Windows Analysis Report
Axactor Microsoft - Introduksjonsm#U00f8te.msg

Overview

General Information

Sample name: Axactor Microsoft - Introduksjonsm#U00f8te.msg
renamed because original name is a hash value
Original sample name: Axactor Microsoft - Introduksjonsmte.msg
Analysis ID: 1524035
MD5: 753e07dc560986e69a18fd3ec1bcce68
SHA1: ebe1bb8775e0f44126f1806aacfefcd0bac08734
SHA256: d7fbed810d6e04385a98349f8e3a76904bd13799bd1e4035f5ceb8216cc54460
Infos:

Detection

EvilProxy
Score: 48
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Yara detected Evil Proxy Phishing kit
Detected hidden input values containing email addresses (often used in phishing pages)
Form action URLs do not match main URL
Found iframes
HTML body contains low number of good links
HTML page contains hidden javascript code
HTML title does not match URL
Queries the volume information (name, serial number etc) of a device
Sigma detected: Office Autorun Keys Modification
Stores files to the Windows start menu directory

Classification

Phishing

barindex
Source: Yara match File source: 103.146..script.csv, type: HTML
Source: Yara match File source: 192.237..script.csv, type: HTML
Source: https://adfs.intility.com/adfs/ls/?client-request-id=e3da3a6f-a6e3-4440-87bf-e3f1ffa1ec3f&wa=wsignin1.0&wtrealm=urn%3afederation%3aMicrosoftOnline&wctx=LoginOptions%3D3%26estsredirect%3d2%26estsrequest%3drQQIARAA42Iz1DPQM7TQYjbUM7RSMU01Tk41SzbQNUoyTNM1MbIw1bVIMUnSNTdNTTW3AEJjE7MiIS6BfKtbjx8vc3Bp3__44_-Fb-xXMWpnlJQUFFvp65ekJuYW6-VmJhflF-enlegl5-fq56amlmTmpfsXlGTm5xXr72BkvMDI-IKRcRWTSnKioYFxkqmxblKSpZmuiWGKia6FhVmibpqZIdA6SxNDIwOLW0z8_o6lJRlGICK_KLMqdRazSgrQdSaGxka6xqZJ5romZqamukmpZqa6KQamycbG5mapQAM2MbMBrc_Nz7vBzPiIWaAktbjEIbEiMbkkvwjkrgssjK9YxDgYBRgkhBQYNNgNmK04OLiAPAYFhh8sjItYgT51uD33g6z5cd-Zuv6Oa1XKGE6x6gdqu2V4RQSWu-QER2RZlGhHWHo6h-QbFrumhHgXGhcaVngU5RZkeFimO1rYWlgZTmBjO8XG5FX8gY2xg51hFycpIXWAl-EH34oLB-Y8vLnjnccrfp0g76TUgDxjn4wI13D9jFK_XG9X88C0dI9iE7-yfMvUHJ98k9xkl2TT8kIL2w0CDA8EGAA1&cbcxt=&username=test%40axactor.com&mkt=&lc= HTTP Parser: test@axactor.com
Source: https://support.microsoft.com/en-gb/office/join-a-meeting-in-microsoft-teams-1613bb53-f3fa-431e-85a9-d6a91e3468c9?omkt=en-gb&ui=en-us&rs=en-gb&ad=gb HTTP Parser: Form action: https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=ee272b19-4411-433f-8f28-5c13cb6fd407&redirect_uri=https%3A%2F%2Fsupport.microsoft.com%2Fsignin-oidc&response_type=code%20id_token&scope=openid%20profile%20offline_access&response_mode=form_post&nonce=638634621177179473.YzM5ODQ5YjEtYWRhMS00Mzk4LWJlNDUtNDdiMzA2YjdhOTJlMWIxODczMTEtZDczMy00NzM3LTg1NjQtZmIxM2Q3OTljNDQ4&prompt=none&nopa=2&state=CfDJ8LWN6nmb9HBGpcIJvpEgkL3d2c8fAPYKSaSZ5BjwI0EWkfebehLiewgDjY8wJBQjDIgXDMHifx19x-47oi8dERoztpuDnjfPEGTRdaXRBLViCUM4JFEv9ANyXbTm4_2JAZFFAWwapJsiVt4rhkW96prRE15BevFsrhCwIlJnUMMFFoZ8ltg8npj31b0Qd0oORh03Cn1cCjBZnTm4WVdD4kdGgdZFDOz89Wj3xL35lOHAEvwosvYS41li6jwb5I3nssG3aDZ-CKWnjUNACEAF0s1oqlYsNOyHX63UqD9jzkOZGc6_rYaI7NSmK0JSsdIyAyjoRnzipqAu5wdgl0IHtJ2Csiky8nvQ59kK_1zgv5-w&x-client-SKU=ID_NET6_0&x-client-ver=8.0.2.0&sso_reload=true microsoft microsoftonline
Source: https://support.microsoft.com/en-gb/office/join-a-meeting-in-microsoft-teams-1613bb53-f3fa-431e-85a9-d6a91e3468c9?omkt=en-gb&ui=en-us&rs=en-gb&ad=gb HTTP Parser: Iframe src: https://login.live.com/Me.htm?v=3
Source: https://support.microsoft.com/en-gb/office/join-a-meeting-in-microsoft-teams-1613bb53-f3fa-431e-85a9-d6a91e3468c9?omkt=en-gb&ui=en-us&rs=en-gb&ad=gb HTTP Parser: Number of links: 0
Source: https://login.microsoftonline.com/common/oauth2/authorize?response_type=id_token&client_id=5e3ce6c0-2b1f-4285-8d4b-75ee78787346&redirect_uri=https%3A%2F%2Fteams.microsoft.com%2FmeetingOptions%2F&state=d4284132-35b7-4655-be65-d05c3376e617&client-request-id=e3da3a6f-a6e3-4440-87bf-e3f1ffa1ec3f&x-client-SKU=Js&x-client-Ver=1.0.18&nonce=ca103b53-bb96-41d4-886a-f61787941208 HTTP Parser: Number of links: 0
Source: https://adfs.intility.com/adfs/ls/?client-request-id=e3da3a6f-a6e3-4440-87bf-e3f1ffa1ec3f&wa=wsignin1.0&wtrealm=urn%3afederation%3aMicrosoftOnline&wctx=LoginOptions%3D3%26estsredirect%3d2%26estsrequest%3drQQIARAA42Iz1DPQM7TQYjbUM7RSMU01Tk41SzbQNUoyTNM1MbIw1bVIMUnSNTdNTTW3AEJjE7MiIS6BfKtbjx8vc3Bp3__44_-Fb-xXMWpnlJQUFFvp65ekJuYW6-VmJhflF-enlegl5-fq56amlmTmpfsXlGTm5xXr72BkvMDI-IKRcRWTSnKioYFxkqmxblKSpZmuiWGKia6FhVmibpqZIdA6SxNDIwOLW0z8_o6lJRlGICK_KLMqdRazSgrQdSaGxka6xqZJ5romZqamukmpZqa6KQamycbG5mapQAM2MbMBrc_Nz7vBzPiIWaAktbjEIbEiMbkkvwjkrgssjK9YxDgYBRgkhBQYNNgNmK04OLiAPAYFhh8sjItYgT51uD33g6z5cd-Zuv6Oa1XKGE6x6gdqu2V4RQSWu-QER2RZlGhHWHo6h-QbFrumhHgXGhcaVngU5RZkeFimO1rYWlgZTmBjO8XG5FX8gY2xg51hFycpIXWAl-EH34oLB-Y8vLnjnccrfp0g76TUgDxjn4wI13D9jFK_XG9X88C0dI9iE7-yfMvUHJ98k9xkl2TT8kIL2w0CDA8EGAA1&cbcxt=&username=test%40axactor.com&mkt=&lc= HTTP Parser: Number of links: 0
Source: https://support.microsoft.com/en-gb/office/join-a-meeting-in-microsoft-teams-1613bb53-f3fa-431e-85a9-d6a91e3468c9?omkt=en-gb&ui=en-us&rs=en-gb&ad=gb HTTP Parser: Base64 decoded: c39849b1-ada1-4398-be45-47b306b7a92e1b187311-d733-4737-8564-fb13d799c448
Source: https://support.microsoft.com/en-gb/office/join-a-meeting-in-microsoft-teams-1613bb53-f3fa-431e-85a9-d6a91e3468c9?omkt=en-gb&ui=en-us&rs=en-gb&ad=gb HTTP Parser: Title: Redirecting does not match URL
Source: https://login.microsoftonline.com/common/oauth2/authorize?response_type=id_token&client_id=5e3ce6c0-2b1f-4285-8d4b-75ee78787346&redirect_uri=https%3A%2F%2Fteams.microsoft.com%2FmeetingOptions%2F&state=d4284132-35b7-4655-be65-d05c3376e617&client-request-id=e3da3a6f-a6e3-4440-87bf-e3f1ffa1ec3f&x-client-SKU=Js&x-client-Ver=1.0.18&nonce=ca103b53-bb96-41d4-886a-f61787941208 HTTP Parser: Title: Sign in to your account does not match URL
Source: https://adfs.intility.com/adfs/ls/?client-request-id=e3da3a6f-a6e3-4440-87bf-e3f1ffa1ec3f&wa=wsignin1.0&wtrealm=urn%3afederation%3aMicrosoftOnline&wctx=LoginOptions%3D3%26estsredirect%3d2%26estsrequest%3drQQIARAA42Iz1DPQM7TQYjbUM7RSMU01Tk41SzbQNUoyTNM1MbIw1bVIMUnSNTdNTTW3AEJjE7MiIS6BfKtbjx8vc3Bp3__44_-Fb-xXMWpnlJQUFFvp65ekJuYW6-VmJhflF-enlegl5-fq56amlmTmpfsXlGTm5xXr72BkvMDI-IKRcRWTSnKioYFxkqmxblKSpZmuiWGKia6FhVmibpqZIdA6SxNDIwOLW0z8_o6lJRlGICK_KLMqdRazSgrQdSaGxka6xqZJ5romZqamukmpZqa6KQamycbG5mapQAM2MbMBrc_Nz7vBzPiIWaAktbjEIbEiMbkkvwjkrgssjK9YxDgYBRgkhBQYNNgNmK04OLiAPAYFhh8sjItYgT51uD33g6z5cd-Zuv6Oa1XKGE6x6gdqu2V4RQSWu-QER2RZlGhHWHo6h-QbFrumhHgXGhcaVngU5RZkeFimO1rYWlgZTmBjO8XG5FX8gY2xg51hFycpIXWAl-EH34oLB-Y8vLnjnccrfp0g76TUgDxjn4wI13D9jFK_XG9X88C0dI9iE7-yfMvUHJ98k9xkl2TT8kIL2w0CDA8EGAA1&cbcxt=&username=test%40axactor.com&mkt=&lc= HTTP Parser: Title: Sign In does not match URL
Source: https://login.microsoftonline.com/common/oauth2/authorize?response_type=id_token&client_id=5e3ce6c0-2b1f-4285-8d4b-75ee78787346&redirect_uri=https%3A%2F%2Fteams.microsoft.com%2FmeetingOptions%2F&state=d4284132-35b7-4655-be65-d05c3376e617&client-request-id=e3da3a6f-a6e3-4440-87bf-e3f1ffa1ec3f&x-client-SKU=Js&x-client-Ver=1.0.18&nonce=ca103b53-bb96-41d4-886a-f61787941208 HTTP Parser: <input type="password" .../> found
Source: https://adfs.intility.com/adfs/ls/?client-request-id=e3da3a6f-a6e3-4440-87bf-e3f1ffa1ec3f&wa=wsignin1.0&wtrealm=urn%3afederation%3aMicrosoftOnline&wctx=LoginOptions%3D3%26estsredirect%3d2%26estsrequest%3drQQIARAA42Iz1DPQM7TQYjbUM7RSMU01Tk41SzbQNUoyTNM1MbIw1bVIMUnSNTdNTTW3AEJjE7MiIS6BfKtbjx8vc3Bp3__44_-Fb-xXMWpnlJQUFFvp65ekJuYW6-VmJhflF-enlegl5-fq56amlmTmpfsXlGTm5xXr72BkvMDI-IKRcRWTSnKioYFxkqmxblKSpZmuiWGKia6FhVmibpqZIdA6SxNDIwOLW0z8_o6lJRlGICK_KLMqdRazSgrQdSaGxka6xqZJ5romZqamukmpZqa6KQamycbG5mapQAM2MbMBrc_Nz7vBzPiIWaAktbjEIbEiMbkkvwjkrgssjK9YxDgYBRgkhBQYNNgNmK04OLiAPAYFhh8sjItYgT51uD33g6z5cd-Zuv6Oa1XKGE6x6gdqu2V4RQSWu-QER2RZlGhHWHo6h-QbFrumhHgXGhcaVngU5RZkeFimO1rYWlgZTmBjO8XG5FX8gY2xg51hFycpIXWAl-EH34oLB-Y8vLnjnccrfp0g76TUgDxjn4wI13D9jFK_XG9X88C0dI9iE7-yfMvUHJ98k9xkl2TT8kIL2w0CDA8EGAA1&cbcxt=&username=test%40axactor.com&mkt=&lc= HTTP Parser: <input type="password" .../> found
Source: https://support.microsoft.com/en-gb/office/join-a-meeting-in-microsoft-teams-1613bb53-f3fa-431e-85a9-d6a91e3468c9?omkt=en-gb&ui=en-us&rs=en-gb&ad=gb HTTP Parser: No favicon
Source: https://support.microsoft.com/en-gb/office/join-a-meeting-in-microsoft-teams-1613bb53-f3fa-431e-85a9-d6a91e3468c9?omkt=en-gb&ui=en-us&rs=en-gb&ad=gb HTTP Parser: No favicon
Source: https://support.microsoft.com/en-gb/office/join-a-meeting-in-microsoft-teams-1613bb53-f3fa-431e-85a9-d6a91e3468c9?omkt=en-gb&ui=en-us&rs=en-gb&ad=gb HTTP Parser: No favicon
Source: https://teams.microsoft.com/meetingOptions/?organizerId=3366eb58-cbb1-4993-b451-2cb027033b57&tenantId=72f988bf-86f1-41af-91ab-2d7cd011db47&threadId=19_meeting_OTEzNTZlOTYtZmZjOC00YWZhLWI4NGMtMmM1OGI0NDQxMGIx@thread.v2&messageId=0&language=en-GB HTTP Parser: No favicon
Source: https://teams.microsoft.com/meetingOptions/?organizerId=3366eb58-cbb1-4993-b451-2cb027033b57&tenantId=72f988bf-86f1-41af-91ab-2d7cd011db47&threadId=19_meeting_OTEzNTZlOTYtZmZjOC00YWZhLWI4NGMtMmM1OGI0NDQxMGIx@thread.v2&messageId=0&language=en-GB HTTP Parser: No favicon
Source: https://adfs.intility.com/adfs/ls/?client-request-id=e3da3a6f-a6e3-4440-87bf-e3f1ffa1ec3f&wa=wsignin1.0&wtrealm=urn%3afederation%3aMicrosoftOnline&wctx=LoginOptions%3D3%26estsredirect%3d2%26estsrequest%3drQQIARAA42Iz1DPQM7TQYjbUM7RSMU01Tk41SzbQNUoyTNM1MbIw1bVIMUnSNTdNTTW3AEJjE7MiIS6BfKtbjx8vc3Bp3__44_-Fb-xXMWpnlJQUFFvp65ekJuYW6-VmJhflF-enlegl5-fq56amlmTmpfsXlGTm5xXr72BkvMDI-IKRcRWTSnKioYFxkqmxblKSpZmuiWGKia6FhVmibpqZIdA6SxNDIwOLW0z8_o6lJRlGICK_KLMqdRazSgrQdSaGxka6xqZJ5romZqamukmpZqa6KQamycbG5mapQAM2MbMBrc_Nz7vBzPiIWaAktbjEIbEiMbkkvwjkrgssjK9YxDgYBRgkhBQYNNgNmK04OLiAPAYFhh8sjItYgT51uD33g6z5cd-Zuv6Oa1XKGE6x6gdqu2V4RQSWu-QER2RZlGhHWHo6h-QbFrumhHgXGhcaVngU5RZkeFimO1rYWlgZTmBjO8XG5FX8gY2xg51hFycpIXWAl-EH34oLB-Y8vLnjnccrfp0g76TUgDxjn4wI13D9jFK_XG9X88C0dI9iE7-yfMvUHJ98k9xkl2TT8kIL2w0CDA8EGAA1&cbcxt=&username=test%40axactor.com&mkt=&lc= HTTP Parser: No favicon
Source: https://adfs.intility.com/adfs/ls/?client-request-id=e3da3a6f-a6e3-4440-87bf-e3f1ffa1ec3f&wa=wsignin1.0&wtrealm=urn%3afederation%3aMicrosoftOnline&wctx=LoginOptions%3D3%26estsredirect%3d2%26estsrequest%3drQQIARAA42Iz1DPQM7TQYjbUM7RSMU01Tk41SzbQNUoyTNM1MbIw1bVIMUnSNTdNTTW3AEJjE7MiIS6BfKtbjx8vc3Bp3__44_-Fb-xXMWpnlJQUFFvp65ekJuYW6-VmJhflF-enlegl5-fq56amlmTmpfsXlGTm5xXr72BkvMDI-IKRcRWTSnKioYFxkqmxblKSpZmuiWGKia6FhVmibpqZIdA6SxNDIwOLW0z8_o6lJRlGICK_KLMqdRazSgrQdSaGxka6xqZJ5romZqamukmpZqa6KQamycbG5mapQAM2MbMBrc_Nz7vBzPiIWaAktbjEIbEiMbkkvwjkrgssjK9YxDgYBRgkhBQYNNgNmK04OLiAPAYFhh8sjItYgT51uD33g6z5cd-Zuv6Oa1XKGE6x6gdqu2V4RQSWu-QER2RZlGhHWHo6h-QbFrumhHgXGhcaVngU5RZkeFimO1rYWlgZTmBjO8XG5FX8gY2xg51hFycpIXWAl-EH34oLB-Y8vLnjnccrfp0g76TUgDxjn4wI13D9jFK_XG9X88C0dI9iE7-yfMvUHJ98k9xkl2TT8kIL2w0CDA8EGAA1&cbcxt=&username=test%40axactor.com&mkt=&lc= HTTP Parser: No favicon
Source: https://support.microsoft.com/en-gb/office/join-a-meeting-in-microsoft-teams-1613bb53-f3fa-431e-85a9-d6a91e3468c9?omkt=en-gb&ui=en-us&rs=en-gb&ad=gb HTTP Parser: No <meta name="author".. found
Source: https://support.microsoft.com/en-gb/office/join-a-meeting-in-microsoft-teams-1613bb53-f3fa-431e-85a9-d6a91e3468c9?omkt=en-gb&ui=en-us&rs=en-gb&ad=gb HTTP Parser: No <meta name="author".. found
Source: https://login.microsoftonline.com/common/oauth2/authorize?response_type=id_token&client_id=5e3ce6c0-2b1f-4285-8d4b-75ee78787346&redirect_uri=https%3A%2F%2Fteams.microsoft.com%2FmeetingOptions%2F&state=d4284132-35b7-4655-be65-d05c3376e617&client-request-id=e3da3a6f-a6e3-4440-87bf-e3f1ffa1ec3f&x-client-SKU=Js&x-client-Ver=1.0.18&nonce=ca103b53-bb96-41d4-886a-f61787941208 HTTP Parser: No <meta name="author".. found
Source: https://login.microsoftonline.com/common/oauth2/authorize?response_type=id_token&client_id=5e3ce6c0-2b1f-4285-8d4b-75ee78787346&redirect_uri=https%3A%2F%2Fteams.microsoft.com%2FmeetingOptions%2F&state=d4284132-35b7-4655-be65-d05c3376e617&client-request-id=e3da3a6f-a6e3-4440-87bf-e3f1ffa1ec3f&x-client-SKU=Js&x-client-Ver=1.0.18&nonce=ca103b53-bb96-41d4-886a-f61787941208 HTTP Parser: No <meta name="author".. found
Source: https://login.microsoftonline.com/common/oauth2/authorize?response_type=id_token&client_id=5e3ce6c0-2b1f-4285-8d4b-75ee78787346&redirect_uri=https%3A%2F%2Fteams.microsoft.com%2FmeetingOptions%2F&state=d4284132-35b7-4655-be65-d05c3376e617&client-request-id=e3da3a6f-a6e3-4440-87bf-e3f1ffa1ec3f&x-client-SKU=Js&x-client-Ver=1.0.18&nonce=ca103b53-bb96-41d4-886a-f61787941208 HTTP Parser: No <meta name="author".. found
Source: https://adfs.intility.com/adfs/ls/?client-request-id=e3da3a6f-a6e3-4440-87bf-e3f1ffa1ec3f&wa=wsignin1.0&wtrealm=urn%3afederation%3aMicrosoftOnline&wctx=LoginOptions%3D3%26estsredirect%3d2%26estsrequest%3drQQIARAA42Iz1DPQM7TQYjbUM7RSMU01Tk41SzbQNUoyTNM1MbIw1bVIMUnSNTdNTTW3AEJjE7MiIS6BfKtbjx8vc3Bp3__44_-Fb-xXMWpnlJQUFFvp65ekJuYW6-VmJhflF-enlegl5-fq56amlmTmpfsXlGTm5xXr72BkvMDI-IKRcRWTSnKioYFxkqmxblKSpZmuiWGKia6FhVmibpqZIdA6SxNDIwOLW0z8_o6lJRlGICK_KLMqdRazSgrQdSaGxka6xqZJ5romZqamukmpZqa6KQamycbG5mapQAM2MbMBrc_Nz7vBzPiIWaAktbjEIbEiMbkkvwjkrgssjK9YxDgYBRgkhBQYNNgNmK04OLiAPAYFhh8sjItYgT51uD33g6z5cd-Zuv6Oa1XKGE6x6gdqu2V4RQSWu-QER2RZlGhHWHo6h-QbFrumhHgXGhcaVngU5RZkeFimO1rYWlgZTmBjO8XG5FX8gY2xg51hFycpIXWAl-EH34oLB-Y8vLnjnccrfp0g76TUgDxjn4wI13D9jFK_XG9X88C0dI9iE7-yfMvUHJ98k9xkl2TT8kIL2w0CDA8EGAA1&cbcxt=&username=test%40axactor.com&mkt=&lc= HTTP Parser: No <meta name="author".. found
Source: https://adfs.intility.com/adfs/ls/?client-request-id=e3da3a6f-a6e3-4440-87bf-e3f1ffa1ec3f&wa=wsignin1.0&wtrealm=urn%3afederation%3aMicrosoftOnline&wctx=LoginOptions%3D3%26estsredirect%3d2%26estsrequest%3drQQIARAA42Iz1DPQM7TQYjbUM7RSMU01Tk41SzbQNUoyTNM1MbIw1bVIMUnSNTdNTTW3AEJjE7MiIS6BfKtbjx8vc3Bp3__44_-Fb-xXMWpnlJQUFFvp65ekJuYW6-VmJhflF-enlegl5-fq56amlmTmpfsXlGTm5xXr72BkvMDI-IKRcRWTSnKioYFxkqmxblKSpZmuiWGKia6FhVmibpqZIdA6SxNDIwOLW0z8_o6lJRlGICK_KLMqdRazSgrQdSaGxka6xqZJ5romZqamukmpZqa6KQamycbG5mapQAM2MbMBrc_Nz7vBzPiIWaAktbjEIbEiMbkkvwjkrgssjK9YxDgYBRgkhBQYNNgNmK04OLiAPAYFhh8sjItYgT51uD33g6z5cd-Zuv6Oa1XKGE6x6gdqu2V4RQSWu-QER2RZlGhHWHo6h-QbFrumhHgXGhcaVngU5RZkeFimO1rYWlgZTmBjO8XG5FX8gY2xg51hFycpIXWAl-EH34oLB-Y8vLnjnccrfp0g76TUgDxjn4wI13D9jFK_XG9X88C0dI9iE7-yfMvUHJ98k9xkl2TT8kIL2w0CDA8EGAA1&cbcxt=&username=test%40axactor.com&mkt=&lc= HTTP Parser: No <meta name="author".. found
Source: https://support.microsoft.com/en-gb/office/join-a-meeting-in-microsoft-teams-1613bb53-f3fa-431e-85a9-d6a91e3468c9?omkt=en-gb&ui=en-us&rs=en-gb&ad=gb HTTP Parser: No <meta name="copyright".. found
Source: https://support.microsoft.com/en-gb/office/join-a-meeting-in-microsoft-teams-1613bb53-f3fa-431e-85a9-d6a91e3468c9?omkt=en-gb&ui=en-us&rs=en-gb&ad=gb HTTP Parser: No <meta name="copyright".. found
Source: https://login.microsoftonline.com/common/oauth2/authorize?response_type=id_token&client_id=5e3ce6c0-2b1f-4285-8d4b-75ee78787346&redirect_uri=https%3A%2F%2Fteams.microsoft.com%2FmeetingOptions%2F&state=d4284132-35b7-4655-be65-d05c3376e617&client-request-id=e3da3a6f-a6e3-4440-87bf-e3f1ffa1ec3f&x-client-SKU=Js&x-client-Ver=1.0.18&nonce=ca103b53-bb96-41d4-886a-f61787941208 HTTP Parser: No <meta name="copyright".. found
Source: https://login.microsoftonline.com/common/oauth2/authorize?response_type=id_token&client_id=5e3ce6c0-2b1f-4285-8d4b-75ee78787346&redirect_uri=https%3A%2F%2Fteams.microsoft.com%2FmeetingOptions%2F&state=d4284132-35b7-4655-be65-d05c3376e617&client-request-id=e3da3a6f-a6e3-4440-87bf-e3f1ffa1ec3f&x-client-SKU=Js&x-client-Ver=1.0.18&nonce=ca103b53-bb96-41d4-886a-f61787941208 HTTP Parser: No <meta name="copyright".. found
Source: https://login.microsoftonline.com/common/oauth2/authorize?response_type=id_token&client_id=5e3ce6c0-2b1f-4285-8d4b-75ee78787346&redirect_uri=https%3A%2F%2Fteams.microsoft.com%2FmeetingOptions%2F&state=d4284132-35b7-4655-be65-d05c3376e617&client-request-id=e3da3a6f-a6e3-4440-87bf-e3f1ffa1ec3f&x-client-SKU=Js&x-client-Ver=1.0.18&nonce=ca103b53-bb96-41d4-886a-f61787941208 HTTP Parser: No <meta name="copyright".. found
Source: https://adfs.intility.com/adfs/ls/?client-request-id=e3da3a6f-a6e3-4440-87bf-e3f1ffa1ec3f&wa=wsignin1.0&wtrealm=urn%3afederation%3aMicrosoftOnline&wctx=LoginOptions%3D3%26estsredirect%3d2%26estsrequest%3drQQIARAA42Iz1DPQM7TQYjbUM7RSMU01Tk41SzbQNUoyTNM1MbIw1bVIMUnSNTdNTTW3AEJjE7MiIS6BfKtbjx8vc3Bp3__44_-Fb-xXMWpnlJQUFFvp65ekJuYW6-VmJhflF-enlegl5-fq56amlmTmpfsXlGTm5xXr72BkvMDI-IKRcRWTSnKioYFxkqmxblKSpZmuiWGKia6FhVmibpqZIdA6SxNDIwOLW0z8_o6lJRlGICK_KLMqdRazSgrQdSaGxka6xqZJ5romZqamukmpZqa6KQamycbG5mapQAM2MbMBrc_Nz7vBzPiIWaAktbjEIbEiMbkkvwjkrgssjK9YxDgYBRgkhBQYNNgNmK04OLiAPAYFhh8sjItYgT51uD33g6z5cd-Zuv6Oa1XKGE6x6gdqu2V4RQSWu-QER2RZlGhHWHo6h-QbFrumhHgXGhcaVngU5RZkeFimO1rYWlgZTmBjO8XG5FX8gY2xg51hFycpIXWAl-EH34oLB-Y8vLnjnccrfp0g76TUgDxjn4wI13D9jFK_XG9X88C0dI9iE7-yfMvUHJ98k9xkl2TT8kIL2w0CDA8EGAA1&cbcxt=&username=test%40axactor.com&mkt=&lc= HTTP Parser: No <meta name="copyright".. found
Source: https://adfs.intility.com/adfs/ls/?client-request-id=e3da3a6f-a6e3-4440-87bf-e3f1ffa1ec3f&wa=wsignin1.0&wtrealm=urn%3afederation%3aMicrosoftOnline&wctx=LoginOptions%3D3%26estsredirect%3d2%26estsrequest%3drQQIARAA42Iz1DPQM7TQYjbUM7RSMU01Tk41SzbQNUoyTNM1MbIw1bVIMUnSNTdNTTW3AEJjE7MiIS6BfKtbjx8vc3Bp3__44_-Fb-xXMWpnlJQUFFvp65ekJuYW6-VmJhflF-enlegl5-fq56amlmTmpfsXlGTm5xXr72BkvMDI-IKRcRWTSnKioYFxkqmxblKSpZmuiWGKia6FhVmibpqZIdA6SxNDIwOLW0z8_o6lJRlGICK_KLMqdRazSgrQdSaGxka6xqZJ5romZqamukmpZqa6KQamycbG5mapQAM2MbMBrc_Nz7vBzPiIWaAktbjEIbEiMbkkvwjkrgssjK9YxDgYBRgkhBQYNNgNmK04OLiAPAYFhh8sjItYgT51uD33g6z5cd-Zuv6Oa1XKGE6x6gdqu2V4RQSWu-QER2RZlGhHWHo6h-QbFrumhHgXGhcaVngU5RZkeFimO1rYWlgZTmBjO8XG5FX8gY2xg51hFycpIXWAl-EH34oLB-Y8vLnjnccrfp0g76TUgDxjn4wI13D9jFK_XG9X88C0dI9iE7-yfMvUHJ98k9xkl2TT8kIL2w0CDA8EGAA1&cbcxt=&username=test%40axactor.com&mkt=&lc= HTTP Parser: No <meta name="copyright".. found
Source: chrome.exe Memory has grown: Private usage: 11MB later: 28MB
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.31.73
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.31.73
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.31.73
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.31.73
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.31.73
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.31.73
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.31.73
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.31.73
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknown TCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknown TCP traffic detected without corresponding DNS query: 20.190.160.20
Source: unknown TCP traffic detected without corresponding DNS query: 20.190.160.20
Source: unknown TCP traffic detected without corresponding DNS query: 20.190.160.20
Source: unknown TCP traffic detected without corresponding DNS query: 20.190.160.20
Source: unknown TCP traffic detected without corresponding DNS query: 20.190.160.20
Source: unknown TCP traffic detected without corresponding DNS query: 20.190.160.20
Source: unknown TCP traffic detected without corresponding DNS query: 20.190.160.20
Source: unknown TCP traffic detected without corresponding DNS query: 20.190.160.20
Source: unknown TCP traffic detected without corresponding DNS query: 20.190.160.20
Source: unknown TCP traffic detected without corresponding DNS query: 20.190.160.20
Source: unknown TCP traffic detected without corresponding DNS query: 20.190.160.20
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global traffic DNS traffic detected: DNS query: eur02.safelinks.protection.outlook.com
Source: global traffic DNS traffic detected: DNS query: aka.ms
Source: global traffic DNS traffic detected: DNS query: support.office.com
Source: global traffic DNS traffic detected: DNS query: www.google.com
Source: global traffic DNS traffic detected: DNS query: support.content.office.net
Source: global traffic DNS traffic detected: DNS query: c.s-microsoft.com
Source: global traffic DNS traffic detected: DNS query: js.monitor.azure.com
Source: global traffic DNS traffic detected: DNS query: aadcdn.msftauth.net
Source: global traffic DNS traffic detected: DNS query: mem.gfx.ms
Source: global traffic DNS traffic detected: DNS query: login.microsoftonline.com
Source: global traffic DNS traffic detected: DNS query: teams.nel.measure.office.net
Source: global traffic DNS traffic detected: DNS query: us-api.asm.skype.com
Source: global traffic DNS traffic detected: DNS query: adfs.intility.com
Source: unknown Network traffic detected: HTTP traffic on port 49795 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50395 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50182
Source: unknown Network traffic detected: HTTP traffic on port 50360 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49732
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50501
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49731
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49730
Source: unknown Network traffic detected: HTTP traffic on port 49732 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50503
Source: unknown Network traffic detected: HTTP traffic on port 50423 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50506
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50507
Source: unknown Network traffic detected: HTTP traffic on port 50377 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50500
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50191
Source: unknown Network traffic detected: HTTP traffic on port 50004 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50073
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49729
Source: unknown Network traffic detected: HTTP traffic on port 49790 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50470 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49731 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50517
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50519
Source: unknown Network traffic detected: HTTP traffic on port 50422 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50518
Source: unknown Network traffic detected: HTTP traffic on port 49748 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50079
Source: unknown Network traffic detected: HTTP traffic on port 50390 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50487 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50073 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49717
Source: unknown Network traffic detected: HTTP traffic on port 49715 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49716
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49715
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49711
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50524
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49710
Source: unknown Network traffic detected: HTTP traffic on port 49709 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50525
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50407
Source: unknown Network traffic detected: HTTP traffic on port 50555 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50409
Source: unknown Network traffic detected: HTTP traffic on port 50572 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50408
Source: unknown Network traffic detected: HTTP traffic on port 50507 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50520
Source: unknown Network traffic detected: HTTP traffic on port 49910 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50401
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50522
Source: unknown Network traffic detected: HTTP traffic on port 50079 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49796 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50411 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49709
Source: unknown Network traffic detected: HTTP traffic on port 49811 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49825
Source: unknown Network traffic detected: HTTP traffic on port 50382 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49824
Source: unknown Network traffic detected: HTTP traffic on port 50418 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49783
Source: unknown Network traffic detected: HTTP traffic on port 50556 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50373
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50375
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50374
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50377
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50379
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50378
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50499
Source: unknown Network traffic detected: HTTP traffic on port 50324 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50380
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50382
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49779
Source: unknown Network traffic detected: HTTP traffic on port 50574 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50391 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50386
Source: unknown Network traffic detected: HTTP traffic on port 50522 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50501 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50407 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50391
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50390
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50393
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50392
Source: unknown Network traffic detected: HTTP traffic on port 50342 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50568 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50468 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50506 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50166 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50573 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50395
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50035
Source: unknown Network traffic detected: HTTP traffic on port 50182 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50429 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49797 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49801 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50567 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49824 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49730 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50166
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50167
Source: unknown Network traffic detected: HTTP traffic on port 50375 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50539 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50401 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50126 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49748
Source: unknown Network traffic detected: HTTP traffic on port 49792 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49746
Source: unknown Network traffic detected: HTTP traffic on port 50443 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50386 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50392 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50573
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50572
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50454
Source: unknown Network traffic detected: HTTP traffic on port 50500 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50574
Source: unknown Network traffic detected: HTTP traffic on port 49746 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50517 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50408 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49717 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50328 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50468
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50349
Source: unknown Network traffic detected: HTTP traffic on port 49711 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50342
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50470
Source: unknown Network traffic detected: HTTP traffic on port 49798 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50380 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49819 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50350
Source: unknown Network traffic detected: HTTP traffic on port 49729 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50374 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49793 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50360
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49798
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49797
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49796
Source: unknown Network traffic detected: HTTP traffic on port 50530 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49795
Source: unknown Network traffic detected: HTTP traffic on port 50524 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50167 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49793
Source: unknown Network traffic detected: HTTP traffic on port 49814 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49792
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49790
Source: unknown Network traffic detected: HTTP traffic on port 50393 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50379 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50487
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50002
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50126
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50004
Source: unknown Network traffic detected: HTTP traffic on port 50541 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49825 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50518 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49710 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49779 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50418
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50539
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50410
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50531
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50530
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50411
Source: unknown Network traffic detected: HTTP traffic on port 50350 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50410 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50542 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50433 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49819
Source: unknown Network traffic detected: HTTP traffic on port 49810 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49814
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49811
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49810
Source: unknown Network traffic detected: HTTP traffic on port 50444 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50427
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50429
Source: unknown Network traffic detected: HTTP traffic on port 50035 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50427 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50542
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50541
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50423
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50422
Source: unknown Network traffic detected: HTTP traffic on port 50373 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49804
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49801
Source: unknown Network traffic detected: HTTP traffic on port 49783 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50556
Source: unknown Network traffic detected: HTTP traffic on port 50191 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50531 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50525 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50378 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50555
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50433
Source: unknown Network traffic detected: HTTP traffic on port 50454 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50519 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50349 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49910
Source: unknown Network traffic detected: HTTP traffic on port 50503 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50568
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50567
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50328
Source: unknown Network traffic detected: HTTP traffic on port 50520 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50324
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50444
Source: unknown Network traffic detected: HTTP traffic on port 49804 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50002 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50409 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50499 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49716 -> 443
Source: classification engine Classification label: mal48.phis.winMSG@41/362@46/391
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE File created: C:\Users\user\Documents\Outlook Files\~Outlook Data File - NoEmail.pst.tmp
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE File created: C:\Users\user\AppData\Local\Temp\Outlook Logging\OUTLOOK_16_0_16827_20130-20241002T0634500677-748.etl
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE File read: C:\Users\desktop.ini
Source: unknown Process created: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" /f "C:\Users\user\Desktop\Axactor Microsoft - Introduksjonsm#U00f8te.msg"
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe "C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe" "B3E5F1FE-73F6-4000-9720-263F8E60BA53" "C1112B52-984E-440F-B103-631AC57D1B36" "748" "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" "WordCombinedFloatieLreOnline.onnx"
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe "C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe" "B3E5F1FE-73F6-4000-9720-263F8E60BA53" "C1112B52-984E-440F-B103-631AC57D1B36" "748" "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" "WordCombinedFloatieLreOnline.onnx"
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Faka.ms%2FJoinTeamsMeeting%3Fomkt%3Den-GB&data=05%7C02%7Croger.opstad%40axactor.com%7C4a827b5916584ac981ec08dce21410f1%7Caa047274bbe64fbd98b6b244735e8553%7C0%7C0%7C638633823023809669%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&sdata=e3f5e2YsMf4auieHhuQLrf6StyMcHyg4rtLR2tjaFyA%3D&reserved=0
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2140 --field-trial-handle=1968,i,2377736179412861234,1555685963266848789,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Faka.ms%2FJoinTeamsMeeting%3Fomkt%3Den-GB&data=05%7C02%7Croger.opstad%40axactor.com%7C4a827b5916584ac981ec08dce21410f1%7Caa047274bbe64fbd98b6b244735e8553%7C0%7C0%7C638633823023809669%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&sdata=e3f5e2YsMf4auieHhuQLrf6StyMcHyg4rtLR2tjaFyA%3D&reserved=0
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2140 --field-trial-handle=1968,i,2377736179412861234,1555685963266848789,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://eur02.safelinks.protection.outlook.com/ap/t-59584e83/?url=https%3A%2F%2Fteams.microsoft.com%2Fl%2Fmeetup-join%2F19%253ameeting_OTEzNTZlOTYtZmZjOC00YWZhLWI4NGMtMmM1OGI0NDQxMGIx%2540thread.v2%2F0%3Fcontext%3D%257b%2522Tid%2522%253a%252272f988bf-86f1-41af-91ab-2d7cd011db47%2522%252c%2522Oid%2522%253a%25223366eb58-cbb1-4993-b451-2cb027033b57%2522%257d&data=05%7C02%7Croger.opstad%40axactor.com%7C4a827b5916584ac981ec08dce21410f1%7Caa047274bbe64fbd98b6b244735e8553%7C0%7C0%7C638633823023835110%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&sdata=kvD%2B1Q%2BUFI%2BV%2BXxU1PKXUc9Ado4RbBhpSwWd55N6J0E%3D&reserved=0
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2112 --field-trial-handle=1924,i,6217254323683358986,4135135347063110520,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://eur02.safelinks.protection.outlook.com/ap/t-59584e83/?url=https%3A%2F%2Fteams.microsoft.com%2Fl%2Fmeetup-join%2F19%253ameeting_OTEzNTZlOTYtZmZjOC00YWZhLWI4NGMtMmM1OGI0NDQxMGIx%2540thread.v2%2F0%3Fcontext%3D%257b%2522Tid%2522%253a%252272f988bf-86f1-41af-91ab-2d7cd011db47%2522%252c%2522Oid%2522%253a%25223366eb58-cbb1-4993-b451-2cb027033b57%2522%257d&data=05%7C02%7Croger.opstad%40axactor.com%7C4a827b5916584ac981ec08dce21410f1%7Caa047274bbe64fbd98b6b244735e8553%7C0%7C0%7C638633823023835110%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&sdata=kvD%2B1Q%2BUFI%2BV%2BXxU1PKXUc9Ado4RbBhpSwWd55N6J0E%3D&reserved=0
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2112 --field-trial-handle=1924,i,6217254323683358986,4135135347063110520,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fteams.microsoft.com%2FmeetingOptions%2F%3ForganizerId%3D3366eb58-cbb1-4993-b451-2cb027033b57%26tenantId%3D72f988bf-86f1-41af-91ab-2d7cd011db47%26threadId%3D19_meeting_OTEzNTZlOTYtZmZjOC00YWZhLWI4NGMtMmM1OGI0NDQxMGIx%40thread.v2%26messageId%3D0%26language%3Den-GB&data=05%7C02%7Croger.opstad%40axactor.com%7C4a827b5916584ac981ec08dce21410f1%7Caa047274bbe64fbd98b6b244735e8553%7C0%7C0%7C638633823023849968%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&sdata=PuHggXlZqVMexd2Z8IcKAv55uAmv97qQOZ%2F2%2BTf6KKI%3D&reserved=0
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2028 --field-trial-handle=1960,i,4011647941606630197,8454412328851240415,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fteams.microsoft.com%2FmeetingOptions%2F%3ForganizerId%3D3366eb58-cbb1-4993-b451-2cb027033b57%26tenantId%3D72f988bf-86f1-41af-91ab-2d7cd011db47%26threadId%3D19_meeting_OTEzNTZlOTYtZmZjOC00YWZhLWI4NGMtMmM1OGI0NDQxMGIx%40thread.v2%26messageId%3D0%26language%3Den-GB&data=05%7C02%7Croger.opstad%40axactor.com%7C4a827b5916584ac981ec08dce21410f1%7Caa047274bbe64fbd98b6b244735e8553%7C0%7C0%7C638633823023849968%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&sdata=PuHggXlZqVMexd2Z8IcKAv55uAmv97qQOZ%2F2%2BTf6KKI%3D&reserved=0
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2028 --field-trial-handle=1960,i,4011647941606630197,8454412328851240415,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Section loaded: apphelp.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Section loaded: c2r64.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Section loaded: userenv.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Section loaded: msasn1.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Section loaded: kernel.appcore.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Section loaded: cryptsp.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Section loaded: rsaenh.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Section loaded: cryptbase.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Section loaded: gpapi.dll
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{2E1271D5-2FF2-4EA4-9647-C67A82A2D85C}\InProcServer32
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Window found: window name: SysTabControl32
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Common
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE File Volume queried: C:\Windows\SysWOW64 FullSizeInformation
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE Process information queried: ProcessInformation
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Queries volume information: C:\Program Files (x86)\Microsoft Office\root\Office16\AI\WordCombinedFloatieLreOnline.onnx VolumeInformation
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs