E654F82FFB82DB288D685538B2FF039F7
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="700951" V="1" DC="SM" EN="Office.Telemetry.Event.Office.DynamicCanvas.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenWildfire" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1361
                                                                    Entropy (8bit):4.848504126163618
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9rFTDluMt1k3BNjXMi+EsdnKE+2h6wl/FfcFE0Q8:chFfluMteNjXMzbdKshBdEw8
                                                                    MD5:491056D095AAD4F225D85F36E656B9B2
                                                                    SHA1:CCD2133FB244AB86B9F3B7115603351804F915B3
                                                                    SHA-256:EE67AF8222350B8CB0D237E56FF2F77CFBBCC269D237033F3594010DFF4FE558
                                                                    SHA-512:7BFC1FF6E7BA46ABAEE2C91DCC2E89893CA5CE6E3270737009D86DBB581066E598231AAC472ABE0EAA6BBA5F8ED916563266EC9DC7A5D015B96AFD255900702F
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="701050" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Release" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenRelease" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="W" I="6" O="false" N="EventTy
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1398
                                                                    Entropy (8bit):4.8838124424443485
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9r6hDluct1k3BNjXMi+EsdnKE+2h6wl/FfcFE0Q8:ch6RlucteNjXMzbdKshBdEw8
                                                                    MD5:6F8D4C93DABAB34519AF6CE90028BD0E
                                                                    SHA1:291D8729727AE3850F464E41FE6D8771EB9F73DA
                                                                    SHA-256:2B666C43A56D70270612CC47E012F9FD363C335C57191BD9FB682C2F83A56CB3
                                                                    SHA-512:44C5C272681BFDF98364242A79969F9FBA7167207B6C33D43BED680BBD80184E84C35F4FD3045D622DACA9EEA39C210C7644E85983D229E718E1689C890F6558
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="701051" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Release.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenRelease" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1373
                                                                    Entropy (8bit):4.870676852445164
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9H6DiuMt1k3BNjXMi+EsdnKE+2h6wl/Ffb/R6:c1aiuMteNjXMzbdKshBdbR6
                                                                    MD5:77B56E43D73FA188917E562B70842BFA
                                                                    SHA1:652A37D897D870576A87E64474FCEE3149E87E00
                                                                    SHA-256:0D9142E0149C9C142D3CD95DD8DC7138ACC43F42B9D0D6C5A8C1809055AC4BD6
                                                                    SHA-512:CBBFDE5C510A9750E013B99857B293D564071937B1DBAABB28BC06AD0D8B260672B5908A69ACDC5D611FA5605606FFC36E13D41966C3DC1036B8D791961432CF
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="701100" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Accessibility" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenAccessibility" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="W" I="6" O="false
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1410
                                                                    Entropy (8bit):4.9032649064965685
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d98CDiuct1k3BNjXMi+EsdnKE+2h6wl/Ffb/R6:cqCiucteNjXMzbdKshBdbR6
                                                                    MD5:507BA271196503239BE13EE1BA321855
                                                                    SHA1:99680772A05B7975AEBC04F9E8902A4702FF70F2
                                                                    SHA-256:524B24FAC548B58AAA409B523C0AE670DB695BE965FF6B1DF40B5AC43DA1C6BC
                                                                    SHA-512:A41C8754A818D799F076C6E571FD48C21596EAD3CB5DB77D89FFFA890FE1A8DD809BBB6BFA63280E54692187E6BA1F2034679BD42C597F036BFB3C2AE1F64F77
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="701101" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Accessibility.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenAccessibility" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo"
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1363
                                                                    Entropy (8bit):4.859493863374326
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9yRDrouMt1k3BNjXMi+EsdnKE+2h6wl/Ffrk:cYhrouMteNjXMzbdKshBd4
                                                                    MD5:2FB9137F9A1706197FB55DF8517A82C3
                                                                    SHA1:C0FE0FC455F8AD087B533863410F6A9FFB5D0ACB
                                                                    SHA-256:ECA6F8A4572C305B76ED9E7B7EC0AB299EBDD39B77EB63E2BDAB8AE87A3FE912
                                                                    SHA-512:C6F1775B5583826E6C07F3F6476A4A173DFC25F0ED6731325D3867515B5C232AFD6994B7FB326944FE6A233B60C96B4439882179E569F98EDC99596C23288789
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="701150" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Text" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenTextAndFonts" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="W" I="6" O="false" N="Event
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1400
                                                                    Entropy (8bit):4.8949038661110205
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d99bDrouct1k3BNjXMi+EsdnKE+2h6wl/Ffrk:cDnroucteNjXMzbdKshBd4
                                                                    MD5:3A9820D070C1565C16916844FE33DA09
                                                                    SHA1:8BA5B6149C4B36937D26220C57A407736A4B73DE
                                                                    SHA-256:4B92B65AA0321B6707B143642440084C0B9A57E83CFC8A58555EE570FC2E0343
                                                                    SHA-512:8BE95144D5D25EB6E74DE0A04A53E356F281DD8720C25929A4A0E82B4B9460FEEF72C8009BAD7ECCA4E782E91841D7075E74043225EAB4DE5161CE76D2E20684
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="701151" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Text.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenTextAndFonts" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1355
                                                                    Entropy (8bit):4.859306526630754
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9WuS0DguMt1k3BNjXMi+EsdnKE+2h6wl/FflwrkaMp:cwuPguMteNjXMzbdKshBdNMk
                                                                    MD5:287129FFB36E1F7977F1A70ABBC8D7DF
                                                                    SHA1:0C17106216B5637D5FC192BFF8F185E1045A278E
                                                                    SHA-256:A4E20CA3E4F76D270BF165D6D607464CB344A2BF0C36009E84A68A3B0F37CE79
                                                                    SHA-512:7BF495AFA6821BFD168EBB098ABC251288F16EF93C73202A77D74CFBADC0CF7417FA98144849577D81BD8358B687D69113CA4363D03DF16F01510A2D9C6E98FB
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="701200" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Xaml" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenXaml" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="W" I="6" O="false" N="EventTypeInfo
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1392
                                                                    Entropy (8bit):4.894375938062735
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9RgDguct1k3BNjXMi+EsdnKE+2h6wl/FflwrkaMp:c7kgucteNjXMzbdKshBdNMk
                                                                    MD5:CCABD847AAA5D7E103CEDBEF2A9EAD23
                                                                    SHA1:F64D34258E147E8746925ED0BEB75FF664116F32
                                                                    SHA-256:37ED0C183C6AC628BA7F6F7A8812D28B163ACA6597FD57C5E8673A878C254A34
                                                                    SHA-512:F644163E2648F43F88DBCB0D460D878A70229B6046ED998E64278C663751FFC9EBFD420BAAE6C1A105FE982BD6043CB42E1D5F2927D96583FE593538157EBD69
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="701201" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Xaml.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenXaml" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1357
                                                                    Entropy (8bit):4.852145737506613
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9jxE7DVOuMt1k3BNjXMi+EsdnKE+2h6wl/Ff/Fv:ctaHEuMteNjXMzbdKshBd1
                                                                    MD5:5EBEF9B192C8103FFDCCC72DD9EDAFD1
                                                                    SHA1:8A4314B788DE4AD3E80759994F4AFBD8669D9A74
                                                                    SHA-256:24A0BB2950AF30622B152250D0FB321AC92103D37E6361B2680ADBDEEE93FAA7
                                                                    SHA-512:A488EB52EE5DC29DA021D38FA0A217075D064519C42590CB4BCB6DF31D1EB046FE95E6BAA6622E1C6DC600825F6B6E3D1CEDF4C16111987AF9206D06CBDAF570
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="701250" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Visio" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenVisio" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="W" I="6" O="false" N="EventTypeIn
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1394
                                                                    Entropy (8bit):4.887592597470845
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d94xCDVOuct1k3BNjXMi+EsdnKE+2h6wl/Ff/Fv:ciIEucteNjXMzbdKshBd1
                                                                    MD5:41FAF032C1FFDADEB437507E63713EB1
                                                                    SHA1:CD6DA1A22C070B1DA423F43A0CBB691D0262AE33
                                                                    SHA-256:722C2A2B9D6ECD2D7823E518CCFEDCF5576BC23D187A8704B0D4C0BAA4C75DF9
                                                                    SHA-512:1BC0B64B95DAF7C0E6947FBE264C55B53BCC2C29CB5C1BE90EAAC3F9F5FDF24A059A321567FAEAF986115C32A46EE34D831B9EA6E7822B8BB6F0FD3A5242B871
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="701251" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Visio.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenVisio" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1365
                                                                    Entropy (8bit):4.853574157223617
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9puD+uMt1k3BNjXMi+EsdnKE+2h6wl/FfF5Mvj8+9:cTe+uMteNjXMzbdKshBd4jN
                                                                    MD5:0071603D76F450E66200CE966EDDE2D9
                                                                    SHA1:3127073FE22FC7154F7C708FC43EFF877CBE0292
                                                                    SHA-256:BC2B76A72E5D0A52749E01239F95B757E75535B6C6B64D1FB8C9529E36AC0A96
                                                                    SHA-512:5878E247DFA7C683D753FA68C438E9A34F0A10AE6B661C91C641475053A8402FC959B653F6F7F8D57BB34C26C4D584B2FE4A51F0A6F9B78882019BB851278ECB
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="701300" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Licensing" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenLicensing" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="W" I="6" O="false" N="Eve
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1402
                                                                    Entropy (8bit):4.888179763188237
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9u0JD+uct1k3BNjXMi+EsdnKE+2h6wl/FfF5Mvj8+9:co0Z+ucteNjXMzbdKshBd4jN
                                                                    MD5:5116C3B1152C0D2A5F8D815C5AF0CBDA
                                                                    SHA1:7D441291A22AAC03BA9BE6A21DD4C828CA276356
                                                                    SHA-256:D14D9A1F4F46C9D62315414C36514B70CE6FF6D2348ECA4E9CA189F670EF2939
                                                                    SHA-512:2FF0D0D11CBA4E80EDB7BC7CA7101840BF62C11C44BD973D518A34D27EB5A6FA9372A7361061B1A0CC73768BB83F4F97F5E00A82DC4D09C5C5AEF0703A3362F4
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="701301" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Licensing.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenLicensing" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1369
                                                                    Entropy (8bit):4.862955605597379
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9UEDAuMt1k3BNjXMi+EsdnKE+2h6wl/FfFUZC:cGYAuMteNjXMzbdKshBd9T
                                                                    MD5:8D4222D4E369261410799F61C69AD049
                                                                    SHA1:A71B914EF1706C027F653386CB311138486748D5
                                                                    SHA-256:BD87BF4A112F0856EB0709D3F455C5FF05BDDB91532912639CFB1C05897A838F
                                                                    SHA-512:CAEE9ED333E79578E603902DCA35FEE216540C769EDBA17E157535B5FF0659AB5087A04CF050DB3E72825F8E2B00954F6304398A9F1A2F925BD0C3C3BD6EC507
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="701350" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Performance" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenPerformance" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="W" I="6" O="false" N=
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1406
                                                                    Entropy (8bit):4.8974766228830156
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9fIDAuct1k3BNjXMi+EsdnKE+2h6wl/FfFUZC:cBMAucteNjXMzbdKshBd9T
                                                                    MD5:93A2B72717297C77249A66A699AE28A8
                                                                    SHA1:E7EADA3ACB405CAFD9EAA452F86EAD27F201C255
                                                                    SHA-256:60D1D22F84121CA3F9FCEF5F6072BD2F813945B33D30358BA2ED325495B63CDE
                                                                    SHA-512:5E9B9206D1379F936984BD46420C1F8112C8265F2F1EBE58BF7B6930FBCB418AEFDEE4D6D38260080E0706EE8EF80D5EDCEFCE9727E600B8E5BF5CCA96D25B32
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="701351" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Performance.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenPerformance" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1363
                                                                    Entropy (8bit):4.859497537258701
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9AF7DPuMt1k3BNjXMi+EsdnKE+2h6wl/FfSoiD:cG5PuMteNjXMzbdKshBdqoiD
                                                                    MD5:49DF4E9962115C2F2744C11B74C1F9C0
                                                                    SHA1:C39F235ECA2C756CC1FD01CA7E906925076A1613
                                                                    SHA-256:7F5E0293010B58D70ED1FE59D9B3C44AEBDCFC81697C2EDFB0835576E787233B
                                                                    SHA-512:C88FFEAC935D37B2AE8C709D55442AA387C7EBFC8B8E1C9D69193BA915251E3FB7655C82A7A25A884FCA593E98D194B856E29280A3E7DC227138CB326FABDC53
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="701400" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Feedback" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenFeedback" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="W" I="6" O="false" N="Event
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1400
                                                                    Entropy (8bit):4.895259032059607
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9d1F5DPuct1k3BNjXMi+EsdnKE+2h6wl/FfSoiD:cBvPucteNjXMzbdKshBdqoiD
                                                                    MD5:C4069B4A7EAA85DEBF9149CC4F611A1E
                                                                    SHA1:4E41E49FE3F8F9C33121664783049831AD8DEEDA
                                                                    SHA-256:7FEFF4A2068F486999519CA82547F08C6C10B28B9AC8BF62D8CF503B1EE5EB7E
                                                                    SHA-512:089F8A6D741A55AD798F2B07E940CBFE9C339E7751C88979C7237270750FC8E61268D81BBAA0DD25EDAC155646CD68004C6CFE2817B6865AF685903076B11C56
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="701401" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Feedback.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenFeedback" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1363
                                                                    Entropy (8bit):4.851189495849424
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9jsD4uMt1k3BNjXMi+EsdnKE+2h6wl/FfZl94dl:cZA4uMteNjXMzbdKshBdlWl
                                                                    MD5:50655123E33AFFD5929AF51CDD7F910D
                                                                    SHA1:C55BC2D107AC025AA86B83F25A92BB4E047CA7A4
                                                                    SHA-256:403E85A8659EC5EC09EC28C48CCD7018980BF907974A5A823CC61FD4CA6376C5
                                                                    SHA-512:2210958C932CBC3CA733A7754975261195B1C7A2189179BD699641A17426625F4D10616536C7827F8E10FC6226CF6F82F8207C000F52CB59E7EA063624A9975A
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="701500" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Security" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenSecurity" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="W" I="6" O="false" N="Event
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1400
                                                                    Entropy (8bit):4.885644101734657
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d94gD4uct1k3BNjXMi+EsdnKE+2h6wl/FfZl94dl:cek4ucteNjXMzbdKshBdlWl
                                                                    MD5:7EE84B67DA2B177BB9F7970E17EFDFA3
                                                                    SHA1:09D0F753289494D6AA385531DB8FD9D65B320B9F
                                                                    SHA-256:94558DDF61F07FDE04A9F64B2FE3089B1387D04AE32B74AA40F6380157333A9C
                                                                    SHA-512:8A7986847A0262983EEEA11DE5740044270F8AB165DB15C9236CE6391AB9A2D1BAA6B75064ACC17B09FC0229F454876027D7F7BC7E75F6F4D5381E16E73BF41E
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="701501" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Security.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenSecurity" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1367
                                                                    Entropy (8bit):4.867050300290955
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9WEBDY5BuMt1k3BNjXMi+EsdnKE+2h6wl/FfdNG:cEExY5BuMteNjXMzbdKshBdrG
                                                                    MD5:D3581FFA64962E5B3A88823EEB2C7E13
                                                                    SHA1:E7165CDFF344D68D415818BDFDA28335055AD58C
                                                                    SHA-256:4BF376373582C62D9CFA456B49563FDFFC18AF24863569E58A33460C9C4FF9EC
                                                                    SHA-512:6AE2D062A67C56BF0D7D23B033B96EF452148F6CB44BB965F07A592948CA06B3A1C03C16713FC4CFC2B7A12780ABDFED1BC4571A2799FEFC0523FE9F91894C02
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="701550" V="1" DC="SM" EN="Office.Telemetry.Event.Office.ClickToRun" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenClickToRun" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="W" I="6" O="false" N="E
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1404
                                                                    Entropy (8bit):4.901397951222752
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9RELDY5Buct1k3BNjXMi+EsdnKE+2h6wl/FfdNG:cPE3Y5BucteNjXMzbdKshBdrG
                                                                    MD5:45C8ADC97B153AD4E7C9F7CD20C7C596
                                                                    SHA1:3D339434F78E7B46650B20AC2203512E9651F00A
                                                                    SHA-256:1644BC64BACC9EA3CB3A0D7700444BA620C781921B790B3304FBBA5C3E3A23C2
                                                                    SHA-512:C1C1784CB97B45842CEA7CFA77750185F1350B9CB1F275CDB59A1FFB6FAF6DC59BC318F910A22CA4EEFB97277AD2CF1A3016BB4B09E4F11E9FD0E5E534F16ECB
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="701551" V="1" DC="SM" EN="Office.Telemetry.Event.Office.ClickToRun.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenClickToRun" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1371
                                                                    Entropy (8bit):4.87143922286121
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d93AcqUDcczuMt1k3BNjXMi+EsdnKE+2h6wl/FfbWd:cJA3IcEuMteNjXMzbdKshBdzu
                                                                    MD5:C5425337BB1BD1AE05FCD194702CE5E8
                                                                    SHA1:A46BD1FDD5DF067614FBB385874C7532C936A6AD
                                                                    SHA-256:00E3250D9C0B3EC068EBFB018C6BC8AD65672B0C3146A42ED23F824011232599
                                                                    SHA-512:6AEE85BFF6C2A6406DFB311A5E0E32774F4A25B49AAF89A4B3AE652FA5CAD1E8B5A57833B795F1C297210D85C7CD0E05E09980E212F25F41AF0724526C8EF85D
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="701650" V="1" DC="SM" EN="Office.Telemetry.Event.Office.ActivityFeed" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenActivityFeed" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="W" I="6" O="false"
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1408
                                                                    Entropy (8bit):4.9044836874199635
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d90jAcLDcczuct1k3BNjXMi+EsdnKE+2h6wl/FfbWd:cOAscEucteNjXMzbdKshBdzu
                                                                    MD5:86B949CE5600C4EA98588727559FA6A2
                                                                    SHA1:18510336146B37806CC5959D9C6262B557426513
                                                                    SHA-256:297C295BEE147DEE6EC4B606127F0A4CF506537A9C953E79C38AD1FD88E0E375
                                                                    SHA-512:4A747163E5E11FF4E25F2489DCF276A2AA6C1A2D258927314BDD39CE5B36F7C6A4976F350312AC7D69EAA9BC7A04DD148F178D1C420976A578762502858C80BB
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="701651" V="1" DC="SM" EN="Office.Telemetry.Event.Office.ActivityFeed.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenActivityFeed" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1385
                                                                    Entropy (8bit):4.869280310390715
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9FC8fDW8NuMt1k3BNjXMi+EsdnKE+2h6wl/FfiyO:c3n9uMteNjXMzbdKshBd6yO
                                                                    MD5:B4FFA67DBCA2C36C65CF2CEC21C194AF
                                                                    SHA1:91AF529A50648564FB4E7AE434F33236842096C3
                                                                    SHA-256:AE3DC19A7465F1504949B7482CFEA3D7FE7A6E168972227DFC12D76BF73A6DBE
                                                                    SHA-512:16579529198940AAC23986E9EA3D4DD99B39982E8CEE751E06CBB6A8767EC5A4CC5AA40A5566A30755C756346EFB8CB85CAE873FD53ED780C08050A45FEEAA1A
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="701700" V="1" DC="SM" EN="Office.Telemetry.Event.Office.IntelligentServices" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenIntelligentServices" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="W" I=
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1422
                                                                    Entropy (8bit):4.901909400554976
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d96C8tDW8Nuct1k3BNjXMi+EsdnKE+2h6wl/FfiyO:csJ9ucteNjXMzbdKshBd6yO
                                                                    MD5:0DC5F0FD97C8670F3FAEC6EA67CE413E
                                                                    SHA1:E099D77DBF97E2FCECB3CA5F81658B4D8670F8ED
                                                                    SHA-256:952718E98154DA263DB3F4310FBF492D9133306B43FA85F5B246683F966DE924
                                                                    SHA-512:8A3D80F49F59BCD5A773CF94C55171002AF9748D919F2D4B866DED4B8E2D41F56023CDD22D8D0103E8C2B4D6A5EE4F704116E297CF913433D07C58568A2EE45B
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="701701" V="1" DC="SM" EN="Office.Telemetry.Event.Office.IntelligentServices.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenIntelligentServices" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventCo
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1363
                                                                    Entropy (8bit):4.855593221051942
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9o4D52uMt1k3BNjXMi+EsdnKE+2h6wl/FfiDR6j9:cic52uMteNjXMzbdKshBdoR6J
                                                                    MD5:92A739745511ED4C0C1D45D82C77658D
                                                                    SHA1:5CC7B83D590F7738D647FA4F523CEE679125943C
                                                                    SHA-256:B6D3E25D682C863466B53086C5DAB1523408F587D0ECC9C1B9E29274879F1717
                                                                    SHA-512:5275E7B7BD85BDC8E4CBB826B135D12AACD74F4A6E0195D01E0B1FC9B879FAFD8541DEF44739BFC052C950D26AF3CE3B86C0849A15C240F2A6950ACE25B87A51
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="701750" V="1" DC="SM" EN="Office.Telemetry.Event.Office.AirSpace" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenAirspace" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="W" I="6" O="false" N="Event
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1400
                                                                    Entropy (8bit):4.889762408334574
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9T8D52uct1k3BNjXMi+EsdnKE+2h6wl/FfiDR6j9:ctw52ucteNjXMzbdKshBdoR6J
                                                                    MD5:DC9D9CFCF426D0CEFE55DE1849D2DCC7
                                                                    SHA1:450A7A6D23546C99218403C136622DE77F2F704F
                                                                    SHA-256:2D5479AA25459D68178F9DA0E51522F6365DDAE4B88E0ED74CFD6EDF98BE8DCC
                                                                    SHA-512:86336F858EBBC92C5928053360B53F92FC96A10999157652424D7CC98253324B1FC7DF5E4E5BEF3A89824F3D62CBE8FE16FA15BF9E875D712CD605D8AA1AB973
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="701751" V="1" DC="SM" EN="Office.Telemetry.Event.Office.AirSpace.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenAirspace" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1365
                                                                    Entropy (8bit):4.861678713883639
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9MISDtuMt1k3BNjXMi+EsdnKE+2h6wl/FfH3/j+:c6IytuMteNjXMzbdKshBdy
                                                                    MD5:09F6C193C63584980525CCEB8AD3DE1C
                                                                    SHA1:51A0723A0DF9354146A1A98C31A144AD4FEAFB99
                                                                    SHA-256:20CBFF7F69A6F9950FD9CFDE3A060078AD35FE8BFF36E5CE6ABEB8EC79C2425D
                                                                    SHA-512:B3BE6EA621D5F874D06225DED34365728A65ED9B1AF2045D06C5C46BD30B0A39028A452438BCB43080B61C9D714BE0AF1940B7E78E16F289B66073011BADB9E1
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="701800" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Resources" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenResources" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="W" I="6" O="false" N="Eve
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1402
                                                                    Entropy (8bit):4.8964391267970955
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9XIKDtuct1k3BNjXMi+EsdnKE+2h6wl/FfH3/j+:cFIKtucteNjXMzbdKshBdy
                                                                    MD5:30C63769311E091B113962414D87C0F6
                                                                    SHA1:5A296B9CE8814B2D69507A596B4FF52E8E7B4F03
                                                                    SHA-256:F0920A54B5440E436A5467F531E6E39847AB8D49DDC947F3CC6ADFC3132DABB6
                                                                    SHA-512:2F7A0C3C415F06E5B73F347E428330EACF9BBAFCD4E5A9FF0918E5BF1E43D8E006D6FB2FE6C0BD525606C1CC51D1AF485EFDE8DF89AABF3D49EE93E2052EA11B
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="701801" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Resources.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenResources" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1370
                                                                    Entropy (8bit):4.863237258346602
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9zFbD0auMt1k3BNjXMi+EsdnKE+2h6wl/FfnSip:cPn0auMteNjXMzbdKshBd/SU
                                                                    MD5:FF99C0CD717BEC9058D85C1CED6F4360
                                                                    SHA1:8DD634D41C3706CCDEBCD0B6F5DDCF5F08C93610
                                                                    SHA-256:3D7510364704F1B2F2BC376D618C449298D86AB18536F08E5146A17881035A79
                                                                    SHA-512:ABB7B2E0304D80EDF3FCCD696E6E1D61C5957FA43F03CA08A1DA5A79815BADFFFE1761C3E8F9DCC03B9A6923ADE1D656567320C9E04F1D94FB9E0E597135244D
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="701850" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Excel.Mobile" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenExcelMobile" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="W" I="6" O="false" N
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1407
                                                                    Entropy (8bit):4.897385308857073
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9z6ZD0auct1k3BNjXMi+EsdnKE+2h6wl/FfnSip:cEJ0aucteNjXMzbdKshBd/SU
                                                                    MD5:11905A5A24EABADC513921F6C88E04B8
                                                                    SHA1:9752BD755BA4CDAF81154A6A840F15FFFF01637A
                                                                    SHA-256:D558157AE718D287481689C47D0B5E7DF83C74EDC9388F7E33A57AF2813EA3DA
                                                                    SHA-512:8F078265587E1C14FC20B5DF6A5DA38F356BEF1918F6D624D7E1B2BE4ACA9C847ABB7D5AE1B5747A352F683F4608AD782122D896654BC9C8E0FC3F8E2B88C1B9
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="701851" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Excel.Mobile.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenExcelMobile" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1369
                                                                    Entropy (8bit):4.856329203731458
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9vKDiuMt1k3BNjXMi+EsdnKE+2h6wl/FfYmlBu:cdKiuMteNjXMzbdKshBd9Bu
                                                                    MD5:70C9FD7930D05F6C33023761320B0CBC
                                                                    SHA1:67BCE0044DADFA4BAC7106CEDF7888E14AF2ADEE
                                                                    SHA-256:E06034DB8142BC440CEAE157936F7E7E3334874FF81E9A81EA0309E9A166BC71
                                                                    SHA-512:7E67849DE3BAEC3531C2504E1A3A33DAA7EF76E29ADD485F9216E389BF20A374F86BE23DA233F3E7DAA9567787A15D08D40BDCBB46ADD779E3CADFD79FD35225
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="701900" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Diagnostics" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenDiagnostics" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="W" I="6" O="false" N=
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1406
                                                                    Entropy (8bit):4.889929045928819
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9zQSDiuct1k3BNjXMi+EsdnKE+2h6wl/FfYmlBu:cNQyiucteNjXMzbdKshBd9Bu
                                                                    MD5:B9034C0C9143AF5225DA9645221E7917
                                                                    SHA1:251BD49A87280053A868D828B61DF8534CE2FD49
                                                                    SHA-256:9F7B8822B3EB45462F588B4220A3F8D754181FBE59CF4D1149DEF67C57D84B62
                                                                    SHA-512:1176A1D00CF58FA61131317F292F3B784631815DCCC0969C37093419399A477565915001868AE515711ACED8BF5145347EEA6C95DFE34AAF1084D36BC3EE2076
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="701901" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Diagnostics.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenDiagnostics" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1379
                                                                    Entropy (8bit):4.877346383504526
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d90HjTDuXCuMt1k3BNjXMi+EsdnKE+2h6wl/FfAC9:c4jfluMteNjXMzbdKshBdYM
                                                                    MD5:EB441D671A38322EE807CD5BDA5E286E
                                                                    SHA1:0D0E5982290AE2DE61F690BF841F5AE7269BC289
                                                                    SHA-256:4F149C5B60B44541AE45B9EF603C8218FD63552B29AAA311B06567DAC3D7C44E
                                                                    SHA-512:F78F88A8C6E4A7F91F23B7A422E1BF6A9C497C24B7B205564201A7231597EB44CB265F90D0FE562F552C1B0FB756E5FBFA65AB68A9754DE4640F4B7F1BB678F3
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="701950" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Extensibility" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenOfficeExtensibility" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="W" I="6" O=
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1416
                                                                    Entropy (8bit):4.910169708231961
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9lhDuXCuct1k3BNjXMi+EsdnKE+2h6wl/FfAC9:crRlucteNjXMzbdKshBdYM
                                                                    MD5:D567F8BB0A30CD0686098E282DC3CE81
                                                                    SHA1:64EBFF6B42312ACF34D5F7D7E299C15530C2ED64
                                                                    SHA-256:55C50CBE81DF8D8D28E0034C816ABE0669C64603097351526A382C91A65DAEC9
                                                                    SHA-512:CA2A287824B2157BBA35F4C7082FF5B8827F96972B9439C4D7E4A0EC8941ED295FBA351EF2E4A21599D5AD19174C0F2CA564843826450DFEB69E705AF97BD12A
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="701951" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Extensibility.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenOfficeExtensibility" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContract
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1359
                                                                    Entropy (8bit):4.847219471844708
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d97eDeuMt1k3BNjXMi+EsdnKE+2h6wl/FfIz:cdueuMteNjXMzbdKshBdQz
                                                                    MD5:9D476B531E8DA41C0A5ED4E239D6B608
                                                                    SHA1:CEDF64800042FA58EBB83A9A6DA5162A1DD33B1F
                                                                    SHA-256:12D10CC7648B4CF04A1CEE6AF9B6B30B590D26873F73877C9668FC547197536E
                                                                    SHA-512:213EEA422E997D180C4CF16782376FAB3592C4C760EE920F6BD33A24EC8F1B7835501F50F97C3D7D578FF8ECB9AD00195F14429D27C82417CD46D9ACFB2A24E4
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="702000" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Canvas" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenCanvas" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="W" I="6" O="false" N="EventType
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1396
                                                                    Entropy (8bit):4.883161848414622
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9wmDeuct1k3BNjXMi+EsdnKE+2h6wl/FfIz:cS2eucteNjXMzbdKshBdQz
                                                                    MD5:B9BF687E74025DF2569940711DAF8AA4
                                                                    SHA1:F1F57E2AEAA9204AD316F1D1EDB26BE44450A902
                                                                    SHA-256:FD24BDD9AF494E0FCBDE490252149BFAE30BC35127AE3C909FD268369C60FD3B
                                                                    SHA-512:75D8656D26F54680CA8EC75BCC88560512C26CBD99A0FEE8011D9BB33D98380C2C3CEBD937FD805FE31448EE66BA19BDF20FE1B6FBC557637AB042B0FB2D40AC
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="702001" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Canvas.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenCanvas" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1363
                                                                    Entropy (8bit):4.869360909608632
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9u3DBuMt1k3BNjXMi+EsdnKE+2h6wl/FfZdXxF:cgzBuMteNjXMzbdKshBdv
                                                                    MD5:DBE9893A8EB8023E809A3FAEB0656D89
                                                                    SHA1:18E6C669A5113B6195FC8896EDE86027E08F326F
                                                                    SHA-256:0A787B6B1FF8015C7F510D8F97225F543E4F834757E4B613B400ABEB9321AF66
                                                                    SHA-512:513E51894469C84C499A911CADA8F4515D5DFBB10D6FBE6A72B283FE9F5DB210CAC9D41E5CCE4B37548A8DA44BCD83C93AB0F25EF89BCF673BA549349C45D775
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="702050" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Insights" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenInsights" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="W" I="6" O="false" N="Event
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1400
                                                                    Entropy (8bit):4.903756644188613
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9pV/DBuct1k3BNjXMi+EsdnKE+2h6wl/FfZdXxF:crVBucteNjXMzbdKshBdv
                                                                    MD5:830779C0CEA72EA22A414EA90C901513
                                                                    SHA1:26FEF6C49EA022216364B168C99A4085B98E9D5A
                                                                    SHA-256:FBE85A3BBD77573CB3235D935CD94D69557985FD4EAA4B0598890738A8564505
                                                                    SHA-512:3440D27DD94649E43F1BEDDCEA1FE98761CF472AB1B519E68544126DF120FDA241C7C4FB1C4DCDC27DAA3752A49481C7F3B9528E23D38DB19146007CE1596A7D
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="702051" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Insights.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenInsights" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1370
                                                                    Entropy (8bit):4.8734818259143164
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d941DVhuMt1k3BNjXMi+EsdnKE+2h6wl/Ff4N2l:c613uMteNjXMzbdKshBd7
                                                                    MD5:DC825B13A6CCC5EAF723B80F00CB1C36
                                                                    SHA1:327A6AA4D8B560321FAA3CE760F00E805FFF0B4B
                                                                    SHA-256:795D06B04546DF2D59F7356036C9C3D2DC37A07A415E9A4C9D59A5F9C4379B12
                                                                    SHA-512:3C8C8C27EB6CDC9C83F3BA6200D26DEE35DB758DBBCEB04BCEB7589BFF780B7D8C01848F10D3922D80C89881EE28286BA81F7DFEB684465E2E951F0CC7AA7BD4
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="702100" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Excel.Coauth" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenExcelCoauth" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="W" I="6" O="false" N
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1407
                                                                    Entropy (8bit):4.907864691504703
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9jPDVhuct1k3BNjXMi+EsdnKE+2h6wl/Ff4N2l:cFL3ucteNjXMzbdKshBd7
                                                                    MD5:30BC05A755F47783B673F4EEE9870607
                                                                    SHA1:F07FF0D46443129C089104CE7FC3EE0413E1E74A
                                                                    SHA-256:B567447C4F609274D89CD110AA7EC79D6ACB7898D292995B652EB4E5AB290405
                                                                    SHA-512:1A10E82A3A34E8D156467D4C5F0C3E80ED7019C3DF9882FD6662E3923CCB5798037791DB1D7CAE81C555A513523BFE907180DDAF6392E27E48F077EE5AE0EB45
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="702101" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Excel.Coauth.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenExcelCoauth" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1359
                                                                    Entropy (8bit):4.8484339473244455
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9V1jDRpuMt1k3BNjXMi+EsdnKE+2h6wl/FfvnrQc:cP1PRpuMteNjXMzbdKshBdXL
                                                                    MD5:7FB0C817901D941800C481A38A8CC17A
                                                                    SHA1:20A20AC4CAAFFFE0E9D9B74F124CAD0058C125E9
                                                                    SHA-256:614BAA2D9917DBDE24110978D4092EA2FEE838FA45F2641C750DBF87F4E9A83B
                                                                    SHA-512:A7EA7E8DED442BAFD0881B47D2B276B1E991FB5B5E9C4DECE2AFC28158579BA54CEF6A8229BE20E35EF22AD4AE60D6F040633A5CFC197FDB946C7AD9869A6763
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="702150" V="1" DC="SM" EN="Office.Telemetry.Event.Office.People" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenPeople" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="W" I="6" O="false" N="EventType
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1396
                                                                    Entropy (8bit):4.883223789400444
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9K1JDRpuct1k3BNjXMi+EsdnKE+2h6wl/FfvnrQc:cE1ZRpucteNjXMzbdKshBdXL
                                                                    MD5:7656765B7584DFB783360CB8F47E5D23
                                                                    SHA1:B02517D35C9EA4260DD59935604E86986C5EBCC4
                                                                    SHA-256:4003F869317FCB9E17D98F904DAAF832F83140F4630F901E7186597144118F13
                                                                    SHA-512:4B7DAE54AB3F0C03F59C7531E660963F8047EB3481FEEC8F084FB5C947260ECE38E1E44581FFD9D9593CF64880661CF97A664365AB93ECD78AC66FD8777EADEA
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="702151" V="1" DC="SM" EN="Office.Telemetry.Event.Office.People.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenPeople" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1359
                                                                    Entropy (8bit):4.8521344178314765
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d99XDpuMt1k3BNjXMi+EsdnKE+2h6wl/FfiNH:cbTpuMteNjXMzbdKshBdaNH
                                                                    MD5:8B12A3BE5E9A298FD83BE50B551A8A32
                                                                    SHA1:6CF04E21824563B41B78A5B0C381503654E14091
                                                                    SHA-256:A567C13BDB63704D34B77F250A3C30DBCEB4CDE8C4DCFBCF8160CA73D0217021
                                                                    SHA-512:23503BFF85AAA224CE26A58C3B57A59D44AFCC7967197D70D8F71AFDA751D30E3C030583BE5F82B7A7C5D7781E6DA34F66EB4596D4C92387A0F9954B848DBD67
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="702200" V="1" DC="SM" EN="Office.Telemetry.Event.Office.TellMe" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenTellMe" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="W" I="6" O="false" N="EventType
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1396
                                                                    Entropy (8bit):4.888051950170804
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9y1Dpuct1k3BNjXMi+EsdnKE+2h6wl/FfiNH:cQ1pucteNjXMzbdKshBdaNH
                                                                    MD5:3CC524AD6BC477CD95CE494744D555EB
                                                                    SHA1:44D551654E1970DFC0E227E95249A9ADAE21666C
                                                                    SHA-256:ECD09824022E8907115AE81C5DA80797831985F1B5F96774652941004718C3FD
                                                                    SHA-512:D1859D24B9C102BFD5B29340E7EEB19ED8918C18EF537C797173D30E77643B2A479AC8B263EA5FD1FCC7FDE941D4EFBF71A5C272CEB3224EE3C6B60D6B63221E
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="702201" V="1" DC="SM" EN="Office.Telemetry.Event.Office.TellMe.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenTellMe" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1351
                                                                    Entropy (8bit):4.8450235834940685
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9A7DluMt1k3BNjXMi+EsdnKE+2h6wl/FfGz:cOHluMteNjXMzbdKshBdez
                                                                    MD5:CFE543816FFD6673341C7391165B29FE
                                                                    SHA1:26DB9A356E6D6F7C398B75079965030BC830FCFB
                                                                    SHA-256:978FAC4DE66D33F98198203B490D7588A69C71604FF1373F889212E24ABE231B
                                                                    SHA-512:527251D533D7B7D434F1F4CB29A7EEC8B241DA7A0E2204449DA9E81A0C5EE3FAC824F412D6F8B6FC22FD6EA7362672709D8E37BC63CE22BD4E3C033C5BD3672C
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="702250" V="1" DC="SM" EN="Office.Telemetry.Event.Office.ML" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenML" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="W" I="6" O="false" N="EventTypeInfo">..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1388
                                                                    Entropy (8bit):4.882059181952758
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9vjqeDluct1k3BNjXMi+EsdnKE+2h6wl/FfGz:cJqulucteNjXMzbdKshBdez
                                                                    MD5:4D6D96F7C89EF1BCD191FEB18744511B
                                                                    SHA1:D0F5AE7A901461C509B1CCFE216F057B812B35FE
                                                                    SHA-256:A113433CB369766811C09887D0DDF5117CC7A178489F0DB0C4D1F5E9DEA8523A
                                                                    SHA-512:B7A2EBECCEC4A12F71D9E5628150EBC6F86E169132BDF40EF0F04397A50F82CA1C28E5C929A99E940F217155BF5FB04A889BEFC22CF62EC11A999526B16694F8
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="702251" V="1" DC="SM" EN="Office.Telemetry.Event.Office.ML.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenML" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="W"
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1361
                                                                    Entropy (8bit):4.8575454867833265
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9aLDVuMt1k3BNjXMi+EsdnKE+2h6wl/Ff3:cY3VuMteNjXMzbdKshBdv
                                                                    MD5:CABB0385BB66E5DC371590623C32ED02
                                                                    SHA1:8E611EC8927D51B6CE947567E6D5985ED47B2F78
                                                                    SHA-256:618F8D832BD4F54B016BC090E98A60508D564286BD81BE049071E209CD7F12F4
                                                                    SHA-512:A109475FD973D3C123190F315732095202770AE5A3549D5A3F1685C27E7C091E4B714F264692EE9804DF78EBF242515C395687A2C74691441E7A99F5DBC676D2
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="702300" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Project" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenProject" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="W" I="6" O="false" N="EventTy
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1398
                                                                    Entropy (8bit):4.891463643270291
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9lJDVuct1k3BNjXMi+EsdnKE+2h6wl/Ff3:cDZVucteNjXMzbdKshBdv
                                                                    MD5:750A77DD35B8545C846C702F05340D54
                                                                    SHA1:D65AC0B396D633D53C9FF88E72F232CCE5EA14B9
                                                                    SHA-256:293B3954DF0FD4372B74F7FACB28D7F7FB746B91654C1C439DF8E09B3CFE38CF
                                                                    SHA-512:FC6870B552E62F7A750CE234A9D07E4D95F29F7B05A693993E6D7F0926D98528C3921E5AA97D91382F063ECC81AEDE1E5B37E1A33A4D9C0A04E99E0AC09F62C7
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="702301" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Project.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenProject" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1357
                                                                    Entropy (8bit):4.860956043026469
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9v8DguMt1k3BNjXMi+EsdnKE+2h6wl/FfmS8ec:c1wguMteNjXMzbdKshBdOL
                                                                    MD5:1CE5913AF2B5F72E0B0F8EAB0BE8E266
                                                                    SHA1:4B566C33DF3EF0548F6F71C1ABBD6EFAE3011E73
                                                                    SHA-256:D997C5C6E2AA2CD9E2ABC3014D72396B85CD4B43E978D4546A7003D0B440D684
                                                                    SHA-512:F3B148F87E9FD7C5765543C35D6DA00B1CC2E03EA3D763FD024D5ACD18414D96F09B51EB07A57EB2EF04CE24F36249235627474BB85500F9861A5367307245B6
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="702350" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Voice" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenVoice" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="W" I="6" O="false" N="EventTypeIn
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1394
                                                                    Entropy (8bit):4.896099533418246
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9k1wDguct1k3BNjXMi+EsdnKE+2h6wl/FfmS8ec:cK1UgucteNjXMzbdKshBdOL
                                                                    MD5:E0C15863E759C7F593DC1A04CB4475A6
                                                                    SHA1:B864E5843A5C58927A419EEE43EFBC2ECE5F8455
                                                                    SHA-256:1CD727AFC748A855C207E875E57E67987304A5B9F5BA0F0E65321EFC9E84A73F
                                                                    SHA-512:A32D2FE4E4842956D406F32D734E34CAB83A1033D46D98B207C8305051B3403F6B750CED2A2B43FC6946E9B80F4A3FB9EB1C3B10D1A37636A1FE6D9B7020F8F3
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="702351" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Voice.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenVoice" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1367
                                                                    Entropy (8bit):4.8601857535171655
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9/XNDGEXuMt1k3BNjXMi+EsdnKE+2h6wl/FfOnEc:ch9juMteNjXMzbdKshBdML
                                                                    MD5:D38B0A5D5BACC4183C16D4658431C5D9
                                                                    SHA1:CC870E920915F5DA9FDBC177F3ECA66111BF40D2
                                                                    SHA-256:F12AD7AAFE8A663CDED48BF5AA3EF9AAD334EA1254FC59E304ACD2533DB36E17
                                                                    SHA-512:AFD26230A1FD7BDE585B326115689B92F8982E4F004195276666E241603D95D8E1360C11AAE6C361F3C19DE097A2B2EC0781A7815E5CBD6DAC33A1C75AF7ABBC
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="702400" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Compliance" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenCompliance" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="W" I="6" O="false" N="E
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1404
                                                                    Entropy (8bit):4.89369333887998
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d90XXDGEXuct1k3BNjXMi+EsdnKE+2h6wl/FfOnEc:cmDjucteNjXMzbdKshBdML
                                                                    MD5:822794C66A8AB57B7AA0200FBEA87C4E
                                                                    SHA1:A4780F7FC418F55D5C1C9919FE872FE00CDEBE68
                                                                    SHA-256:FAF758BDD27A5B3FF78764346495D2E2CA2F4222A106E3F46E156165C03191F0
                                                                    SHA-512:82614AB16D86118F63A88C6848FAA788EE4F1E82850F40039ACA76A899EF48077833A5DDCFBEE8489234326944ACF92CE2856B3C898C80D2565689397AC1E609
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="702401" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Compliance.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenCompliance" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1359
                                                                    Entropy (8bit):4.857265439256473
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9qEDAuMt1k3BNjXMi+EsdnKE+2h6wl/FfsQkRc8z:cMYAuMteNjXMzbdKshBd5kRcC
                                                                    MD5:14DED8518922A53B7923A9BE2CCCAF26
                                                                    SHA1:DFF3BBB86A2CAF886F54C1ED90C5823E112BA975
                                                                    SHA-256:FA5488CD9A6BDDE6BBD5F97F5787E168E1F0963EB6BB582DB43846A978F750AD
                                                                    SHA-512:FDD3D07BEAE92AD18F320DEB051AD85313556372C4F4935F5ECF2E88981F14433942E423C016187FCA2F91AD0A81FA6D57578BBF256C90495A8E46E4DCA79C8B
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="702450" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Access" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenAccess" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="W" I="6" O="false" N="EventType
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1396
                                                                    Entropy (8bit):4.891847134561355
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d91IDAuct1k3BNjXMi+EsdnKE+2h6wl/FfsQkRc8z:cXMAucteNjXMzbdKshBd5kRcC
                                                                    MD5:9D6AAD18C5340CA0DFE89276C63F1A38
                                                                    SHA1:08428AA083261A4E0A85C7237B05526E5BBC030D
                                                                    SHA-256:3252787E6DB6D6F4D5284F5D403C8D020EA1845E217B127CC34D645168ED6813
                                                                    SHA-512:85B57E30D183C8831A23D0B1C2513F0044F681AB68D5DF1F9419F3928925BA28E356F20DE63BC444896FB2F2E06601C2E76F26192CF2019D3B2B6BAD902C132C
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="702451" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Access.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenAccess" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1377
                                                                    Entropy (8bit):4.874186173241039
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9chD/uMt1k3BNjXMi+EsdnKE+2h6wl/FfiGS9:cOR/uMteNjXMzbdKshBdPc
                                                                    MD5:EDF0612FFF076A8D46C063D2D312CF7C
                                                                    SHA1:8898030DE0AD851893A1703C3936637C095D7C14
                                                                    SHA-256:D4417BC67DF4A3189A4030A211799F6DD097841A9D4DF6B64C5DE04451308901
                                                                    SHA-512:E51611AD0CB8BACBF2B082A65091C24AFFD150012F199509D5BC669752E8CB7E3753B3700A9FCEE93B7DE16932B95957F90FA5F1BD2F733211CCC2648206C531
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="702500" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Programmability" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenProgrammability" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="W" I="6" O="f
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1414
                                                                    Entropy (8bit):4.905863048995714
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9nrD/uct1k3BNjXMi+EsdnKE+2h6wl/FfiGS9:cJX/ucteNjXMzbdKshBdPc
                                                                    MD5:64BEA3D5636B437D569F3F6DACBE8B73
                                                                    SHA1:B04054A0A4E64234B6378179DBE0176AC2199922
                                                                    SHA-256:BC5E11806B5118AC6B6EAA7E8EDD234302D418A379377467D183D7AEC6605020
                                                                    SHA-512:D1C18B4DBF70B864BB877AA1B2F77CCD5EAC6D47242918AB1706B478646CB36F0D4F2E31CDC46841D45AB29269B045218E99B441B6A8AAF26A997B65B6C50E87
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="702501" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Programmability.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenProgrammability" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractIn
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1377
                                                                    Entropy (8bit):4.86968935598947
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9Jj0jDApuMt1k3BNjXMi+EsdnKE+2h6wl/FfeX4WGVSH:cfj0PApuMteNjXMzbdKshBd17Q
                                                                    MD5:7E769AA0B30512CAEA169E76720A8BB6
                                                                    SHA1:A106C3EA653C018707822D56D1D55D3E9C1CEDCE
                                                                    SHA-256:CF387A3BF6721E44C234F0FBC1D450C301E9C4C73F38D9353CC79E182724CE04
                                                                    SHA-512:8914A2DBEC611B84E8106BE670C5B88D883276217B069A4245EB86E5F061E57C623CB57BEAFF09470F23F038187311F8487C416B58B38034147908E0D79A49C4
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="702550" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Personalization" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenPersonalization" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="W" I="6" O="f
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1414
                                                                    Entropy (8bit):4.901920052386891
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d92CDApuct1k3BNjXMi+EsdnKE+2h6wl/FfeX4WGVSH:cQCApucteNjXMzbdKshBd17Q
                                                                    MD5:F16096A8504154B1BA78953D9AA77970
                                                                    SHA1:EE25EDB8E4E0E2036B021DEABEFDC33FD02EAC1A
                                                                    SHA-256:EA3FD83EC8EC8E89BF29A1BA2A3AE67EB676897A6790CAEA162394D9945B3B35
                                                                    SHA-512:18C43D15FC52A8F7BA3D345E500ADD6BB6B7FE764E5DFC7ACC8B8ADFD2F1F26CE5264EF2462D87A70C22ABC04417669EBAFA84B69A10A136489EC4F3F5F4DABB
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="702551" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Personalization.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenPersonalization" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractIn
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1371
                                                                    Entropy (8bit):4.865695804192339
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9BjDFuMt1k3BNjXMi+EsdnKE+2h6wl/FftI:cfPFuMteNjXMzbdKshBde
                                                                    MD5:44EA22233A3BA65F69A91CBFC74EE941
                                                                    SHA1:11A54DEA94DB48356C769DE7DACC88F8344CE53F
                                                                    SHA-256:177467AC052CFD3F1A38BBA0A883F78E11B9753CD5DD9818B4CEA7E5146540CC
                                                                    SHA-512:9C1BC17CD7C0F7F60E12CAE9F9CB78C1E6B6FF41302AA22C2296E4F7BB392DE058D1E177E56A7E6B79BFF7C6870D49995BC69D8120CFD45305B7BA86FE4A23C5
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="702600" V="1" DC="SM" EN="Office.Telemetry.Event.Office.AutoTemplate" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenAutoTemplate" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="W" I="6" O="false"
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1408
                                                                    Entropy (8bit):4.899679787486778
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9GgODFuct1k3BNjXMi+EsdnKE+2h6wl/FftI:cUBFucteNjXMzbdKshBde
                                                                    MD5:760048411FFA7EFDE7E6B8ED20A65494
                                                                    SHA1:B1E404A91A80EF2C6C2C27F9A668FEF563A6AAE5
                                                                    SHA-256:F0212114B2FDD6CDB24B551C7D6BC8D2C3D29EC76EF1B38084024CF56115E6DB
                                                                    SHA-512:9B12E04EC7FC64D55E554C8DDA522D499C7D5B22A6B924A8459BD7906227EE8F0AE1B922858E2D7A949B48DC40155115056D57942D1D35753A66E9FE2D4E706F
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="702601" V="1" DC="SM" EN="Office.Telemetry.Event.Office.AutoTemplate.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenAutoTemplate" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1357
                                                                    Entropy (8bit):4.848587052076145
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9WFiDquMt1k3BNjXMi+EsdnKE+2h6wl/Ffo+p4i68:ccFiquMteNjXMzbdKshBdHpf
                                                                    MD5:CE95C0A8A6ED5C107AD72EDC361BB27C
                                                                    SHA1:687FC63DF62E09A10C2715E713628972BF77803F
                                                                    SHA-256:D4D7BB7E1C072B2841268133186FC32E29405816E0654A34D1AFC418E67142C9
                                                                    SHA-512:5691EC54B9C1AFA274B472C14D2753C9A1C48A1038DE5389A10B9E28B8C863AD772A0DDBDEBC24AC6F41B98A988C31F78C0CDB390133582DA2BC4CA9F1E6CE6B
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="702650" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Media" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenMedia" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="W" I="6" O="false" N="EventTypeIn
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1394
                                                                    Entropy (8bit):4.884966778735232
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9W6aDquct1k3BNjXMi+EsdnKE+2h6wl/Ffo+p4i68:cc66qucteNjXMzbdKshBdHpf
                                                                    MD5:AAC474FF69C74EA0705CA7978F9E59F4
                                                                    SHA1:AD3C65C507A6DE36B105C97E5056EB120F516329
                                                                    SHA-256:F9F1E41E5C8832E20DB14D6F40A864F362BECB494B24559E32089E846487253E
                                                                    SHA-512:99B3CD319762C4E52712138096A4B2B2EE62AE9A6799A78562002BDF5CD863BB99AD4095D1F34E00E52734F9AE89EE2DF89A2BD5BD9AE170ADE08AB76526875C
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="702651" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Media.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenMedia" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1366
                                                                    Entropy (8bit):4.8662369056062404
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9wrsuDpuMt1k3BNjXMi+EsdnKE+2h6wl/Ff8EcK:c8sepuMteNjXMzbdKshBdUED
                                                                    MD5:AFE1F0B2C50217E7CAE443AF21136F34
                                                                    SHA1:AA679F19A69C907653C3A3FB062EFA0C9BDEDA88
                                                                    SHA-256:5BBB64A464F1F1B58A42D578BD57D9836601B313C009F9AF63E9DC301E1AA208
                                                                    SHA-512:CBC2D975370FB099552E29E9A5A07CDF676F1AF61498E211B6AA9F5DA98BD5128C97F216771260898A420F9A1582EB26AB62FD8E88FE38FE9619210AEA78EAB6
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="702700" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Docs.Apple" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenDocsApple" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="W" I="6" O="false" N="Ev
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1403
                                                                    Entropy (8bit):4.901234050569788
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9wgs0JDpuct1k3BNjXMi+EsdnKE+2h6wl/Ff8EcK:cHs0ZpucteNjXMzbdKshBdUED
                                                                    MD5:AF325C9B941D11C9232D4400E589A834
                                                                    SHA1:42A1AE4434F085D0442E9B359F5064AAFC0DC252
                                                                    SHA-256:E1F72F3EBD439D87AC24710E5E20D47B188D29943CD627C90BB363CD3E8AE667
                                                                    SHA-512:4F50A3A296E831322401A5B493E8E403FEA02FE2612A5668D994B5AA0AE9B995F24E7D1472D61544F6F6952DDA73B8E62E337589CD164E36077DBD64A4D03937
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="702701" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Docs.Apple.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenDocsApple" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. <
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1365
                                                                    Entropy (8bit):4.874109702881827
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9weSDKuMt1k3BNjXMi+EsdnKE+2h6wl/Ff1xs:cRyKuMteNjXMzbdKshBdg
                                                                    MD5:64BF386BD9E91986551188D6A17C0411
                                                                    SHA1:D2C6EF24870049E6C4B0593856D56B75801202EA
                                                                    SHA-256:B976BF8C7EC165D88D602B113982457663A718EEB63B1B97A0B019E2AEB0CCBF
                                                                    SHA-512:297F46DFE20739BFB328B6DCE2B362B08FC82D0BBDB676406197AAC7383635D886F9F7F185C66ADD4C66C57461EA32D513B56A56DE2A01C91E013C2F57A9F7D8
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="702750" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Publisher" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenPublisher" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="W" I="6" O="false" N="Eve
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1402
                                                                    Entropy (8bit):4.907444238942649
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9wZzeDKuct1k3BNjXMi+EsdnKE+2h6wl/Ff1xs:cWKKucteNjXMzbdKshBdg
                                                                    MD5:07DA5CB0EB4215C6E66251D1D915B103
                                                                    SHA1:A56A946240961B6739153B266E6F68A03B18B946
                                                                    SHA-256:D6750361BA69395D8E827B93D0E350235CFB7E6DBCBFF632BCC8646D687CA00B
                                                                    SHA-512:910CD40650AE804DE0D12DB3688326B04A64000178F119CCE76A82E25893336DC2FD45F34C1B1BA71E53FFDD8A3A0BED52CAE6B7AC25B053EA9065E521CFB5F2
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="702751" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Publisher.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenPublisher" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1353
                                                                    Entropy (8bit):4.853435750554847
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9zXD5uMt1k3BNjXMi+EsdnKE+2h6wl/Ff1e9:c1T5uMteNjXMzbdKshBd9I
                                                                    MD5:53429B1DCE25B171CD3B10FB2ED28490
                                                                    SHA1:B07A6E17CCC2A61CA88373A72461A5366C0B78AD
                                                                    SHA-256:88723C7BEE9F58E5B21C44BEC8AC6D815B1966050D7D195FCC2A50467D0B7AD5
                                                                    SHA-512:A38576D1E27CB258041904B9F702F4F82C61E00204824A804674F3C91C3AB818EBA5C9E0AA2A16C058263F4619FBA2753D7573184A09D1E63144D2DCB5099DC8
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="702800" V="1" DC="SM" EN="Office.Telemetry.Event.Office.SDX" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenSDX" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="W" I="6" O="false" N="EventTypeInfo">
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1390
                                                                    Entropy (8bit):4.889693035476156
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9Aj1D5uct1k3BNjXMi+EsdnKE+2h6wl/Ff1e9:cq15ucteNjXMzbdKshBd9I
                                                                    MD5:E816090F522A6E3DD7BAA2BCD68954BD
                                                                    SHA1:7F4D28269BB944EE40782F11AE3F064EF687A138
                                                                    SHA-256:5FB01AD53F0E2861A8487BA66E0793CE50181A69F7BA5B8FBB1C5B350199A18C
                                                                    SHA-512:19C235A9679F8B6E2C92903C78DC00F68B56674E40D01B434EB2F145468440B4728CE1B319F50553FA6C700439093CD5388691ECE15C0A5249D1D6E6C64A969F
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="702801" V="1" DC="SM" EN="Office.Telemetry.Event.Office.SDX.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenSDX" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1367
                                                                    Entropy (8bit):4.864270560319576
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9mVDfLuMt1k3BNjXMi+EsdnKE+2h6wl/Ffdd:cYVfLuMteNjXMzbdKshBdH
                                                                    MD5:1D773D3AF285F5118515600DD911BFCA
                                                                    SHA1:E20155A71B9AE5B75E3A611EF1C3410B17A8B7E1
                                                                    SHA-256:A230DE9B438B55732875A58C8DE6D074C14AFC7096B49702C85F54FF43757F5C
                                                                    SHA-512:AC932050B91E59C53984A2454DCE6C86309021598B5BE8B5967E6E1C1688599621C381E09C5FF36BCDDFF23B7EA2FBF7A1F0198745AC4E23BF935A1FE14A6A54
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="702850" V="1" DC="SM" EN="Office.Telemetry.Event.Office.FileSystem" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenFileSystem" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="W" I="6" O="false" N="E
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1404
                                                                    Entropy (8bit):4.89890901835996
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d95D+ODfLuct1k3BNjXMi+EsdnKE+2h6wl/Ffdd:cnD++fLucteNjXMzbdKshBdH
                                                                    MD5:D5ECCBD7AA02D7C554E2E2090DAA48AB
                                                                    SHA1:6CDA18520E3B88AEA015759E8890B17F369F4BD5
                                                                    SHA-256:10827F68053A4626910C4CFF518EE6D262611CDCA7BFA58BFB026E981A4EFCAD
                                                                    SHA-512:A37AB861277CB1F2987FF5F65D60FF77F631D83B2D596CB25895038FA33077FFC1F9E10E4B4974FF38BA9F82E54AD6C445DE709770452DCC50E3B39F02A94776
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="702851" V="1" DC="SM" EN="Office.Telemetry.Event.Office.FileSystem.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenFileSystem" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1373
                                                                    Entropy (8bit):4.866360064001697
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9QbCy3Dn5FuMt1k3BNjXMi+EsdnKE+2h6wl/FffkNH:cSbpnLuMteNjXMzbdKshBdOH
                                                                    MD5:0D9907663B5829E7ACC504F697A70EF4
                                                                    SHA1:8C85C0173A1861B6C62DA9B040A42D9736AA009E
                                                                    SHA-256:6A2EA9732AF530ED2B5F53726455E22A03FA2F1350DB86A30D7CB92778992245
                                                                    SHA-512:D49E061429473AADD9B9338417B736320DA91B7E9F162D4B4A695249C62C0AA4523A1DA4AF4EFC1930AA1F71AB0B23CF2CB2F1F6C1B2AE416A36CDCF05341E53
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="702900" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Manageability" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenManageability" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="W" I="6" O="false
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1410
                                                                    Entropy (8bit):4.9005604200237975
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9uQbCyVDn5Fuct1k3BNjXMi+EsdnKE+2h6wl/FffkNH:ccQbfnLucteNjXMzbdKshBdOH
                                                                    MD5:856B1A968638299EAD00ABF6E7EF741F
                                                                    SHA1:B01A7DEDAA4E093DACFA8431363807D85D05FEBA
                                                                    SHA-256:50EBC398555FE89CB0A37E45BDECEECC4F7A7BB644530FB2B76F94F6891661B2
                                                                    SHA-512:6A49535E200E8E0AC00D81D86C3A0D3851EE72D39DE272C2A10C92EB067170AF6C61655EBA08E1EA6524A090DEC9D0F2E37F85A1CE7ABD58C6533B559ED2BD65
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="702901" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Manageability.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenManageability" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo"
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1367
                                                                    Entropy (8bit):4.848792627939081
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9N92DJiuMt1k3BNjXMi+EsdnKE+2h6wl/Ff+8o:cn4QuMteNjXMzbdKshBdGN
                                                                    MD5:851F6F8B8B7A6E3D931ABFDE1F6900FF
                                                                    SHA1:988B6B78351513E1BA63CD204251B4F628148B25
                                                                    SHA-256:DAB5941E15D0B7FDFFC854F7C386E79BE57EF123CDE6C65563A5B2A6D70C3736
                                                                    SHA-512:1079C0957C6370DBCF488645CACE78E433BB4D3AD11B3262628556DFD4C5FA32844595FB612621A82271282F28E49921C7505CDCB4BAF9B649C8D79BCDE46EB1
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="702950" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Translator" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenTranslator" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="W" I="6" O="false" N="E
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1404
                                                                    Entropy (8bit):4.884123808992733
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9S193eDJiuct1k3BNjXMi+EsdnKE+2h6wl/Ff+8o:ccZuQucteNjXMzbdKshBdGN
                                                                    MD5:5407C855C4FE9E79664D49DA8B30BE96
                                                                    SHA1:7A2D82905D2CAA0F7F2E0177739885D32C3D921A
                                                                    SHA-256:A58630F62679A47FBD477197285083C0F1CFD4D0597C23EF653EB7109164A8EA
                                                                    SHA-512:F696C5343FA6118F16D2473D46856DBF28A37BF513E17514EB076AF76BC27FDF119E423A59880467F812A90AE1D30AF9CBC01C469C45DFC8092A4DC11C828B0A
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="702951" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Translator.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenTranslator" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1368
                                                                    Entropy (8bit):4.860904905531245
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9K1zgDXcuMt1k3BNjXMi+EsdnKE+2h6wl/FfHWCE6:cMzkXcuMteNjXMzbdKshBd+CE6
                                                                    MD5:026BBE4C1EB10588938F3A662B6AEA3D
                                                                    SHA1:48BFF05EB5FA808C71335D8831E9B9D56CBB2547
                                                                    SHA-256:DE1C44D033E13DE75C9287BEEF9BADFE0B2EE152EDB8ABB693607A5F0245736D
                                                                    SHA-512:1B797145EC54FE0518C9229366A5138D244D4826A7C3C43E6219F2643978CE3D5CAA3D63D60A7FCCBDC454BD2EB3026D34BD445302A1CA168F170A266B3C100B
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="703000" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Outlook.Mac" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenOutlookMac" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="W" I="6" O="false" N="
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1405
                                                                    Entropy (8bit):4.894903657691117
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d91zUDXcuct1k3BNjXMi+EsdnKE+2h6wl/FfHWCE6:cXzIXcucteNjXMzbdKshBd+CE6
                                                                    MD5:C5AF174C3F9F271FF368C6006E65AAC4
                                                                    SHA1:6B816E248743E47A6316F9BAEC3BF7F0E0BA6392
                                                                    SHA-256:71003E14585F42EE9FA5850585728E60F5537FDAD3D7B35144FED37AC3CE0EBA
                                                                    SHA-512:0AA4E7D9ABC010747C1B7CC24CD80A7F2C83C5E7F54E0DE7320712B079D4628C1CB94C4745942C2F0E9063B034271358CE5F9E18DCCD60559B2CFF541DAA5C73
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="703001" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Outlook.Mac.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenOutlookMac" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1390
                                                                    Entropy (8bit):4.890103420426988
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9r18DEuMt1k3BNjXMi+EsdnKE+2h6wl/FfG0El:cHwEuMteNjXMzbdKshBdTC
                                                                    MD5:7D34A851A603CF1D0311FF1A556079DD
                                                                    SHA1:30F8F484CD7B9A41E8093831A786E7BDA76D273D
                                                                    SHA-256:1C993DAB7FFA80E62A8866E63244AA039F21AE2564B974F8CF9CD0F16B5D2620
                                                                    SHA-512:AB5491623D6C95C1CC9DA65087E89C07BE1D2D525B53A84B5E18FAC7E1BE5C69A5E00CC08C1398E7139098FBDAE24742B4DC77EA914BAB0DAE337FF10DBCD11D
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="703050" V="3" DC="SM" EN="Office.Telemetry.Event.Office.Excel.InsightsServices" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenExcelInsightsServices" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1427
                                                                    Entropy (8bit):4.922148272354155
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d901wDEuct1k3BNjXMi+EsdnKE+2h6wl/FfG0El:cMUEucteNjXMzbdKshBdTC
                                                                    MD5:09F7F4554846D917D939007CE5A32F0E
                                                                    SHA1:06D0618014C9DB9B3CA0ABC75C5BEC0929700B4C
                                                                    SHA-256:FE8010EB040113BD25DB7D7B6ED00DF1B3D55BEDC1F80E101D57DB52FC5EA445
                                                                    SHA-512:561BD028655C17CC1EDC69F8B8197C47034B0EFC2B3D03E45D7463B4B74A5E99F669EA062355FD1434FD7D652ABACDEED7E617AB14F608960BF3A93F5EA49838
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="703051" V="3" DC="SM" EN="Office.Telemetry.Event.Office.Excel.InsightsServices.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenExcelInsightsServices" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="Ev
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1355
                                                                    Entropy (8bit):4.838395899121383
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9NZDfuMt1k3BNjXMi+EsdnKE+2h6wl/FfAzgmEc:cvJfuMteNjXMzbdKshBdIUmL
                                                                    MD5:40B49E7382E51BFC1B22F2E813C7BDC4
                                                                    SHA1:B54D93EE22E1D2BF7CA74A2C45DD5325E3D214C1
                                                                    SHA-256:8CFABCB91E29E13955341C68E77655F21ECDC9166C85391E8A515B651DE02CEC
                                                                    SHA-512:618748254F8E096247A590054FC81A03A9D0DD1B6AF8B6A73531EBC800185BA8980801DB07BABDA931A8E8B75A53778F344CCFC91B8203FA86D775374B962661
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="703100" V="1" DC="SM" EN="Office.Telemetry.Event.Office.MATS" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenMATS" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="W" I="6" O="false" N="EventTypeInfo
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1392
                                                                    Entropy (8bit):4.874935439748928
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9CzDfuct1k3BNjXMi+EsdnKE+2h6wl/FfAzgmEc:ck/fucteNjXMzbdKshBdIUmL
                                                                    MD5:03ABF772886BBBB0ADAA2A1024C13E4D
                                                                    SHA1:010FA3AD6A6174599D27947A79A0F7C2C9690E69
                                                                    SHA-256:ED848D97D02F997B2805760E5D162D94B1A6EA36425740421090F05D7FCCD76A
                                                                    SHA-512:085B5D413A7F89DBE4490D519F652AF58756FB49FD78756159C7B443F2DD6C5B384051762C4E78AFE0C97E08E73BC0AE94146C88DA64B29148CB0F301BC0BDF7
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="703101" V="1" DC="SM" EN="Office.Telemetry.Event.Office.MATS.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenMATS" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1373
                                                                    Entropy (8bit):4.866844555220709
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9+RPjD7puMt1k3BNjXMi+EsdnKE+2h6wl/FfVQ1o:cYRPP7puMteNjXMzbdKshBdG1o
                                                                    MD5:5223B1A215A6C37054AA8133B58F938E
                                                                    SHA1:AC6AAB30131AC1D9356D2BC77F3DCF57B9B149F5
                                                                    SHA-256:9B0A039141EB8D1094A6FC7E2B69E99385AE210C51654566BE240949C73AB3EB
                                                                    SHA-512:920E31B4084B94624421007D8F90FC9434FA4339203CAFD32C12634AB66EEAF87991253B8C381B9D2D5341C63A66B86226331A0F267B45E63F2D62021E6C8AED
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="703150" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Globalization" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenGlobalization" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="W" I="6" O="false
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1410
                                                                    Entropy (8bit):4.898899268686255
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9bpD7puct1k3BNjXMi+EsdnKE+2h6wl/FfVQ1o:cl57pucteNjXMzbdKshBdG1o
                                                                    MD5:BBE18D80D907C0B0E55A87AA8840CD85
                                                                    SHA1:37BF7337AA5CD23DC51085F941415FC81C2DE1D6
                                                                    SHA-256:A46D40068E5AD986139CD19A20DFAFAE3DB13DB9D37B99071D5A42B6F31C34DA
                                                                    SHA-512:4B5CD1C1ABBE9713BFE21E463058C17C158315E9DEBD8CA84E60D10D385C9B9B6725ADFFB5AFF6FD9C74C4C2A7049E81291348C67F229A1932EA3008C3EF12BB
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="703151" V="1" DC="SM" EN="Office.Telemetry.Event.Office.Globalization.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenGlobalization" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo"
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1361
                                                                    Entropy (8bit):4.8754299888628925
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9IUUDpuMt1k3BNjXMi+EsdnKE+2h6wl/Ffj9G:cejpuMteNjXMzbdKshBdw
                                                                    MD5:F0CE8F7747A2A80487D3C870C15952B3
                                                                    SHA1:F6A7B00D1162D9763F6A591FDB7390FA0195B70A
                                                                    SHA-256:8947B4CC3C0862D8AB36A7CD8A792B6D7DDA852FAEC09213A974C43FFA917292
                                                                    SHA-512:D67E5A9C1CCD9C0716DF32A744E98F7ABBF2B9CECE2FD3C5CA46B496D4808B91BD3236A98F26E38360DC942FCBDD02754EDFDA8BB89977A7282C94F6F83CCE08
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="703200" V="1" DC="SM" EN="Office.Telemetry.Event.Office.AugLoop" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenAugLoop" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="W" I="6" O="false" N="EventTy
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1398
                                                                    Entropy (8bit):4.911190538820968
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9zlDpuct1k3BNjXMi+EsdnKE+2h6wl/Ffj9G:cZFpucteNjXMzbdKshBdw
                                                                    MD5:04DD2251CD07AFD0A3B5C302E3DF5571
                                                                    SHA1:145D11D0F87AA6C5AA8F655C8340C83582F00EAC
                                                                    SHA-256:50102D04B4AF640640DB5638F61529A4D6860299F4DDFD51DCDADC436C3045E3
                                                                    SHA-512:A9B9233E3D9FCF4E3670D8CCC8A586228E696C74898A8FA981BA86D2BB8B9D6E34CD436579FEE158E475194C82C325E7F12CB06221A9827D9E8DFDD14AA007BC
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="703201" V="1" DC="SM" EN="Office.Telemetry.Event.Office.AugLoop.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenAugLoop" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1359
                                                                    Entropy (8bit):4.858209494900091
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d91DLD9uMt1k3BNjXMi+EsdnKE+2h6wl/Ff389Up:cr39uMteNjXMzbdKshBdP89K
                                                                    MD5:492AE2EE576C8819345087F6FEF9D84D
                                                                    SHA1:E3082AC9757B5C3161E56CD93D2DF6F5539ECE31
                                                                    SHA-256:2ACB4D158A03C29DDAFEB3AD9555908568CCED9C1F4158A1D40241B066F8F4AD
                                                                    SHA-512:93966AFED0AE6C87FCD5BF47E77643E52788D092220950B60B595FF4F34978F604B064FD278756CEC946F3F7AA2523C60B7AA3E9EBEAA13425F455F86AF4C6A2
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="703250" V="1" DC="SM" EN="Office.Telemetry.Event.Office.CoreUI" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenCoreUI" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="W" I="6" O="false" N="EventType
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1396
                                                                    Entropy (8bit):4.8934439311342315
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9YRJD9uct1k3BNjXMi+EsdnKE+2h6wl/Ff389Up:cgZ9ucteNjXMzbdKshBdP89K
                                                                    MD5:FEA9571104FABC4FE14D19EE23DA2FF6
                                                                    SHA1:4904F1A791F6CB57ABD8B38C58D1304A4627C910
                                                                    SHA-256:A2D6B14C6BB86CD33463566E04157C9CC96E8A9714BA50C06DE0CD7F2B60EF45
                                                                    SHA-512:5469FC47711235C85900E5D6851372DE735C58B828521D12E24BB339C641E65FF324DBB156311A0946A0A43C4FD49D4FF1BAAEB5F767269B70F87F0171D3B108
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="703251" V="1" DC="SM" EN="Office.Telemetry.Event.Office.CoreUI.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenCoreUI" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1381
                                                                    Entropy (8bit):4.868924601340603
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d98rD0DcGguMt1k3BNjXMi+EsdnKE+2h6wl/FfiOW:cC4cDuMteNjXMzbdKshBdaOW
                                                                    MD5:C701244AEAB9D2037135EA2BF1A33290
                                                                    SHA1:0E8EFBB54AD75DB628F101285AA381B762BD3BBE
                                                                    SHA-256:1CC71E6C5084DAF260C252042C891A3E452C2B1FD2D0E10F4916A15253879BDE
                                                                    SHA-512:C87D27DC5BDB1A68568A048BC02E8955326F2D7EF2FCF106FFFC4F3CD5E7AD1C84D88DCF0403C522B1AB80999C8240E04D3EBE9C5C586487A1099F02C3795570
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="703300" V="0" DC="SM" EN="Office.Telemetry.Event.Office.AirTrafficControl" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenAirTrafficControl" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="W" I="6"
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1418
                                                                    Entropy (8bit):4.902831236582554
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9PrcDcGguct1k3BNjXMi+EsdnKE+2h6wl/FfiOW:cFscDucteNjXMzbdKshBdaOW
                                                                    MD5:C25838065FD5367CAC961906C9E0D83F
                                                                    SHA1:4F217AAC1EE6F06F7D7FCE941B237A9018ABD98D
                                                                    SHA-256:CFE1C6E451FE036846B65625630D1AAA9CFFECE4752534466DAC9741545801E6
                                                                    SHA-512:03DC16C2D2EEDF83C2E37432D48ED1CAD5E49067495C2DF62EFD76B996CD7533D29DC721C71A17B7739ED9D184BF02D7FB447C834B9264CF86754B5CA8E1F537
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="703301" V="0" DC="SM" EN="Office.Telemetry.Event.Office.AirTrafficControl.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenAirTrafficControl" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContra
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1365
                                                                    Entropy (8bit):4.867179322734424
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9NwDohuMt1k3BNjXMi+EsdnKE+2h6wl/Ffssl:crUohuMteNjXMzbdKshBddl
                                                                    MD5:6646F9BE2FE762564208BA36DD0F31A2
                                                                    SHA1:9E899E1A081FE6D95F2F8C57796B2A1B9E6C7BDE
                                                                    SHA-256:636668AB90D90FCDAFE2AF01594532F455AEC45EED2246D60164D61952D2A84E
                                                                    SHA-512:F299CFEFC3E1DA119C8DA16E446ADD81DC99B12D841CA442108901859FC0AD045363D9753CF787E3AB0F494808BECE63C180EBB6B1E93FF71555407AAA1A9817
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="703350" V="0" DC="SM" EN="Office.Telemetry.Event.Office.ScriptLab" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenScriptLab" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="W" I="6" O="false" N="Eve
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1402
                                                                    Entropy (8bit):4.901565760313767
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9KkDohuct1k3BNjXMi+EsdnKE+2h6wl/Ffssl:c44ohucteNjXMzbdKshBddl
                                                                    MD5:ADD122069E5B52B89CC0D6BBFADC2B0D
                                                                    SHA1:0AD48A61FD49220D2B3C8A6F7BDE62A3594E7454
                                                                    SHA-256:DEDC32D4D2A6646E0ACFF3856668BE0CCA5EB69440FCA35C56386FD9EC5D0996
                                                                    SHA-512:270F3A228429F0014DE76163438689B7AB4360C6597E7E6CF09E5A1759318B67550A2FF1315BF7EC2831C57DA63DE7190540AAF513B858F7E88BFF1D07AC17F0
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="703351" V="0" DC="SM" EN="Office.Telemetry.Event.Office.ScriptLab.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenScriptLab" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1387
                                                                    Entropy (8bit):4.8898697870907935
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9NFD7uMt1k3BNjXMi+EsdnKE+2h6wl/FfbpZae:cXl7uMteNjXMzbdKshBdPZ
                                                                    MD5:DD2930326CDD833E3F2768CC47B20046
                                                                    SHA1:2B5C12463D031AFA1547B50B489BA43019B553E5
                                                                    SHA-256:6708BB726F2C7CCE1D19BBA4ACCB228C3483A0483102AE6432CA36DB07411A51
                                                                    SHA-512:1B14C94B3331790E8EC1CB3F608BD7A9A89E61584EE6F0CB7916597FAA913B578E0D34CD89F3319A771F43DEBD2F78CD4D7E416FF6B056442F3C41E1B96F4FEB
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="703400" V="0" DC="SM" EN="Office.Telemetry.Event.Office.ProgrammableSurfaces" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenProgrammableSurfaces" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="W"
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1424
                                                                    Entropy (8bit):4.921719665185987
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9KfD7uct1k3BNjXMi+EsdnKE+2h6wl/FfbpZae:ck77ucteNjXMzbdKshBdPZ
                                                                    MD5:6F62B52632B214B3C7A238A3A95630F1
                                                                    SHA1:365422A8C1A579BBDA591CC6BF3F5A7B186D662F
                                                                    SHA-256:9D1A174D7B2953B3EBD03447FE077748A880EE49919935D0CAF58046113F1014
                                                                    SHA-512:FFB96A3674E572E1A50E82464BC896054E756710678B427A67C0BEE86B803FCE5CDEA354800BDCC96FF370B08A52D117981E01A8733B4BF92B8DC53F792ACD49
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="703401" V="0" DC="SM" EN="Office.Telemetry.Event.Office.ProgrammableSurfaces.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenProgrammableSurfaces" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="Event
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1371
                                                                    Entropy (8bit):4.864841997755804
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9LxM7DuXRuMt1k3BNjXMi+EsdnKE+2h6wl/Ff6I8:cFxuQuMteNjXMzbdKshBdm
                                                                    MD5:7FDAA3AC847B46B66090A42F1D5AB013
                                                                    SHA1:492D3930CD2A2EFAB0F90113DF6DB9A543B17B8D
                                                                    SHA-256:F16618618E862E447D756B24C88B67AF60AE14E5097B6AC116DD1300B0C16028
                                                                    SHA-512:0EDF7EC2282DA17BA2CF7B17297CE1DB45118AE017B6CB15BAA867F4228F9DFD13B5F0E09C0C84D33A031FAD0050C843A1E4CF6644ED5FA18308AAFAC059FCA4
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="703450" V="1" DC="SM" EN="Office.Telemetry.Event.Office.OfficeMobile" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenOfficeMobile" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="W" I="6" O="false"
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1408
                                                                    Entropy (8bit):4.89913278806516
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9AxM5DuXRuct1k3BNjXMi+EsdnKE+2h6wl/Ff6I8:c6x2QucteNjXMzbdKshBdm
                                                                    MD5:E402EE99F54F1E40DAB2C7582A097F8C
                                                                    SHA1:BDEE323A673FBB14DEE7D14E8EE3261B0B65EFD6
                                                                    SHA-256:E10B63C8CFD6F66E82579805B99ED460FCF29063D845004915C5B57C3EA43A45
                                                                    SHA-512:A1DEE904DAFEEDD583996D2E67BF435571FE2866767E0DE70A7125CD4ED312235B9C47A726DD02675D91702F758C2288362A845A400154FDADDE65EA68A39FCD
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="703451" V="1" DC="SM" EN="Office.Telemetry.Event.Office.OfficeMobile.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenOfficeMobile" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1361
                                                                    Entropy (8bit):4.859111574808197
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9ni6V0DTuMt1k3BNjXMi+EsdnKE+2h6wl/FfKkt7mu89:cc4oTuMteNjXMzbdKshBdSkt7i
                                                                    MD5:3BD2CC15EF4C839B1C59C96CA807F42E
                                                                    SHA1:8D14EA3DF984F04C18FEEB61294DCADA6AF91AD7
                                                                    SHA-256:52410E5DD10F9318E0E1ED27F5C150C75614CD1BAB59E70971115FF67D5A1525
                                                                    SHA-512:69D81D88C105B15B1AD6FCCD4356315BC14FE58F2633F945715A0C0D0B368BC720C54B0B7D6DA82025A882F9A1BA161EA6290B76C3E2A33E62C655EBB99B40E2
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="703500" V="0" DC="SM" EN="Office.Telemetry.Event.Office.Sandbox" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenSandbox" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="W" I="6" O="false" N="EventTy
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1398
                                                                    Entropy (8bit):4.89492777462298
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9l6+DTuct1k3BNjXMi+EsdnKE+2h6wl/FfKkt7mu89:cv7TucteNjXMzbdKshBdSkt7i
                                                                    MD5:80EBB69E8179832F57512973B75F1208
                                                                    SHA1:5A915AC2D87B3DB7054E34D46D6A467A41C48924
                                                                    SHA-256:DF9125ECA25AFF8FE30A3EAD60B730837564A0EEC8B2BB23F9250EE5EE1E9A03
                                                                    SHA-512:D6E4509CEBC0C62FDB08B34767EBBFE63B775E9FB1CF4160B4D4705A0BC59F412D4D6CD2F2AC57C9532AEC9B09C0C5F5A11E0479205C8558F244BC3ED845DAF1
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="703501" V="0" DC="SM" EN="Office.Telemetry.Event.Office.Sandbox.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenSandbox" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1371
                                                                    Entropy (8bit):4.876198111520159
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9L3DxuMt1k3BNjXMi+EsdnKE+2h6wl/Ff7ISqxTn:ctzxuMteNjXMzbdKshBdDDqxTn
                                                                    MD5:377AB25CBEEA1DD89D36A96DD2D82A44
                                                                    SHA1:E66602C8B87CB9E3D05B05DD45C8160179904F70
                                                                    SHA-256:0E37FBA93D072F750D2F5E318C49A581C1910445DC9F901A9B957609716770C0
                                                                    SHA-512:AFB84B3D39BB1C0CE475075ACA9A79E79453DED6FEFD5EF0F2F02756AAEEAB8029B3173ACC0ABCDC51DC723348B89E0F6C90B4CC564280FCBE3122342589F009
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="703550" V="0" DC="SM" EN="Office.Telemetry.Event.Office.DocumentXRay" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenDocumentXRay" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="W" I="6" O="false"
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1408
                                                                    Entropy (8bit):4.911520641736649
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9YVDxuct1k3BNjXMi+EsdnKE+2h6wl/Ff7ISqxTn:cqVxucteNjXMzbdKshBdDDqxTn
                                                                    MD5:BD4E2DA8485B6D0BC66D8A0BAEA1734B
                                                                    SHA1:7417F992A74DDA744B626206C4EE454585390B4F
                                                                    SHA-256:D301B6889AA30ED8DFF47EE23122494F245484794BC3D8587F74F828AEA062E8
                                                                    SHA-512:81D480A416E2FF69C9EAA1FDE809066495586D871D8040177EF33F676BD7B8C71AC6055ADB0AF710838F9F32B12A7B63A7BB94B6869B5FD8B3DDFF60DC4EDB0A
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="703551" V="0" DC="SM" EN="Office.Telemetry.Event.Office.DocumentXRay.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenDocumentXRay" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1357
                                                                    Entropy (8bit):4.859441213383502
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d98m+DWuMt1k3BNjXMi+EsdnKE+2h6wl/FfOoZ0Q:cqmOWuMteNjXMzbdKshBdN0Q
                                                                    MD5:27F76678384A95485AE180F16E0185E9
                                                                    SHA1:A1C41002FA958BB20C0B0C84B68B9809C49328B3
                                                                    SHA-256:66E960ACC0AF642EA064AD201CA59597303EFBFC389C3BE925A97ECF167EC7DC
                                                                    SHA-512:96680D31059F9663ABAD45EFA6A5A973A057E69C3DAF62B09645476C2EE5224DF0F0E83BCD104C07C140F1E146930A6827D179E18AAAC6F6E5A9E4BA8A2CF5F8
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="703600" V="0" DC="SM" EN="Office.Telemetry.Event.Office.Maker" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenMaker" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="W" I="6" O="false" N="EventTypeIn
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1394
                                                                    Entropy (8bit):4.895873875742196
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d91iGDWuct1k3BNjXMi+EsdnKE+2h6wl/FfOoZ0Q:cTiWWucteNjXMzbdKshBdN0Q
                                                                    MD5:114A3AC4EAF14E47CD9E073586230913
                                                                    SHA1:45087CE9681EE9097DA930F5C73C148158ACD40F
                                                                    SHA-256:41B17C542CD95EA0A28DC436A95B79C128C910918F1D3F44F1A6066A85C00207
                                                                    SHA-512:001A9F69187B56E90C5CC83F89F0A7533E83103318711E015547D47EC466E3CE8EF4A0E071C8207240D4A79B280D4F06C4D157BBEBC8E835C08A41E2D87AE09A
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="703601" V="0" DC="SM" EN="Office.Telemetry.Event.Office.Maker.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenMaker" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1359
                                                                    Entropy (8bit):4.859074979008148
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9S0DAuMt1k3BNjXMi+EsdnKE+2h6wl/Ff9b1Q:cQoAuMteNjXMzbdKshBdFRQ
                                                                    MD5:9349AC351BD06F127744059870024F71
                                                                    SHA1:B5CBB56FCB74D4CEEAD87FF564DC4F40AB68F992
                                                                    SHA-256:1B15D449E8E450468F8EA5CBA9C8D78715986BA844FDBE4225704C68E65AC9FE
                                                                    SHA-512:471B844789E6B70080F2C7AED4C39EA1130762C0FA6F8128A65CBC91FB12703CB5F74F9E4808CA6B47973E97DCD26EA8402E9C99DF82FD7760C244D2232D44E6
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="703650" V="0" DC="SM" EN="Office.Telemetry.Event.Office.Groove" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenGroove" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="W" I="6" O="false" N="EventType
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1396
                                                                    Entropy (8bit):4.893131061328472
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9VpeDAuct1k3BNjXMi+EsdnKE+2h6wl/Ff9b1Q:cDcAucteNjXMzbdKshBdFRQ
                                                                    MD5:A3D9E93082257775C9A6A6C7E68C4A16
                                                                    SHA1:0703359A9F07E521BD0167021059A3B1AE73CDFF
                                                                    SHA-256:6C450A8DE75AB9CD4876FC3CCFEEC02D979528DE4BD178FFFA8C42E07E4FEDFE
                                                                    SHA-512:63D95062E7835CC8C221C8830274CB29B00D6C5E1A36453D11E7A34B1E5D42C28F9F4F5F1BBB28124CE4B316B692289B63BB3568A8275D6D54CFB67777278522
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="703651" V="0" DC="SM" EN="Office.Telemetry.Event.Office.Groove.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenGroove" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1377
                                                                    Entropy (8bit):4.869487277433382
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9A6DSuMt1k3BNjXMi+EsdnKE+2h6wl/FfqRjJNk:ceaSuMteNjXMzbdKshBdyRjJC
                                                                    MD5:D563C8B0249B69D9FEDE0952EB0C3C5C
                                                                    SHA1:2FAB9B0EA578383F7CADEAC43119C1144973A6E9
                                                                    SHA-256:A2A28812A62146DEA0D8560E316B06933DBAE3EE9830F2A7B37E3657F1F90803
                                                                    SHA-512:B25437A3545EBD14AE0C0E73487671F5A70568483635588C315851E200EAF2C260CEEBE3A2FFD2D377F469D03F1538399B995F8EB00B889BF2FEB9B6E21E29C7
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="703700" V="0" DC="SM" EN="Office.Telemetry.Event.Office.LivePersonaCard" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenLivePersonaCard" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="W" I="6" O="f
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1414
                                                                    Entropy (8bit):4.902951734564792
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9zIJDSuct1k3BNjXMi+EsdnKE+2h6wl/FfqRjJNk:cRIZSucteNjXMzbdKshBdyRjJC
                                                                    MD5:D179C943A3CE7C71D98AE9D316D44EE0
                                                                    SHA1:87181E44F0427F40B448BA5F5FB5D04529A2925E
                                                                    SHA-256:A17B805BC4F3EED671B69876DB1A89BC19CA4A306707672919FEBE3725BFD0FD
                                                                    SHA-512:8739CBA564703EA74D32E38BDD94FB766434F2D873465EDF52A85B5BA8DA871155173CFB3C55BAA50F67D2DD6AB8837972887AAE0EDDA79C3B5D189962AFFF95
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="703701" V="0" DC="SM" EN="Office.Telemetry.Event.Office.LivePersonaCard.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenLivePersonaCard" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractIn
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1399
                                                                    Entropy (8bit):4.898773611960046
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9p0D4uMt1k3BNjXMi+EsdnKE+2h6wl/Ff+V8E:c/o4uMteNjXMzbdKshBdTE
                                                                    MD5:DB17844E55942774E1889C0F89CB33D4
                                                                    SHA1:27E6275660DDCC8834BB339D7DF4E73478745196
                                                                    SHA-256:7DF652C2790E1FDF16E030B9EE6286DCCB429E36C80E2CFFADC92DE576893444
                                                                    SHA-512:16DDD00E6161833D881D397BC6EA1356B458A55D3CD815D63A8CE65D5D824302D2CCB8E91DE914FF42D11602E2ECCEB9B864DA267EDC29758294D7064C94621F
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="703750" V="0" DC="SM" EN="Office.Telemetry.Event.Office.LivePersonaCardUserActions" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenLivePersonaCardUserActions" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1436
                                                                    Entropy (8bit):4.929467842574553
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d924D4uct1k3BNjXMi+EsdnKE+2h6wl/Ff+V8E:csc4ucteNjXMzbdKshBdTE
                                                                    MD5:9ECC80BB2FF6C61C59B9368F34A7FCE2
                                                                    SHA1:CB866F2D3ADF0BEAF7301784A03BC07B48756ACB
                                                                    SHA-256:BD0D504A09D5745DB2C1866F08D8D391972C0256ED97A6FA8E326FC7DF5BC36A
                                                                    SHA-512:0F9093498487D91A2E84E7AE864143AEF0031C308915914D5FD67585E31FCAE01745D1B6CD8B74725D6CD01C7218BD2B258AA2EDE3DDC4CAECE6388D2FE49823
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="703751" V="0" DC="SM" EN="Office.Telemetry.Event.Office.LivePersonaCardUserActions.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenLivePersonaCardUserActions" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T=
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1381
                                                                    Entropy (8bit):4.889079229821002
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9xGDmuMt1k3BNjXMi+EsdnKE+2h6wl/Ff+c:czWmuMteNjXMzbdKshBdmc
                                                                    MD5:0579512EEFB11E803D2CF5019B8150D7
                                                                    SHA1:86086FD8D862B2C243E29F89D3E344A908A36B42
                                                                    SHA-256:C3CF94AD2BE85D20575195602902F5EB3862B92A56E25C628A0F2EC8F8233338
                                                                    SHA-512:876A87B3BC0E1AAE525B569E648FFF2EE8BD87864ADCAA6A834DFE78129D2055C9111516890B6B2732760873065815946AD75AB190325ABD0A5C4AA24DF6037F
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="703800" V="0" DC="SM" EN="Office.Telemetry.Event.Office.LivePersonaPicker" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenLivePersonaPicker" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="W" I="6"
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1418
                                                                    Entropy (8bit):4.921065578166547
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9++Dmuct1k3BNjXMi+EsdnKE+2h6wl/Ff+c:cAOmucteNjXMzbdKshBdmc
                                                                    MD5:B2EA0FAAC79444CB793E4C999F5CCD94
                                                                    SHA1:2C83F03CA96B58E00DA42BAA4ACA9B45B2410528
                                                                    SHA-256:A7A890DF0CC1E3B29A6CC66FBDDB8CE28223A3E3405B360B65CFA740BD1C6052
                                                                    SHA-512:143F8456F89F338D2BD136BDB60440B99CC49954C4045BAAA8F4A3B9C4D384F952FAB5696C46F7B85A3856E4F667438395502746A8157CC5569196A8105E0822
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="703801" V="0" DC="SM" EN="Office.Telemetry.Event.Office.LivePersonaPicker.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenLivePersonaPicker" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContra
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1404
                                                                    Entropy (8bit):4.9085076597309225
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9ogJDMuMt1k3BNjXMi+EsdnKE+2h6wl/Ff48z5l:cqOMuMteNjXMzbdKshBdddl
                                                                    MD5:93CD889E0520AC00A54903F2023267FA
                                                                    SHA1:2837F1B19D5431374D4BBBB8C25F34289EF6D0CE
                                                                    SHA-256:5165B4D3461B52C51B82B52099B5C43950A3CF918507D080E170D2D383E63E6B
                                                                    SHA-512:463A502EB0C6783C9C440ED275C0019BF7C2D1CBAB89B58FF075ACE1D6BB38937C5ABCD519CE2CA79FA0B73C8674F3839E9383FBA901F5759ECB548C2C4DDFFB
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="703850" V="0" DC="SM" EN="Office.Telemetry.Event.Office.LivePersonaPicker.UserActions" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenLivePersonaPickerUserActions" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1441
                                                                    Entropy (8bit):4.938740750695626
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9bgjDMuct1k3BNjXMi+EsdnKE+2h6wl/Ff48z5l:ctWMucteNjXMzbdKshBdddl
                                                                    MD5:BA77A847F8C91B20E9D25B8C95E73A09
                                                                    SHA1:C57A8549318B0373EF2D2C2F1048B2A0A21CCE22
                                                                    SHA-256:889C789156B4E363814DEDD7B91C3A536E8AD55EF18A59D6CB886828136CE6C8
                                                                    SHA-512:33A58C7487191F193291F0E28B0913ED4EF63F91758A32EB3400367CA008A7BBD1A9A25A000DC4137EC712D25D73BC2574C6A68AB03255C23C4D37028FE59C19
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="703851" V="0" DC="SM" EN="Office.Telemetry.Event.Office.LivePersonaPicker.UserActions.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenLivePersonaPickerUserActions" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1389
                                                                    Entropy (8bit):4.879092955369256
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9W+d7DiDuMt1k3BNjXMi+EsdnKE+2h6wl/FffmEj:cYgQuMteNjXMzbdKshBdXbj
                                                                    MD5:2DCC31926D121AC271F9826708601148
                                                                    SHA1:31E2CF7E0875B51F61E442470E9A0F9E7EFB085B
                                                                    SHA-256:431C879A0838C65C792183D23BBC9B79292D5CDFB10869D2A12CB25D2BFAB271
                                                                    SHA-512:0FED34754EFB09AB16F1B7946DE9A0C460D58768B81E98A35D08D0BD8D27BF61618042A10903040CF10AF0137A599266229B1C498B658F981B2E3CDB08C227F2
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="703900" V="0" DC="SM" EN="Office.Telemetry.Event.Office.ServiceabilityManager" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenServiceabilityManager" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="W
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1426
                                                                    Entropy (8bit):4.912185438232315
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d902f+7DiDuct1k3BNjXMi+EsdnKE+2h6wl/FffmEj:cLfEQucteNjXMzbdKshBdXbj
                                                                    MD5:E137206782A64799CFE71598CFC0E274
                                                                    SHA1:04F35055C6314D4A174D9B246EA722769DF352FD
                                                                    SHA-256:D396F94786A116D5ADD114308B712F9EA80A2D4CA6461A7904278AF0C77BA224
                                                                    SHA-512:7EB478A86D5BC1D12771D9B4F0E6994C640D7F63E6D2B99E135D1D8BB19ABB5E441C0C0FEBF2CF1A3260DDB8D661CBFFD53450DC876179841E8A0C6E820AC594
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="703901" V="0" DC="SM" EN="Office.Telemetry.Event.Office.ServiceabilityManager.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenServiceabilityManager" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="Eve
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1365
                                                                    Entropy (8bit):4.860514751542863
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d93RDvuMt1k3BNjXMi+EsdnKE+2h6wl/FfQ6YiW:chhvuMteNjXMzbdKshBdCiW
                                                                    MD5:D0DE499215C43B263D29D8792084B221
                                                                    SHA1:81248A3E1CB557868FE563DF7D50FAB362102714
                                                                    SHA-256:4DD6609F46C919E5328820FBD0F4D2821E7B816C10DBDADD77B3F8C77453773D
                                                                    SHA-512:1513FE90213D3295513EE0A594CB23BD816B02C4641FDA9D38FBC598F189CA54FE388F2BFA07BF4D64775EE06601419C21D9414144F75E22A48D1FFEF76760A9
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="703950" V="0" DC="SM" EN="Office.Telemetry.Event.Office.Floodgate" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenFloodgate" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="W" I="6" O="false" N="Eve
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1402
                                                                    Entropy (8bit):4.8964130495018665
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9EbDvuct1k3BNjXMi+EsdnKE+2h6wl/FfQ6YiW:cunvucteNjXMzbdKshBdCiW
                                                                    MD5:1BED13AF260A25C341B88834C49F7BDB
                                                                    SHA1:73112A338E4EA6A2B110D92E914955BB3A86C0E7
                                                                    SHA-256:70264E80F11549C63AE55D534D690A3CCA6C9DF17303DD4F6E759060FEACF058
                                                                    SHA-512:47EB73AB6CC6A918A6D694AD6995827EBBE3815E66836F4EF1C01FAA93BF52D579299B89788C407C3A3515C8B2D937C14A5DF920396C25075E745F9674DC2404
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="703951" V="0" DC="SM" EN="Office.Telemetry.Event.Office.Floodgate.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenFloodgate" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1381
                                                                    Entropy (8bit):4.881737011521532
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9yTDluMt1k3BNjXMi+EsdnKE+2h6wl/Ffgp2i:cAfluMteNjXMzbdKshBdY8i
                                                                    MD5:A88E3E9B0F81BA54B760FCE5ED9D387A
                                                                    SHA1:0E7C2382DD2CA6E1BA77948D517357D000ADDF14
                                                                    SHA-256:A478FED1246A705770CFA224A6684CC9A57563865BE16EEBCF4551E4097BD0E9
                                                                    SHA-512:A324FBF06CBAD813386820901D0FB6230389CB430482477853AD35FD16031B8C75C997B5DA6C8608E454C06FFF0C40BB501135A0DD88113EEB7A54247EC77824
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="704000" V="0" DC="SM" EN="Office.Telemetry.Event.Office.DiagnosticsSystem" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenDiagnosticsSystem" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="W" I="6"
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1418
                                                                    Entropy (8bit):4.914410926227558
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d91QODluct1k3BNjXMi+EsdnKE+2h6wl/Ffgp2i:czQ+lucteNjXMzbdKshBdY8i
                                                                    MD5:54E386392B8B5FB83174CAF60681280B
                                                                    SHA1:2645B59A6068CF22F7D599F65FFD3293505C9F85
                                                                    SHA-256:5CE5FB59264E0720FD55EA20A722C25F6572FA2A613A9474C4831BD6C7EF64C6
                                                                    SHA-512:1C7BF0DCDF58FADD08B37A44048AF6FCDC05D19BE6ED03091F385738FF3204E88FD627FD2FDCC05BE80C3E23B299ECDFD00FAD43356A1317D0CF270571F96DF5
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="704001" V="0" DC="SM" EN="Office.Telemetry.Event.Office.DiagnosticsSystem.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenDiagnosticsSystem" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContra
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1355
                                                                    Entropy (8bit):4.854080661479833
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9bOD2uMt1k3BNjXMi+EsdnKE+2h6wl/Ffox4dVXHj:cp+2uMteNjXMzbdKshBdfLXj
                                                                    MD5:04CFF2F72C92D2045E147E0C596E1406
                                                                    SHA1:554F906AA205C9F8BFF0F903F2C2728158754E06
                                                                    SHA-256:F3944740EFBC7263F1B3CD168B05096C89128F250859D4669372C9B182102D9A
                                                                    SHA-512:4D289411E4B2E6085E388ED7C4C07530575E1F564BD2739678BB0F95A50587DFF104983FB275F39F0D9BE3EF910C7BE2126B3880A53004644514AA7B6F467257
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="704050" V="0" DC="SM" EN="Office.Telemetry.Event.Office.Lens" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenLens" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="W" I="6" O="false" N="EventTypeInfo
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1392
                                                                    Entropy (8bit):4.890484382283006
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9oWD2uct1k3BNjXMi+EsdnKE+2h6wl/Ffox4dVXHj:c2G2ucteNjXMzbdKshBdfLXj
                                                                    MD5:159F78A647A1A88E948F2C86FD139740
                                                                    SHA1:1C57A440FFC4107477F457E3DD17EC61CCBD9D24
                                                                    SHA-256:EA3E5405E34AE8C26D60A1B771C54A3BF584A6845E9B405919680B4573B7F656
                                                                    SHA-512:1CE2C45657991ADEEC1FD2CF7A07DC41ADA361E75D2BBB7F6432B5AA33DB56FED8C06C2DBFE6451FBF597C4E737DF06065AB81F0BE064D3AAF18FC228744E138
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="704051" V="0" DC="SM" EN="Office.Telemetry.Event.Office.Lens.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenLens" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1361
                                                                    Entropy (8bit):4.853437171089294
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9QcaDj2uMt1k3BNjXMi+EsdnKE+2h6wl/FfjOLzW:cCc6j2uMteNjXMzbdKshBdbOLzW
                                                                    MD5:2EB1BE5B405D6C20F0BDD5F88F456FF5
                                                                    SHA1:4897036F6EC16977E2532F8530C483052EF6CABC
                                                                    SHA-256:6AB904B21B2C83DEC84A380210941569623EBE9D7DC35A3381BB5F4A991960BB
                                                                    SHA-512:F0F825A3C5D4F4984230FA2FB66A76ACB1859A35B432759E7FF1B5FCEF49AB3655C294BCFDCF714763A19CD82E1CE274FECBB6D036C591D458671F3A95BB7210
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="704100" V="0" DC="SM" EN="Office.Telemetry.Event.Office.Privacy" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenPrivacy" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="W" I="6" O="false" N="EventTy
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1398
                                                                    Entropy (8bit):4.88763297443542
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9QviDj2uct1k3BNjXMi+EsdnKE+2h6wl/FfjOLzW:cCvij2ucteNjXMzbdKshBdbOLzW
                                                                    MD5:741C697019FAF642C271D48B3152C103
                                                                    SHA1:B2D476DFE45A9BA9F45B60645D8CE8283CC85D27
                                                                    SHA-256:94ADD8B3467767795B062E554EC24B395641436ED6C9C61E947F908DF92DB0BB
                                                                    SHA-512:37FD72A476E07ABE872841C2AF631B47692FA61416E6C06AA13B32DABA6F755015383A0115681CC6E09F31463E4A40118438D1C1850366D29EC0DDB908692E40
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="704101" V="0" DC="SM" EN="Office.Telemetry.Event.Office.Privacy.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenPrivacy" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1361
                                                                    Entropy (8bit):4.863515036936551
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9Qt4jD82YBuMt1k3BNjXMi+EsdnKE+2h6wl/Ffg3i9r9:cCt+2uMteNjXMzbdKshBdag
                                                                    MD5:8C161F15E9201A91FEA611C248925EC2
                                                                    SHA1:774BCD74AA6EA9DBA80E9E0E94C393BF2ABFDEA5
                                                                    SHA-256:B46ED3FB8B9BFA797A0FF0F5B0C7498C6DC8546069E38D521CE8E59E4C282EAA
                                                                    SHA-512:C2BD900358753F9739051056F65D45013077527041D7B7B71051BA8695A5A0B5C663235733A3B94EA327A21C696DB5E760FBC3C8439868D5866B8D1DE9346E22
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="704150" V="0" DC="SM" EN="Office.Telemetry.Event.Office.AppDocs" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenAppDocs" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="W" I="6" O="false" N="EventTy
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1398
                                                                    Entropy (8bit):4.898410545870133
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9QqWD82YBuct1k3BNjXMi+EsdnKE+2h6wl/Ffg3i9r9:cCqG2ucteNjXMzbdKshBdag
                                                                    MD5:51CB4C96AEA134C37512CC4054BDAD39
                                                                    SHA1:EAE365A38489E8D6946D2F3C2081C20B3713D1AD
                                                                    SHA-256:0B91234B8F45EBFC03B3F7656F25CC320F616180514C8368F2154DEE6ADFCBDD
                                                                    SHA-512:9100F3A88255E3EE56B9995E91D029E6AF5FCB068CF148E05CACB59B2C270EB8EE48030A7BC111448BDFFFC2DDD6A3CFD6B566086B3CAF68775576058BA8FC33
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="704151" V="0" DC="SM" EN="Office.Telemetry.Event.Office.AppDocs.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenAppDocs" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1379
                                                                    Entropy (8bit):4.864383829099071
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9QzDluMt1k3BNjXMi+EsdnKE+2h6wl/FfIH:ci/luMteNjXMzbdKshBdAH
                                                                    MD5:566827AF91A5B4B56E549962CE94456B
                                                                    SHA1:A59ED5BB9B2EC70CFD5877B0B13499D5871AD557
                                                                    SHA-256:278E94C0AEAE3488C7B0DBBC12F879804A45124AC74F5D3AF1C327D714916BC2
                                                                    SHA-512:C8DB4187CB5631777466EEA00EF228102B49740DD535D857F6790B51A93E41DCCE854D50A8C4F02E3B2ECDEF4D538C59B3C2C7ED5F7EFE5F7AE43AB69F7BC435
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="704200" V="0" DC="SM" EN="Office.Telemetry.Event.Office.CommandExecution" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenCommandExecution" S="Medium" />.. <F T="2">.. <O T="LT">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContractInfo" />.. </C>.. <C T="W" I="6" O=
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1416
                                                                    Entropy (8bit):4.8984573728935095
                                                                    Encrypted:false
                                                                    SSDEEP:24:2d9DBDluct1k3BNjXMi+EsdnKE+2h6wl/FfIH:clxlucteNjXMzbdKshBdAH
                                                                    MD5:B11B43352E13CDC0B66DA5E6F394D72A
                                                                    SHA1:D8458DB86F0C92B7296650A158AB377DE4744409
                                                                    SHA-256:2A399A6E39E0F33C0B355A4F6986E7250DD20AD4CEF5BD3605BF88009158C82D
                                                                    SHA-512:6B3DB204E34464B6BE1FD9B5B729C70996B37622BFC47524B503D2789EB3A218BC1F92E3A53229AF246866476250BCFB95D4735A8C005D3DC64B862FE7E303E5
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="704201" V="0" DC="SM" EN="Office.Telemetry.Event.Office.CommandExecution.Critical" SP="CriticalBusinessImpact" DL="A" xmlns="">.. <RIS>.. <RI N="Event" />.. </RIS>.. <S>.. <UCSS T="1" C="NexusTenantTokenCommandExecution" S="Medium" />.. <F T="2">.. <O T="GE">.. <L>.. <S T="1" F="EventSamplingPolicy" />.. </L>.. <R>.. <V V="191" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="W" I="0" O="false" N="EventName">.. <S T="2" F="EventName" />.. </C>.. <C T="W" I="1" O="true" N="EventContract">.. <S T="2" F="EventContract" M="Ignore" />.. </C>.. <C T="U64" I="2" O="false" N="EventFlags">.. <S T="2" F="EventFlags" />.. </C>.. <C T="D" I="3" O="false" N="EventSampleRate">.. <V V="1.0" T="D" />.. </C>.. <C T="W" I="4" O="false" N="EventData">.. <S T="2" F="EventData" />.. </C>.. <C T="W" I="5" O="false" N="EventContractInfo">.. <S T="2" F="EventContract
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):480
                                                                    Entropy (8bit):5.140990380367097
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHd92KU3b03CMgZYAQier8lV16jnfEtNO2su:2d9hU3Xgr8Pun8j
                                                                    MD5:75FBAA9EDF3A3AB4269BB70E46B0E9E7
                                                                    SHA1:F88290AB65E11898E895A0829CA42A4F0395E9B5
                                                                    SHA-256:5CE9599ECF96CB3793A8188B25496C7360150894AADA3B87FC50917AF9B5D068
                                                                    SHA-512:2C79A12C02A2ED3906F2A0B496223453DCC13923037746AF4FDD7CE6B1ADB9B173D4D180460A92FD3B2C2E44CB3AC5942C9F4FC725C10E64B9D442606AB3BED7
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="70500" V="0" DC="SM" EN="Office.Help.HelpTaskPaneSessionTime" ATT="f0ef8c1d59b54013a78c8cce0b75bb44-d4a21f0a-ff29-4a4c-81e7-bc7f69607cc5-7242" SP="CriticalBusinessImpact" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="bhgtp" />.. </S>.. <C T="FT" I="0" O="false" N="Time">.. <S T="1" F="TimeStamp100ns" />.. </C>.. <C T="U8" I="1" O="false" N="State">.. <S T="1" F="Event" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):2739
                                                                    Entropy (8bit):3.5524500936112124
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dSLCCw6YiZys1OrTuiReWuUjO8PROt0FuoqfOi9w8hWD4:cgbai3OHuKesP1dD4
                                                                    MD5:D47112F111C28F2F8DDBF45FD0144286
                                                                    SHA1:F5F6B49ABA23F550DBB02931B3D5C2C3CD703D9A
                                                                    SHA-256:CCCB616EAFD1D6BFF3EAFDE3E361498975726661B671A9AFBBBF053F7F72EDF7
                                                                    SHA-512:83B7CA629FA40A40EF1D31232F4EC56D4D293C7EBE7F67081D54C923D67419DC67D5FA22040755404D4844C2FDC433C35A8A05E6D08E1D52C5A722E7026018C1
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="840000" V="1" DC="SM" EN="Office.Floodgate.Client.CampaignExperimentLoad" ATT="d526a9052e444f1d8706529ef111b101-1a23544e-ef74-4a87-9979-78386cb3c5e6-6762" SP="CriticalExperimentation" DL="N" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="920pg" />.. <F T="2">.. <O T="AND">.. <L>.. <O T="AND">.. <L>.. <O T="AND">.. <L>.. <O T="NE">.. <L>.. <S T="1" F="CampaignId" />.. </L>.. <R>.. <V V="8a42827d-29d2-473e-998e-3217724c5b68" T="W" />.. </R>.. </O>.. </L>.. <R>.. <O T="NE">.. <L>.. <S T="1" F="CampaignId" />.. </L>.. <R>.. <V V="c3b31d20-81f5-49ee-8c43-b12d3f898c06" T="W" />..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):689
                                                                    Entropy (8bit):5.139406679616707
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdSGMd/RZUCw6DEi3FerJMfUIdLWtlAGnp9l/+b4RCffE2NO2su:2dSFrUCw6Yi3wrJ/kK1FCnEG
                                                                    MD5:891964456DC56DA862EC2C3D6F08E59A
                                                                    SHA1:3BCEE1F0E28162B84A83A6E682A877867B30C1E5
                                                                    SHA-256:FE695C7F1A05ABC6E80CB3C417032E39CAD9BAB6D3486C4B68E047789B0D7302
                                                                    SHA-512:3B5F43D02327FF094F984532E7B25DDD8359B7534B9A3F193CB869FEC48E11F911063DE1344A7DC2AAC3F5747CB56D6A68CC95C2D2F686222DBEC32404067F6B
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="840001" V="0" DC="SM" EN="Office.Floodgate.GetDecisionForAction.LastMileCheck" ATT="d526a9052e444f1d8706529ef111b101-1a23544e-ef74-4a87-9979-78386cb3c5e6-6762" T="Upload-Medium" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="82pu4" />.. </S>.. <C T="TAG" I="0" O="false" N="EventId">.. <S T="1" F="ULS_Tag" />.. </C>.. <C T="W" I="1" O="true" N="SurveyId">.. <S T="1" F="ActionId" M="Ignore" />.. </C>.. <C T="U32" I="2" O="true" N="Decision">.. <S T="1" F="Decision" M="Ignore" />.. </C>.. <C T="U32" I="3" O="true" N="ChannelType">.. <S T="1" F="ChannelType" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1032
                                                                    Entropy (8bit):4.971711898879209
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dS87Cw6YiZmZrbmux+agGik3CD81gGJAl:cSaicfmuI58gGJAl
                                                                    MD5:CEA0F586D250A26787D5E9FFAD3DB1CF
                                                                    SHA1:118830963080E8CAF28D7F664F0F23B018CBCB3B
                                                                    SHA-256:FA8B5A1D0881EF3E48433CEE79F1831AA77AFFF0484771D4EC27156049C9C011
                                                                    SHA-512:613852F9CAF6A1EC7D3B780AB0665F748FFE16890FB8940CDBC1E8A6A2B42798A1F17170257B06AE93BAB795087EF9AD6C081EE546F7F0CEA42F374E16518AAF
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="840002" V="1" DC="SM" EN="Office.Floodgate.SurveyTracked" ATT="d526a9052e444f1d8706529ef111b101-1a23544e-ef74-4a87-9979-78386cb3c5e6-6762" SP="CriticalBusinessImpact" T="Upload-Medium" DL="N" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="b9q72" A="c2gya c2g72 dciyl" />.. <F T="2">.. <O T="GT">.. <L>.. <S T="1" F="GovernedChannelType" />.. </L>.. <R>.. <V V="2" T="U32" />.. </R>.. </O>.. </F>.. </S>.. <C T="TAG" I="0" O="false" N="EventId">.. <S T="2" F="ULS_Tag" />.. </C>.. <C T="W" I="1" O="true" N="SurveyId">.. <S T="2" F="SurveyId" M="Ignore" />.. </C>.. <C T="W" I="2" O="true" N="UniqueId">.. <S T="2" F="UniqueId" M="Ignore" />.. </C>.. <C T="U32" I="3" O="true" N="GovernedChannelType">.. <S T="2" F="GovernedChannelType" M="Ignore" />.. </C>.. <C T="U32" I="4" O="true" N="PrimaryPriority">.. <S T="2" F="PrimaryPriority" M="Ignore" />.. </C>.. <T>.
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):855
                                                                    Entropy (8bit):4.992943901171179
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdt9ynFVkHzpRtRVHvAQjerPW/+u/5lOES1c/NX/c//+pONLjsfTS12xP6+/TI:2dzynFVOLzorPFunuc/Jks7u2Rbuc/qj
                                                                    MD5:A87FAB872DC651710C78C6A9EDB7B568
                                                                    SHA1:40C9AC6D5CAF4A2119924B52944C8A6C2243A256
                                                                    SHA-256:1EBCF0BA9F86FC852D094DDA1B13C5B61BBC8BFF8832213E1C56222D12661E1C
                                                                    SHA-512:19D0DB06C86FCC21792E739455353956B4C363BF15D92A89838C6F8F11B6B27045EBAFC1B5A14FC646EFF367942B139C47174C6433AB0E97A358EE89B8BB7231
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="890000" V="2" DC="SM" EN="Office.Privacy.OffersOptIn" ATT="0cc923f8e48042f9b5193007cf34d1ae-def86b84-7392-4e7f-8da6-ecea0a375ec4-7160" SP="CriticalBusinessImpact" DL="B" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="77rqq" />.. <F T="2">.. <O T="NE">.. <L>.. <S T="1" F="DirectMarketingSettingSourceLocation" />.. </L>.. <R>.. <V V="8" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <C T="U8" I="0" O="false" N="OffersConsentState">.. <S T="2" F="DirectMarketingSettingState" />.. </C>.. <C T="U8" I="1" O="false" N="OffersConsentSourceLocation">.. <S T="2" F="DirectMarketingSettingSourceLocation" />.. </C>.. <C T="U8" I="2" O="false" N="ConsentGroup">.. <S T="2" F="UserConsentGroup" />.. </C>.. <T>.. <S T="2" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):991
                                                                    Entropy (8bit):4.852534729172089
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdtu3NP2xVkHzpRtRVKerner1er8OerXergzahIffO9G9+lSGT+9d7yXGUEBI+:2dASVOLzDrergrarOrEw3aO2UGgC162J
                                                                    MD5:E64C5756C5F8BEE7CF937BD78576B04B
                                                                    SHA1:31EC7E2B454C6A2C0A776FA064B92CB1A96638C3
                                                                    SHA-256:FCE8C7CB6CD54FEDAB891BAC2791D1954785AE47B98D9C6340AB303A77A8A1E1
                                                                    SHA-512:501756A98F0DF5B7616CFC941E9FF70E6F2BAC6ECF1465A08EA7E190C5D6D0B92E51160B354A7CCA22748B645AA97D3E0541375569F0EB3C04BE4959A459065B
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="890002" V="0" DC="SM" EN="Office.Privacy.UnifiedConsent.API.HttpSendFailureReason" ATT="0cc923f8e48042f9b5193007cf34d1ae-def86b84-7392-4e7f-8da6-ecea0a375ec4-7160" DCa="PSP" xmlns="">.. <S>.. <UTS T="1" Id="48bo8" />.. <UTS T="2" Id="48bo7" />.. <UTS T="3" Id="48bo6" />.. <UTS T="4" Id="495q9" />.. <UTS T="5" Id="48i2c" />.. <US T="6">.. <S T="1" />.. <S T="2" />.. <S T="3" />.. <S T="4" />.. <S T="5" />.. </US>.. </S>.. <C T="TAG" I="0" O="false" N="Tag">.. <S T="6" F="ULS_Tag" />.. </C>.. <C T="I32" I="1" O="true" N="Result">.. <S T="6" F="Result" M="Ignore" />.. </C>.. <C T="U8" I="2" O="true" N="Endpoint">.. <S T="6" F="Endpoint" M="Ignore" />.. </C>.. <C T="U8" I="3" O="true" N="Method">.. <S T="6" F="Method" M="Ignore" />.. </C>.. <C T="I32" I="4" O="true" N="ResponseCode">.. <S T="6" F="Code" M="Ignore" />.. </C>.. <T>.. <S T="6" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1271
                                                                    Entropy (8bit):4.8349878632894505
                                                                    Encrypted:false
                                                                    SSDEEP:24:2deqEXVOLzDrar0rt2rGr4rirSrFeOw9gOdq1ABR:ceHXVOLzDG4x2qEmOZeOwjd+8
                                                                    MD5:A5CA1FC64A64C3E1FFBC783E656CD0BA
                                                                    SHA1:07CDDEB1B609DB33B23CBAA2291E883846510594
                                                                    SHA-256:52E8F9BC4DF5348A6277E4A833C7BB9C39B9CC6EAD477179D45290C90FB54929
                                                                    SHA-512:F176CB2AE721FF2205E8A5E5B3B0EB5774DB2B38475A4F13504365654BB83E97FEC0C2622AB8F85CECC30481B413EB9CC43B90BE3AA5CC0C72540924B4D6ED18
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="890003" V="1" DC="SM" EN="Office.Privacy.UnifiedConsent.API.CreateHttpRequestFailureReason" ATT="0cc923f8e48042f9b5193007cf34d1ae-def86b84-7392-4e7f-8da6-ecea0a375ec4-7160" DCa="PSP" xmlns="">.. <S>.. <UTS T="1" Id="48bo4" />.. <UTS T="2" Id="48bo3" />.. <UTS T="3" Id="4yvlj" />.. <UTS T="4" Id="4yvli" />.. <UTS T="5" Id="4yvll" />.. <UTS T="6" Id="4yvlk" />.. <UTS T="7" Id="495ry" />.. <UTS T="8" Id="495rx" />.. <US T="9">.. <S T="1" />.. <S T="2" />.. <S T="3" />.. <S T="4" />.. <S T="5" />.. <S T="6" />.. <S T="7" />.. <S T="8" />.. </US>.. </S>.. <C T="TAG" I="0" O="false" N="Tag">.. <S T="9" F="ULS_Tag" />.. </C>.. <C T="U8" I="1" O="true" N="Endpoint">.. <S T="9" F="Endpoint" M="Ignore" />.. </C>.. <C T="U8" I="2" O="true" N="Method">.. <S T="9" F="Method" M="Ignore" />.. </C>.. <C T="U32" I="3" O="true" N="IdentityProvider">.. <S T="9" F="Prov
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):395
                                                                    Entropy (8bit):5.238922111527346
                                                                    Encrypted:false
                                                                    SSDEEP:6:TMVBdPVVKmkl3mcf1LJL/cUdkTAHzpRsE6KVEDFperhnZkdx486/MveNOn2sby:TMHdt43NLIVkHzpRtRVKer/SWMmNO2su
                                                                    MD5:587FFD728B56B8F98457A2ECFF8B79A5
                                                                    SHA1:3AF515FF69FE49ED760C6D5E0591E37DADDB4D69
                                                                    SHA-256:4EE9188EA332BA457C8552B88DF077207C6706CB8AC929D81FADED03025E0A51
                                                                    SHA-512:6447E1AD791217FA2119053AB8E39E61C5097A58D7FBC5F86DF7D7F7E192E29AC6C2691BE704C8A463907547DE3E4949B50E349F9D01C04C09F3047F2BA0DF85
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="890004" V="0" DC="SM" EN="Office.Privacy.UnifiedConsent.UI.ParseModelPropsFail" ATT="0cc923f8e48042f9b5193007cf34d1ae-def86b84-7392-4e7f-8da6-ecea0a375ec4-7160" DCa="PSP" xmlns="">.. <S>.. <UTS T="1" Id="4yc1x" />.. </S>.. <C T="W" I="0" O="false" N="ErrorMessage">.. <S T="1" F="Message" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):613
                                                                    Entropy (8bit):5.1350527003055335
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdK/ksCSawSCSvAQqWnerfNsmEtadFv15nt9NI7NO2su:2dUYlwTrfNeQ8
                                                                    MD5:E93A3F7C362C08930DF1A31C2DC07DCD
                                                                    SHA1:30A67CB549BA881C211F759E9E53C0506265ABF8
                                                                    SHA-256:7D4B9BAE5416E2C11EE97C85A52E25399B6807DEB9AED4614F00D402B9A75CC5
                                                                    SHA-512:53253490BD2D6502F01696B1D017492E12E08DF6A8DEA61088CB108AD88AF3A7E07C593F44AAC3AB6737909D8D63F5493FFDD5E9D921928B117E4AF816F90FCF
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="90117" V="1" DC="SM" EN="Office.Telemetry.InvalidDataFieldName" ATT="f998cc5ba4d448d6a1e8e913ff18be94-dd122e0a-fcf8-4dc5-9dbb-6afac5325183-7405" SP="CriticalBusinessImpact" DL="A" DCa="PSP PSU" xmlns="">.. <S>.. <UTS T="1" Id="bqca9" />.. </S>.. <C T="W" I="0" O="true" N="EventName">.. <S T="1" F="EventName" M="Ignore" />.. </C>.. <C T="W" I="1" O="false" N="DataFieldName">.. <S T="1" F="DataFieldName" />.. </C>.. <C T="B" I="2" O="true" N="IsRuleEvent">.. <S T="1" F="IsRuleEvent" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):598
                                                                    Entropy (8bit):5.1438660018382025
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdKqm4KlCSawSCSvAQ4WnerqsmEtadFv15r9LnoNO2su:2dVmWlwLrqeQk
                                                                    MD5:15026FBAF6581B344DB36463667B6080
                                                                    SHA1:4CDF73D92318DDF4BF9694A31E94EC261A48548C
                                                                    SHA-256:7BE56FAF8FECF3A05FCE1CA94BC948186DFCDD5815E32847F874AD22F3CD86B3
                                                                    SHA-512:73D1265CCBBB26D266F818E16AC84BA8BE4CC57F7390819F21FED0C5B41B7A119CABBAA26B9A6CA3AA1E7C94AC2B89333D1370880447A0E4FE7C795D44B09B3B
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="90118" V="1" DC="SM" EN="Office.Telemetry.TooLongDataFieldName" ATT="f998cc5ba4d448d6a1e8e913ff18be94-dd122e0a-fcf8-4dc5-9dbb-6afac5325183-7405" SP="CriticalBusinessImpact" DCa="PSP PSU" xmlns="">.. <S>.. <UTS T="1" Id="brt7j" />.. </S>.. <C T="W" I="0" O="true" N="EventName">.. <S T="1" F="EventName" M="Ignore" />.. </C>.. <C T="W" I="1" O="false" N="DataFieldName">.. <S T="1" F="DataFieldName" />.. </C>.. <C T="U16" I="2" O="true" N="Length">.. <S T="1" F="Length" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):622
                                                                    Entropy (8bit):5.138423191976508
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdK1kAmjSawSCSvAQqWnerLsmEtadrFbmMnt9NI7NO2su:2dKHMlwTrLeQrRu
                                                                    MD5:7DE02652297BEE60BF6AB2EC192CDF72
                                                                    SHA1:36A03D3AD7F9556F3DFA7B4F17FB32C0D3994EB0
                                                                    SHA-256:6591703BC5D3AD4C7CD26A0559C3A43F8FF15CCC1390FECA70DB7C3BFF9A7677
                                                                    SHA-512:E7814AC30B9A7ABE975FC1CB3C7EC8A8034C7CB4E70A53B4D6541A0B775C79CBEBF30BFBF3A1B7463A72C503A650F51FFAFE8E0B0552266F1B28166186F08A0C
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="90119" V="1" DC="SM" EN="Office.Telemetry.InvalidDataContractName" ATT="f998cc5ba4d448d6a1e8e913ff18be94-dd122e0a-fcf8-4dc5-9dbb-6afac5325183-7405" SP="CriticalBusinessImpact" DL="A" DCa="PSP PSU" xmlns="">.. <S>.. <UTS T="1" Id="brt7k" />.. </S>.. <C T="W" I="0" O="true" N="EventName">.. <S T="1" F="EventName" M="Ignore" />.. </C>.. <C T="W" I="1" O="false" N="DataContractName">.. <S T="1" F="DataContractName" />.. </C>.. <C T="B" I="2" O="true" N="IsRuleEvent">.. <S T="1" F="IsRuleEvent" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):621
                                                                    Entropy (8bit):5.131103601127074
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdK1kYJnmjSawSCSvAQUerbK7smEtadoEnFE9EnmMnt9NI7NO2su:2d6pMlw4rceQomS9mu
                                                                    MD5:2C960A01352809BB453D4FFEA7F3A24F
                                                                    SHA1:797FB120E06777A834417B891D12DF2426109266
                                                                    SHA-256:0001E299C1537E4310ABEC01E44FFA398D7A8EEF2D087F68A18EF1DEC43EE19F
                                                                    SHA-512:DCDCBFC6C908456BD189C38B40FCFBDAAE537272FFC991AF3182337E40E05435349D59C93B5D4A81EF072A6B27B6A4FFAA592E7D38D2536B7BE7FA6EDD6F58E8
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="90120" V="1" DC="SM" EN="Office.Telemetry.InvalidEventContractName" ATT="f998cc5ba4d448d6a1e8e913ff18be94-dd122e0a-fcf8-4dc5-9dbb-6afac5325183-7405" SP="CriticalBusinessImpact" DL="A" DCa="PSU" xmlns="">.. <S>.. <UTS T="1" Id="brt7l" />.. </S>.. <C T="W" I="0" O="true" N="EventName">.. <S T="1" F="EventName" M="Ignore" />.. </C>.. <C T="W" I="1" O="false" N="EventContractName">.. <S T="1" F="EventContractName" />.. </C>.. <C T="B" I="2" O="true" N="IsRuleEvent">.. <S T="1" F="IsRuleEvent" M="Ignore" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):614
                                                                    Entropy (8bit):5.031646670731258
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdBK9SP4SawSCENXWnerJENerCUxlVqK7PNWXf/0//ChmMNOSjsu:2dA9SQlw+JrmYrCUxPLPQp
                                                                    MD5:75330F00B384B4F740260B35CB5C498A
                                                                    SHA1:91693E52C808F245B4BDC7857E7568239F5C3594
                                                                    SHA-256:157DA506F55CFD9B87AE8A740ECAA11E43CAE6CA2093DC465A09BD4DE71C2E2E
                                                                    SHA-512:3042AF7252D2A5BECB6A2A7E73F5A18772A5AE887440905535EEFEE11A377C13CC8EF9D01E61EF43E2E49C20BC8FDCA76E362031D2E5EB8ACC00747A919E70B2
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="90200" V="4" DC="SM" EN="Office.Telemetry.RulesEngineThrottled" ATT="f998cc5ba4d448d6a1e8e913ff18be94-dd122e0a-fcf8-4dc5-9dbb-6afac5325183-7405" T="Upload-Critical" DL="A" DCa="PSP PSU" xmlns="">.. <S>.. <UTS T="1" Id="bhyua" A="a6iyn" />.. <UTS T="2" Id="bhyt2" A="bac31" />.. </S>.. <C T="FT" I="0" O="false" N="ThrottlingTimestamp">.. <O T="COALESCE">.. <L>.. <S T="1" F="TimeStamp100ns" />.. </L>.. <R>.. <S T="2" F="TimeStamp100ns" />.. </R>.. </O>.. </C>.. <T>.. <S T="1" />.. <S T="2" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1131
                                                                    Entropy (8bit):5.119788069276698
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdjSyC4SawSCSvAQENXWneralVqK6Vu+SrYOZe/7yHagaIZiN1Dp+hqTHEYoxJ:2djSulwTJraPIBGeDCaaI10j1b
                                                                    MD5:82B5617CB37E4C60FA416E9F3EDB5901
                                                                    SHA1:A88F62CA2AA97B900132F7ABE8E3777BF3E967F1
                                                                    SHA-256:9EE913D9BECC4260D53F6D216F376BB6DDFC459E17A8EB3BEC32E92D5C4121BF
                                                                    SHA-512:05D18A2D446BB713D9801E6586BB0CCFCE40D947035C0F9BDA798469FEDEBC1C6E310429A2E45796E34821C6108153CBB6FDCB6361B97738C06D38C8EEB769D5
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="90201" V="2" DC="SM" EN="Office.Telemetry.RulesEngineSpikeThrottled" ATT="f998cc5ba4d448d6a1e8e913ff18be94-dd122e0a-fcf8-4dc5-9dbb-6afac5325183-7405" SP="CriticalBusinessImpact" T="Upload-Critical" DL="A" DCa="PSP PSU" xmlns="">.. <S>.. <UTS T="1" Id="bhyud" A="azxaq" />.. </S>.. <C T="FT" I="0" O="false" N="ThrottlingTimestamp">.. <S T="1" F="TimeStamp100ns" />.. </C>.. <C T="U32" I="1" O="false" N="HighestImpactingRuleId">.. <S T="1" F="RuleId" />.. </C>.. <C T="U16" I="2" O="false" N="HighestImpactingRuleVersion">.. <S T="1" F="RuleVersion" />.. </C>.. <C T="U32" I="3" O="false" N="HighestImpactingRuleBytes">.. <S T="1" F="ImpactingBytes" />.. </C>.. <C T="U32" I="4" O="false" N="CurrentLimit">.. <S T="1" F="SpikeCurrentLimit" />.. </C>.. <C T="U32" I="5" O="false" N="MaxLimit">.. <S T="1" F="SpikeMaxLimit" />.. </C>.. <C T="U32" I="6" O="false" N="Factor">.. <S T="1" F="SpikeFactor" />.. </C>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):851
                                                                    Entropy (8bit):5.13362900928204
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdNjStk4SawSCSvAQENXWnerTPlVqK63XMpy/Py8/Ny4DFZNO2su:2dNjSDlwTJrbP6dr5
                                                                    MD5:A739D4DE49237DBAC4D3C707E80E8B96
                                                                    SHA1:08E9077E7A8E7A3F60600EEC861D944287338DDB
                                                                    SHA-256:F7802065990652094646F86074118DF52AC92AFE0AA4AE9F4C9B51407817E112
                                                                    SHA-512:BA11F5B70C32B06F14A76D6157979668165A5A4113D52DEF6A3C8A50D993C6BAAFC6C5EF0E12C4087BBC34042AE2B6CDE519BCC058852942DF7EBD628AEADB3E
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="90204" V="1" DC="SM" EN="Office.Telemetry.RulesEngineDiskThrottled" ATT="f998cc5ba4d448d6a1e8e913ff18be94-dd122e0a-fcf8-4dc5-9dbb-6afac5325183-7405" SP="CriticalBusinessImpact" T="Upload-Critical" DL="A" DCa="PSP PSU" xmlns="">.. <S>.. <UTS T="1" Id="bdc2l" A="a4biy" />.. </S>.. <C T="FT" I="0" O="false" N="ThrottlingTimestamp">.. <S T="1" F="TimeStamp100ns" />.. </C>.. <C T="U64" I="1" O="false" N="PayloadSize">.. <S T="1" F="PayloadSize" />.. </C>.. <C T="U64" I="2" O="false" N="SessionDiskWriteTotal">.. <S T="1" F="SessionDiskWriteTotal" />.. </C>.. <C T="U64" I="3" O="false" N="DiskWriteTotal">.. <S T="1" F="DiskWriteTotal" />.. </C>.. <C T="U64" I="4" O="false" N="DiskWriteLimit">.. <S T="1" F="DiskWriteLimit" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):760
                                                                    Entropy (8bit):4.67263028306523
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdQ5Suu74SawSCENXWnerJENerCUO+tNqNOUX/c//ZpONd+kXqNOzX/c//ZpOi:2d+SuuElw+JrmYrCUNt49CTqC
                                                                    MD5:29B9F2DBA856F305C9A9C50683CC87A0
                                                                    SHA1:D8B61550E9734A7A6C476DD75528D342EFCCA93F
                                                                    SHA-256:5E9A5A5009CF8D5F4F7861F00B4A6B8974F4F9B92D68045C36C9E1C244435B65
                                                                    SHA-512:07FD2EC529B68CA7193FE05FDCA83BEAFDB325759346A7F30BF1BF372F9046526E0705ED008140503B22B2B24CE23AFE826058D07D923537FEB38E9C5924E86F
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="90206" V="2" DC="SM" EN="Office.Telemetry.RulesEngineMediumCostThrottled" ATT="f998cc5ba4d448d6a1e8e913ff18be94-dd122e0a-fcf8-4dc5-9dbb-6afac5325183-7405" T="Upload-Critical" DL="A" DCa="PSP PSU" xmlns="">.. <S>.. <UTS T="1" Id="bhyua" A="a6iyn" />.. <UTS T="2" Id="bhyt2" A="bac31" />.. <F T="3">.. <O T="EQ">.. <L>.. <S T="1" F="NetworkCost" />.. </L>.. <R>.. <V V="1" T="U8" />.. </R>.. </O>.. </F>.. <F T="4">.. <O T="EQ">.. <L>.. <S T="2" F="NetworkCost" />.. </L>.. <R>.. <V V="1" T="U8" />.. </R>.. </O>.. </F>.. </S>.. <T>.. <S T="3" />.. <S T="4" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):673
                                                                    Entropy (8bit):5.071752018187274
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdWRBlbSawSC2RWnerlXFJjEQicitGzNUINO5AdHNUlu:2dozblwwzrJvLYR87
                                                                    MD5:95C1115BEC4D9DEB62C114707373435E
                                                                    SHA1:3FEC93A24BF9D3A4D0EE6035E57337C92B452FE2
                                                                    SHA-256:D7D89C0A1594E4CB047340691648D53016A83A17E52DBC1C2A053B86AC2823F3
                                                                    SHA-512:F44142723089D902016565736BA15358CFF18BE3FD33BED59CE2FC7822213FB346ED2CD394BB9F2A4C4BFA0C5BFBE5DF66BEB3F5985985FE962060C02167EC2D
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="90207" V="1" DC="SM" EN="Office.Telemetry.SystemHealthMetadataNetworkCost" ATT="f998cc5ba4d448d6a1e8e913ff18be94-dd122e0a-fcf8-4dc5-9dbb-6afac5325183-7405" T="Upload-Medium" DL="A" DCa="PSP PSU" xmlns="">.. <S>.. <UTS T="1" Id="a426l" />.. <A T="2" E="TelemetrySuspend" />.. <A T="3" E="TelemetryShutdown" />.. <TI T="4" I="Hourly" />.. </S>.. <C T="U8" I="0" O="false" N="NetworkCost">.. <S T="1" F="NetworkCost" />.. </C>.. <C T="TAG" I="1" O="false" N="Tag">.. <S T="1" F="ULS_Tag" />.. </C>.. <T>.. <S T="2" />.. <S T="3" />.. <S T="4" />.. </T>.. <ST>.. <S T="1" />.. </ST>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):604
                                                                    Entropy (8bit):5.179855489867653
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMHdZ0Bl0iSQSawSC2RWnerc3ntoBs/mUINO2su:2dyz0Clwwzr8QSg
                                                                    MD5:5F549CF5E15807BBEAD072D8A8B5CC17
                                                                    SHA1:B420B54B33FA37A0EDC7EE6C31D84C2B856BE190
                                                                    SHA-256:6DEB2D4AD918DA376C0CF7476B3E70FE23F6517AF08252E8DAD4D8CE89386EE0
                                                                    SHA-512:288C55CE7F9FEB2760B9F191C9D65956723207E0D20D33EA1898AA30CB90CE753382F35BD3158D1336D8F23E2E8695AD887123FAEF97B7FE8A473AD1D7A899B4
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="90208" V="0" DC="SM" EN="Office.Telemetry.SystemHealthMetadataNetworkCostChange" ATT="f998cc5ba4d448d6a1e8e913ff18be94-dd122e0a-fcf8-4dc5-9dbb-6afac5325183-7405" T="Upload-Medium" DL="A" DCa="PSP PSU" xmlns="">.. <S>.. <UTS T="1" Id="a426m" />.. </S>.. <C T="U8" I="0" O="false" N="NewNetworkCost">.. <S T="1" F="NewNetworkCost" />.. </C>.. <C T="U8" I="1" O="false" N="OldNetworkCost">.. <S T="1" F="OldNetworkCost" />.. </C>.. <C T="TAG" I="2" O="false" N="Tag">.. <S T="1" F="ULS_Tag" />.. </C>.. <T>.. <S T="1" />.. </T>..</R>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1877
                                                                    Entropy (8bit):4.975115444313837
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dVpqslwK3bTw2ritdFPZfPiIfzf9a/992iIylJw9hlPZ+:cVpqJK3bU22tTPV9aV92iulPA
                                                                    MD5:2CB1C9F1FD72BA022D6F43711D948110
                                                                    SHA1:FA7DDAB8A22298E24AF05042B29BA0BD81DEC01D
                                                                    SHA-256:6E63C111270BEE2D36BE2B09AB627D4EAD9BCC5957217602075D7CD2DEBD4FEA
                                                                    SHA-512:2DA24657DD4BB1CF80BAB6A1DCC6FD44B26971828C501F64D75AE780409C987615CAE10132D2CA5E6C2BA3D486E6C1C75B4972EF3DB953605FEB4FB1B6E142C2
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="90303" V="1" DC="SM" EN="Office.Telemetry.TelemetryUlsQueueUsage" ATT="f998cc5ba4d448d6a1e8e913ff18be94-dd122e0a-fcf8-4dc5-9dbb-6afac5325183-7405" SP="CriticalBusinessImpact" DL="A" DCa="PSP PSU" xmlns="">.. <S>.. <Etw T="1" E="192" G="{02fd33df-f746-4a10-93a0-2bc6273bc8e4}" />.. <UTS T="2" Id="avuo1" />.. <F T="3">.. <O T="GE">.. <L>.. <S T="1" F="QueueSizeInBytes" />.. </L>.. <R>.. <S T="1" F="ExtraProcessingLimit" />.. </R>.. </O>.. </F>.. <TR T="4" />.. </S>.. <C T="FT" I="0" O="false" N="ResultTime">.. <S T="4" F="TimeStamp100ns" />.. </C>.. <C T="U32" I="1" O="falseNoError" N="PeakQueueCB">.. <A T="MAX">.. <S T="1" F="QueueSizeInBytes" />.. </A>.. </C>.. <C T="U16" I="2" O="falseNoError" N="PeakEventCount">.. <A T="MAX">.. <S T="1" F="EventCount" />.. </A>.. </C>.. <C T="U32" I="3" O="falseNoError" N="AverageQueueCB">.. <A T="A
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):1249
                                                                    Entropy (8bit):4.85725913320415
                                                                    Encrypted:false
                                                                    SSDEEP:24:2dokNYwlwZlYrlHlqgVwPwlNBHVCPw9uP2f7eVie7:cBYdTYZF7+7
                                                                    MD5:01BDEC61AF8A91F0974FA2877635C522
                                                                    SHA1:65BCD305418E0F394BF8A480CB312C2DD2006B2E
                                                                    SHA-256:CB9AFFBB94DE8A990E1C1FE1F108947D0BE197C7D95483C774A758DBC594C677
                                                                    SHA-512:98FCAA668198A45B741C849137D0AF8C8DA2EB0409D9A47B86520CF7F14B7CEB78D9BA88B7F26F0D873CC036925FB52720A91582FD04889D5790CBD0D5E9B635
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<R Id="90401" V="3" DC="ESM" EN="Office.Telemetry.SamplingPolicy" ATT="f998cc5ba4d448d6a1e8e913ff18be94-dd122e0a-fcf8-4dc5-9dbb-6afac5325183-7405" DL="A" DCa="PSP PSU" xmlns="">.. <RIS>.. <RI N="Metadata" />.. </RIS>.. <S>.. <UTS T="1" Id="c57bd" />.. <R T="2" R="120100" />.. <SS T="3" G="{805a23b4-c402-413c-bc13-1861553d4b03}" />.. </S>.. <C T="W" I="0" O="false" N="SamplingMethod">.. <O T="COALESCE">.. <L>.. <S T="3" F="SamplingMethod" M="Ignore" />.. </L>.. <R>.. <V V="Unknown" T="W" />.. </R>.. </O>.. </C>.. <C T="W" I="1" O="false" N="SamplingKey">.. <O T="COALESCE">.. <L>.. <S T="3" F="SamplingKey" M="Ignore" />.. </L>.. <R>.. <V V="Unknown" T="W" />.. </R>.. </O>.. </C>.. <C T="B" I="2" O="false" N="MeasuresEnabled">.. <O T="COALESCE">.. <L>.. <S T="3" F="MeasuresEnabled" M="Ignore" />.. </L>.. <R>.. <V V="tr
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:SQLite 3.x database, last written using SQLite version 3034001, writer version 2, read version 2, file counter 2, database pages 1, cookie 0, schema 0, largest root page 1, unknown 0 encoding, version-valid-for 2
                                                                    Category:dropped
                                                                    Size (bytes):4096
                                                                    Entropy (8bit):0.09304735440217722
                                                                    Encrypted:false
                                                                    SSDEEP:3:lSWFN3l/klslpEl9Xll:l9F8E+9
                                                                    MD5:D0DE7DB24F7B0C0FE636B34E253F1562
                                                                    SHA1:6EF2957FDEDDC3EB84974F136C22E39553287B80
                                                                    SHA-256:B6DC74E4A39FFA38ED8C93D58AADEB7E7A0674DAC1152AF413E9DA7313ADE6ED
                                                                    SHA-512:42D00510CD9771CE63D44991EA10C10C8FBCF69DF08819D60B7F8E7B0F9B1D385AE26912C847A024D1D127EC098904784147218869AE8D2050BCE9B306DB2DDE
                                                                    Malicious:false
                                                                    Preview:SQLite format 3......@ ..........................................................................K.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:SQLite Rollback Journal
                                                                    Category:dropped
                                                                    Size (bytes):4616
                                                                    Entropy (8bit):0.1384465837476566
                                                                    Encrypted:false
                                                                    SSDEEP:3:7FEG2l++8/4/FllkpMRgSWbNFl/sl+ltlslN04l9Xll5p:7+/lB8/gg9bNFlEs1E39Bp
                                                                    MD5:958D8AC3F887302DE660310C75824E6D
                                                                    SHA1:537F29211FDF561DB5798445194D096A778484DF
                                                                    SHA-256:75E4642DD4906ADCB531435B3D3F04E7EDA50F4BC928231CB6E0BB7A7060CD27
                                                                    SHA-512:CE526C64DD243ACD0F8ECF9E766EDD4016625A73119CF07EDAD94C9F27E4490E4F65F77ADF368233FAED2711327BFA9A82878354BD5A0B18C93F748BF150B8B9
                                                                    Malicious:false
                                                                    Preview:.... .c............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................SQLite format 3......@ ..........................................................................K.................................................................................................................................................................................................................................................................................................................................................................................................
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:data
                                                                    Category:dropped
                                                                    Size (bytes):32768
                                                                    Entropy (8bit):0.04604146709717531
                                                                    Encrypted:false
                                                                    SSDEEP:3:GtlxtjlhyWP05Lc5IttlxtjlhyWP05LcTl/jR9//8l1lvlll1lllwlvlllglbelL:GtAhntAhG/t9X01PH4l942wU
                                                                    MD5:7C200343BFF2F44877A0B15D645B14BD
                                                                    SHA1:A46177216032E6CEA71941836F2F729DF91D5D7B
                                                                    SHA-256:49BBCD7C57100268C2E6F2C90C90916576F6CC7BD7CAC73666EC70D95E9A064C
                                                                    SHA-512:A4A01DEB4D27CF6852FD0359B6AE44E0E72724E43B8F9ED8E173D68D948952F88A3D0AE9ECF6A303455C6221F05673494AD2A2C76E04EA65D744862AD610A0E9
                                                                    Malicious:false
                                                                    Preview:..-.....................X...I...j.....l.R.@...-.....................X...I...j.....l.R.@.........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:SQLite Write-Ahead Log, version 3007000
                                                                    Category:dropped
                                                                    Size (bytes):49472
                                                                    Entropy (8bit):0.4856412103217
                                                                    Encrypted:false
                                                                    SSDEEP:48:MpQjvAXill7DYM3LXxO8VFDYMZUvBO8VFDYML:5bAyll4ELhjVG3jVGC
                                                                    MD5:196FC04B1C8F8A0C29EFA5A5591AAF0D
                                                                    SHA1:15AD2F4C0EE836DFBC50BA7EDDF2F2170DAC5EAE
                                                                    SHA-256:94BCF1904B05BCBD5D8E68575A34037A562393B8295E33A685F27940E46BF83F
                                                                    SHA-512:C8AF2FA6D19729CD1AFC2813A69ED5AD09AFBAA7C12F44236E0499342B6EEE39A79CE4C3754DE2914581C8662461246A5CF6D5F3946D69F7ACC18BD272444823
                                                                    Malicious:false
                                                                    Preview:7....-...........j......m..`0..........j....o....#.SQLite format 3......@ ..........................................................................K.............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):422
                                                                    Entropy (8bit):5.324913317979872
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMG8ORCA+xWWAGABxWWAeWWAnRAHYWWAAc+Sj86m:3PQA+fAGAZAedAnRA4dAmSjo
                                                                    MD5:554108A20E410C7CD1C5F36036146887
                                                                    SHA1:6C865CB3A2B51A3EF44235986B25DD541563BACE
                                                                    SHA-256:22AA981F10E839FBF2C5C3A8F3DE7CAA2F9C3ADD7AF4750420FD2B1A05BE1709
                                                                    SHA-512:1E9D8D6B3D184DAAAE2F9A23AEFE60F8D235DDC624034722E1E5CD982985B8F24B03A39BFA754E6E9504DEDB735E79FEEE1BB0771556287532FCC8AB98281F9C
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0"?>..<UserConfiguration>...<Info version="Outlook.16"/>...<Data>....<e k="18-piAvailGCShowPopup" v="3-True"/>....<e k="18-piFBUserPublishRange" v="9-2"/>....<e k="18-piAvailMtgShowPopup" v="3-True"/>....<e k="18-piAvailGCTextInGrid" v="3-True"/>....<e k="18-piFBUpdateSecs" v="9-900"/>....<e k="18-piAvailMtgTextInGrid" v="3-True"/>....<e k="18-OLPrefsVersion" v="9-1"/>...</Data>..</UserConfiguration>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):535
                                                                    Entropy (8bit):5.244869893194183
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMG8ORCA+mHKAlN3AoQME5LA2eqiAoQME5XAoQME5mAAc+S4ASAGtWuYj86m:3PQA+mHKAlN3AT5A1ATxATIAmS4ASAGL
                                                                    MD5:8689A861A9B529A49674FC3073DFD876
                                                                    SHA1:5210588E1B9A70AB7A9BF4CBD6BAA1099430D2DB
                                                                    SHA-256:55B7FFB57DF26E835EB39FB35F4B57A5057D48FFA7CF7CF94312E322C5BE21F7
                                                                    SHA-512:0A5A1699816FB28DE6CF6407542EE16B70229C3A66319359FF8E88B257EAD5B5DDD723702C05A62C3F181D7B8B53F73B4744FF6617E6771F6C3B07F678BCB413
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0"?>..<UserConfiguration>...<Info version="Outlook.16"/>...<Data>....<e k="18-piAutoProcess" v="3-True"/>....<e k="18-piRemindDefault" v="9-15"/>....<e k="18-piGroupCalendarShowMyDepartment" v="3-True"/>....<e k="18-piAutoDeleteReceipts" v="3-False"/>....<e k="18-piGroupCalendarShowDirectReports" v="3-True"/>....<e k="18-piGroupCalendarShowCoworkers" v="3-True"/>....<e k="18-OLPrefsVersion" v="9-1"/>....<e k="18-piShowFreeItems" v="9-0"/>....<e k="18-piShowWorkHourOnly" v="9-1"/>...</Data>..</UserConfiguration>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):267
                                                                    Entropy (8bit):5.160869873037959
                                                                    Encrypted:false
                                                                    SSDEEP:6:TMV08OLWYR9OAK2vsNRRM2fOgLs4ARUQMdMhUvARac+gKsjv06m:TMG8ORCA+W4AOQM5AAc+Sj86m
                                                                    MD5:F351722FC2FCF3A1585D2A4FCD3174F9
                                                                    SHA1:7107F9791498794416A472633D25F760FF62921C
                                                                    SHA-256:0A4D7E4860AFAC36C43F2E5272678B7E267B46618AB46A596DD28DBC4C5915E3
                                                                    SHA-512:EEF511A0E8C17D8DC6DB00BFBB46AE55E5F9257D9EA4B9ED1FCA1E0C4BD2EC7F96D859C76D67E8B2DF72E9336693337BBCC269C929CFC3AD2D4AD04DA08B355B
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0"?>..<UserConfiguration>...<Info version="Outlook.16"/>...<Data>....<e k="18-piConversationsOnInAllFoldersChangeNumber" v="9-1"/>....<e k="18-piUpgradeToConversations" v="9-2"/>....<e k="18-OLPrefsVersion" v="9-1"/>...</Data>..</UserConfiguration>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):196
                                                                    Entropy (8bit):5.121404985534659
                                                                    Encrypted:false
                                                                    SSDEEP:6:TMV08OLWYR9OAK2vsNRz+HKdMARac+gKsjv06m:TMG8ORCA+1+qiAAc+Sj86m
                                                                    MD5:18DD6E6C7E001E6EB529C89CB34A0035
                                                                    SHA1:936B54A457C3C556F9450B145FE8C2C37E39EDB2
                                                                    SHA-256:DFBDE381FDE1A284C81A72D06A1A43FAF49CD1C085C87234E34E50B881567806
                                                                    SHA-512:05B58C78D721E3D30815D964F997AF0B768D63F061AB1A4881E38C6FEBA89DF630828B5AE9AA54B8CF6C6124B773ADAE682BACD655B043C60F6C4F4A9058891D
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0"?>..<UserConfiguration>...<Info version="Outlook.16"/>...<Data>....<e k="18-piRuleOnAllRss" v="3-False"/>....<e k="18-OLPrefsVersion" v="9-1"/>...</Data>..</UserConfiguration>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):204
                                                                    Entropy (8bit):5.146779630782915
                                                                    Encrypted:false
                                                                    SSDEEP:6:TMV08OLWYR9OAK2vsNRKQKSBCKoUprARac+gKsjv06m:TMG8ORCA+oQrBCOAAc+Sj86m
                                                                    MD5:A4DA275C13ACAA46CEB0D2158220CA0B
                                                                    SHA1:9933ED454356A170E1CB3DB18ED7CB2895FDE004
                                                                    SHA-256:3F476C44779AE7EAE8BF64111B9D90E7A24D43B88A9E62507956A534C997C467
                                                                    SHA-512:69083E5BFCB09043044807452C78D680D5440D6E80F9311284518E15FBA7D7D8A71FD6DF18DFD8C479C27C8C80A8E73822D3D41BA2E0DC4DBFEF7AF4090A3CF9
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0"?>..<UserConfiguration>...<Info version="Outlook.16"/>...<Data>....<e k="18-piGroupExpandAnimations" v="3-True"/>....<e k="18-OLPrefsVersion" v="9-1"/>...</Data>..</UserConfiguration>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):634
                                                                    Entropy (8bit):4.927042331600238
                                                                    Encrypted:false
                                                                    SSDEEP:12:TMG45G7PHzABooZKIYhrxioxhoeBooZKIYhMQioXeotMYocLssFW0:3ikHI0IYhrx1b0IYhMQ79MNcLZFW0
                                                                    MD5:7C6BDDECBE4CFE6C1B9378ECDC6683A1
                                                                    SHA1:9023DCF630347858DC32844810CE514C28452B35
                                                                    SHA-256:C4777DFADCF735BF552275C911A28D9C612D7671B21F7C29B7281365AD72C1A8
                                                                    SHA-512:75660937C119C1A5B099B6B65EF4ACA69976337F7A8FC210FA6B40C52AE3149B190769D63DEDC52957D5B13A603BF5182C90DCA0399A7BF25F1C4F185370CE2F
                                                                    Malicious:false
                                                                    Preview:<?xml version="1.0"?>..<Root xmlns="WorkingHours.xsd">...<WorkHoursVersion1>....<TimeZone>.....<Bias>300</Bias>.....<Standard>......<Bias>0</Bias>......<ChangeDate>.......<Time>02:00:00</Time>.......<Date>0000/11/01</Date>.......<DayOfWeek>0</DayOfWeek>......</ChangeDate>.....</Standard>.....<DaylightSavings>......<Bias>-60</Bias>......<ChangeDate>.......<Time>02:00:00</Time>.......<Date>0000/03/02</Date>.......<DayOfWeek>0</DayOfWeek>......</ChangeDate>.....</DaylightSavings>.....<Name>Eastern Standard Time</Name>....</TimeZone>....<WorkDays>Monday Tuesday Wednesday Thursday Friday</WorkDays>...</WorkHoursVersion1>..</Root>..
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:PNG image data, 1149 x 101, 8-bit/color RGBA, non-interlaced
                                                                    Category:dropped
                                                                    Size (bytes):5696
                                                                    Entropy (8bit):7.625370767134974
                                                                    Encrypted:false
                                                                    SSDEEP:96:zEyPlQRlj6LutLN2h1K1P4nelwKzoeQWDJTw9U6UsPDGQEphBui8cqlPTDf:wiQLZCA1TlwvxWDbU8bBd8fZf
                                                                    MD5:E1715B9C9413A328E78802698E9319F5
                                                                    SHA1:EA2192D498AD180D51904A793FE7ECBC2C6EBD36
                                                                    SHA-256:1FEC8777EB117C2A859B433AFA013CF4C61CC1928B18EC2072FBAFEA723E401F
                                                                    SHA-512:18D4E98A3B51DC8A5B8AD0053ED8B88C39CA39C3CC90488D3A4247260697BE48CBD7619E1B594463CCD5FAA01BE4A0080BD06A86DBF2D7D3719C394AD8445808
                                                                    Malicious:false
                                                                    Preview:.PNG........IHDR...}...e.......Q....sRGB.........gAMA......a.....pHYs..........o.d....IDATx^..M..6..n...........y..9..v.s.ka.u....H.d...$.>...J$@...{hI..............Sys;......`"........../}......&.K........=............&......>.......y....y.......Yk.[W..<.X...#b_.s.{.......-.....[.K...>>.......|.t....f..5o.]}o.l`.....}9.U.%..0..C...>..r......../}......&.K................`B........../}......&.K................`B........../}......&.K................`B........../}......&.K...?........w....{........=.....g.....~...............q.5.k.Qi....0.......+...Z..z.y..1Fs8.<.G4..j.......}.w.-.R...s]......w..k...^{i....o9.{]..q-.Gt.%.`>C........2b.I?g0z.8.......;.)Gf..s|..Z..Go>."{.uo.....R.}.U....IYbi.#.1.V.:G....CJ..| #{....K......=.b... ...G66.......\..=Ec.1..=q=....{K...8.Z...(..}....{...5.g?&..c.h...kx..g...+.m.l..i<..8.O.S..e.fv.rn.....T..H......s.sD..G[.(."...~..}N.v/..ey[.........jQ>...9.l\Q\.}n...(...z.Bsm,......A.Z.../}.BZt......q..s....\d..Rt}{..%..|U
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:data
                                                                    Category:dropped
                                                                    Size (bytes):1024
                                                                    Entropy (8bit):0.03351732319703582
                                                                    Encrypted:false
                                                                    SSDEEP:3:ol3lG:40
                                                                    MD5:830FBF83999E052538EAF156AB6ECB17
                                                                    SHA1:9F6C69FA4232801D3A4857C630BA7A719662135A
                                                                    SHA-256:D5098A2CEAE815DB29CD53C76F85240C95DC4D2E3FEDDD71D628617064C29869
                                                                    SHA-512:A83E2E9D5274F0065A26C306F355E9590D6126297EAD87AF053CC78FB64CB31694C533139F72686C77FC772148181D8AAE973E65978D04E5F20F6F6C6BA0A013
                                                                    Malicious:false
                                                                    Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:data
                                                                    Category:dropped
                                                                    Size (bytes):78336
                                                                    Entropy (8bit):4.121496776157116
                                                                    Encrypted:false
                                                                    SSDEEP:768:Uvx0y7i4g00QHDpmN6BCfcsCE+y7smMwmBDcvl23DKc8KjMyKE0E+uEI/lT+x:E50N2CfcsCE+ldDkl23DK4lyx
                                                                    MD5:85F2D9656CB5D87AEED33A62560C38EC
                                                                    SHA1:CFA64BC70198D06B27D8EEF4F45CBF0213B8B56D
                                                                    SHA-256:A8F55D1FC995CD71C79B56720B03845AFAF81B58B1569503F2AC283169F356FD
                                                                    SHA-512:A318F6CDD3AF835174FD386DA36BC70BBF666586C9E027AB8841FF023FD62A29A52D8442D2F14048F2BAAC26C72661D8162D4186DCEB13D1CCA4A5D21E8A93A9
                                                                    Malicious:false
                                                                    Preview:....H.i. .B.e.t.s.y. .....W.e. .h.a.v.e. .r.e.c.e.i.v.e.d. .y.o.u.r. .p.a.y.m.e.n.t. .b.e.l.o.w. .i.n. .r.e.c.e.n.t. .d.a.y.s.,. .m.a.n.y. .t.h.a.n.k.s.....F.r.o.m. .o.u.r. .s.y.s.t.e.m. .t.h.o.u.g.h. .i.t. .l.o.o.k.s. .l.i.k.e. .y.o.u. .h.a.v.e. .p.a.i.d. .i.n.v.o.i.c.e. .r.e.f. .2.0.1.3.2.6.3.9.1. .t.w.i.c.e.?...T.h.e.r.e. .w.a.s. .o.n.l.y. .o.n.e. .o.u.t.s.t.a.n.d.i.n.g. .i.n.v.o.i.c.e. .a.s. .b.e.l.o.w.,. .2.0.1.3.2.6.3.9.0.........................................................................................................<...........D...F...b...........*...,=...=...>...>...@...@..:F..JF..LF...H...H..\O..^O..........................................................................................................................................................................................................................................................................................................................................................................................
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:ASCII text, with very long lines (28731), with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):20971520
                                                                    Entropy (8bit):0.14625086094287204
                                                                    Encrypted:false
                                                                    SSDEEP:1536:S1P2LJVClGTG2PCL/8Xbs6aR6VnHvhJjtARMsW4acSj0B6:XJ8MnPCwQEpz
                                                                    MD5:4FF0EAED24E2F61DDC3C1DF765912474
                                                                    SHA1:06EBCAB8D9F49474479E7F499C06DA1518DAEB01
                                                                    SHA-256:64A06940F3660090D9374A69E23074B5E58DA143B110D5EE0A728E29C313BA74
                                                                    SHA-512:E1D99BE56B61E05B8C9B88527C68AFC639539C527D834AFF13AA7FC41886BD37F1C67AB088AD2AF2619EBB8B8A890B769CDCC079BD6FB15D0C871CB0D786B9A3
                                                                    Malicious:false
                                                                    Preview:Timestamp.Process.TID.Area.Category.EventID.Level.Message.Correlation..09/27/2024 14:48:44.805.OUTLOOK (0x1AFC).0x1B00.Microsoft Outlook.Telemetry Event.b7vzq.Medium.SendEvent {"EventName":"Office.Text.GDIAssistant.HandleCallback","Flags":30962256044949761,"InternalSequenceNumber":21,"Time":"2024-09-27T14:48:44.805Z","Contract":"Office.System.Activity","Activity.CV":"bq2tqmq5okm13uKYgerGcQ.4.9","Activity.Duration":15,"Activity.Count":1,"Activity.AggMode":0,"Activity.Success":true,"Data.GdiFamilyName":"","Data.CloudFontStatus":6,"Data.CloudFontTypes":256}...09/27/2024 14:48:44.821.OUTLOOK (0x1AFC).0x1B00.Microsoft Outlook.Telemetry Event.b7vzq.Medium.SendEvent {"EventName":"Office.Text.ResourceClient.Deserialize","Flags":30962256044949761,"InternalSequenceNumber":23,"Time":"2024-09-27T14:48:44.821Z","Contract":"Office.System.Activity","Activity.CV":"bq2tqmq5okm13uKYgerGcQ.4.10","Activity.Duration":10710,"Activity.Count":1,"Activity.AggMode":0,"Activity.Success":true,"Data.JsonFileMajorV
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:data
                                                                    Category:dropped
                                                                    Size (bytes):20971520
                                                                    Entropy (8bit):0.0
                                                                    Encrypted:false
                                                                    SSDEEP:3::
                                                                    MD5:8F4E33F3DC3E414FF94E5FB6905CBA8C
                                                                    SHA1:9674344C90C2F0646F0B78026E127C9B86E3AD77
                                                                    SHA-256:CD52D81E25F372E6FA4DB2C0DFCEB59862C1969CAB17096DA352B34950C973CC
                                                                    SHA-512:7FB91E868F3923BBD043725818EF3A5D8D08EBF1059A18AC0FE07040D32EEBA517DA11515E6A4AFAEB29BCC5E0F1543BA2C595B0FE8E6167DDC5E6793EDEF5BB
                                                                    Malicious:false
                                                                    Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:ASCII text, with very long lines (28791), with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):20971520
                                                                    Entropy (8bit):0.1787163612098277
                                                                    Encrypted:false
                                                                    SSDEEP:1536:NUs8tsO3zQY8xkl4WoC2awOSfNTnTt6A1Q/wQfbCcl2/chcN4BSFjhgb+XSB9fN3:MsIzQNceOXf
                                                                    MD5:D20297F89CFF19E228491E5BF6BCFBF9
                                                                    SHA1:21EB4886BF12B58F819F20C7A9BF045FBC73A3FE
                                                                    SHA-256:17D2D9BEEA98A5A6191425E4F782316784DBC360E7A69D1A89CB0846B9338FA9
                                                                    SHA-512:B194B2D280678ABC013653BBD9BB7117FD8C0715D2CC44770B99D44002ECD060D40DC2D1494C58D5C44A49572678DB8C5C09632F42BB8A251F5E1AAC5E757A98
                                                                    Malicious:false
                                                                    Preview:Timestamp.Process.TID.Area.Category.EventID.Level.Message.Correlation..09/27/2024 14:50:37.526.OUTLOOK (0xCD4).0xCF0.Microsoft Outlook.Telemetry Event.b7vzq.Medium.SendEvent {"EventName":"Office.Text.GDIAssistant.HandleCallback","Flags":30962256044949761,"InternalSequenceNumber":25,"Time":"2024-09-27T14:50:37.526Z","Contract":"Office.System.Activity","Activity.CV":"PWQzL2lWCEi9cy0NnRWZTg.4.12","Activity.Duration":17,"Activity.Count":1,"Activity.AggMode":0,"Activity.Success":true,"Data.GdiFamilyName":"","Data.CloudFontStatus":6,"Data.CloudFontTypes":256}...09/27/2024 14:50:37.542.OUTLOOK (0xCD4).0xCF0.Microsoft Outlook.Telemetry Event.b7vzq.Medium.SendEvent {"EventName":"Office.Text.ResourceClient.Deserialize","Flags":30962256044949761,"InternalSequenceNumber":27,"Time":"2024-09-27T14:50:37.542Z","Contract":"Office.System.Activity","Activity.CV":"PWQzL2lWCEi9cy0NnRWZTg.4.13","Activity.Duration":13233,"Activity.Count":1,"Activity.AggMode":0,"Activity.Success":true,"Data.JsonFileMajorVers
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:data
                                                                    Category:dropped
                                                                    Size (bytes):20971520
                                                                    Entropy (8bit):0.0
                                                                    Encrypted:false
                                                                    SSDEEP:3::
                                                                    MD5:8F4E33F3DC3E414FF94E5FB6905CBA8C
                                                                    SHA1:9674344C90C2F0646F0B78026E127C9B86E3AD77
                                                                    SHA-256:CD52D81E25F372E6FA4DB2C0DFCEB59862C1969CAB17096DA352B34950C973CC
                                                                    SHA-512:7FB91E868F3923BBD043725818EF3A5D8D08EBF1059A18AC0FE07040D32EEBA517DA11515E6A4AFAEB29BCC5E0F1543BA2C595B0FE8E6167DDC5E6793EDEF5BB
                                                                    Malicious:false
                                                                    Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:DIY-Thermocam raw data (Lepton 3.x), scale 0-0, spot sensor temperature 0.000000, unit celsius, color scheme 0, userbration: offset 0.000000, slope 134217728.000000
                                                                    Category:dropped
                                                                    Size (bytes):90112
                                                                    Entropy (8bit):4.482222143468273
                                                                    Encrypted:false
                                                                    SSDEEP:768:/fjO2F45ZZ6gYZLb47e9uyJ3LATt7XmOdJu0IXV/yhEORM6VC9o+:D347e9uytJXJKjM60
                                                                    MD5:4A02806B24DBC638EC9031694413E528
                                                                    SHA1:1A5AB8DCD1D26DE49BB6A2A88A5E81DAA886E967
                                                                    SHA-256:9B6B582239813523F2BA569BB7375A83E0A4E5F49F4DBAFA20848399286FB8F0
                                                                    SHA-512:DAEB49217E08E7F1A48934B7678BB6B616012A3AD43EF690E8726559E53D3C4844C26CA1D9A25ECA7E16913A56676119F5AF09D5E1AC812C44059AC997A9AEEB
                                                                    Malicious:false
                                                                    Preview:............................................................................`...........(..Y....................eJ..............Zb..2...................................,...@.t.z.r.e.s...d.l.l.,.-.1.1.2.......................................................@.t.z.r.e.s...d.l.l.,.-.1.1.1...........................................................0Z.7.Y..........(..Y............v.2._.O.U.T.L.O.O.K.:.1.a.f.c.:.9.b.3.e.0.f.c.5.f.3.6.f.4.0.f.0.8.a.7.c.0.1.e.6.8.7.c.9.e.5.8.4...C.:.\.U.s.e.r.s.\.c.a.l.i.\.A.p.p.D.a.t.a.\.L.o.c.a.l.\.T.e.m.p.\.O.u.t.l.o.o.k. .L.o.g.g.i.n.g.\.O.U.T.L.O.O.K._.1.6._.0._.1.6.8.2.7._.2.0.1.3.0.-.2.0.2.4.0.9.2.7.T.1.0.4.8.4.4.0.5.0.7.-.6.9.0.8...e.t.l.......P.P.........(..Y............................................................................................................................................................................................................................................................................................................
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:data
                                                                    Category:dropped
                                                                    Size (bytes):81920
                                                                    Entropy (8bit):4.4050962635908295
                                                                    Encrypted:false
                                                                    SSDEEP:768:w2e8Ll9PqyLFu5r8epV4G19lNTeCU4oPfNXe:Itq4b4G19lNTeC7ClXe
                                                                    MD5:F2D736DD602D7811344281FEA6DA5598
                                                                    SHA1:74BE70E314011448FD1D76BFB512BAD3637B2B44
                                                                    SHA-256:96AD9742213BE210B7BAD20C29A6FA4AC892FA3FCF2CCC1BD8E89679DD8D9CE6
                                                                    SHA-512:97E1EE1C72CF46D143FCC7AC1F17BB77173FCD46637B07E1A68CC93815C30E4BE42F94E79EA224F5D1DFECAB7B93297F03D290EBA56894455FE5E2BAE12E12C0
                                                                    Malicious:false
                                                                    Preview:............................................................................^...........p$(.....................eJ..............Zb..2...................................,...@.t.z.r.e.s...d.l.l.,.-.1.1.2.......................................................@.t.z.r.e.s...d.l.l.,.-.1.1.1...........................................................0Z.7.Y..........p$(.............v.2._.O.U.T.L.O.O.K.:.c.d.4.:.e.0.4.7.0.8.3.7.4.2.2.d.4.d.5.a.8.3.e.1.c.b.5.9.d.d.0.8.1.f.e.4...C.:.\.U.s.e.r.s.\.c.a.l.i.\.A.p.p.D.a.t.a.\.L.o.c.a.l.\.T.e.m.p.\.O.u.t.l.o.o.k. .L.o.g.g.i.n.g.\.O.U.T.L.O.O.K._.1.6._.0._.1.6.8.2.7._.2.0.1.3.0.-.2.0.2.4.0.9.2.7.T.1.0.5.0.3.7.0.2.5.4.-.3.2.8.4...e.t.l.........P.P..........*.............................................................................................................................................................................................................................................................................................................
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):214
                                                                    Entropy (8bit):5.150004008618427
                                                                    Encrypted:false
                                                                    SSDEEP:6:+Q3adOECOq4RMAZgRsDjn/PA0ttnuUYyyHT7wn:V3LeMAW2fPhttZyHfw
                                                                    MD5:97370BEAA1C83E15765DD0B04322B5B6
                                                                    SHA1:96081028896C94D5791EE0EDEC32673358AA5C92
                                                                    SHA-256:A33788C08EA038B1AB4C8218C269008B40F9E8EAC96FEC74593F3EDB60F633E0
                                                                    SHA-512:7F74A52E0D6616F5B3CE356F1D56A35521C7762975D947D4C4497963904FC777B0F027664CE5F75614F96EF3FEF0250E6AF070C08AB838A3092E74632C090969
                                                                    Malicious:false
                                                                    Preview:Final-recipient: RFC822; Damien.Fitzpatrick@combilift.com..Disposition: automatic-action/MDN-sent-automatically; displayed..X-MSExch-Correlation-Key: ZV9ue+/Me0qHok5FURXKCA==..X-Display-Name: Damien Fitzpatrick....
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:data
                                                                    Category:dropped
                                                                    Size (bytes):30
                                                                    Entropy (8bit):1.2389205950315936
                                                                    Encrypted:false
                                                                    SSDEEP:3:Dblt:vl
                                                                    MD5:FF4EA0A14F7DA281601A647DA579ACB3
                                                                    SHA1:0DC2EE4F1B3B79E39C449B8E87D2ED87FB4EF398
                                                                    SHA-256:E58EFC2316F71BDA5329F934FF9D3ECF39BC8B0FA9ED4DE395B2A481F05DF389
                                                                    SHA-512:09EC22CB9724265DC112E40BA8A09F0208A43A9CFECC09D4479D1672419B0ADCDB66324F7B8F30AD40A2A4205CFA935E7562BD6F3F1678120E74B19BE901D45C
                                                                    Malicious:false
                                                                    Preview:....4.........................
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:Composite Document File V2 Document, Cannot read section info
                                                                    Category:dropped
                                                                    Size (bytes):2560
                                                                    Entropy (8bit):2.0143311438239095
                                                                    Encrypted:false
                                                                    SSDEEP:12:rl3baFiHqLKeTy2MyheC8T23BMyhe+S7wzQe9zNMyhe+S7xMyheC1B:rgmnq1Pj961j
                                                                    MD5:68A526B19D224B7C8EADD1F46BF53F35
                                                                    SHA1:C5C49721444431CAF4927E6B755B92FCD4C05B26
                                                                    SHA-256:EA4D299A45A7DE8268C8E58D2166C4F48A64FA09F036E5A25A196970545261D5
                                                                    SHA-512:4B3FB14B1F9710E6D1B98A1AA0C183E4654DB65A2418C28A38C58B96A5E6177F5CDB3543C713DB75F529AA3F7DBA0878D3A51BB2D527582AD307083370100999
                                                                    Malicious:false
                                                                    Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:Microsoft Word 2007+
                                                                    Category:dropped
                                                                    Size (bytes):19613
                                                                    Entropy (8bit):7.479410129087913
                                                                    Encrypted:false
                                                                    SSDEEP:384:Jrt+xRLymSajsqEWzFCjCw/vhg8L7KYA8DPWdvBAFW4U:VywGvEWz/wBgG77Au+dvmU
                                                                    MD5:67BB53E2A97A7CFF3BF3E5C86FF2E104
                                                                    SHA1:E4B3CE896FBFC9AEA55175620A0D875775FA27EB
                                                                    SHA-256:5575B146D9A270329B6B6A6AE6B7DA05502D96F093D82F055D344FD62884EAB0
                                                                    SHA-512:C0717A511882781A1D532C752C9BBE0E3E3E6BBEF604C5432100A37469C41FD8A7DDEBE9F6F50E53DA8744B00AFAC5F0E5C9C4501499CD44D6D165423244321D
                                                                    Malicious:false
                                                                    Preview:PK..........!.Q3.p............[Content_Types].xml ...(.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................N.0.E.H.C.-J\X ......J..0....K......H...R*.D.g..3.H....M!`.l.....J.j;*...>.b.Fa...B....wz...<`F..K6.._s.r.F`.<X.T....7....U.._t:.\:...<&....A%&:f.9..H.hd..*1y.Lx.k)".........e..k.g.....)....&......A...3..WNN.U..e...<....'4(.....x.....nh.t.....p7..j..s...I@.w6.X..C.Tp...r+..^..F.N...".az...h.[!F.!...g...i"...C..n9.~l...3.....H..V..9.2.,)s..GZD..mo6M..a.!...q$.......O..r-.........PK..........!.........N......
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:data
                                                                    Category:modified
                                                                    Size (bytes):162
                                                                    Entropy (8bit):4.810030080572816
                                                                    Encrypted:false
                                                                    SSDEEP:3:8lZlYl1B/7Q4kLuMuU2INbkkD+ul/FceJUkc25kG:0ZiHhoCMuU2ekDq/mWrcskG
                                                                    MD5:CB19DDBAB18EF1BCE0B7CB2C3E5B934C
                                                                    SHA1:555169524D8D751160D5C1914D7F910F91913E59
                                                                    SHA-256:DB95B0255BCD3911997845A4CC209909404B4A86C56CDAD59F551665FBE134AB
                                                                    SHA-512:4FC66D82C54ADBC44954BAB70616C37196C1B931254E8E06E12F34E670B76ED86C6ED02F727C868278ACCADD8AAFF441F977AE97EED92FFA7F8168D920C834CC
                                                                    Malicious:false
                                                                    Preview:.user...................................................c.a.l.i...,....*E.l.....M.X<K..oI$I.......D......4....(....D..)9............P..lq..}.c....PM...=Ac
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:Microsoft Word 2007+
                                                                    Category:dropped
                                                                    Size (bytes):19613
                                                                    Entropy (8bit):7.479410129087913
                                                                    Encrypted:false
                                                                    SSDEEP:384:Jrt+xRLymSajsqEWzFCjCw/vhg8L7KYA8DPWdvBAFW4U:VywGvEWz/wBgG77Au+dvmU
                                                                    MD5:67BB53E2A97A7CFF3BF3E5C86FF2E104
                                                                    SHA1:E4B3CE896FBFC9AEA55175620A0D875775FA27EB
                                                                    SHA-256:5575B146D9A270329B6B6A6AE6B7DA05502D96F093D82F055D344FD62884EAB0
                                                                    SHA-512:C0717A511882781A1D532C752C9BBE0E3E3E6BBEF604C5432100A37469C41FD8A7DDEBE9F6F50E53DA8744B00AFAC5F0E5C9C4501499CD44D6D165423244321D
                                                                    Malicious:false
                                                                    Preview:PK..........!.Q3.p............[Content_Types].xml ...(.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................N.0.E.H.C.-J\X ......J..0....K......H...R*.D.g..3.H....M!`.l.....J.j;*...>.b.Fa...B....wz...<`F..K6.._s.r.F`.<X.T....7....U.._t:.\:...<&....A%&:f.9..H.hd..*1y.Lx.k)".........e..k.g.....)....&......A...3..WNN.U..e...<....'4(.....x.....nh.t.....p7..j..s...I@.w6.X..C.Tp...r+..^..F.N...".az...h.[!F.!...g...i"...C..n9.~l...3.....H..V..9.2.,)s..GZD..mo6M..a.!...q$.......O..r-.........PK..........!.........N......
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:Microsoft Outlook email folder (>=2003)
                                                                    Category:dropped
                                                                    Size (bytes):271360
                                                                    Entropy (8bit):2.460309909836974
                                                                    Encrypted:false
                                                                    SSDEEP:1536:Im0zhpqFSC5n2v3kdR+SLdLZEwW53jEpEHP4qQ10PAwr1uxd3W53jEpEHP4qQ10/:O25n2v38TLdLSyp9dZp9
                                                                    MD5:6BA5B0DA44F315D039E7E1E7B729B9A0
                                                                    SHA1:E5D4277FCF722D7BAD1277946D71EF9DDA061C4A
                                                                    SHA-256:717F1E0DEFE148CCF5C93267D16D5B8AA4FC8F084EEFCC92FC546FF19E6F97E2
                                                                    SHA-512:FE6D824CC2EE068EFBCB6A01067DE09C020920C64F8603A2733D3BED1C4F476420E6DE863E3C84854E2B04F91DCF3D5C19B3708ABA3B4903B07ABFB7AAFF627E
                                                                    Malicious:false
                                                                    Preview:!BDN..SM......\..."...................a................@...........@...@...................................@...........................................................................$.......D......@........................Z...............J..................................................................................................................................................................................................................................................................................(.......[....&......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                    Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    File Type:data
                                                                    Category:dropped
                                                                    Size (bytes):131072
                                                                    Entropy (8bit):0.03451453321691608
                                                                    Encrypted:false
                                                                    SSDEEP:3:RllFlCJd1lzohKE/L/l/EhTlu/m8hlGJ7lplplu/0J0JmFlplplplplplplplpll:5yd19vE6E/mwb/0J0JmYX4b//B6/w
                                                                    MD5:91F452B2855D5E4A7FE1F9965043E417
                                                                    SHA1:0E3F98F4EF2EEB81590A4172275274A498498BBE
                                                                    SHA-256:39BC2FCF9933B587857BBE3645887902307800C9DD0BC1AAB746B11F2B6CEEEB
                                                                    SHA-512:02EFD9EEEDCA1BEE6564848E88A7EEE11B0F1FB9F03EF9040803F3D110397C032B340675DDCA5823A710ADA8F4D054949175D15159585F1F4C8FFF912B6F5598
                                                                    Malicious:false
                                                                    Preview::.u|C...............oS........................#.!BDN..SM......\..."...................a................@...........@...@...................................@...........................................................................$.......D......@........................Z...............J..................................................................................................................................................................................................................................................................................(.......[....&......................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                    File type:RFC 822 mail, ASCII text, with very long lines (679), with CRLF line terminators
                                                                    Entropy (8bit):5.648893468428007
                                                                    TrID:
                                                                    • E-Mail message (Var. 5) (54515/1) 100.00%
                                                                    File name:Read_ Statement.eml
                                                                    File size:11'951 bytes
                                                                    MD5:d913c22b4dce731e1cd11b9845086244
                                                                    SHA1:f13468f3f2d34e34636aa11ff37ffd6e8fa38225
                                                                    SHA256:18e76a6e3004e92dec27187b944ea5302368a1756e1812926b4bdebb09fde1e6
                                                                    SHA512:eb020af09c92a7ae69d0da2e962f08e7f50bd71cfb3d9b4ad393bdc5814326ab6b889b2f1ff57464e182f3a50057448b625f0cbb743dc9c260c2c710e196f692
                                                                    SSDEEP:192:9PJuL9bymTkbGrDIwIeMF3meRGFjvCbh2GPxPR7zJmWqeuUi1RZri:yL5kb6DFcFOlaJLeUci
                                                                    TLSH:EE3213A2D20C3037ACE267AE6BA03681DE7D5DC8C6D65C92A9BCD9C417474C0B35EF85
                                                                    File Content Preview:Received: from AS2PR08MB9714.eurprd08.prod.outlook.com (2603:10a6:20b:606::16).. by VI0PR08MB11170.eurprd08.prod.outlook.com (2603:10a6:800:251::18) with.. Microsoft SMTP Server (version=TLS1_2,.. cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.800
                                                                    Subject:Read: Statement
                                                                    From:Damien Fitzpatrick <Damien.Fitzpatrick@combilift.com>
                                                                    To:"Nilges, Bridget" <nilgesb@cbequipment.com>
                                                                    Cc:
                                                                    BCC:
                                                                    Date:Fri, 27 Sep 2024 07:30:44 +0000
                                                                    Communications:
                                                                    • Your message To: Damien Fitzpatrick Subject: Statement Sent: Thursday, September 26, 2024 6:18:51 PM (UTC+00:00) Dublin, Edinburgh, Lisbon, London was read on Friday, September 27, 2024 8:30:26 AM (UTC+00:00) Dublin, Edinburgh, Lisbon, London.
                                                                    Attachments:
                                                                    Key Value
                                                                    Receivedfrom AS2PR08MB9714.eurprd08.prod.outlook.com ([fe80::bab7:28d5:94bd:ed6f]) by AS2PR08MB9714.eurprd08.prod.outlook.com ([fe80::bab7:28d5:94bd:ed6f%3]) with mapi id 15.20.8026.005; Fri, 27 Sep 2024 07:30:44 +0000
                                                                    FromDamien Fitzpatrick <Damien.Fitzpatrick@combilift.com>
                                                                    To"Nilges, Bridget" <nilgesb@cbequipment.com>
                                                                    SubjectRead: Statement
                                                                    Thread-TopicStatement
                                                                    Thread-IndexAQHbEDfoWaqBRuCP/0yFCXbt6kxjzLJrPc6p
                                                                    DateFri, 27 Sep 2024 07:30:44 +0000
                                                                    Message-ID<f0-1eAS2PR08MB97140FE0C41B9DE5F6CB4B609B6B2@AS2PR08MB9714.eurprd08.prod.outlook.com>
                                                                    In-Reply-To<SJ0PR07MB75208BE1B6BBF9B83F6213AAA66A2@SJ0PR07MB7520.namprd07.prod.outlook.com>
                                                                    Accept-Languageen-GB, en-US
                                                                    X-MS-Exchange-Organization-AuthAsInternal
                                                                    X-MS-Exchange-Organization-AuthMechanism04
                                                                    X-MS-Exchange-Organization-AuthSourceAS2PR08MB9714.eurprd08.prod.outlook.com
                                                                    X-MS-Has-Attach
                                                                    X-MS-Exchange-Organization-SCL-1
                                                                    X-MS-TNEF-Correlator
                                                                    x-ms-exchange-organization-internalorgsenderTrue
                                                                    authentication-resultsdkim=none (message not signed) header.d=none;dmarc=none action=none header.from=combilift.com
                                                                    x-ms-exchange-organization-recordreviewcfmtype0
                                                                    x-ms-exchange-organization-originalsize7070
                                                                    x-ms-exchange-organization-originalarrivaltime27 Sep 2024 07:30:44.3125 (UTC)
                                                                    x-ms-exchange-organization-messagesourceStoreDriver
                                                                    x-ms-exchange-organization-fromentityheaderHosted
                                                                    x-ms-exchange-organization-messagedirectionalityOriginating
                                                                    x-ms-exchange-organization-id30e7cfeb-de63-4c35-b2be-c898f97b9519
                                                                    X-MS-Exchange-Organization-BCC
                                                                    x-ms-exchange-organization-originalclientipaddress213.133.69.138
                                                                    x-ms-exchange-organization-mailuseragent-ipaddress[213.133.69.138]
                                                                    x-ms-exchange-organization-originalserveripaddress2603:10a6:20b:606::16
                                                                    x-ms-exchange-organization-submissionrecipientcount1
                                                                    x-ms-exchange-organization-orgeopforestEUR04
                                                                    x-ms-exchange-organization-network-message-idd921f761-d1b5-4c1f-598d-08dcdec64c3c
                                                                    x-ms-exchange-organization-transporttraffictypeEmail
                                                                    x-ms-publictraffictypeEmail
                                                                    x-ms-traffictypediagnosticAS2PR08MB9714:EE_|VI0PR08MB11170:EE_
                                                                    x-ms-exchange-organization-mailboxtypeHOSTED
                                                                    x-ms-exchange-organization-userprincipalnameMTip1pdMmM23hrDyD3XR1Fgo2O2XVS6AJMbn9XveXdbnU6WCaxse0kKjlH6v1fZpCdoMsgPlLSBo4Q6rQBj3GCGAsNSimUU76uti3aiTsHWlvUJ2+UPFtl47yJbHcuYx
                                                                    x-ms-exchange-organization-antispam-mailboxsubmissionfilter-policyloadtimeMSFAPolicyLoadTime:0
                                                                    x-ms-exchange-organization-sendspamsignaltohostedmailboxtrue
                                                                    x-ms-exchange-organization-usermbx-userprincipalnamedamien.fitzpatrick@combilift.com
                                                                    x-ms-exchange-organization-usermbx-aadobjectida4e4f9e6-c44d-48ca-ae07-fcf2a5310fab
                                                                    x-ms-exchange-organization-aadsender-passwordlastset636831499328468696
                                                                    x-ms-exchange-organization-aadsender-creationtime636794537150000000
                                                                    x-ms-exchange-organization-aadsender-isdirsynced1
                                                                    x-ms-exchange-organization-aadsender-accounttypeUserMailbox
                                                                    x-ms-exchange-organization-mailuseragent-clienttypeMoMT
                                                                    x-ms-exchange-organization-usermbx-cpev6572
                                                                    x-ms-exchange-organization-usermbx-throttlelvl0
                                                                    x-ms-exchange-organization-usermbx-24hrsusalrts0
                                                                    x-ms-exchange-organization-usermbx-24hrblockcnt0
                                                                    x-ms-exchange-organization-usermbx-24hrmsgssent64
                                                                    x-ms-exchange-organization-usermbx-minutesfromclientipfirstseentonow2409085
                                                                    x-ms-exchange-organization-usermbx-minutesfromclientiplastseentonow5
                                                                    x-ms-exchange-organization-usermbx-minutesfromcountryfirstseentonow2697117
                                                                    x-ms-exchange-organization-usermbx-minutesfromcountrylastseentonow5
                                                                    x-ms-exchange-organization-usermbx-minutesfromclienttypefirstseentonow2852655
                                                                    x-ms-exchange-organization-usermbx-minutesfromclienttypelastseentonow5
                                                                    x-ms-exchange-organization-usermbx-currentmsgexternalrcptcount1
                                                                    x-ms-exchange-organization-orderedprecisionlatencyinprogressLSRV=AS2PR08MB9714.eurprd08.prod.outlook.com:TOTAL-SUB=0.251|EBA=0.055|MTSS-PEN=0.196(MTSSD-PEN=0.196(MTSSDC=0.146|MTSSDSDM=0.039(MTSSDSDM-Mailbox Submission Filter Agent=0.038 (SDMMP=0.038(SDMSE=0.021)))));2024-09-27T07:30:44.563Z
                                                                    x-ms-exchange-forest-arrivalhubserverVI0PR08MB11170.eurprd08.prod.outlook.com
                                                                    x-ms-exchange-organization-expirationstarttime27 Sep 2024 07:30:44.7085 (UTC)
                                                                    x-ms-exchange-organization-expirationstarttimereasonOriginalSubmit
                                                                    x-ms-exchange-organization-expirationinterval1:00:00:00.0000000
                                                                    x-ms-exchange-organization-expirationintervalreasonOriginalSubmit
                                                                    x-ms-exchange-organization-messagescope4125a922-5945-406b-9480-34c07b5078d6
                                                                    x-ms-exchange-forest-messagescope4125a922-5945-406b-9480-34c07b5078d6
                                                                    x-ms-exchange-organization-cross-premises-headers-processedVI0PR08MB11170.eurprd08.prod.outlook.com
                                                                    x-ms-exchange-organization-antispam-protocolfilterhub-scancontextProtocolFilterHub:SmtpOnEndOfData
                                                                    x-ms-exchange-organization-accepteddomainTrue
                                                                    x-ms-exchange-organization-oldtenantTrue
                                                                    x-ms-exchange-organization-recentvshistoricDifferent
                                                                    x-ms-exchange-organization-mailtier1
                                                                    x-ms-exchange-organization-tenantage2127
                                                                    x-ms-exchange-organization-istrialFalse
                                                                    x-ms-exchange-organization-paidseats517
                                                                    x-ms-exchange-organization-eduseats0
                                                                    x-ms-exchange-organization-messagesent243758
                                                                    x-ms-exchange-organization-repstatus1
                                                                    x-ms-office365-filtering-correlation-idd921f761-d1b5-4c1f-598d-08dcdec64c3c
                                                                    x-ms-exchange-organization-p2senderdisplaynamepiiH100055(XjgPyhFlkhrvQUxzOH291aPxRRxZ4NyjC2fbi5yw/M4=)
                                                                    x-ms-exchange-organization-p2senderpii<PII:H100055(1WMRpRg6hU7rqeRNe7JWENeFHNC+TgJIlb6dA7yu0w4=)>@combilift.com
                                                                    x-ms-exchange-organization-antispam-authresults{"DkimAuthStatus":"None","DkimSubStatus":"None","DmarcAuthStatus":"None","DmarcAction":"None"}
                                                                    x-ms-exchange-organization-pfahub-total-message-size14061
                                                                    x-ms-exchange-organization-hygienepolicyPremium
                                                                    x-ms-exchange-organization-replicationinfoReplicaId=52020120-b27e-56dc-81d0-5a4cc6dedc08;ReplicatingServerFqdn=PAWPR08MB11159.eurprd08.prod.outlook.com
                                                                    x-ms-exchange-organization-messagelatencySRV=AS2PR08MB9714.eurprd08.prod.outlook.com:TOTAL-SUB=0.300|EBA=0.055|MTSS-PEN=0.246(MTSSD-PEN=0.246(MTSSDC=0.146|MTSSDSDM=0.039(MTSSDSDM-Mailbox Submission Filter Agent=0.038 (SDMMP=0.038(SDMSE=0.021)))|SDSSO-PEN=0.049(SMSC-PEN=0.049)))
                                                                    x-ms-exchange-forest-languageen
                                                                    x-ms-exchange-forest-indexagent-0AQ0CZW4AARkAAAAPAAADH4sIAAAAAAAEAGMAAI3vAtIBAAAA
                                                                    x-ms-exchange-forest-indexagent1 36
                                                                    x-ms-exchange-forest-emailmessagehash00000000
                                                                    x-ms-exchange-organization-antispam-precontentfilter-policyloadtimePSOSUB:45;PSOSUBLOAD:43;PSOSUBRUN:0;PSOSUBCOUNT:0;SMORES:45;SMORESLOAD:43;SMORESRUN:0;SMORESCOUNT:0;SAORES:131;SAORESLOAD:42;SLORES:45;APORES:45;APORESLOAD:43;APORESRUN:0;APORESCOUNT:1;RSORES:43;SLORESLOAD:43
                                                                    x-ms-exchange-organization-messagefingerprint
                                                                    x-ms-exchange-organization-featuretable{1010:0,1011:"7706030B;652D9054;",1022:"213.133.69.138"}
                                                                    x-ms-exchange-organization-antispam-precontentfilter-scancontextCategorizerOnSubmitted;CategorizerOnResolved
                                                                    x-ms-exchange-organization-emailfingerprintsdetailsinfo-chunkcount1
                                                                    x-ms-exchange-organization-emailfingerprintsdetailsinfo-0[{"Type":"VA11","Val":"VA11_C13D9C344D15966C7412C9000B7E925351EAC1E948694183F81F96E36EE727FB","Func":"SHA256","FF":0,"PD":{}},{"Type":"VA10","Val":"VA10_C475343183CC8B5CB8A7B5D26B3520CABC7EF07C84598619E5C9F1E6A6054F23","Func":"SHA256","FF":0,"PD":{}},{"Type":"VA2","Val":"VA2_733EFCAF29A52FA8B88BF9A50701FFD7D57BB28C028D33D2A7489E39DF8BCF23","Func":"SHA256","FF":0,"PD":{}},{"Type":"VA1","Val":"VA1_01DC82FBB6C05AD866361D05BCE4D61F9C150FA889CCA7DEF5B691EEF2B77D14","Func":"SHA256","FF":0,"PD":{}},{"Type":"VA0","Val":"VA0_D7CEF547BB2A8E9BC8FC500483EC9FD6FDAF03E659B1ADDA2C3F42844B13FD55","Func":"SHA256","FF":0,"PD":{}}]
                                                                    x-ms-exchange-organization-recipient-limit-verifiedTrue
                                                                    x-ms-exchange-organization-totalrecipientcount1
                                                                    x-ms-exchange-organization-externalrecipientcount1
                                                                    x-ms-exchange-organization-issinglerepresentativeTrue
                                                                    x-ms-exchange-organization-asdirectionalitytype2
                                                                    x-ms-exchange-organization-hverecipientsforked1.0
                                                                    x-ms-exchange-organization-safeattachmentpolicy-enable0
                                                                    x-ms-exchange-organization-safelinkspolicy-enablesafelinksforemail0
                                                                    x-ms-exchange-organization-safelinkspolicy-enablesafelinksforinternalsenders0
                                                                    x-ms-exchange-organization-antispam-analystfeaturefilter-scancontextCategorizerOnResolved
                                                                    x-ms-exchange-organization-cross-session-cache01antedBulkV1B\;2\;25\;150;CLEPV_CFG=M3ECV3\;2\;22\;30;SAEPV_CFG=SAEPV\;1\;TBD;SUEPV_CFG=SUEPV\;1\;TBD;UESELV3_CFG=UESELV3\;3\;TBD
                                                                    x-ms-exchange-organization-rules-execution-history0cdc2a59-1eed-4cf4-b97d-c44bcf65796d%%%962e322e-7626-40be-af8b-7a341cbbc4fa%%%b41b95df-c4d9-4e3c-bfed-356889d812c3%%%76a13832-002c-49ed-b96b-8ccb06a480c8%%%b1400651-6be2-493d-9ab5-54ab93047190%%%7257567a-9f59-4984-bad8-1acb451b6d85%%%40cb5b7c-43e1-4cd9-afb1-c70453b12b28%%%b25adab9-cd10-419f-abe7-a18bca42fa7c%%%2d88bea1-a505-4606-8a2d-2fe5a315f0f5%%%5f9abb4a-87e6-4456-9667-b3121dbd3713%%%804dc71c-8800-49c1-95b6-3d0431cbef61%%%9335cea0-fe1e-433f-9f4e-10c77ce17614%%%a8173fa9-1fe5-4e77-a892-026885799a63%%%6c58eb1b-39ac-48ec-8271-9eaeb14c00e3
                                                                    x-ms-exchange-organization-antispam-tenantmessageruleinfoScl:-1;RuleId:7257567a-9f59-4984-bad8-1acb451b6d85
                                                                    x-ms-exchange-organization-rules-execution-log7257567a-9f59-4984-bad8-1acb451b6d85
                                                                    x-ms-exchange-organization-rulename-execution-logQnlwYXNzIFNwYW0gRmlsdGVyaW5nIC0gTWltZWNhc3Q=
                                                                    Content-Languageen-US
                                                                    Content-Typemultipart/report; boundary="_000_f01eAS2PR08MB97140FE0C41B9DE5F6CB4B609B6B2AS2PR08MB9714_"; report-type="disposition-notification"
                                                                    MIME-Version1.0

                                                                    Icon Hash:46070c0a8e0c67d6
                                                                    TimestampSource PortDest PortSource IPDest IP
                                                                    Sep 27, 2024 16:50:38.306046009 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:38.306143045 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:38.306282997 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:38.308450937 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:38.308480978 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:38.959791899 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:38.959896088 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:38.965307951 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:38.965339899 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:38.965837002 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.021040916 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.052345037 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.099410057 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.237046957 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.237109900 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.237128973 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.237147093 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.237179041 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.237185955 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.237205029 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.237230062 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.237236977 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.237251997 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.237281084 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.237301111 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.323429108 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.323478937 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.323518038 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.323554039 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.323594093 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.323617935 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.325685978 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.325726986 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.325800896 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.325815916 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.325845003 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.325910091 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.410149097 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.410206079 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.410264015 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.410290956 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.410339117 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.410361052 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.411505938 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.411547899 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.411596060 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.411609888 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.411655903 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.411680937 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.412528992 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.412570953 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.412627935 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.412641048 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.412672997 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.412693977 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.414305925 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.414349079 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.414400101 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.414413929 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.414450884 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.414484978 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.498481035 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.498559952 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.498665094 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.498688936 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.498733997 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.498830080 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.498920918 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.498982906 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.499002934 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.499017000 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.499070883 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.499099016 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.499705076 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.499752045 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.499798059 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.499809980 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.499841928 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.499891043 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.500428915 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.500471115 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.500510931 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.500524044 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.500560045 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.500580072 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.501287937 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.501329899 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.501372099 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.501384020 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.501415014 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.501454115 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.502182007 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.502226114 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.502270937 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.502284050 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.502314091 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.502336979 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.503320932 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.503360987 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.503429890 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.503443956 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.503472090 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.503761053 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.585848093 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.585865021 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.585933924 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.585961103 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.586028099 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.586177111 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.586205006 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.586242914 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.586251020 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.586289883 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.586308956 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.586699009 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.586724043 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.586765051 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.586771965 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.586818933 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.587255001 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.587276936 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.587315083 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.587321997 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.587347984 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.587376118 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.587676048 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.587697029 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.587904930 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.587937117 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.588028908 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.595071077 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.595101118 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.595158100 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.595169067 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.595232964 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.595438957 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.595463991 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.595518112 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.595526934 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.595571041 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.595602036 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.595858097 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.595877886 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.595930099 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.595937967 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.595993996 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.673815012 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.673861980 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.673927069 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.673952103 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.673999071 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.674035072 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.674180031 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.674211979 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.674261093 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.674273968 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.674319029 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.674360991 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.674844980 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.674875975 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.674927950 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.674941063 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.675036907 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.675136089 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.675163984 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.675204992 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.675216913 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.675247908 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.675268888 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.675614119 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.675654888 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.675704956 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.675718069 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.675765991 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.675806999 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.676215887 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.676251888 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.676299095 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.676311970 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.676356077 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.676395893 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.676887035 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.676912069 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.676976919 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.676990986 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.677016973 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.677052021 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.677115917 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.761415958 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.761477947 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.761535883 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.761554003 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.761604071 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.761624098 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.761810064 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.761854887 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.761921883 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.761934042 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.761967897 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.762001991 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.762336969 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.762379885 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.762423992 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.762437105 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.762485981 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.762523890 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.762938023 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.762985945 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.763022900 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.763036013 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.763078928 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.763106108 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.763411999 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.763468027 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.763495922 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.763509989 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.763546944 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.763572931 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.764110088 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.764153004 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.764200926 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.764214039 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.764245033 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.764271021 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.764775991 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.764816046 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.764859915 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.764872074 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.764908075 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.764918089 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.764947891 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.764961004 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.764997959 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.765043020 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.765043974 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.765063047 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.765091896 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.765110016 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.848942041 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.848993063 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.849047899 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.849071980 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.849127054 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.849147081 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.849288940 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.849330902 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.849364996 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.849378109 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.849414110 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.849432945 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.849836111 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.849877119 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.849915028 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.849926949 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.849976063 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.849994898 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.850599051 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.850640059 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.850676060 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.850688934 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.850761890 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.850779057 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.850779057 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.850799084 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.850831985 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.850833893 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.850862026 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.850874901 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.850915909 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.850954056 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.851489067 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.851527929 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.851561069 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.851573944 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.851603031 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.851623058 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.851912975 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.852000952 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.852024078 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.852101088 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.852722883 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.852761984 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.852802992 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.852817059 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.852854013 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.852874041 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.885812044 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.936743975 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.936791897 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.936866045 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.936882019 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.936949015 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.936983109 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.937199116 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.937238932 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.937279940 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.937293053 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.937334061 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.937355042 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.937748909 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.937788010 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.937835932 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.937849045 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.937885046 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.937916994 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.938128948 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.938169956 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.938205957 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.938219070 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.938257933 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.938297987 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.938711882 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.938752890 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.938793898 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.938807011 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.938846111 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.938884020 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.939241886 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.939282894 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.939327002 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.939340115 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.939368010 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.939421892 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.939884901 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.939939022 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.940001965 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.940016031 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.940063000 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.940057993 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.940097094 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.940148115 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.940162897 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.940216064 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.940243959 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.940256119 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:39.940291882 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:39.940346003 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.024003983 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.024053097 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.024106979 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.024136066 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.024183989 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.024204969 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.024411917 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.024451971 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.024501085 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.024514914 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.024547100 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.024564981 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.025032043 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.025070906 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.025108099 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.025120974 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.025155067 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.025176048 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.025502920 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.025543928 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.025578022 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.025589943 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.025624990 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.025660992 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.026210070 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.026249886 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.026289940 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.026303053 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.026349068 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.026370049 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.026458979 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.026499033 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.026534081 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.026566982 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.026592970 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.026628971 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.026973963 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.027028084 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.027067900 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.027081013 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.027108908 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.027208090 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.027209044 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.027695894 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.027738094 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.027786016 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.027798891 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.027848959 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.027868986 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.111531019 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.111579895 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.111660957 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.111692905 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.111731052 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.111751080 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.112020969 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.112062931 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.112113953 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.112128019 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.112162113 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.112200022 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.112545013 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.112586021 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.112637997 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.112651110 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.112679958 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.112715960 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.113023043 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.113063097 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.113110065 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.113122940 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.113154888 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.113173962 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.113464117 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.113508940 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.113543034 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.113554955 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.113599062 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.113620043 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.114007950 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.114063025 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.114095926 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.114108086 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.114142895 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.114167929 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.114470959 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.114557981 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.114562988 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.114588022 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.114638090 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.114672899 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.115170956 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.115214109 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.115259886 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.115272045 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.115309000 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.115336895 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.207828045 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.207871914 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.207926989 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.207946062 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.208026886 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.208049059 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.208090067 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.208122015 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.208134890 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.208164930 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.208194017 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.208592892 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.208631039 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.208684921 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.208698034 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.208730936 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.208769083 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.209512949 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.209553003 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.209603071 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.209616899 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.209650040 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.209657907 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.209693909 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.209706068 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.209739923 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.209743023 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.209779024 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.209790945 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.209822893 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.209861994 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.210422039 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.210460901 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.210517883 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.210530996 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.210556030 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.210570097 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.210596085 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.210607052 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.210630894 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.210638046 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.210688114 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.210731030 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.211381912 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.211441040 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.211492062 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.211507082 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.211570024 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.295135975 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.295201063 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.295243025 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.295269012 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.295324087 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.295362949 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.295376062 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.295420885 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.295475006 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.295461893 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.295496941 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.295511007 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.295553923 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.295602083 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.295725107 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.295783997 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.295820951 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.295834064 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.295865059 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.296061039 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.296309948 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.296351910 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.296396971 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.296411037 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.296458960 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.296480894 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.297079086 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.297137022 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.297195911 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.297209024 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.297231913 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.297245979 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.297267914 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.297283888 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.297308922 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.297324896 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.297377110 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.297996998 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.298037052 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.298090935 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.298110008 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.298134089 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.298213959 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.298798084 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.298841000 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.298880100 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.298892975 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.298927069 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.298978090 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.382801056 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.382864952 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.382930040 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.382987022 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.383025885 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.383166075 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.383218050 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.383281946 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.383297920 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.383332014 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.383368969 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.383914948 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.383955956 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.384028912 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.384043932 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.384089947 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.384128094 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.384329081 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.384371996 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.384428024 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.384439945 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.384485960 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.384510040 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.384728909 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.384771109 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.384815931 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.384829044 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.384865999 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.384886026 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.385391951 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.385431051 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.385510921 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.385525942 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.385549068 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.385584116 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.385596991 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.385626078 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.385633945 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.385663033 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.385674953 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.385706902 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.385745049 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.386351109 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.386392117 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.386436939 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.386450052 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.386497021 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.386518955 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.475783110 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.475862026 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.475897074 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.475954056 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.475987911 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.476013899 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.476041079 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.476069927 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.476110935 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.476141930 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.476154089 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.476176023 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.476219893 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.476263046 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.476908922 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.476953983 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.477029085 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.477044106 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.477068901 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.477078915 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.477125883 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.477138042 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.477160931 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.477168083 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.477216959 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.477682114 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.477721930 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.477768898 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.477782011 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.477819920 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.477850914 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.478657961 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.478697062 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.478744984 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.478764057 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.478797913 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.478805065 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.478846073 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.478857040 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.478882074 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.478904009 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.478944063 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.479454994 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.479496002 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.479540110 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.479552984 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.479609966 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.479635954 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.563165903 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.563199997 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.563275099 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.563352108 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.563422918 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.563422918 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.563616991 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.563637018 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.563688993 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.563703060 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.563760042 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.563760042 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.564376116 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.564397097 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.564451933 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.564466000 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.564481974 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.564517021 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.564517975 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.564551115 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.564564943 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.564605951 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.564625978 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.565166950 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.565188885 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.565244913 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.565258980 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.565291882 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.565340996 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.566051960 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.566075087 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.566131115 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.566133022 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.566149950 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.566174030 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.566179991 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.566230059 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.566258907 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.566288948 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.566464901 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.566951990 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.566976070 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.567039013 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.567050934 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.567091942 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.567110062 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.652956963 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.653038979 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.653065920 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.653121948 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.653151989 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.653179884 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.653204918 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.653255939 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.653285980 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.653300047 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.653328896 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.653350115 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.653867960 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.653924942 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.653980970 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.653994083 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.654020071 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.654061079 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.654076099 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.654119968 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.654154062 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.654166937 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.654192924 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.654215097 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.654592037 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.654644966 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.654684067 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.654696941 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.654726982 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.654747009 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.655158043 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.655196905 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.655244112 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.655256987 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.655284882 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.655324936 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.655793905 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.655843019 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.655877113 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.655889988 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.655922890 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.655944109 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.656583071 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.656632900 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.656661034 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.656673908 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.656702042 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.656719923 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.740523100 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.740551949 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.740612984 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.740639925 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.740672112 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.740797043 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.740806103 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.740822077 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.740845919 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.740875006 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.740907907 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.740926981 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.741077900 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.741287947 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.741307020 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.741416931 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.741416931 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.741435051 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.741507053 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.741918087 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.741946936 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.742013931 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.742027998 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.742091894 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.742186069 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.742202997 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.742269039 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.742283106 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.742343903 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.742938042 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.742957115 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.743001938 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.743016005 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.743043900 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.743062019 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.743464947 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.743486881 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.743535042 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.743549109 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.743576050 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.743593931 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.744236946 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.744256973 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.744302034 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.744313955 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.744338989 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.744442940 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.828262091 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.828293085 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.828366041 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.828440905 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.828475952 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.828500986 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.828551054 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.828577995 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.828619003 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.828634977 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.828685045 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.828723907 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.829207897 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.829229116 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.829288006 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.829302073 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.829336882 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.829678059 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.829828024 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.829848051 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.829916000 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.829931021 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.829994917 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.830046892 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.830068111 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.830106974 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.830120087 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.830152035 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.830192089 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.830741882 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.830760956 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.830822945 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.830837011 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.830863953 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.830914974 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.831530094 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.831549883 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.831599951 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.831599951 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.831615925 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.831630945 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.831670046 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.831682920 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.831713915 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.831765890 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.831989050 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.831989050 CEST49715443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:40.832024097 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:40.832046032 CEST4434971513.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:47.730688095 CEST49718443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:47.730726957 CEST4434971813.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:47.730804920 CEST49718443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:47.731010914 CEST49718443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:47.731025934 CEST4434971813.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:48.428236961 CEST4434971813.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:48.428889990 CEST49718443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:48.428921938 CEST4434971813.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:48.429824114 CEST49718443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:48.429831028 CEST4434971813.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:48.575977087 CEST4434971813.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:48.576026917 CEST4434971813.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:48.576081038 CEST49718443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:48.576107025 CEST4434971813.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:48.576164961 CEST4434971813.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:48.576216936 CEST49718443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:48.576308966 CEST49718443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:48.576325893 CEST4434971813.107.246.60192.168.2.16
                                                                    Sep 27, 2024 16:50:48.576339006 CEST49718443192.168.2.1613.107.246.60
                                                                    Sep 27, 2024 16:50:48.576345921 CEST4434971813.107.246.60192.168.2.16
                                                                    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                                    Sep 27, 2024 16:50:38.294217110 CEST1.1.1.1192.168.2.160x621fNo error (0)shed.dual-low.s-part-0032.t-0009.t-msedge.nets-part-0032.t-0009.t-msedge.netCNAME (Canonical name)IN (0x0001)false
                                                                    Sep 27, 2024 16:50:38.294217110 CEST1.1.1.1192.168.2.160x621fNo error (0)s-part-0032.t-0009.t-msedge.net13.107.246.60A (IP address)IN (0x0001)false
                                                                    • otelrules.azureedge.net
                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                    0192.168.2.164971513.107.246.604433284C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    TimestampBytes transferredDirectionData
                                                                    2024-09-27 14:50:39 UTC223OUTGET /rules/outlook.exe-Production-v19.bundle HTTP/1.1
                                                                    Connection: Keep-Alive
                                                                    Accept-Encoding: gzip
                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; Microsoft Outlook 16.0.16827; Pro)
                                                                    Host: otelrules.azureedge.net
                                                                    2024-09-27 14:50:39 UTC542INHTTP/1.1 200 OK
                                                                    Date: Fri, 27 Sep 2024 14:50:39 GMT
                                                                    Content-Type: text/plain
                                                                    Content-Length: 2187344
                                                                    Connection: close
                                                                    Vary: Accept-Encoding
                                                                    Vary: Accept-Encoding
                                                                    Vary: Accept-Encoding
                                                                    Vary: Accept-Encoding
                                                                    Cache-Control: public
                                                                    Last-Modified: Fri, 27 Sep 2024 01:34:01 GMT
                                                                    ETag: "0x8DCDE9477309F18"
                                                                    x-ms-request-id: 92439145-201e-0000-3aec-10a537000000
                                                                    x-ms-version: 2018-03-28
                                                                    x-azure-ref: 20240927T145039Z-15767c5fc55d6fcl6x6bw8cpdc000000024g000000005s5k
                                                                    x-fd-int-roxy-purgeid: 0
                                                                    X-Cache: TCP_MISS
                                                                    Accept-Ranges: bytes
                                                                    2024-09-27 14:50:39 UTC15842INData Raw: 31 30 30 30 34 32 76 32 2b 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 30 30 30 34 32 22 20 56 3d 22 32 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 55 58 2e 44 65 73 6b 74 6f 70 2e 4f 66 66 69 63 65 54 68 65 6d 65 2e 41 70 70 2e 49 6e 69 74 22 20 41 54 54 3d 22 63 34 33 38 38 63 39 37 37 32 39 37 34 31 33 62 62 30 35 34 62 61 64 31 61 63 66 30 61 64 65 31 2d 63 63 35 38 65 35 33 65 2d 66 35 61 34 2d 34 66 33 37 2d 62 30 64 32 2d 39 61 38 30 37 39 65 33 34 34 32 30 2d 36 38 37 39 22 20 44 43 61 3d 22 50 53 55 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 55 54 53 20 54 3d 22 31 22 20 49 64 3d 22 63 6d 39 79 35
                                                                    Data Ascii: 100042v2+<?xml version="1.0" encoding="utf-8"?><R Id="100042" V="2" DC="SM" EN="Office.UX.Desktop.OfficeTheme.App.Init" ATT="c4388c977297413bb054bad1acf0ade1-cc58e53e-f5a4-4f37-b0d2-9a8079e34420-6879" DCa="PSU" xmlns=""> <S> <UTS T="1" Id="cm9y5
                                                                    2024-09-27 14:50:39 UTC16384INData Raw: 3d 22 31 22 20 46 3d 22 54 65 61 63 68 69 6e 67 43 61 6c 6c 6f 75 74 49 64 22 20 2f 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 31 22 20 4f 3d 22 66 61 6c 73 65 22 20 4e 3d 22 41 50 49 48 52 65 73 75 6c 74 22 3e 0d 0a 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 41 50 49 48 52 65 73 75 6c 74 22 20 2f 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 54 3e 0d 0a 20 20 20 20 3c 53 20 54 3d 22 31 22 20 2f 3e 0d 0a 20 20 3c 2f 54 3e 0d 0a 3c 2f 52 3e 0d 0a 3c 24 21 23 3e 31 30 30 31 32 38 76 31 2b 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 30 30 31 32 38 22 20 56 3d 22 31 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63
                                                                    Data Ascii: ="1" F="TeachingCalloutId" /> </C> <C T="U32" I="1" O="false" N="APIHResult"> <S T="1" F="APIHResult" /> </C> <T> <S T="1" /> </T></R><$!#>100128v1+<?xml version="1.0" encoding="utf-8"?><R Id="100128" V="1" DC="SM" EN="Offic
                                                                    2024-09-27 14:50:39 UTC16384INData Raw: 34 34 32 34 35 62 61 66 38 31 62 66 37 62 63 38 30 33 33 66 36 2d 32 32 36 38 65 33 37 34 2d 37 37 36 36 2d 34 39 37 36 2d 62 65 34 34 2d 62 36 61 64 35 62 64 64 63 35 62 36 2d 37 38 31 33 22 20 44 43 61 3d 22 50 53 55 22 20 78 6d 6c 6e 73 3d 22 22 3e 0d 0a 20 20 3c 53 3e 0d 0a 20 20 20 20 3c 45 74 77 20 54 3d 22 31 22 20 45 3d 22 34 31 31 31 22 20 47 3d 22 7b 36 39 31 65 31 63 31 32 2d 32 36 39 33 2d 34 64 34 61 2d 38 35 32 63 2d 37 34 37 38 36 35 37 62 62 65 36 65 7d 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 49 20 54 3d 22 32 22 20 49 3d 22 44 61 69 6c 79 22 20 2f 3e 0d 0a 20 20 20 20 3c 41 20 54 3d 22 33 22 20 45 3d 22 54 65 6c 65 6d 65 74 72 79 53 68 75 74 64 6f 77 6e 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 52 20 54 3d 22 34 22 20 2f 3e 0d 0a 20 20 20 20 3c 46
                                                                    Data Ascii: 44245baf81bf7bc8033f6-2268e374-7766-4976-be44-b6ad5bddc5b6-7813" DCa="PSU" xmlns=""> <S> <Etw T="1" E="4111" G="{691e1c12-2693-4d4a-852c-7478657bbe6e}" /> <TI T="2" I="Daily" /> <A T="3" E="TelemetryShutdown" /> <TR T="4" /> <F
                                                                    2024-09-27 14:50:39 UTC16384INData Raw: 3d 22 31 30 30 30 22 20 54 3d 22 55 33 32 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 2f 4f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 52 3e 0d 0a 20 20 20 20 20 20 3c 2f 4f 3e 0d 0a 20 20 20 20 3c 2f 46 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 37 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 41 4e 44 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 4f 20 54 3d 22 47 45 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 31 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20
                                                                    Data Ascii: ="1000" T="U32" /> </R> </O> </R> </O> </F> <F T="7"> <O T="AND"> <L> <O T="GE"> <L> <S T="1" F="1" /> </L> <R>
                                                                    2024-09-27 14:50:39 UTC16384INData Raw: 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 56 20 56 3d 22 30 22 20 54 3d 22 55 33 32 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 52 3e 0d 0a 20 20 20 20 20 20 3c 2f 4f 3e 0d 0a 20 20 20 20 3c 2f 46 3e 0d 0a 20 20 20 20 3c 54 49 20 54 3d 22 36 22 20 49 3d 22 48 6f 75 72 6c 79 22 20 2f 3e 0d 0a 20 20 20 20 3c 41 20 54 3d 22 37 22 20 45 3d 22 54 65 6c 65 6d 65 74 72 79 53 68 75 74 64 6f 77 6e 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 52 20 54 3d 22 38 22 20 2f 3e 0d 0a 20 20 20 20 3c 52 20 54 3d 22 39 22 20 52 3d 22 31 30 32 30 37 22 20 2f 3e 0d 0a 20 20 3c 2f 53 3e 0d 0a 20 20 3c 43 20 54 3d 22 46 54 22 20 49 3d 22 30 22 20 4f 3d 22 66 61 6c 73 65 22 20 4e 3d 22 43 6f 6c 6c 65 63 74 69 6f 6e 54 69 6d 65 22
                                                                    Data Ascii: </L> <R> <V V="0" T="U32" /> </R> </O> </F> <TI T="6" I="Hourly" /> <A T="7" E="TelemetryShutdown" /> <TR T="8" /> <R T="9" R="10207" /> </S> <C T="FT" I="0" O="false" N="CollectionTime"
                                                                    2024-09-27 14:50:39 UTC16384INData Raw: 2d 37 34 37 38 36 35 37 62 62 65 36 65 7d 22 20 2f 3e 0d 0a 20 20 20 20 3c 54 49 20 54 3d 22 32 22 20 49 3d 22 44 61 69 6c 79 22 20 2f 3e 0d 0a 20 20 20 20 3c 41 20 54 3d 22 33 22 20 45 3d 22 54 65 6c 65 6d 65 74 72 79 53 68 75 74 64 6f 77 6e 22 20 2f 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 34 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 45 51 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 22 20 46 3d 22 56 69 65 77 4d 65 74 68 6f 64 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 56 20 56 3d 22 30 22 20 54 3d 22 49 33 32 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 52 3e 0d 0a 20 20 20 20 20 20 3c 2f 4f 3e 0d 0a
                                                                    Data Ascii: -7478657bbe6e}" /> <TI T="2" I="Daily" /> <A T="3" E="TelemetryShutdown" /> <F T="4"> <O T="EQ"> <L> <S T="1" F="ViewMethod" /> </L> <R> <V V="0" T="I32" /> </R> </O>
                                                                    2024-09-27 14:50:39 UTC16384INData Raw: 20 20 20 3c 4f 20 54 3d 22 4e 45 22 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 34 22 20 46 3d 22 64 77 48 52 65 73 75 6c 74 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 3c 56 20 56 3d 22 30 22 20 54 3d 22 55 33 32 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 3c 2f 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 2f 4f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 52 3e 0d 0a 20 20 20 20 20 20 3c 2f 4f 3e 0d 0a 20 20 20 20 3c 2f 46 3e 0d 0a 20 20 20 20 3c 46 20 54 3d 22 32 38 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 41 4e 44 22 3e 0d 0a 20 20 20 20 20 20 20
                                                                    Data Ascii: <O T="NE"> <L> <S T="4" F="dwHResult" /> </L> <R> <V V="0" T="U32" /> </R> </O> </R> </O> </F> <F T="28"> <O T="AND">
                                                                    2024-09-27 14:50:39 UTC16384INData Raw: 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 31 30 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 43 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 33 22 20 4f 3d 22 66 61 6c 73 65 22 20 4e 3d 22 51 52 42 5f 41 64 64 4d 65 73 73 61 67 65 5f 43 6f 75 6e 74 22 3e 0d 0a 20 20 20 20 3c 43 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 35 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 43 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 34 22 20 4f 3d 22 66 61 6c 73 65 22 20 4e 3d 22 51 52 42 5f 50 6f 70 4f 75 74 5f 43 6f 75 6e 74 22 3e 0d 0a 20 20 20 20 3c 43 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 36 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 43 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d
                                                                    Data Ascii: <S T="10" /> </C> </C> <C T="U32" I="3" O="false" N="QRB_AddMessage_Count"> <C> <S T="5" /> </C> </C> <C T="U32" I="4" O="false" N="QRB_PopOut_Count"> <C> <S T="6" /> </C> </C> <C T="U32" I=
                                                                    2024-09-27 14:50:39 UTC16384INData Raw: 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 4c 3e 0d 0a 20 20 20 20 20 20 20 20 3c 52 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 32 22 20 46 3d 22 54 69 6d 65 53 74 61 6d 70 31 30 30 6e 73 22 20 2f 3e 0d 0a 20 20 20 20 20 20 20 20 3c 2f 52 3e 0d 0a 20 20 20 20 20 20 3c 2f 4f 3e 0d 0a 20 20 20 20 3c 2f 55 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 36 34 22 20 49 3d 22 31 31 22 20 4f 3d 22 74 72 75 65 22 20 4e 3d 22 46 41 53 54 54 6f 74 61 6c 54 69 6d 65 22 3e 0d 0a 20 20 20 20 3c 55 20 54 3d 22 31 30 30 6e 73 54 6f 4d 73 22 3e 0d 0a 20 20 20 20 20 20 3c 4f 20 54 3d 22 53 55 42 22 3e 0d 0a 20 20 20 20 20 20 20 20 3c 4c 3e 0d 0a 20 20 20 20 20 20 20 20 20 20 3c 53 20 54 3d 22 31 32 22 20 46 3d 22 54 69 6d 65 53 74 61 6d 70 31 30 30
                                                                    Data Ascii: > </L> <R> <S T="2" F="TimeStamp100ns" /> </R> </O> </U> </C> <C T="U64" I="11" O="true" N="FASTTotalTime"> <U T="100nsToMs"> <O T="SUB"> <L> <S T="12" F="TimeStamp100
                                                                    2024-09-27 14:50:39 UTC16384INData Raw: 20 20 20 3c 53 20 54 3d 22 33 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 43 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 34 22 20 4f 3d 22 66 61 6c 73 65 22 20 4e 3d 22 49 64 46 72 6f 6d 4c 74 69 64 43 6f 75 6e 74 22 3e 0d 0a 20 20 20 20 3c 43 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 34 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 43 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 43 20 54 3d 22 55 33 32 22 20 49 3d 22 35 22 20 4f 3d 22 66 61 6c 73 65 22 20 4e 3d 22 47 65 74 49 44 73 46 72 6f 6d 4e 61 6d 65 73 43 6f 75 6e 74 22 3e 0d 0a 20 20 20 20 3c 43 3e 0d 0a 20 20 20 20 20 20 3c 53 20 54 3d 22 35 22 20 2f 3e 0d 0a 20 20 20 20 3c 2f 43 3e 0d 0a 20 20 3c 2f 43 3e 0d 0a 20 20 3c 54 3e 0d 0a 20 20 20 20 3c 53 20 54 3d 22 32 22 20 2f 3e
                                                                    Data Ascii: <S T="3" /> </C> </C> <C T="U32" I="4" O="false" N="IdFromLtidCount"> <C> <S T="4" /> </C> </C> <C T="U32" I="5" O="false" N="GetIDsFromNamesCount"> <C> <S T="5" /> </C> </C> <T> <S T="2" />


                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                    1192.168.2.164971813.107.246.604433284C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    TimestampBytes transferredDirectionData
                                                                    2024-09-27 14:50:48 UTC209OUTGET /rules/rule120603v8s19.xml HTTP/1.1
                                                                    Connection: Keep-Alive
                                                                    Accept-Encoding: gzip
                                                                    User-Agent: Microsoft Office/16.0 (Windows NT 10.0; Microsoft Outlook 16.0.16827; Pro)
                                                                    Host: otelrules.azureedge.net
                                                                    2024-09-27 14:50:48 UTC564INHTTP/1.1 200 OK
                                                                    Date: Fri, 27 Sep 2024 14:50:48 GMT
                                                                    Content-Type: text/xml
                                                                    Content-Length: 2128
                                                                    Connection: close
                                                                    Vary: Accept-Encoding
                                                                    Vary: Accept-Encoding
                                                                    Vary: Accept-Encoding
                                                                    Vary: Accept-Encoding
                                                                    Cache-Control: public, max-age=604800, immutable
                                                                    Last-Modified: Tue, 09 Apr 2024 00:26:04 GMT
                                                                    ETag: "0x8DC582BA41F3C62"
                                                                    x-ms-request-id: c553d102-301e-0051-25ec-1038bb000000
                                                                    x-ms-version: 2018-03-28
                                                                    x-azure-ref: 20240927T145048Z-15767c5fc55ncqdn59ub6rndq000000001w000000000bxpr
                                                                    x-fd-int-roxy-purgeid: 0
                                                                    X-Cache: TCP_MISS
                                                                    Accept-Ranges: bytes
                                                                    2024-09-27 14:50:48 UTC2128INData Raw: ef bb bf 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 0d 0a 3c 52 20 49 64 3d 22 31 32 30 36 30 33 22 20 56 3d 22 38 22 20 44 43 3d 22 53 4d 22 20 45 4e 3d 22 4f 66 66 69 63 65 2e 53 79 73 74 65 6d 2e 53 79 73 74 65 6d 48 65 61 6c 74 68 4d 65 74 61 64 61 74 61 41 70 70 6c 69 63 61 74 69 6f 6e 41 64 64 69 74 69 6f 6e 61 6c 22 20 41 54 54 3d 22 63 64 38 33 36 36 32 36 36 31 31 63 34 63 61 61 61 38 66 63 35 62 32 65 37 32 38 65 65 38 31 64 2d 33 62 36 64 36 63 34 35 2d 36 33 37 37 2d 34 62 66 35 2d 39 37 39 32 2d 64 62 66 38 65 31 38 38 31 30 38 38 2d 37 35 32 31 22 20 53 50 3d 22 43 72 69 74 69 63 61 6c 42 75 73 69 6e 65 73 73 49 6d 70 61 63 74 22 20 45 3d 22 66 61 6c 73 65 22 20 44 4c 3d
                                                                    Data Ascii: <?xml version="1.0" encoding="utf-8"?><R Id="120603" V="8" DC="SM" EN="Office.System.SystemHealthMetadataApplicationAdditional" ATT="cd836626611c4caaa8fc5b2e728ee81d-3b6d6c45-6377-4bf5-9792-dbf8e1881088-7521" SP="CriticalBusinessImpact" E="false" DL=


                                                                    Click to jump to process

                                                                    Click to jump to process

                                                                    Click to dive into process behavior distribution

                                                                    Click to jump to process

                                                                    Target ID:0
                                                                    Start time:10:48:44
                                                                    Start date:27/09/2024
                                                                    Path:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    Wow64 process (32bit):true
                                                                    Commandline:"C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" /eml "C:\Users\user\Desktop\Read_ Statement.eml"
                                                                    Imagebase:0x860000
                                                                    File size:34'446'744 bytes
                                                                    MD5 hash:91A5292942864110ED734005B7E005C0
                                                                    Has elevated privileges:true
                                                                    Has administrator privileges:true
                                                                    Programmed in:C, C++ or other language
                                                                    Reputation:high
                                                                    Has exited:true

                                                                    Target ID:3
                                                                    Start time:10:48:45
                                                                    Start date:27/09/2024
                                                                    Path:C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe
                                                                    Wow64 process (32bit):false
                                                                    Commandline:"C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe" "9FED77D2-8569-46B4-A9E6-C030199CA153" "753032D4-7DA5-4A69-AB42-A122198C7FE5" "6908" "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" "WordCombinedFloatieLreOnline.onnx"
                                                                    Imagebase:0x7ff7c0b20000
                                                                    File size:710'048 bytes
                                                                    MD5 hash:EC652BEDD90E089D9406AFED89A8A8BD
                                                                    Has elevated privileges:true
                                                                    Has administrator privileges:true
                                                                    Programmed in:C, C++ or other language
                                                                    Reputation:high
                                                                    Has exited:true

                                                                    Target ID:13
                                                                    Start time:10:50:37
                                                                    Start date:27/09/2024
                                                                    Path:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                                                                    Wow64 process (32bit):true
                                                                    Commandline:"C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" /eml "C:\Users\user\Desktop\RE_ Overdue Invoice ___IMPORTANT___.eml"
                                                                    Imagebase:0x860000
                                                                    File size:34'446'744 bytes
                                                                    MD5 hash:91A5292942864110ED734005B7E005C0
                                                                    Has elevated privileges:false
                                                                    Has administrator privileges:false
                                                                    Programmed in:C, C++ or other language
                                                                    Reputation:high
                                                                    Has exited:false

                                                                    Target ID:17
                                                                    Start time:10:50:38
                                                                    Start date:27/09/2024
                                                                    Path:C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe
                                                                    Wow64 process (32bit):false
                                                                    Commandline:"C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe" "6BBBA20A-876A-4E8A-8AD8-D424E4FB21D8" "DB3CCE73-E394-4AB6-9B07-DCD2D719738B" "3284" "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" "WordCombinedFloatieLreOnline.onnx"
                                                                    Imagebase:0x7ff7c0b20000
                                                                    File size:710'048 bytes
                                                                    MD5 hash:EC652BEDD90E089D9406AFED89A8A8BD
                                                                    Has elevated privileges:false
                                                                    Has administrator privileges:false
                                                                    Programmed in:C, C++ or other language
                                                                    Reputation:high
                                                                    Has exited:false

                                                                    No disassembly